Privacy Policy
Last updated: July 2026
Overview
What we collect
We collect the minimum data needed to give you an account and run the service:
- Name — from your Google or GitHub profile, used to address you in the dashboard and chat.
- Email — from your OAuth provider, used as your unique sign-in identifier and for important notifications (e.g. order updates).
- Content you create — orders, catalog entries, and chat messages you send or receive.
Authentication & session
Sign-in is handled by Supabase Auth using OAuth (Google or GitHub). We never see or store your password. Supabase issues a short-lived session cookie that keeps you signed in — this is the only cookie we set, and it expires when you sign out.
How we use your data
We use the data above to:
- Authenticate you and keep your account secure.
- Display and manage your orders, catalog, and chat history.
- Send transactional notifications (e.g. new order alerts).
We do not sell, rent, or trade your data to third parties.
How we keep your data secure
Data is stored in Supabase (Postgres + Row-Level Security), which means every read and write is checked against a per-user policy before it reaches the database. All traffic is served over HTTPS. Access to the database is gated by the same policies — even our own team can only see what your role allows.
Your rights
You can request a copy of your data, ask us to correct it, or close your account at any time. Closing your account permanently deletes your profile, orders, and chat history.
Contact
Questions, concerns, or data requests — reach out to Nelsen Chandra at nelsen@example.com.