Privacy Policy.
How we collect, use, store, and protect your information across the Sourceby platform — written in plain English, not legalese.
Introduction
Sourceby ("we", "us", "our") operates the Sourceby AI-enabled sourcing platform, including our website, applications, and related services (collectively, the "Service"). This Privacy Policy explains what information we collect, how we use it, who we share it with, and the rights you have over your information.
By using the Service, you agree to the practices described in this Policy. If you do not agree, please do not use the Service. This Policy applies to buyers, suppliers, visitors, and anyone who interacts with Sourceby.
Information we collect
We collect information in three ways: information you give us directly, information collected automatically when you use the Service, and information we receive from third parties.
Information you give us
- Account information — name, work email, phone number, company name, role, and password.
- Profile information — for suppliers: capabilities, categories, materials, certifications, locations, capacity, and supporting documents.
- Sourcing content — for buyers: RFQs, BOQs, RFIs, drawings, BOMs, specifications, line items, clarifications, and award data.
- Communication — messages, support requests, survey responses, and any content you share with our team.
- Billing information — billing address and tax IDs. Payment card data is collected directly by our PCI-compliant payment processors; we don't store it.
Information collected automatically
- Device & usage — IP address, browser type, operating system, referring URLs, page interactions, timestamps, and error logs.
- Cookies & similar tech — see Section 05 for details.
- Location — approximate location derived from IP address, used for routing, security, and regional features.
Information from third parties
- SSO providers — basic profile fields when you sign in via Google, Okta, Microsoft, or other identity providers you choose to connect.
- Enrichment — public business registry data, company metadata, and verification signals from authorized data partners.
- Referrals — if someone invites you to the Service, we receive your name and email from them.
| Data category | Examples | Purpose |
|---|---|---|
| Identity | Name, email, role | Account & communications |
| Business | Company, categories, capacity | Sourcing & matching |
| Content | RFQs, BOMs, drawings | Service delivery |
| Technical | IP, browser, logs | Security & debugging |
| Commercial | Billing, plan | Subscription management |
How we use information
We use your information for the following purposes, each with a corresponding legal basis under GDPR / DPDP:
- Provide and operate the Service — account setup, supplier discovery, RFQ workflows, evaluation, dashboards, and awards. (Contract)
- Improve and develop the Service — analytics, performance monitoring, debugging, and product improvements. (Legitimate interest)
- Communicate with you — service updates, security alerts, billing, support replies. (Contract / Legitimate interest)
- Marketing — newsletters, product updates, event invitations. You can unsubscribe at any time. (Consent)
- Security & fraud prevention — protecting against abuse, unauthorized access, and policy violations. (Legitimate interest / Legal obligation)
- Legal compliance — tax, audit, regulatory reporting, and responding to lawful requests. (Legal obligation)
AI & machine learning
We use AI to support supplier discovery, matching, response comparison, and workflow efficiency. Your private RFQs, drawings, and sourcing content are never used to train our AI models or those of any third party. We use anonymized, aggregate signals — such as completed match outcomes — only to improve ranking and discovery quality, never to expose private content.
Cookies & tracking
We use cookies and similar technologies to keep you logged in, remember preferences, measure usage, and improve performance. You can manage cookie preferences in your browser or via our cookie banner.
- Essential — required for login, session management, and security. Cannot be disabled.
- Functional — remember preferences like theme, timezone, and language.
- Analytics — aggregated usage analytics (page views, errors, performance). We use privacy-respecting providers.
- Marketing — only with your explicit consent, used to measure marketing campaign effectiveness.
We respect Do Not Track signals where required by law.
Security
We take reasonable, industry-standard measures to protect your information:
- Encryption in transit (TLS 1.3) and at rest (AES-256).
- Role-based access controls and SSO (SAML 2.0) for enterprise plans.
- Audit logs covering every event action, clarification, and award decision.
- Regular vulnerability scans, penetration testing, and dependency monitoring.
- SOC 2 Type II in audit; ISO 27001 roadmap in progress.
- Strict employee access policies and confidentiality agreements.
No internet transmission or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security. Promptly notify us at info@sourceby.io if you suspect any unauthorized access.
Data retention
We retain your information for as long as your account is active and as needed to provide the Service. After account closure, we retain data only as required by law, for legitimate business needs (audit, fraud prevention, dispute resolution), or as needed to honor your rights requests.
- Account data — kept while your account is active; deleted within 30 days of account closure unless retention is required.
- Sourcing content — retained for the duration of your subscription and exportable on departure.
- Billing records — retained for the period required by applicable tax and accounting laws (typically 7 years).
- Backups — encrypted backups may persist for up to 90 days after deletion and are also purged in due course.
International transfers
Sourceby is operated globally and your information may be transferred to and processed in countries other than where you reside. When we transfer personal data from the EEA, UK, or Switzerland to other countries, we rely on lawful transfer mechanisms including Standard Contractual Clauses (SCCs) and equivalent safeguards.
Enterprise plans offer regional data residency (IN, EU, US) and private VPC deployments on request.
Your rights
Depending on where you live, you may have the following rights regarding your personal information:
- Access — request a copy of the information we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion of your data (with limited legal exceptions).
- Portability — receive your data in a structured, machine-readable format.
- Restriction — limit how we process your data in certain circumstances.
- Objection — object to processing based on legitimate interests, including direct marketing.
- Consent withdrawal — where processing is based on consent, you can withdraw at any time.
- Complaint — lodge a complaint with your local supervisory authority (e.g. DPB in India, ICO in the UK, your EU DPA).
To exercise any of these rights, email info@sourceby.io. We respond within 30 days. We may verify your identity before fulfilling sensitive requests.
Children's privacy
Sourceby is a B2B service intended for use by businesses and their employees. It is not directed to children under the age of 16, and we do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately so we can delete it.
Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or in-app notice and update the "Last Updated" date at the top of this page. Continued use of the Service after the effective date constitutes acceptance of the revised Policy.
Contact us
If you have questions about this Policy or how we handle your information, get in touch — we read every message.
Reach our privacy team
For privacy questions, requests, or data-protection inquiries, use one of the channels below. We respond within 30 days.
2530 Meridian Pkwy, Durham, NC 27713, USA
Prefer to write us via the contact form? Visit our Contact page.
We're happy to walk you through it.
Need an MSA, DPA, or custom enterprise terms? Get in touch and we'll route it to the right team.