1. Scope and who is responsible
This Privacy Policy explains how SupplyDesk ("SupplyDesk", "we", "us", or "our") handles personal information in the SupplyDesk application, supplier dashboards, buyer portals, support channels, and related services (the "Service"). SupplyDesk is currently the operator's trading name and is the organization responsible for the account, billing, support, and other information described below that we control.
Access to the Service is generally provided to suppliers and their invited buyers through accounts we or the supplier set up. This Policy describes the Service itself; our public marketing website may publish a separate notice for website visitors and lead forms.
A supplier using SupplyDesk generally decides why and how its buyer, contact, catalog, pricing, quote, and order data is used. For that Customer Data, the supplier is the organization responsible for the information and SupplyDesk processes it on the supplier's instructions to provide the Service. Buyers should contact their supplier first about the supplier's business records or decisions.
SupplyDesk operates from Ontario, Canada, and handles personal information in accordance with applicable Canadian private-sector privacy law, including the Personal Information Protection and Electronic Documents Act (PIPEDA) where it applies, and other laws that apply to you.
2. Personal information we collect
Depending on how you use the Service, we collect:
- Account and identity data: name, business email, company name, role, account identifiers, and authentication-related information needed to sign you in securely.
- Supplier and buyer business data: contact details, addresses, catalog and product information, prices, inventory figures shown in the Service, buyer access rules, RFQs, quotes, orders, purchase-order references, notes, invoices, and files you or the supplier upload.
- Billing data: customer and subscription identifiers, plan and payment status, invoice metadata, and limited card descriptors (such as brand and last four digits) returned by our payment processor. Full payment-card details are collected by the payment processor—not by SupplyDesk.
- Integration data: when a supplier connects an accounting system, identifiers and business records the supplier chooses to sync (for example customers, items, and invoices), plus connection status needed to keep the integration working.
- Device and security data: IP address, approximate location derived from it, browser and device type, timestamps, sign-in and security events, and operational logs used to run and protect the Service.
- Legal records: the version and time of Terms acceptance and Privacy Policy acknowledgement, and limited technical context needed to evidence that acceptance.
- Communications: support messages and transactional email delivery details.
- Optional analytics: limited product-usage information (such as page views) only if you allow analytics. The Service does not use Google Analytics. Advertising cookies are not used in the Service.
3. How information is collected
- directly from you when you register, accept an invitation, configure an account, order, or contact us;
- from the supplier that creates or manages a buyer or team-member account;
- automatically from your browser, device, and interactions with the Service;
- from connected services such as QuickBooks Online and Stripe at your or the supplier's direction; and
- from infrastructure providers that help us host, authenticate, deliver email, and monitor reliability.
4. Why we use personal information
- create and secure accounts, authenticate users, and enforce permissions;
- provide supplier dashboards, buyer portals, catalogs, pricing, ordering, RFQs, quotes, and integrations;
- process subscriptions, taxes, invoices, and billing administration;
- send invitations, password actions, receipts, order updates, and other transactional communications;
- detect abuse, investigate incidents, maintain availability, and protect users and the Service;
- provide support, improve functionality, and understand product usage where analytics is allowed;
- keep evidence of contracts and legal-policy acceptance; and
- comply with legal obligations and establish, exercise, or defend legal claims.
5. Legal grounds where GDPR or UK GDPR applies
We rely on the ground appropriate to each activity:
- Contract: account administration and processing needed to provide the Service requested by a customer or authorized user.
- Legitimate interests: B2B service operations, security, fraud prevention, support, service improvement, and protecting legal rights, balanced against individual rights.
- Legal obligation: tax, accounting, regulatory, and lawful-request requirements.
- Consent: optional analytics and any other processing clearly presented as optional. Consent can be withdrawn without affecting earlier lawful processing.
Accepting the Terms is a contract action. Acknowledging this Privacy Policy confirms that the notice was presented; it is not bundled consent for optional analytics.
