1. Who is responsible
SupplierSift is operated by Travis Steward in Alberta, Canada. In this policy, “SupplierSift,” “we,” and “us” refer to Travis Steward operating the SupplierSift service.
For personal information submitted through a customer account, the customer organization decides why the information is processed. SupplierSift processes it to provide the service. For account, website, sales, and support information collected directly by us, SupplierSift is responsible for that information.
2. Information we handle
Account and business information
We collect names, business email addresses, company details, roles, account membership, login records, settings, and support communications.
Invoices, receipts, and workflow records
Customers send supplier invoices, receipts, email content, attachments, project references, vendor details, amounts, tax information, approval records, and other accounts payable material. These records can contain personal information about workers, suppliers, project managers, or other people.
Connected-service information
When a customer connects another service, we receive the identifiers, permitted business records, configuration, and authorization material needed to operate that connection. Connections can include Microsoft 365, Procore, QuickBooks Desktop through Conductor, Stripe, and Twilio.
Website and device information
Our public marketing pages use Google Analytics 4 to collect page views, approximate location, browser and device details, referring pages, and interactions such as opening the contact form. Google Analytics does not run on the SupplierSift dashboard, login page, or private review links. Cloudflare also processes request, network, and security data needed to deliver and protect the site.
3. Why we use information
- Receive, read, validate, route, approve, and record invoices and receipts.
- Connect customer-authorized Procore, QuickBooks Desktop, Microsoft 365, email, billing, and messaging services.
- Authenticate users, enforce tenant and role boundaries, and secure review links.
- Operate support, billing, service communications, and customer-requested workflows.
- Detect abuse, investigate failures, maintain audit history, and improve service reliability.
- Understand public-site traffic and respond to sales inquiries.
- Meet legal, accounting, security, and regulatory obligations.
We do not sell personal information. We do not use customer documents for interest-based advertising, and we do not use them to train a general-purpose SupplierSift model.
4. Automation and human decisions
SupplierSift uses automated extraction and deterministic checks to read accounts payable documents and prepare workflow suggestions. Google Gemini receives document content for extraction tasks. Cross-provider model processing may be used when the primary extraction path fails.
Uncertainty stays visible for review. Customers control approvals and destination writes. SupplierSift does not make final employment, credit, legal, or payment decisions about a person.
5. Service providers and connected systems
We disclose information only as needed to run the service, follow a customer instruction, protect the service, complete a business transaction, or comply with law. Current providers and connected systems include:
- Cloudflare for website delivery, Workers, email processing, security, and R2 document storage.
- Neon for hosted PostgreSQL records.
- Google for Gemini document extraction and Analytics on public marketing pages.
- Microsoft when a customer connects a Microsoft 365 mailbox.
- Procore for customer-authorized project data and confirmed writes.
- Conductor for the customer-authorized QuickBooks Desktop bridge.
- Twilio for email delivery signals and receipt or worker messaging where enabled.
- Stripe for payment and subscription administration where billing is enabled.
These providers can process information in Canada, the United States, or other countries where they operate. Information in another country can be subject to that country’s laws and lawful access requests.
6. Retention and deletion
We keep information while an account is active and for as long as needed to provide the service, preserve an audit trail, resolve disputes, meet legal or accounting duties, and enforce agreements. Retention can also be set by a customer agreement or service configuration.
Source documents that are not valid business records may be discarded while a limited workflow record is kept. Backups and provider systems can take additional time to cycle out after deletion. We may retain records when the law requires it or when needed for a legal claim, security investigation, or fraud prevention.
7. Security
We use access controls, tenant checks, secure cookies, scoped review links, encrypted Procore connection tokens, managed infrastructure secrets, and action history. The level of protection depends on the sensitivity of the information. No internet service can promise absolute security.
Our Security page describes the current technical boundaries and providers. It does not claim an unearned certification.
8. Your choices and requests
You may ask about personal information we hold about you, request access or correction, withdraw consent where consent is the legal basis, or raise a privacy concern. Some records may be controlled by a SupplierSift customer. In that case, we may direct the request to that organization.
You can also ask us to delete information. We will assess the request against the customer’s instructions, applicable law, active disputes, and required business records. We may need to verify your identity before acting.
9. Cookies and analytics
SupplierSift uses essential browser storage and cookies for authentication and security. Google Analytics runs on public marketing pages to measure visits and site interactions. We do not use advertising pixels or cross-site behavioural advertising on the service.
You can limit analytics through browser privacy controls, content blockers, or Google’s opt-out tools. Blocking essential cookies can prevent login or dashboard use.
10. Children
SupplierSift is a business service and is not directed to children. Do not submit a child’s personal information unless it is necessary for a legitimate business record and you have authority to do so.
11. Changes to this policy
We may update this policy as the service, providers, or legal requirements change. We will post the revised policy here and change the effective date. We will give customers additional notice when a change materially affects how we handle personal information.
12. Contact
Travis Steward is SupplierSift’s privacy contact. Email support@suppliersift.com with “Privacy” in the subject line. You may also use the Contact button in the site footer.
This policy describes SupplierSift’s current practices. A customer contract or data-processing agreement can add stricter requirements for that customer.