Legal
Privacy Policy
Sourcemarking LLC · Effective September 17, 2026 · United States

1. Who We Are

Sourcemarking LLC ("Sourcemarking," "we," "us," or "our") operates the Sourcemarking platform at sourcemarkinglabs.com. We provide procurement price benchmarking and vendor management tools for small and medium businesses in the United States. Sourcemarking is offered solely to U.S.-based businesses, and we store and process data in the United States. We do not knowingly offer the Service to, or collect personal information from, individuals located outside the United States. Questions about this policy can be sent to .

2. What Information We Collect

We collect information in three ways:

Information you provide directly:

Information collected automatically:

Information from third parties:

How benchmark prices are shared between customers. When we look up what a vendor charges for an item, we keep that vendor price and reuse it to answer the same question for other customers, so the same lookup is not repeated needlessly. What is pooled is the vendor's price for a publicly listed product — never your identity, your business, the price you pay, your quantities, your spend, or the fact that you searched for it. No customer can see another customer's catalog, prices, or activity, and we do not compare your prices against other customers' prices.

3. How We Use Your Information

We use the information we collect to:

We do not sell your data, and we do not use your procurement catalog data or pricing information to train machine learning models. The third-party AI providers that process your data to deliver the Service do not use it to train their models.

4. How We Share Your Information

We do not sell your personal information to third parties. We share information only in the following circumstances:

5. Data Retention and Deletion

We retain your account and catalog data for as long as your account is active. Canceling a paid subscription does not delete your data — your account simply moves to the Free plan and your data remains available to you.

You can permanently delete your account and its data at any time from your account settings, or by contacting us at . When you do, we remove your personal and business data — including your catalog, vendors, saved items, and uploaded documents — from our active systems promptly. Deletion is immediate and cannot be undone; there is no recovery period.

A limited set of records may be retained after deletion where we have a legal obligation or legitimate need to keep them — for example, records used for tax, accounting, dispute resolution, or fraud and abuse prevention (such as security and enforcement logs) — and only for as long as necessary for those purposes. Residual copies may also remain in our providers' encrypted, access-controlled backups for a limited period in the ordinary course before being overwritten. Activity and audit logs are retained on a rolling basis according to your account settings.

We keep a de-identified record of savings confirmed on the platform — the savings amount, the date, the product category and the plan — so we can report total savings across all customers. When you delete your account, these records are disconnected from you and your business, and nothing left in them identifies you.

Website visit records are kept for up to 25 months and then deleted. The record of how your account first arrived at our website is kept while your account is active and is deleted when your account is deleted.

6. Security

We use industry-standard security measures including encryption in transit (TLS), encrypted storage, access controls, bot protection, rate limiting, and account- and IP-based abuse controls to protect your data. Our platform is built on Supabase, which maintains SOC 2 Type II compliance. However, no system is completely secure, and we cannot guarantee the absolute security of your information. You are responsible for keeping your account credentials confidential.

7. Your Rights

Subject to applicable U.S. federal and state law, you may have the right to:

To exercise any of these rights, contact us at . We will respond within 30 days.

8. Illinois and Other State Residents

Illinois residents have additional rights under the Illinois Personal Information Protection Act (PIPA) and related statutes. We do not sell personal information. If you believe your rights under Illinois law have been violated, you may contact the Illinois Attorney General's office.

Residents of other U.S. states — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and a growing number of others — may have additional rights under their state privacy laws, such as the right to access, correct, delete, or obtain a copy of their personal information, and to opt out of targeted advertising or the sale of personal information (neither of which we do). To exercise any of these rights, contact us at .

9. California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), gives you specific rights regarding your personal information. This section supplements the rest of this policy.

Categories of personal information we collect. In the preceding 12 months, we have collected the following categories of personal information:

We collect this information for the business purposes described in "How We Use Your Information" and disclose it only to the service providers listed in "How We Share Your Information." We do not use or disclose sensitive personal information beyond the purposes permitted under the CCPA/CPRA.

Your California rights. Subject to certain exceptions, you have the right to:

We do not sell or share your personal information as those terms are defined under the CCPA/CPRA, and we have not done so in the preceding 12 months. We do not knowingly sell or share the personal information of consumers under 16 years of age.

To exercise your California rights, contact us at . We will verify your request using the information associated with your account and respond within 45 days (which may be extended by an additional 45 days where permitted by law). You may use an authorized agent to submit a request on your behalf, subject to verification of the agent's authority.

10. Cookies

If you use Sourcemarking on a phone, we may also set an essential cookie that records that this device is allowed to use the phone version of the app. It identifies the device, not you, and is removed when it expires or when access is withdrawn. Notifications are separate from cookies: they are granted through your browser’s own permission prompt and can be withdrawn at any time in the app or in your phone’s settings.

We use essential cookies and local storage to keep you logged in, maintain your session, remember display preferences you set (such as how many decimals a table shows), and — on our public mobile page — hold a random identifier that lets us count returning visitors without recognising who they are.

We also use our own first-party analytics cookies to understand how visitors find and use our website: a randomly generated visitor identifier (kept for up to 13 months), a visit identifier that expires after 30 minutes of inactivity, and a record of how your browser first arrived at our website (kept for up to 6 months). These cookies are set and read only by Sourcemarking. They are never shared with or sold to third parties and are not used for advertising.

We do not use advertising cookies, and neither our website nor the platform contains third-party tracking pixels. We also use Vercel Web Analytics — a privacy-friendly analytics service that does not use cookies or collect personally identifying information — to understand how the platform is used in aggregate. Product and marketing emails we send may include standard open and click measurement (see "Email engagement" above); transactional emails do not. You may block or delete cookies in your browser settings. Blocking our analytics cookies does not affect your use of the website; blocking essential cookies will prevent you from signing in.

11. Children's Privacy

Sourcemarking is a business tool intended for adults. We do not knowingly collect personal information from anyone under the age of 18. If we become aware that we have collected data from a minor, we will delete it promptly.

12. Changes to this Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and update the effective date above. Your continued use of Sourcemarking after changes are posted constitutes acceptance of the updated policy.

13. Contact

If you have questions about this Privacy Policy or how we handle your data, please contact us at .