Privacy Policy — Origen
Draft pending counsel review.
1. Who we are
[LEGAL ENTITY NAME], contact [EMAIL].
2. What we collect
Account data (name, business, email); billing data (handled by Stripe — we do not store card numbers); Customer Content you upload (BOMs, supplier documents, costs); supplier-portal signer data (name, email, IP, timestamp, signature); usage/log data; cookies for auth and analytics.
3. How we use it
To provide the Service (including AI-assisted extraction and classification of documents you submit), maintain audit-grade records, bill, support, secure the platform, and send service communications. We do not sell personal information. We do not use one customer's confidential content to serve another customer.
4. Processors we share with
Hosting and database ([Vercel], [Supabase]), payments ([Stripe]), AI processing ([Anthropic] — content you submit for extraction/classification is processed to provide the feature), communications ([Twilio/WhatsApp], email provider). Each under contractual confidentiality.
5. Retention
Account data for the life of the account; audit-grade records per the retention terms in the ToS (§6); backups on a rolling schedule.
6. Your choices / rights
Access, export, correction; deletion subject to the audit-retention carve-out in ToS §6; marketing opt-out; California and other state-law rights honored on request at [EMAIL].
7. Security
Encryption in transit and at rest, role-based access, append-only audit logs, content hashing.
8. Children
Not for under-18s.
9. Changes
Versioned; material changes notified.
Version [v0.9 — [DATE]]. These terms are under attorney review; material changes will be announced to account holders.