Data processed
Supplylume stores account email addresses, password hashes, revocable sessions, user-owned searches, usage records, product observations, enrichment evidence, and billing-provider identifiers. Plaintext passwords and Stripe or Apify secrets are not stored in customer-facing records.
Purpose
Data is processed to authenticate users, enforce ownership and plan limits, run requested research workflows, provide exports, manage billing state, prevent abuse, and maintain system reliability.
Third-party processors
The application may use infrastructure providers, Stripe in configured test or production mode, and Apify for requested external research. A final policy must list actual production processors and transfer arrangements.
Retention and rights
[Manual confirmation required: retention periods, deletion process, data-subject request channel, legal bases, cookie disclosures, regional rights, and production subprocessors.]
Security
The application uses hashed passwords, HttpOnly sessions, CSRF protection, ownership checks, server-side entitlements, and restricted secret handling. No system can promise absolute security.
Placeholder updated July 2026.