Privacy Policy
Last updated: August 4, 2026
1. Overview
This policy explains what information SupplySmart (a product of Onwardlabs LLC) collects, how it is used, and the choices you have. It applies to supplysmart.app and to tenant storefronts running on the platform.
2. What we collect
- Account information - name, business name, email, phone, and address provided at signup or in settings.
- Workspace data - the catalogs, customers, orders, invoices, payments, and bookkeeping records that tenants and their customers enter while using the service.
- Payment information - handled by Stripe. Card and bank numbers are entered on Stripe's systems and never stored on ours; we keep only references (such as customer and subscription IDs) and payment status.
- Usage and log data - standard technical logs (IP address, browser type, pages accessed, timestamps) used for security and debugging.
3. How we use information
To operate and secure the service, process subscriptions, send transactional email (order confirmations, invoices, statements, billing and account notices), provide support, and improve the product. We do not sell personal information, and we do not use your workspace data for advertising.
4. Tenant customer data
When a distributor uses SupplySmart, their customers' information (store names, contacts, order history, balances) is entered and controlled by that distributor. We process it on the distributor's behalf to provide the service, as described in our Data Processing Addendum. If you are a store whose supplier uses SupplySmart, direct questions about your information to your supplier first.
One login across distributors.If a store buys from more than one distributor on SupplySmart, it signs in with a single email and password for all of them, and each of those distributors holds its own separate record for that store. Distributors cannot access each other's workspaces or records. Because the login is shared, a password change or reset applies across all of the store's distributors at once.
5. Service providers
We share data only with the providers that run the service:
- Stripe - payment and subscription processing
- Supabase - database, authentication, and file storage
- Vercel - application hosting
- Resend - transactional email delivery
- Sentry - error monitoring (error reports can include technical request details such as IP address and account identifiers)
- Cloudflare - sign-up abuse prevention (Turnstile; sees IP address and browser signals during sign-up)
Each provider processes data only to provide its service to us. We may also disclose information if required by law.
6. Cookies
We use cookies for sign-in sessions and security. We do not use advertising or cross-site tracking cookies.
7. Security and retention
Data is encrypted in transit, tenant workspaces are isolated at the database level, and access within our team is limited to what operating and supporting the service requires. Our practices are described in more detail on the Security page. We retain data while an account is active; after closure, data is deleted on request, except records we are required to keep (such as billing records). Deleted data also ages out of our routine database backups as those backups expire, within 30 days.
8. Your rights and contact
You can access and update account information in the dashboard, request an export, or request deletion by contacting us. For any privacy request or question: hello@supplysmart.app. We may update this policy over time; material changes will be announced by email or in the dashboard.