This Privacy Policy explains how SourceFlow collects, uses, shares and protects personal information when you interact with our website, services, tools, forms, or when you contact us. It describes your rights and choices, and how to contact us. We wrote this policy to be clear and actionable. If you need a copy in another format, email support@sourceflowq.com
Who we are
1.1 Company name
SourceFlow is a sourcing and product development services company that helps founders and brands prototype, source, and scale product manufacturing.
1.2 Contact
Email support@sourceflowq.com for privacy questions, data requests, or security incidents.
Scope of this policy
2.1 When this policy applies
This policy applies to personal information we collect when you visit our website, sign up for or use our services, send files or messages to us, apply for roles, request quotes, or otherwise interact with SourceFlow.
2.2 Information outside the policy
This policy does not cover personal information in public records, information we receive from third parties when permitted by law, or aggregated anonymous data that cannot reasonably be tied to an identifiable person.
Information we collect
We collect information you provide and information we gather automatically.
3.1 Information you provide directly
Contact information such as name, email, phone number, company name.
Billing and payment information when you purchase services, such as invoicing details. Payment processing may be handled by third party payment processors and their privacy notices apply.
Form entries, messages, quotes, proposals, intake forms, typeform responses, and other submissions.
Files and attachments you upload such as CAD files, drawings, images, specifications, code, or other project documents.
Job applicant information including resume, portfolio, work history, references and related communications.
Customer support records and correspondence.
Consent choices and marketing preferences.
3.2 Sensitive information
We do not ask for medical data, government issued identifiers, or other categories of highly sensitive personal information. If you send or upload such data, we will treat it as sensitive and will securely delete it on request. Do not provide social security numbers or other highly sensitive data unless absolutely required and agreed in writing.
3.3 Information collected automatically
Usage data such as pages visited, features used, session duration, and error logs.
Device data such as browser type, operating system, screen size, and IP address.
Cookies and similar technologies for analytics, functionality, and marketing.
How we use information
We use personal information for the following business purposes.
4.1 To provide and operate services
Processing project files, delivering quotes and proposals, communicating project status, billing, shipping coordination, and customer support.
4.2 To improve and secure our services
Product development, debugging, performance monitoring, and security monitoring.
4.3 For marketing and communication
Sending newsletters and promotional communications when you consent, and honoring unsubscribe requests.
4.4 For legal compliance and protection
Complying with legal obligations, enforcing agreements, protecting our rights, and investigating fraud.
4.5 For hiring and human resources
Processing job applications and communications related to recruiting.
4.6 For analytics and business operations
Understanding usage patterns, measuring marketing effectiveness, and running our business.
Legal bases for processing
If you are in the European Economic Area or otherwise subject to data protection laws that require a legal basis, we rely on:
Contract performance where necessary to deliver services.
Our legitimate interests such as improving services, security, and fraud prevention, balanced against your rights.
Consent where required for marketing and certain cookies.
Legal obligations when required by law.
Sharing and disclosure
We do not sell personal information. We share data only as described below.
6.1 Service providers and subprocessors
We may share data with service providers who perform services on our behalf including hosting, analytics, form and intake tools, payment processors, email and marketing platforms, file storage, and customer support tools. Those providers process data under contract and only as needed to provide their services.
6.2 Professional advisors
We may share information with legal advisors, auditors, or other professional advisors to the extent needed.
6.3 Business transfers
If SourceFlow is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction. We will notify affected individuals where required.
6.4 Legal requests and safety
We may disclose information to comply with law, respond to lawful requests, or protect rights, property or safety.
6.5 Aggregated and anonymized data
We may share or publish aggregated data that does not identify an individual.
International transfers
SourceFlow may transfer personal information between countries for processing. When doing so we will protect data using appropriate safeguards such as standard contractual clauses or other legal mechanisms, where required by law.
Retention
We keep personal information only for as long as necessary to fulfill the purposes described in this policy, and to meet legal, tax, accounting, or reporting requirements.
