Privacy Policy.

How we collect, use, store, and protect your information across the Sourceby platform — written in plain English, not legalese.

Effective Date
January 1, 2026
Last Updated
September 1, 2026
Version
v1.0 · GDPR · DPDP
Section 01

Introduction

Sourceby ("we", "us", "our") operates the Sourceby AI-enabled sourcing platform, including our website, applications, and related services (collectively, the "Service"). This Privacy Policy explains what information we collect, how we use it, who we share it with, and the rights you have over your information.

By using the Service, you agree to the practices described in this Policy. If you do not agree, please do not use the Service. This Policy applies to buyers, suppliers, visitors, and anyone who interacts with Sourceby.

The short version
We collect the information needed to run the Service, match buyers with suppliers, and keep your account secure. We don't sell your data, we don't use your private RFQs or drawings to train models, and you can request access, correction, or deletion at any time.
Section 02

Information we collect

We collect information in three ways: information you give us directly, information collected automatically when you use the Service, and information we receive from third parties.

Information you give us

  • Account information — name, work email, phone number, company name, role, and password.
  • Profile information — for suppliers: capabilities, categories, materials, certifications, locations, capacity, and supporting documents.
  • Sourcing content — for buyers: RFQs, BOQs, RFIs, drawings, BOMs, specifications, line items, clarifications, and award data.
  • Communication — messages, support requests, survey responses, and any content you share with our team.
  • Billing information — billing address and tax IDs. Payment card data is collected directly by our PCI-compliant payment processors; we don't store it.

Information collected automatically

  • Device & usage — IP address, browser type, operating system, referring URLs, page interactions, timestamps, and error logs.
  • Cookies & similar tech — see Section 05 for details.
  • Location — approximate location derived from IP address, used for routing, security, and regional features.

Information from third parties

  • SSO providers — basic profile fields when you sign in via Google, Okta, Microsoft, or other identity providers you choose to connect.
  • Enrichment — public business registry data, company metadata, and verification signals from authorized data partners.
  • Referrals — if someone invites you to the Service, we receive your name and email from them.
Data categoryExamplesPurpose
IdentityName, email, roleAccount & communications
BusinessCompany, categories, capacitySourcing & matching
ContentRFQs, BOMs, drawingsService delivery
TechnicalIP, browser, logsSecurity & debugging
CommercialBilling, planSubscription management
Section 03

How we use information

We use your information for the following purposes, each with a corresponding legal basis under GDPR / DPDP:

  • Provide and operate the Service — account setup, supplier discovery, RFQ workflows, evaluation, dashboards, and awards. (Contract)
  • Improve and develop the Service — analytics, performance monitoring, debugging, and product improvements. (Legitimate interest)
  • Communicate with you — service updates, security alerts, billing, support replies. (Contract / Legitimate interest)
  • Marketing — newsletters, product updates, event invitations. You can unsubscribe at any time. (Consent)
  • Security & fraud prevention — protecting against abuse, unauthorized access, and policy violations. (Legitimate interest / Legal obligation)
  • Legal compliance — tax, audit, regulatory reporting, and responding to lawful requests. (Legal obligation)

AI & machine learning

We use AI to support supplier discovery, matching, response comparison, and workflow efficiency. Your private RFQs, drawings, and sourcing content are never used to train our AI models or those of any third party. We use anonymized, aggregate signals — such as completed match outcomes — only to improve ranking and discovery quality, never to expose private content.

