Sourcemarking LLC · Effective September 17, 2026 · United States
1. Who We Are
Sourcemarking LLC ("Sourcemarking," "we," "us," or "our") operates the Sourcemarking platform at sourcemarkinglabs.com. We provide procurement price benchmarking and vendor management tools for small and medium businesses in the United States. Sourcemarking is offered solely to U.S.-based businesses, and we store and process data in the United States. We do not knowingly offer the Service to, or collect personal information from, individuals located outside the United States. Questions about this policy can be sent to .
2. What Information We Collect
We collect information in three ways:
Information you provide directly:
Account information: your email address, and — if you create your account with a password — the password you set (we store it only as a salted hash, never in plain text). If instead you sign in with Google, we receive your email address, your name, and your Google profile picture from Google; we never receive your Google password
Profile details: your first and last name, and a profile photo if you upload one (stored privately and shown only to you and, where you have granted access, to administrators of your account)
Business information: your company name, U.S. address, number of locations, and business type
Procurement catalog data: the items you source, the vendors you use, prices you pay, and annual quantities and spend
Uploaded documents: invoices, spreadsheets, and other files you upload, which we process (including with automated and AI-based tools) to extract item and pricing details
Vendor preferences: vendors you mark as preferred or blocked
Search history: the items you search for when using price lookup
Referral information: if you invite a colleague, the name and email address you provide so we can send the invitation
Communications: feedback, support requests, and messages you send us, including any files or screenshots you attach to them
Waitlist signups: the email address you provide when you ask to be notified about an upcoming feature (such as mobile access)
Payment information: billing details processed by our payment provider (we do not store full card numbers)
Information collected automatically:
Usage data: pages visited, features used, buttons clicked, and time spent on the platform
Device and browser information: browser type, operating system, and IP address
Session data: login timestamps and session duration
Notification data: if you turn on notifications on your phone, we store the notification address your browser generates for that device and the keys needed to encrypt messages to it, so we can tell you when something you asked for is ready. This address identifies a browser on a device, not you by name. We delete it when you turn notifications off, and when the push service tells us the address no longer works
Website visit data: when you visit our website, the pages you open, how long each page is open, the website or link that brought you (including any campaign tags on that link), your device type and browser, and your approximate location (country, state, and city) derived from your network connection. We record visits using randomly generated identifiers stored in first-party cookies, and we do not store your IP address with this data. If you create an account, we save with your account how your browser first arrived at our website (for example, from a link on LinkedIn)
Security and anti-abuse data: IP addresses and related metadata used to detect and prevent fraud, spam, and abuse (including rate limiting and bot protection)
Email engagement: delivery, bounce, open, and click events for the product and marketing emails we send you, used to honor unsubscribes, suppress failing addresses, and measure what's useful (transactional emails such as password resets are not open- or click-tracked)
Information from third parties:
Vendor pricing data sourced from publicly available vendor catalogs and pricing databases used to generate price comparisons
How benchmark prices are shared between customers. When we look up what a vendor charges for an item, we keep that vendor price and reuse it to answer the same question for other customers, so the same lookup is not repeated needlessly. What is pooled is the vendor's price for a publicly listed product — never your identity, your business, the price you pay, your quantities, your spend, or the fact that you searched for it. No customer can see another customer's catalog, prices, or activity, and we do not compare your prices against other customers' prices.
3. How We Use Your Information
We use the information we collect to:
Operate and deliver the Sourcemarking platform and its features
Generate price benchmarks and vendor recommendations specific to your catalog, including by sending item, vendor, and uploaded-document data to third-party AI providers for processing
Extract line items and prices from documents you upload
Suggest and complete addresses you enter, by sending what you type to our mapping provider
Send referral invitations you initiate and administer any referral rewards or promotions
Send product updates and feature announcements, and notify you when a feature you signed up to hear about launches (you may opt out at any time)
Improve the platform through aggregate analysis of usage patterns
Understand how people find and use our website, such as which websites, pages, and campaigns bring visitors and how many of those visitors become customers
Detect and prevent fraud, abuse, and security incidents
Comply with legal obligations
We do not sell your data, and we do not use your procurement catalog data or pricing information to train machine learning models. The third-party AI providers that process your data to deliver the Service do not use it to train their models.
