SupplierHoursTerms of Service

Privacy Policy

Effective July 17, 2026

What we collect

Account data: name, work email, password (stored only as a bcrypt hash), company name, and optional billing details (billing contact, phone, address) you choose to provide.

Facility data:the locations, schedules, closures, and notes suppliers publish. This data is intended to be shared — that is the product — via public pages, widgets, search engines, AI crawlers, and API consumers, unless you turn a location's public page off.

Usage data: API request counts per key (for rate limiting and billing), authentication attempt counters (abuse prevention), an append-only audit log of account actions, and aggregate web analytics (page views, Core Web Vitals) via Vercel Analytics — which does not use cookies or track individuals across sites.

Error data: when something breaks, error reports (which can include request metadata) go to Sentry so we can fix it.

What we do with it

Operate the Service, authenticate you, send transactional email (verification, password resets, team invites, data-freshness reminders), process payments, prevent abuse, and improve the product. We do not sell personal information, and we do not use your data for advertising.

Who touches it (processors)

Infrastructure and subprocessors we rely on: Vercel (hosting, analytics), Neon (database), Stripe (payments — card details go directly to Stripe and never touch our servers), Resend (transactional email), Sentry (error monitoring), and GitHub (source code, not customer data). Each processes data only to provide their service to us.

Retention and deletion

Account and facility data persist until you delete them — deleting a location removes its schedules and closures; deleting your organization removes its users, locations, keys, and invites. Audit logs and aggregate usage counters are retained for security and billing history. Backups age out on our database provider's schedule.

Security

Passwords are bcrypt-hashed; API keys and account tokens are stored only as SHA-256 hashes; all traffic is HTTPS with strict transport security; queries are parameterized; authentication endpoints are rate-limited; and every account mutation is audit logged. No system is perfectly secure, but we take this seriously — see something? Tell us.

Your rights

You can access and correct your account data in the dashboard, export your facility data via the API or CSV, and delete your account. Depending on your jurisdiction you may have additional rights (access, portability, erasure) — contact us and we'll honor them.

Changes and contact

Material changes to this policy will be announced to account holders. Questions or requests: reach us through the contact information on the documentation page.