← Back to home

Privacy Policy

Last updated: July 16, 2026

Draft under legal review. This policy describes how the pilot handles data today. It will be finalized with counsel before general availability.

1. The principle: the least data necessary for each job

  • Your financial ledger never leaves your browser. When you upload spend data, it is parsed, categorized, and aggregated on your device; only category totals (e.g. “Metals: $1.6M”) are sent to us for the emissions calculation. Vendor names and ledger lines stay local.
  • Third-party identifiers are redacted before AI calls. Supplier names, email addresses, and phone numbers are replaced with placeholders before a prompt is sent to our LLM provider, and restored only on our side afterward.
  • Supplier contact emails are encrypted at rest and decrypted only at the moment a buyer explicitly triggers a send. Our own interfaces and APIs show only a masked form (j***@company.com).

2. Who's who (this platform is three-sided)

If you hold an account (supplier or buyer): we process the data you upload to provide the service to you. Your questionnaire content, vault, and results are scoped to your organization.

If you are a supplier contact uploaded by a buyer: a customer of ours listed you as a supplier contact for sustainability reporting. We store your email encrypted, use it only to send that buyer's data request when they trigger it, and every message carries a one-click unsubscribe that permanently suppresses your address. We do not use supplier contact lists for our own marketing.

If you respond to a buyer's request: the structured sustainability data you submit is shared with the requesting buyer — that is the purpose of the request, and the onboarding page says so before you submit. Your raw uploads and data vault are not shared. If a buyer's report includes figures for suppliers who did not respond, those figures are estimates from industry averages, labeled as such — not data you provided.

3. What we store, and where

  • Account data (email, role, organization) — Supabase (auth + database, row-level security per tenant).
  • Questionnaires, generated answers, vault entries — Supabase, scoped to your organization.
  • Supplier lists — names, industry, spend, region in the database; contact emails encrypted at rest (AES-256-GCM).
  • Spend data — category totals only (see §1); we do not receive your ledger.
  • Suppressed emails — kept on the suppression list so we never contact them again.

4. Service providers (subprocessors)

  • Supabase — database, authentication, file storage.
  • Vercel — application hosting.
  • Google (Gemini API) — drafting answers and outreach text. We use billing-enabled (paid-tier) API access, under which Google does not use prompts or responses to improve its products and retains them only briefly for abuse prevention (Gemini API Additional Terms, effective March 23, 2026). Prompts are redacted per §1 before they are sent.
  • Resend — outreach email delivery (only when a buyer triggers sending).

5. Retention, deletion, your rights

Account holders can request export or deletion of their organization's data at any time via the contact below; deletion covers vault, questionnaires, answers, and supplier lists (suppression-list entries are kept, since deleting them would re-enable contact). Supplier contacts can stop all messages with the unsubscribe link in any email. Depending on where you are, you may have statutory rights (access, rectification, erasure, objection) — contact us to exercise them. (Regional specifics — GDPR/CCPA articles, transfer mechanisms — to be finalized with counsel.)

Contact: climacope.com/contact · See also the Terms of Service and, for organizational customers, the Data Processing Addendum.