Last updated · August 9, 2026

Privacy

SupplySlate is an agent-native supply network operated by Timo Akkila in the Netherlands. This notice covers the public website, API, MCP service, buyer and supplier workspaces, sourcing workflows, and operator tools. Privacy questions may be sent to timo@supplyslate.com.

Information SupplySlate processes

Identity and account data. We process a business email address, display name, organization, role, identity-provider subject, session and credential metadata, and account-security events. Raw API keys, session tokens, and CSRF tokens are not stored; one-way hashes are used for verification.

Project and commercial data. When you use the network, we process the requirements, files, artifact metadata, BOMs, shipping region, sourcing requests, supplier matches, disclosed RFQs, clarifications, quotes, approvals, merchant handoffs, merchant-confirmed orders, fulfillment, issues, returns, and warranty state needed to provide the workflow.

Supplier and public-source data. Supplier profiles may contain business contact information and source-backed company, category, capability, brand, and service facts observed on supplier-owned public pages. Supplier participation, catalog, quote, and fulfillment data remain distinct from public research.

Technical and usage data. We and our hosting provider process IP address, user agent, requested route, timestamp, response status, and security events to deliver and protect the service. SupplySlate stores privacy-preserving activity records using a one-way actor hash, route template, client class, status, and date. Agent integrations may supply a client name or user-agent label. We do not use advertising trackers, behavioral advertising, or third-party analytics cookies.

Why we use information

We use information to provide the service requested by a participant; authenticate and authorize people and agents; validate and source projects; route only human-approved requests; return comparable offers; record approvals and merchant state; prevent abuse; maintain auditability; improve reliability; and keep public supplier evidence accurate. Depending on the context, processing is necessary to provide the requested service, meet legal obligations, or support legitimate interests in operating and securing the network. Where consent is legally required, we request it separately.

Agents, suppliers, and recipients

The buyer controls its own agent and organization credentials. SupplySlate records actions against the relevant organization and credential. A matched supplier receives nothing automatically: a human approves the exact supplier, recipient, message, and artifact scope first. Approved information may then be shared with that supplier, a connected catalog or fabrication provider, or a merchant needed to complete the requested sourcing or handoff. SupplySlate does not disclose unrelated project data.

Before an account exists, buyer access requests and supplier authority claims store the details you submit (including your name, email, and organization or company details) so a human operator can verify them. Each application record stores only a SHA-256 hash of its private status token; the link lets you read the review decision without email and without an account, and anyone holding it can read that decision. If a caller supplies an idempotency key, SupplySlate temporarily retains the exact response—including the private link—for up to 24 hours so a lost response can be replayed safely; the request itself is represented in that retry ledger only by a SHA-256 digest.

Service providers

We use infrastructure and communication providers to host the service, store data, authenticate users, deliver approved messages, and connect attributed catalog or fabrication sources. These providers process information only for the relevant operational purpose. The current API identifies connected supply-data providers and their status. We do not sell personal information.

Retention

One-time OAuth state normally expires after 10 minutes and browser sessions after 30 days. Applicant status links expire after 90 days, after which the underlying application record remains only in operator review history. Downloadable organization exports expire after 7 days. Rate-limit counters are removed after 2 hours, privacy-preserving activity telemetry after 90 days, and malware-rejected artifacts are scheduled for deletion within 24 hours. Active project, supplier, quote, approval, order, audit, and correspondence records are retained while needed to provide the service, resolve disputes, preserve transaction evidence, meet legal obligations, or establish legal claims. Public-source supplier evidence is reviewed, corrected, superseded, or removed when it is no longer supportable. Legal holds override ordinary deletion.

Your rights and controls

Depending on applicable law, you may request access, correction, a machine-readable export, deletion, restriction, or objection. Signed-in organization owners can create export, restriction, deletion, and restoration requests in the product; requests that affect shared commercial or legally required records receive human review. You may also contact timo@supplyslate.com. People in the EEA may lodge a complaint with their data-protection authority, including the Dutch Autoriteit Persoonsgegevens.

Security and prohibited data

SupplySlate uses scoped authorization, tenant isolation, encryption in transit, hashed credentials, short-lived access grants, audit events, rate limits, and fail-closed file scanning. Do not submit personal consumer records, payment credentials, regulated data, export-controlled material, or safety-critical confidential files unless SupplySlate has explicitly approved the data class and workflow in writing.

Changes

We will update this notice when the product, providers, retention rules, or legal obligations materially change. The date above identifies the current version.