Privacy Policy — Origen

Draft pending counsel review.

1. Who we are

[LEGAL ENTITY NAME], contact [EMAIL].

2. What we collect

Account data (name, business, email); billing data (handled by Stripe — we do not store card numbers); Customer Content you upload (BOMs, supplier documents, costs); supplier-portal signer data (name, email, IP, timestamp, signature); usage/log data; cookies for auth and analytics.

3. How we use it

To provide the Service (including AI-assisted extraction and classification of documents you submit), maintain audit-grade records, bill, support, secure the platform, and send service communications. We do not sell personal information. We do not use one customer's confidential content to serve another customer.

4. Processors we share with

Hosting and database ([Vercel], [Supabase]), payments ([Stripe]), AI processing ([Anthropic] — content you submit for extraction/classification is processed to provide the feature), communications ([Twilio/WhatsApp], email provider). Each under contractual confidentiality.

5. Retention

Account data for the life of the account; audit-grade records per the retention terms in the ToS (§6); backups on a rolling schedule.

6. Your choices / rights

Access, export, correction; deletion subject to the audit-retention carve-out in ToS §6; marketing opt-out; California and other state-law rights honored on request at [EMAIL].

7. Security

Encryption in transit and at rest, role-based access, append-only audit logs, content hashing.

8. Children

Not for under-18s.

9. Changes

Versioned; material changes notified.

Version [v0.9 — [DATE]]. These terms are under attorney review; material changes will be announced to account holders.