8.1 Typical retention periods
Project and transactional records, including invoices and contracts: seven years.
Marketing consents and unsubscribes: two years or until you unsubscribe.
Job applicant data for candidates not hired: up to two years unless otherwise requested.
Support records and communications: one to three years depending on relevance.
If you request deletion we will remove data subject to legal and contractual retention obligations.
Cookies and tracking
9.1 Types of cookies
We use functional cookies that are necessary for the site to operate, analytics cookies to understand site usage, and optional marketing cookies where you consent.
9.2 Your choices
Most browsers allow you to block or delete cookies. Blocking certain cookies may reduce functionality.
Your privacy rights
Depending on your jurisdiction you may have the following rights.
10.1 Access
Request a copy of the personal information we hold about you.
10.2 Correction
Request correction of inaccurate or incomplete data.
10.3 Deletion
Request deletion of your personal information, subject to legal exceptions.
10.4 Restriction
Request restriction of processing in certain circumstances.
10.5 Portability
Receive your personal information in a portable format when applicable.
10.6 Object and opt out
Object to processing based on legitimate interests and opt out of marketing communications. If you are a resident of California you have the right to opt out of sale of personal information. We do not sell personal information for monetary consideration, but if you believe otherwise contact us and we will investigate.
10.7 How to exercise rights
Email support@sourceflowq.com
and include enough detail to locate your data. We will verify your identity before fulfilling requests to prevent fraud. We will respond within the timeframe required by applicable law.
Security
We use reasonable administrative, technical and physical safeguards to protect personal information. Controls include access restrictions, encrypted communications in transit, secure storage, periodic security reviews, and employee training.
No system is perfect and we cannot guarantee absolute security. If a security incident risks your personal information we will follow applicable notification rules and notify you and regulators as required.
Third party websites and links
Our site may link to third party sites. We are not responsible for their privacy practices. Review the privacy policy of any third party site before sharing personal information.
File uploads and intellectual property
14.1 File uploads
You may upload CAD files, drawings, images, and other project assets. By uploading you represent that you have the right to share those files. We will use uploaded files only to deliver services unless you consent otherwise.
14.2 Intellectual property
You retain ownership of your uploaded work product and project IP unless otherwise agreed in a written contract. Uploading does not transfer ownership except where explicitly stated in a signed agreement.
14.3 Confidentiality and NDA
If you require an NDA we will sign one following our processes. Confidential information shared under an NDA will be handled as confidential and processed only to provide services.
Payment and billing
We may collect billing contact information and details needed to process payments. Payment information may be processed by third party payment processors. We do not store full payment card numbers. For bank transfers or wire payments consult your contract or invoice for instructions.
Hiring and applicants
Application data is used for recruitment. If you do not wish for your data to be retained for future opportunities, notify support@sourceflowq.com
European privacy notice
If you are in the EU, you may request access, rectification, erasure, restriction, portability or lodge a complaint with your supervisory authority. Our lawful bases for processing include contract, consent and legitimate interests.
Changes to this policy
We may update this policy. We will post the revised policy with a new effective date. For material changes we will provide notice via the website or by contacting you if we have your email.
Limitations and disclaimers
This policy describes how SourceFlow handles personal information. It does not create contractual rights beyond those in any signed agreement between you and SourceFlow. We reserve the right to take necessary steps to protect our rights in legal matters and investigations.
How to contact us
For privacy requests, data questions, security incidents or complaints email support@sourceflowq.com
A plain language summary
22.1 The short version
We collect the information needed to provide sourcing and product services, operate our website, bill you, and keep communications working. We do not sell personal information. You can control marketing communications and ask us to access or delete data. We protect data with reasonable safeguards but cannot guarantee perfect security.
Thank you for trusting SourceFlow with your projects. If you want this policy adapted to include specific vendors, a chosen retention schedule, or contract language for NDAs and data processing agreements, tell me which vendors or clauses you want included and I will add them.
© 2025 SourceFlow. All rights reserved.