4. How We Share Your Information
We do not sell your personal information to third parties. We share information only in the following circumstances:
Service providers: We share data with companies that help us operate the platform, each contractually required to protect your data and process it only to provide services to us:
Supabase — database, authentication, and storage of your account and catalog data (hosted in the United States)
Stripe — payment processing and subscription billing
Anthropic — AI processing for price search, document extraction, and other analysis features; we send the data each feature needs — including item descriptions and part numbers, vendor names (including your current vendor), your business location's city and region used to localize prices, the contents of documents you upload, and the text of feedback you submit — and Anthropic does not use this data to train its models
Mapbox — address autocomplete; when you type an address, what you enter is sent to Mapbox to return matching U.S. address suggestions, along with an approximate city-level location derived from your IP address so the suggestions we show you are ones near you
Resend — delivery of transactional and product emails, including the delivery, bounce, and engagement events described above
Google Workspace — business email; messages you send to our contact addresses (such as hello@, support@, legal@, and careers@) are received and stored there
Upstash — rate limiting and abuse prevention
Apple, Google, and Mozilla push services — delivery of notifications to your phone, if you turn them on. Your browser, not us, chooses which of these services your device uses. We send it an address your browser generated for your device and the contents of the notification; we do not send it your name or email address, and we never send the prices or item details themselves. Turning notifications off in the app, or in your phone’s settings, stops this
Cloudflare — bot and abuse protection
Vercel — application hosting and privacy-friendly usage analytics
Google — optional “Sign in with Google”. If you choose it, Google confirms your identity to us and provides your email address, name, and profile picture. We do not post anything to your Google account, and you can revoke our access at any time from your Google account settings
Business transfers: If Sourcemarking is acquired or merges with another company, your information may be transferred as part of that transaction. We will notify you before your data is transferred and becomes subject to a different privacy policy.
Legal requirements: We may disclose your information if required by law, court order, or to protect the rights and safety of Sourcemarking, our users, or the public.
With your consent: We will share your information for any other purpose with your explicit consent.
5. Data Retention and Deletion
We retain your account and catalog data for as long as your account is active. Canceling a paid subscription does not delete your data — your account simply moves to the Free plan and your data remains available to you.
You can permanently delete your account and its data at any time from your account settings, or by contacting us at . When you do, we remove your personal and business data — including your catalog, vendors, saved items, and uploaded documents — from our active systems promptly. Deletion is immediate and cannot be undone; there is no recovery period.
A limited set of records may be retained after deletion where we have a legal obligation or legitimate need to keep them — for example, records used for tax, accounting, dispute resolution, or fraud and abuse prevention (such as security and enforcement logs) — and only for as long as necessary for those purposes. Residual copies may also remain in our providers' encrypted, access-controlled backups for a limited period in the ordinary course before being overwritten. Activity and audit logs are retained on a rolling basis according to your account settings.
We keep a de-identified record of savings confirmed on the platform — the savings amount, the date, the product category and the plan — so we can report total savings across all customers. When you delete your account, these records are disconnected from you and your business, and nothing left in them identifies you.
Website visit records are kept for up to 25 months and then deleted. The record of how your account first arrived at our website is kept while your account is active and is deleted when your account is deleted.
6. Security
We use industry-standard security measures including encryption in transit (TLS), encrypted storage, access controls, bot protection, rate limiting, and account- and IP-based abuse controls to protect your data. Our platform is built on Supabase, which maintains SOC 2 Type II compliance. However, no system is completely secure, and we cannot guarantee the absolute security of your information. You are responsible for keeping your account credentials confidential.
7. Your Rights
Subject to applicable U.S. federal and state law, you may have the right to:
Access: Request a copy of the personal information we hold about you
Correction: Ask us to correct inaccurate or incomplete information
Deletion: Request that we delete your account and associated data
Portability: Receive your data in a machine-readable format
Opt-out: Unsubscribe from marketing communications at any time
To exercise any of these rights, contact us at . We will respond within 30 days.
