Privacy Policy

Last updated 22 September 2026

SupplierProof is a public-source due diligence tool. We process the URL you submit, account data if you sign in, billing metadata for paid plans, and evidence our servers collect from the open internet (WHOIS/RDAP, DNS, website HTML, maps, search snippets, and corporate search APIs).

What we store

  • The domain and structured verification report (public by default so dossiers can be shared). Draft vs full access may control how much detail is shown in the UI.
  • If you sign in: your email, profile, draft-credit balance, referral code, lookup history, and subscription status.
  • Payment records: Stripe customer / subscription IDs, checkout session IDs, and a credit ledger of grants and debits. Card numbers are handled by Stripe — we do not store full card data.
  • Referral cookie (sp_ref) when you arrive via an invite link, used only to attribute signup bonuses.

Processors

We use Supabase for auth and database storage, Stripe for payments, and optional third-party APIs (search, scrape, registries, trade data) solely to build the report you requested.

What we do not sell

We do not sell personal data. Reports describe companies and websites, not private individuals, except where a name is published on the site you asked us to check.

Retention

Account and billing records are kept while your account is active and as needed for accounting and dispute handling. You may request deletion of your account data by emailing us; public dossiers may remain if already shared via a public URL.

Contact

Questions: [email protected]. See also Pricing and Terms.