Privacy policy

Last updated: 2026-06-06

1. Who we are

Sourzi operates the website at sourzi.com and the services described in this policy. For the purposes of the EU GDPR we are the data controller, and for the purposes of the Chinese PIPL we are the personal information handler. You can reach us about anything in this policy at sourcing@sourzi.com.

2. What we collect

When you submit an email capture form, we record your email address, the page URL you submitted from, the position of the form you used (inline or sticky), a timestamp, and the browser user agent string. The user agent is kept only to triage spam. We never use it to track you across the web.

When you create an account, we record your email address and, if you set one, a password. The password is hashed by Supabase Auth and is never stored in plain text. The hashing is handled entirely by Supabase.

When you take out a subscription, Stripe processes your card data. Sourzi receives only a Stripe customer identifier, your subscription status and your billing periods. We never see or store card numbers, expiry dates or CVV codes.

We also record anonymised funnel events, such as a tool being used, a signup being prompted, a paywall being reached or a checkout being started. These events measure how people move through the product. They carry no advertising identifiers and are never sold or licensed.

3. How we use your information

We use your email address to authenticate you through a magic link sign in, to deliver any lead magnet PDF you requested, and to send service notifications about your account, billing and security. We do not add you to a marketing list unless you separately opt in.

We use funnel events to make product decisions. They are aggregated for reporting and are never combined with third party identifiers to build a profile of any individual.

4. Where your data is stored

Account records and email capture rows are held in a Supabase database, hosted in the United States by default. Stripe processes card data under the PCI DSS standard. Vercel hosts the website and analytics on a global edge network. If you are in the EU, you can ask us to enable an EU data residency option.

5. International transfers

In normal operation your personal data moves between Australia, the United States and the EU. Where the recipient sits outside the EU or the UK, those transfers rely on the Standard Contractual Clauses or an equivalent safeguard. Transfers of data out of China rely on the PIPL standard contract where it applies.

6. Lawful bases under GDPR

We rely on your consent for email capture tied to a lead magnet. We rely on performance of a contract to run your account and subscription. We rely on legitimate interest for funnel events and security monitoring. You can withdraw consent at any time by emailing the address in section 1.

7. Your rights and how to use them

You can ask for a copy of the personal information we hold about you, correct anything that is inaccurate, ask us to delete your data, object to our processing, and, under the GDPR and the PIPL, request data portability. Email sourcing@sourzi.com from your account address and we will respond within thirty days, or within the timeframes the PIPL sets for users it covers.

If you are in Australia you may complain to the Office of the Australian Information Commissioner. EU users may complain to their local supervisory authority. Users in China may complain to the Cyberspace Administration of China.

8. How long we keep data

We keep account data while your account is active and for twelve months after it closes, then delete it. Funnel events are kept for twelve months. Email capture rows are kept for thirty six months, then deleted. Stripe billing records are retained on Stripe's own schedule and as tax law requires.

9. Who we share data with

We do not sell personal information. We share it only with the processors we need to run the service: Supabase for our database and authentication, Stripe for payments, Vercel for hosting, and a transactional email provider for magic link and billing emails. Each processor is bound by a data processing agreement consistent with the relevant regime.

10. Cookies and analytics

We set one essential cookie, a session cookie for signed in users. We also run two analytics services, Vercel Analytics and Google Analytics 4. Analytics fire only after you give explicit consent through the cookie banner on your first visit. You can withdraw that consent at any time through the same banner.

11. Children

This site is built for procurement professionals and is not intended for anyone under sixteen. We do not knowingly collect data from children under sixteen. If you believe a child has given us data, contact us using section 1 and we will delete the records.

12. Security and breach notification

The site runs on HTTPS throughout, session cookies are set as HttpOnly, and Supabase enforces row level security policies. Card data is never stored on Sourzi infrastructure; Stripe handles it under PCI DSS Level 1. No system is impregnable. If a breach affects your personal data, we will notify you and the relevant regulator within the required timeframes.

13. Changes to this policy

We may update this policy from time to time. If a change is material, we will email active account holders at least fourteen days before it takes effect.

14. How to contact us

For any privacy enquiry, email sourcing@sourzi.com or use the contact page.