Privacy Policy
Last updated: July 2026
1. General
This policy explains what information DDS — Demand Driven Sourcing (“DDS,” “we”) collects when you use the Service, how we use it, with whom it is shared, and how you can exercise your rights. Use of the Service is subject to this policy and our Terms of Use. Privacy inquiries: partners@ddssourcing.com.
2. Information We Collect
- Account details: email address, full name, and company name (used to sign outreach to manufacturers).
- Usage data: the suppliers and products you ask us to check, check results, draft outreach, and correspondence managed on the platform with manufacturers.
- Payment data: processed by Paddle.com Market Limited (Paddle). We do not see or store your card details — we only receive a payment confirmation from Paddle.
- Technical data: IP address, browser/device type, and statistical usage data (subject to your cookie consent).
3. How We Use Information
- To operate the Service: run checks, produce reports, and email you notifications/a report link;
- To send outreach to manufacturers on your behalf — only after your explicit approval;
- To manage payments, credits, and subscriptions;
- To provide support and improve the Service’s quality and accuracy;
- To meet legal obligations and prevent misuse.
4. The Shared Supplier Catalog — Important Disclosure
To improve check quality for all users, DDS maintains a shared supplier catalog. When a check identifies a manufacturer, we may add to the shared catalog public identity data only about that manufacturer — name, domain, country, category, public source links, and a “found/under-review” status. This lets one user’s check save work for another.
What is never shared: your business identity, your private supplier lists, your specific check queries, the reports produced for you, and your correspondence with manufacturers — all of these are private to your account and isolated at the database level. The shared catalog is a public identity directory, not a sharing of your business information.
5. Sub-Processors (Third-Party Providers)
We use professional providers to operate the Service. Data is shared with them only to the extent required:
- Supabase — database, authentication, and storage (secured hosting, EU region).
- Render — running the check engine.
- Vercel — website hosting.
- Paddle — payment processing and receipts (Merchant of Record).
- Anthropic (Claude) — AI analysis of the public information and your query text.
- Resend — email delivery (notifications, report links, outreach to manufacturers after your approval).
- CallMeBot — an internal WhatsApp notification to the DDS team when you submit the contact form or the sign-up form on the site, so we can get back to you quickly. The notification includes the contact details you entered in that form (name, phone, and email).
- Cloudflare (Turnstile) — a "human, not a bot" check on our forms and sign-up, protecting the service from automated abuse. The check sends Cloudflare a single-use technical token and your IP address; it does not send your name, email, phone, or the contents of the form.
- Sentry — technical error monitoring. When something breaks on the site, a technical error report is sent so we can fix it. We do not send them the content of your checks, your supplier details, or your email address.
- Google Analytics and Microsoft Clarity — statistical measurement and UX improvement (loaded only after your cookie consent). Vercel Analytics — anonymous, cookieless measurement.
6. Cookies & Measurement
We use essential cookies to run authentication and the Service. Measurement cookies (Google Analytics, Microsoft Clarity) load only after you consent in the cookie banner; you can change your choice anytime via your browser settings. Vercel Analytics is anonymous and does not use cookies. Separately, error monitoring (Sentry) runs at all times and does not depend on consent — it is necessary for the security and stability of the Service: it reports technical errors only, uses no cookies, and we do not pass it the content of your checks or your identity.
7. Data Retention
We retain account and check details for as long as your account is active, so you can access your check history. Information required for accounting or legal purposes is retained as required by law. You may request deletion of your account and the personal data in it at any time.
8. Data Security
We apply reasonable, accepted security measures: encryption in transit, database-level data isolation between users (Row-Level Security), and access controls. However, no transmission over the internet is perfectly secure, and complete immunity cannot be guaranteed.
9. Your Rights
Subject to the Israeli Protection of Privacy Law, 5741-1981 (and, where applicable, EU data-protection regulations), you have the right to access the personal data we hold about you, request its correction or deletion, and object to certain uses. To exercise a right, contact us at partners@ddssourcing.com.
10. International Transfers
Some of our sub-processors process data outside Israel (including in the EU and the US). Our engagements with them are subject to accepted contractual safeguards ensuring an adequate level of data protection.
11. Changes to This Policy
We may update this policy from time to time. A material change will be posted on this page with an updated date. Continued use of the Service constitutes acceptance of the updated policy.
12. Contact
For privacy questions or requests: partners@ddssourcing.com.