Section 04

How we share information

We do not sell your personal data. We share information only in the following scenarios:

  • With your direction — for buyers, RFQ content is shared with the suppliers you invite. For suppliers, profile data is visible to buyers in the marketplace per your visibility settings.
  • Sub-processors — vetted third-party vendors that help us operate (cloud hosting, email delivery, analytics, error monitoring, payment processing). A list is available on request.
  • Within your organization — teammates with appropriate role permissions in your workspace.
  • Legal compliance — when required by law, court order, or to protect Sourceby's rights, users, or the public.
  • Business transfers — in connection with a merger, acquisition, or asset sale, subject to confidentiality protections.
Drawings, BOMs & IP
NDAs are auto-signed before any RFQ is shared with a supplier, and you control which suppliers can see which documents. Documents are encrypted in transit and at rest.
Section 05

Cookies & tracking

We use cookies and similar technologies to keep you logged in, remember preferences, measure usage, and improve performance. You can manage cookie preferences in your browser or via our cookie banner.

  • Essential — required for login, session management, and security. Cannot be disabled.
  • Functional — remember preferences like theme, timezone, and language.
  • Analytics — aggregated usage analytics (page views, errors, performance). We use privacy-respecting providers.
  • Marketing — only with your explicit consent, used to measure marketing campaign effectiveness.

We respect Do Not Track signals where required by law.

Section 06

Security

We take reasonable, industry-standard measures to protect your information:

  • Encryption in transit (TLS 1.3) and at rest (AES-256).
  • Role-based access controls and SSO (SAML 2.0) for enterprise plans.
  • Audit logs covering every event action, clarification, and award decision.
  • Regular vulnerability scans, penetration testing, and dependency monitoring.
  • SOC 2 Type II in audit; ISO 27001 roadmap in progress.
  • Strict employee access policies and confidentiality agreements.

No internet transmission or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security. Promptly notify us at info@sourceby.io if you suspect any unauthorized access.

Section 07

Data retention

We retain your information for as long as your account is active and as needed to provide the Service. After account closure, we retain data only as required by law, for legitimate business needs (audit, fraud prevention, dispute resolution), or as needed to honor your rights requests.

  • Account data — kept while your account is active; deleted within 30 days of account closure unless retention is required.
  • Sourcing content — retained for the duration of your subscription and exportable on departure.
  • Billing records — retained for the period required by applicable tax and accounting laws (typically 7 years).
  • Backups — encrypted backups may persist for up to 90 days after deletion and are also purged in due course.
Section 08

International transfers

Sourceby is operated globally and your information may be transferred to and processed in countries other than where you reside. When we transfer personal data from the EEA, UK, or Switzerland to other countries, we rely on lawful transfer mechanisms including Standard Contractual Clauses (SCCs) and equivalent safeguards.

Enterprise plans offer regional data residency (IN, EU, US) and private VPC deployments on request.

Section 09

Your rights

Depending on where you live, you may have the following rights regarding your personal information:

  • Access — request a copy of the information we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — request deletion of your data (with limited legal exceptions).
  • Portability — receive your data in a structured, machine-readable format.
  • Restriction — limit how we process your data in certain circumstances.
  • Objection — object to processing based on legitimate interests, including direct marketing.
  • Consent withdrawal — where processing is based on consent, you can withdraw at any time.
  • Complaint — lodge a complaint with your local supervisory authority (e.g. DPB in India, ICO in the UK, your EU DPA).

To exercise any of these rights, email info@sourceby.io. We respond within 30 days. We may verify your identity before fulfilling sensitive requests.

Section 10

Children's privacy

Sourceby is a B2B service intended for use by businesses and their employees. It is not directed to children under the age of 16, and we do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately so we can delete it.

Section 11

Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or in-app notice and update the "Last Updated" date at the top of this page. Continued use of the Service after the effective date constitutes acceptance of the revised Policy.

Section 12

Contact us

If you have questions about this Policy or how we handle your information, get in touch — we read every message.

Reach our privacy team

For privacy questions, requests, or data-protection inquiries, use one of the channels below. We respond within 30 days.

General support
Postal address
Sourceby HQ · North Carolina, USA
2530 Meridian Pkwy, Durham, NC 27713, USA

Prefer to write us via the contact form? Visit our Contact page.

We're happy to walk you through it.

Need an MSA, DPA, or custom enterprise terms? Get in touch and we'll route it to the right team.