Privacy Policy

DRAFT — pending review by counsel before public launch. Do not rely on this as final legal text.

Controller

Flow Systems, Belgium, operates SupplierSync and is the data controller for personal data processed through it. Contact: privacy@suppliersync.com.

What we store

  • Account — your email address and an encrypted password hash (handled by Supabase Auth).
  • Connections — OAuth access tokens for the Meta ad account and Shopify store you connect. Tokens are encrypted at rest (AES-256-GCM); the encryption key is held only in our server environment. We store the associated account identifiers and granted scopes.
  • Product configuration — the supplier URLs, SKUs and ad set IDs you add, and the status/history of automated checks.
  • Billing — a Stripe customer ID and subscription status. Card details are held by Stripe, not by us.

What we do with it

We use your connections and configuration solely to run the service you asked for: check supplier pages, and — on an out-of-stock — pause the linked Meta ad set and zero the linked Shopify inventory. Supplier page content is sent to our scraping provider (Firecrawl) and to Anthropic (Claude) to classify stock status. We do not sell personal data or use it for advertising.

Sub-processors

  • Supabase — database, authentication (EU region)
  • Vercel — application hosting
  • Firecrawl — supplier page scraping
  • Anthropic — automated stock-status classification
  • Stripe — payments and billing
  • Meta, Shopify — the platforms you connect and instruct us to act on

Retention

Connection tokens are kept until you disconnect or delete your account, then removed. Product history is kept for the life of the account. Deleting your account removes your tokens and configuration; billing records are retained as required by law.

Your rights

Under the GDPR you may request access, correction, deletion, or export of your personal data, and may object to or restrict processing. Contact privacy@suppliersync.com. You may also lodge a complaint with the Belgian Data Protection Authority.

Security

Tokens are encrypted at rest. Access to production data is restricted. Row-level security isolates each customer’s data in the database. Report a vulnerability to security@suppliersync.com.

Last updated 30 August 2026