Legal

Privacy Policy

Last updated: 13 May 2026

This Privacy Policy explains what information SupplierMafia (the "platform", "we", "us") collects when you use our service, how we use it, who we share it with, and the controls you have. It applies to anyone who creates an account at suppliermafia.com.

The short version. We collect the information you give us when you sign up and use the platform (your account details, the messages you send, the invoices you exchange). We use that information to run the service, keep it safe, and respond to you. We do not sell your data, and we do not run third-party advertising trackers on the platform.

0. Who we are

The data controller for the personal information described in this policy is SupplierMafia, operating from the United Kingdom. For all privacy-related questions, contact privacy@suppliermafia.com. We have not appointed a formal Data Protection Officer because we are not required to under UK GDPR — our processing is not core to a regulated activity that triggers the appointment requirement. The privacy inbox above is monitored by the founding team.

EU and EEA users. If you are located in the European Union or wider EEA and would like to contact us about your rights under EU GDPR, please use privacy@suppliermafia.com in the first instance. For the separate Digital Services Act single-point-of-contact and legal-representative details required for non-EU platforms, see Section 17 of our Terms of Service.

1. Information we collect

Account information

When you create an account we collect your name, email address, and (if you sign in with Google) the basic profile information that Google sends us. If you complete your buyer or supplier profile we also store the optional fields you fill in (location, timezone, business hours, bio, profile photo).

Conversation content

SupplierMafia is a chat platform, so the messages you send and receive are stored on the platform. This includes message text, files you attach, invoices, and metadata about the conversation (who is in it, when messages were sent, who has read them). We retain this content for as long as your account is active so that you and your supplier can keep a working record of the relationship.

Usage and technical data

We collect basic technical information when you use the platform: your IP address, browser and device type, the pages you load, and timestamps. This is used to keep the service running, diagnose problems, and detect abuse.

What we do not collect

We do not run third-party advertising trackers. We do not sell your data to anyone. We do not collect payment-card data ourselves; if a payment processor is added in the future, that processor will handle card data under their own terms.

2. How we use your information

3. Legal basis for processing (UK / EU users)

Under UK GDPR and (where applicable) EU GDPR, we rely on the following lawful bases:

4. Who can see your data

Other users on the platform

Anyone you share a conversation with can see your name, profile photo, and the messages you send in that conversation. Suppliers you have not opened a conversation with cannot see your private profile information.

SupplierMafia staff

Our admin team can read conversations when investigating reports, abuse, or platform-safety issues. Every such access is logged in our internal audit log. We do not browse conversations for any other reason.

Service providers (sub-processors)

We use a small number of trusted service providers to operate the platform. Each acts as our data processor under a written data-processing agreement (UK GDPR Article 28) and is contractually bound to handle your data only for the purposes we direct.

Sub-processorPurposeLocation of processingTransfer mechanism
Supabase Inc. Database, authentication, file storage, realtime messaging AWS regions (primary EU-west; some metadata in US-east) Adequacy (UK-EU) for EU-hosted data; UK IDTA for any US transfers
Vercel Inc. Static-site hosting, edge functions, serverless routes Global edge network (closest to user) UK IDTA for US transfers
Resend (Drape Inc.) Transactional and announcement email delivery United States UK IDTA
Cloudflare Inc. DNS, DDoS protection (where in front of our domains) Global edge network UK IDTA for US transfers
Google LLC "Sign in with Google" OAuth identity verification; Google Analytics 4 (only when you accept the analytics cookie banner) United States UK IDTA; OAuth only fires on the Google sign-in path, Analytics only after explicit consent
hCaptcha (Intuition Machines Inc.) Anti-bot challenge at signup (only when enabled) United States UK IDTA

We will notify users at least 14 days in advance of adding a material new sub-processor that has access to user content. To object to a planned change, email privacy@suppliermafia.com before the effective date; we will respond before adding the processor.

Legal requirements

We may disclose information when required by law (court order, valid subpoena, regulatory request), or when necessary to protect the rights, property, or safety of SupplierMafia, our users, or the public. We push back on overbroad requests and notify the affected user where legally permitted to do so.

5. International transfers

SupplierMafia is operated from the United Kingdom. Our service providers may store and process data in other regions — primarily the European Economic Area and the United States. Where data leaves the UK or EEA, we rely on adequacy decisions where available, or on Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum where adequacy is not in force. Your data is not stored in or processed from sanctioned regions.

6. Retention

We keep personal information for as long as is necessary to provide the service and to meet legal obligations:

7. Your rights

Under UK GDPR (and equivalent rights under EU GDPR for users in the EEA), you have the right to:

8. California residents (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act and California Privacy Rights Act:

To exercise any California right, email privacy@suppliermafia.com. We will verify your identity before responding (typically by confirming you control the email tied to the account).

9. Cookies and similar technologies

We use a small number of cookies and similar technologies to keep you signed in, remember your preferences, and detect abuse. We also use Google Analytics 4 with Consent Mode v2 to understand aggregate platform usage, but only after you have explicitly accepted the analytics cookie banner. We do not use third-party advertising cookies and we do not run Google Ads. See the Cookies Policy for the full list and your controls. You can change your analytics choice at any time from the cookie banner (re-open via "Cookie preferences" in the footer).

10. Automated decision-making

We do not make decisions about you that have legal or similarly significant effects based solely on automated processing. Suspicious-activity detection may surface accounts to admins for review, but the final decision to suspend, warn, or close an account is always made by a human.

11. Security

We use industry-standard security practices including encrypted connections (HTTPS / TLS 1.2+), encrypted data at rest, role-based access controls, scoped API keys, and Row Level Security on every database table. Authentication is handled by Supabase Auth with bcrypt password hashing and (optionally) two-factor codes. No platform can guarantee perfect security.

Personal-data breach response. If a security incident results in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to your personal data, we follow the timelines in UK GDPR Article 33 and 34:

For incidents that affect platform availability or service quality without affecting personal data, see our public incident-response and post-mortem practice in our Terms. For US state-law breach notifications (where applicable), we follow the timelines required by the relevant state's data-breach notification statute.

12. Children

SupplierMafia is a B2B platform intended for use by adult business operators. The service is not directed at, and may not be used by, anyone under 18. We do not knowingly collect personal information from anyone under 18, and the platform does not market to or design any feature for under-18 users. If you believe an under-18 user has registered, email privacy@suppliermafia.com and we will close the account and erase the personal data we hold, subject only to the retention exceptions in Section 6.

13. Changes to this policy

If we change this policy materially we will notify you in-app or by email at least 14 days before the changes take effect. The "Last updated" date at the top of this page always reflects the current version. We keep prior versions on request.

14. Contact

Questions about this policy or your data? Email privacy@suppliermafia.com and we will get back to you within five business days.