This Privacy Policy (the "Policy") describes the manner in which Sunhub and its affiliates (collectively, "Sunhub," "we," "us," or "our") collect, use, disclose, and otherwise process personal information in connection with the Sunhub Source Center website, applications, and related services (collectively, the "Services"). This Policy should be read in conjunction with our Terms of Service and Cookie Policy, which are incorporated herein by reference.
1. Scope and Applicability
This Policy applies to personal information processed by Sunhub in its capacity as a controller in connection with the operation of the Services. It is intended to satisfy the disclosure obligations imposed by applicable data protection laws, including, without limitation, the General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), the United Kingdom GDPR, and the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act ("CCPA").
2. Categories of Personal Information Collected
We may collect and process the following categories of personal information:
- Identifiers and Account Information. Name, business email address, telephone number, company affiliation, professional role, credentials, and authentication data.
- Commercial Information. Information submitted in connection with sourcing requests, quotations, specifications, transactional correspondence, and related documentation.
- Internet or Network Activity Information. Internet protocol address, device identifiers, browser type, referring sources, pages accessed, and interaction telemetry.
- Geolocation Information. Approximate location derived from network metadata.
- Inferences. Inferences drawn from the foregoing to characterize preferences and procurement behavior in connection with the Services.
3. Purposes of Processing
Personal information is processed for the following purposes:
- To provide, maintain, administer, and improve the Services;
- To authenticate users and protect the security and integrity of the Services;
- To facilitate the matching of sourcing requests with verified counterparties;
- To deliver transactional communications and respond to inquiries;
- To perform analytics, statistical analysis, and service development activities;
- To deliver marketing communications, subject to applicable consent requirements; and
- To comply with legal, regulatory, accounting, and tax obligations.
4. Legal Bases for Processing
Where the GDPR or other equivalent legislation applies, we rely on the following legal bases:
- Performance of a contract to which the data subject is a party (Art. 6(1)(b) GDPR);
- Compliance with legal obligations to which we are subject (Art. 6(1)(c) GDPR);
- Our legitimate interests, including operating, securing, and improving the Services (Art. 6(1)(f) GDPR); and
- Consent, where required by applicable law (Art. 6(1)(a) GDPR).
5. Disclosure of Personal Information
We may disclose personal information to authorized service providers, hosting and infrastructure providers, communications providers, analytics and security providers, professional advisors, and governmental or regulatory authorities, in each case as necessary to fulfill the purposes set forth herein or as required by applicable law. We do not sell personal information for monetary consideration. To the extent that any sharing of personal information for cross-context behavioral advertising constitutes a "sale" or "sharing" under the CCPA, users may opt out through our consent management mechanism.
The third-party processors that may receive personal information in connection with measurement and marketing are:
- Google (Analytics 4, Tag Manager, Ads). Aggregated usage measurement and advertising attribution. Loaded only with analytics consent; advertising signals only with marketing consent, governed by Google Consent Mode v2.
- Meta Platforms (Facebook Pixel). Advertising measurement and remarketing. Loaded only with marketing consent.
- ActiveCampaign. Site-visit tracking associated with marketing communications. Loaded only with marketing consent.
- Lovable Cloud (Supabase). Hosting, authentication, database, and storage infrastructure. Strictly necessary to operate the Services.
Pseudonymous visit and engagement records (visitor sessions and call-to-action interactions) are collected only where analytics consent has been granted, are retained for no longer than 24 months, and are deleted when you delete your account. A complete inventory of cookies and similar technologies is set forth in our Cookie Policy.
6. International Transfers
Personal information may be transferred to, stored in, and processed in jurisdictions other than the jurisdiction of residence of the data subject. Where such transfers occur, we implement appropriate safeguards in accordance with applicable data protection laws, including, where relevant, the European Commission's Standard Contractual Clauses and supplementary measures as warranted.
7. Retention
We retain personal information for such period as is necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, tax, or reporting requirements, and to establish, exercise, or defend legal claims. Records may be retained in anonymized form thereafter where permitted by law.
8. Your Rights
Subject to and in accordance with applicable law, data subjects may exercise rights of access, rectification, erasure, restriction of processing, objection to processing, portability, and withdrawal of consent. California residents may exercise the rights to know, delete, correct, and opt out of any "sale" or "sharing" of personal information, and to limit the use of sensitive personal information. The exercise of such rights may be effected as follows:
- Export your data. Available at Account Settings → Security.
- Delete your account. Available at Account Settings → Security → Privacy & Data Controls.
- Cookie preferences. May be modified at any time through our consent management mechanism.
9. Security
We maintain administrative, technical, and organizational measures designed to safeguard personal information against unauthorized access, disclosure, alteration, or destruction. No method of transmission or storage, however, is absolutely secure, and we cannot guarantee the absolute security of personal information.
10. Children
The Services are intended for business users and are not directed to individuals under the age of sixteen (16). We do not knowingly collect personal information from such individuals.
11. Amendments
We reserve the right to amend or update this Policy at any time, in our sole discretion, to reflect changes in our practices, the Services, or applicable legal or regulatory requirements. The revised Policy shall be effective as of the date of its publication on the Services.
12. Contact
Inquiries concerning this Policy, or the exercise of rights conferred under applicable data protection laws, may be directed to our privacy office at privacy@sunhub.com.