8. Illinois and Other State Residents
Illinois residents have additional rights under the Illinois Personal Information Protection Act (PIPA) and related statutes. We do not sell personal information. If you believe your rights under Illinois law have been violated, you may contact the Illinois Attorney General's office.
Residents of other U.S. states — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and a growing number of others — may have additional rights under their state privacy laws, such as the right to access, correct, delete, or obtain a copy of their personal information, and to opt out of targeted advertising or the sale of personal information (neither of which we do). To exercise any of these rights, contact us at .
9. California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), gives you specific rights regarding your personal information. This section supplements the rest of this policy.
Categories of personal information we collect. In the preceding 12 months, we have collected the following categories of personal information:
Identifiers — name, email address, IP address, and account identifiers
Commercial information — your procurement catalog, vendors, prices, quantities, spend, and subscription and transaction records
Internet or network activity — usage data, pages visited on our website and platform, the website or link that referred you, features used, and session information
Geolocation data — approximate location derived from your IP address or network connection, used to confirm U.S. access, for security, and to understand where our website visitors are located
Professional or employment-related information — your company name, type, and U.S. business location
We collect this information for the business purposes described in "How We Use Your Information" and disclose it only to the service providers listed in "How We Share Your Information." We do not use or disclose sensitive personal information beyond the purposes permitted under the CCPA/CPRA.
Your California rights. Subject to certain exceptions, you have the right to:
Know and access the categories and specific pieces of personal information we have collected about you
Delete personal information we have collected from you
Correct inaccurate personal information
Opt out of the sale or sharing of personal information
Limit the use and disclosure of sensitive personal information
Non-discrimination for exercising any of these rights
We do not sell or share your personal information as those terms are defined under the CCPA/CPRA, and we have not done so in the preceding 12 months. We do not knowingly sell or share the personal information of consumers under 16 years of age.
To exercise your California rights, contact us at . We will verify your request using the information associated with your account and respond within 45 days (which may be extended by an additional 45 days where permitted by law). You may use an authorized agent to submit a request on your behalf, subject to verification of the agent's authority.
10. Cookies
If you use Sourcemarking on a phone, we may also set an essential cookie that records that this device is allowed to use the phone version of the app. It identifies the device, not you, and is removed when it expires or when access is withdrawn. Notifications are separate from cookies: they are granted through your browser’s own permission prompt and can be withdrawn at any time in the app or in your phone’s settings.
We use essential cookies and local storage to keep you logged in, maintain your session, remember display preferences you set (such as how many decimals a table shows), and — on our public mobile page — hold a random identifier that lets us count returning visitors without recognising who they are.
We also use our own first-party analytics cookies to understand how visitors find and use our website: a randomly generated visitor identifier (kept for up to 13 months), a visit identifier that expires after 30 minutes of inactivity, and a record of how your browser first arrived at our website (kept for up to 6 months). These cookies are set and read only by Sourcemarking. They are never shared with or sold to third parties and are not used for advertising.
We do not use advertising cookies, and neither our website nor the platform contains third-party tracking pixels. We also use Vercel Web Analytics — a privacy-friendly analytics service that does not use cookies or collect personally identifying information — to understand how the platform is used in aggregate. Product and marketing emails we send may include standard open and click measurement (see "Email engagement" above); transactional emails do not. You may block or delete cookies in your browser settings. Blocking our analytics cookies does not affect your use of the website; blocking essential cookies will prevent you from signing in.
11. Children's Privacy
Sourcemarking is a business tool intended for adults. We do not knowingly collect personal information from anyone under the age of 18. If we become aware that we have collected data from a minor, we will delete it promptly.
12. Changes to this Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and update the effective date above. Your continued use of Sourcemarking after changes are posted constitutes acceptance of the updated policy.
13. Contact
If you have questions about this Privacy Policy or how we handle your data, please contact us at .