SUPROOF

Public policy

Privacy Policy

This policy explains the information Suproof processes to provide buyer accounts, supplier verification and client reports.

Last updated: August 28, 2026

1. Information we process

We may process account information such as your name, email, organization, country and phone number; supplier or factory information you submit; documents and evidence used for verification; case activity; and technical security logs.

Apple processes in-app purchases and subscriptions on iOS. Suproof stores signed transaction references, subscription periods, refund status and a pseudonymous purchase account identifier. Stripe processes web payment-card information. Suproof records payment references and status but is not designed to receive or store raw card numbers or card-security codes.

2. Why we use information

We use information to authenticate users, create and manage verification cases, conduct due diligence, communicate case status, produce reports, prevent abuse, protect the platform, maintain audit records and improve service reliability.

3. Service providers

Hosting and authentication use Vercel and Supabase. When you choose AI research, transcription or document analysis, relevant prompts, selected images, audio or document contents may be sent to OpenAI or Doubao to perform that request. The mobile app asks for confirmation before sending user-selected content to an AI provider. Company searches and field-service requests may be processed by specialist providers such as QCC and UU according to the service selected.

Suproof uses infrastructure and specialist service providers to operate the platform, including hosting, database/authentication, payment processing and related security services. These providers process information according to their roles and applicable agreements.

4. Client and supplier information

Supplier records are internal investigation records and do not create supplier accounts. Client-facing evidence and reports are released through access-controlled workspaces. We do not intentionally make private case data public.

5. Retention

We retain account, case, evidence, payment-reference and audit information for as long as reasonably necessary to provide the service, preserve the integrity of reports, meet operational or legal obligations, resolve disputes and protect against abuse. Retention periods may differ by data type and jurisdiction.

6. Security

Suproof uses role-based access controls, row-level database security, private evidence boundaries and audit-oriented controls. No system can guarantee absolute security, so users should also protect account credentials and promptly report suspected unauthorized access.

7. Your choices

In the iOS app, open Account > Delete account to verify your identity and permanently remove your login, profile, private AI history and personal support content. Company records shared with other members and financial records are retained separately from your deleted login where needed for the service or applicable obligations. A team’s last active Super Admin must assign a replacement first. Deleting your account does not cancel an Apple subscription; manage it in Apple subscription settings. Unused personal digital credit becomes inaccessible after deletion.

You may request reasonable access, correction or deletion of personal information, subject to legal, security, audit and contractual retention requirements. Requests may require identity verification.

8. Mobile permissions

You choose when to share camera images, selected photos or files, audio recordings and precise location for a field visit. Location is requested for an explicit capture, not background tracking. You can deny or revoke device permissions in iOS Settings. These features may be unavailable without the relevant permission. We do not use these inputs for advertising tracking across other companies’ apps or websites.

9. Contact

Privacy questions or requests can be sent to info@yiwulian.org.