6. Service providers and disclosures
We use carefully selected companies to help operate the Service. They receive only what is reasonably needed for their role. Categories include:
- Hosting and infrastructure for running the application and related platform services;
- Database, authentication, and file storage providers (currently including Supabase);
- Payment and billing processors (currently including Stripe);
- Transactional email delivery (currently including Resend);
- Accounting integrations the customer chooses to connect (currently including Intuit QuickBooks Online);
- Optional product analytics only after you allow analytics (currently including PostHog — not Google Analytics);
- Reliability and error monitoring tools used to keep the Service available and diagnose failures; and
- Abuse-prevention services when enabled to protect accounts and forms.
We may also disclose information to professional advisers under confidentiality, in a corporate transaction, to comply with valid legal process, or where reasonably necessary to protect rights, safety, and security. We do not sell personal information. We do not share personal information for cross-context behavioural advertising.
7. QuickBooks Online
When an authorized supplier connects QuickBooks, SupplyDesk may access the QuickBooks company data the supplier selects for sync—typically catalog, customer, inventory, and invoice-related information—and may create invoices only when that supplier initiates or enables that workflow. Connection credentials are stored securely and used only to provide the integration. Disconnecting stops future access, subject to records already lawfully retained.
8. International processing
SupplyDesk and its providers may process information in Canada, the United States, and other countries where they operate. Those countries may have different privacy laws, and lawful authorities may access information under local law. Where required, we use contractual and organizational measures intended to provide an appropriate level of protection. Contact us for information about safeguards relevant to your data.
9. Retention
We retain information only for as long as reasonably needed for the purposes described here. Retention depends on the account and subscription lifecycle, the type of data, customer instructions, backup cycles, security needs, contractual commitments, and tax, accounting, dispute, and legal requirements. Legal-acceptance records may be retained for the applicable limitation period as evidence of the agreement. Data no longer needed is deleted, de-identified, or isolated from routine use.
Suppliers control many buyer and business records. A buyer deletion request may therefore need to be handled by the supplier, while we assist as appropriate.
10. Security and incident response
We use administrative, technical, and organizational measures appropriate to a B2B online service, including encrypted connections, access controls, and secure handling of integration credentials. We do not publish detailed security architecture or operational controls in this Policy. No method of storage or transmission is completely secure.
We investigate suspected personal-data incidents and notify affected customers, individuals, or authorities when required by applicable law, including assessment of real risk of significant harm where Canadian law requires it. Please report suspected security or privacy issues to support@supplydesk.ca.
11. Your privacy choices and rights
Subject to applicable law and exceptions, you may ask to access, correct, delete, or obtain a copy of personal information; restrict or object to processing; withdraw consent; or complain to a privacy or data-protection authority. You may change optional analytics choices through the Cookie Policy. We may verify identity and authority before acting and may retain information where lawfully required.
Canadian residents may challenge our compliance with PIPEDA or other applicable private-sector privacy law and may contact the Office of the Privacy Commissioner of Canada. EEA and UK residents may complain to their local supervisory authority. Residents of US states with applicable privacy laws may exercise the rights available in their state and appeal a refusal where required. Individuals covered by India's Digital Personal Data Protection framework may exercise applicable access, correction, erasure, grievance, and consent-withdrawal rights as its provisions apply.
Submit a request to support@supplydesk.ca. We will respond within the period required by the law that applies.
12. Cookies and similar technologies
Essential technologies make sign-in, security, and core features work. Optional product analytics stays off unless you allow it. The Service does not use Google Analytics or advertising cookies. Our Cookie Policy explains the categories and your choices.
13. Children
The Service is a business product and is not directed to children or individuals under 18. We do not knowingly collect children's personal information through account registration. Contact us if you believe a child has provided personal information.
14. Changes to this Policy
We may revise this Policy to reflect changes in the Service, providers, or law. We will publish the version and effective date and give additional notice of material changes where appropriate. If a change requires renewed acknowledgement or consent, we will request it before the relevant processing continues.
15. Contact and complaints
Our Privacy contact for privacy inquiries is available at support@supplydesk.ca. Please include enough information to understand the request, but do not email passwords, payment-card details, or other secrets.
If we cannot resolve your concern, Canadian residents may contact the Office of the Privacy Commissioner of Canada.
SupplyDesk is currently identified by its trading name. Legal-entity, registered-address, and any formally appointed named privacy officer details will be added when incorporation and appointments are completed.