Effective Date: 8/21/2025
Supply Assistant ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our Chrome extension and web application.
Information We Collect
Authentication Information
- Email address for account creation and login
- Authentication tokens to maintain your session
- We do NOT store passwords - authentication is handled securely through Supabase
Website Content
- Supplier page content from Alibaba.com and related domains to provide contextual AI suggestions
- Conversation history with suppliers to improve message generation
- Product information and project requirements you provide
User Activity
- Supplier interactions and conversation patterns
- Project creation and modification activity
- Extension usage patterns to improve functionality
How We Use Your Information
- AI Message Generation: We analyze supplier page content to provide contextual, relevant message suggestions
- Project Management: Store your sourcing projects and requirements to maintain context across conversations
- Account Management: Authenticate users and maintain secure sessions
- Service Improvement: Analyze usage patterns to enhance functionality (anonymized data only)
Data Storage and Security
- Local Storage: Authentication sessions and project context stored locally in your browser
- Secure Database: Project data securely stored in Supabase with encryption at rest and in transit
- No Third-Party Sharing: Your data is never sold or shared with third parties
- API Security: All communications between extension and dashboard use HTTPS encryption
Data Retention
- Account data retained until you delete your account
- Project and conversation data retained for service functionality
- You can delete your data at any time by contacting us
- Inactive accounts may have data purged after 2 years of inactivity
Your Rights
- Access: Request a copy of your personal data
- Correction: Update or correct your information
- Deletion: Request deletion of your account and associated data
- Portability: Export your project and conversation data
Chrome Extension Specific
- Host Permissions: Required only for Alibaba domains and our dashboard (procuro.live)
- No Remote Code: Extension contains no external code references or eval() statements
- Minimal Permissions: Only requests permissions necessary for core functionality
- Local Processing: Page analysis happens locally before sending minimal context to our API
Third-Party Services
We use the following trusted third-party services:
- Supabase: Database and authentication (covered by their privacy policy)
- OpenAI: AI message generation (no personal data sent, only business context)
- Vercel: Web hosting and deployment
Changes to This Policy
We may update this privacy policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Effective Date" above. Continued use of the service constitutes acceptance of the updated policy.
This privacy policy complies with GDPR, CCPA, and Chrome Web Store requirements. Last updated: 8/21/2025