Trust
Security
What we actually do to keep your account and your suppliers' data safe, not a marketing checklist.
Nothing sends without you
Every follow-up is a draft until you review and approve it, and every send is a separate click. There is no bulk-automated sending you haven't explicitly triggered.
Your data is isolated by design
Every account's orders, drafts, and connections are enforced at the database level (row-level security), not just in application code. One account's data is never reachable through another's session.
Encrypted in transit
All traffic to SupplierPing runs over HTTPS. Passwords are hashed, never stored in plain text.
Payments never touch our servers
Card details are handled entirely by Stripe, a PCI-DSS-compliant payment processor used by millions of businesses. We only ever see your subscription status, never your card number.
Gmail access is scoped and revocable
Connecting Gmail requests only the permission to send mail, add a copy of a supplier's reply to your inbox, and confirm your address, never to read your existing mail. You can disconnect it at any time from Account, which immediately revokes SupplierPing's access.
Delete means delete
Deleting your account immediately and permanently removes your orders, uploads, drafts, and any connected Gmail token. It is not a soft delete sitting around indefinitely.
Found a security issue?
Tell us directly at supplierping@gmail.com before disclosing it publicly, and we'll investigate and respond as quickly as we can.