Privacy Policy
Effective September 3, 2026
What we collect
We process account information, workspace membership, supplier URLs you submit, monitoring observations, notification settings, encrypted store credentials, billing identifiers, security logs, and operational diagnostics required to provide SupplyMirror.
Supplier sessions
When a supplier requires authentication, SupplyMirror may store a server-side browser session so scheduled monitoring can continue without keeping your computer online. SupplyMirror is designed to capture only the product data required for monitoring and not unrelated browsing activity.
How we use data
We use data to authenticate users, monitor selected sources, deliver alerts, execute configured store actions, secure the service, provide support, process subscriptions, prevent abuse, and improve reliability.
Service providers
We may use hosting, database, email, billing, observability, and commerce integration providers. They process data only as needed for the relevant service and under their own security and privacy obligations.
Retention and deletion
We retain operational data while your workspace is active and for a limited period afterward for recovery, security, legal, and billing obligations. You may request account deletion through Support. Backups expire according to the backup retention schedule.
Security
SupplyMirror uses scoped access controls, encrypted integration secrets, hashed authentication tokens, signed webhook verification, workspace isolation, rate limits, and fail-closed store-write controls. No online service can guarantee absolute security.
Your choices
You can manage notification channels, connected stores, team members, browser sessions, and subscription settings. Depending on applicable law, you may have rights to access, correct, export, object to, or delete personal data.