Privacy Policy
InsourceAI Pte. Ltd. (“InsourceAI”, “we”, “us”) provides AI-assisted procurement workspaces for buyers and suppliers. This policy explains how we collect, use, disclose, protect and retain personal data when you use the Procurement Agent.
Billing and subscription data
To administer trials, paid plans, upgrades, renewals, cancellations and billing support, we process your workspace and account identifiers, billing contact information, selected plan and currency, subscription status, service dates, usage and promotion records, and Stripe customer, subscription, checkout, invoice and transaction references. Stripe collects payment-method information directly through its hosted payment pages; our application does not store full card numbers or card security codes. We receive payment and subscription notifications from Stripe to maintain access and billing records.
We share the information needed to process your transaction and manage your subscription with Stripe. Where Stripe or its affiliate acts as merchant of record, it also processes information for tax, receipts, transaction support, fraud prevention and dispute handling under its own privacy notice, available at stripe.com/privacy. We may retain billing and transaction records after cancellation or account deletion where needed for accounting, tax, disputes, security or other legal obligations. Cancelling renewal is not the same as requesting deletion of personal data.
For Supplier Priority, we use verified business-email matches to associate supplier workspaces with shared-network profiles and subscription eligibility. Ambiguous matches are not automatically linked. Buyers’ private supplier records are not disclosed to suppliers through this linkage. Supplier-name corrections in a buyer workspace do not rewrite previously sent RFQs, quotes, awards or shared-network identities.
1. Personal data we handle
Depending on how you use the service, we may handle account and workspace information such as your name, work email, company, preferred currency, saved shipping addresses, authentication identifiers and organization membership; procurement information such as BOMs, part numbers, RFQs, quotes, supplier contacts, award decisions and related documents; supplier-network information submitted through an authorized onboarding form, such as company registration details, business contact details, product categories, manufacturers, markets, certifications, consent choices and review status; and service/security information such as session, audit, usage and error records.
2. Connected Gmail and Microsoft 365 accounts
Mailbox connection is optional until you choose to use email-based supplier discovery, RFQ sending or reply monitoring. When you connect a mailbox, we receive connection credentials and the permissions shown on the provider consent screen. Stored mailbox refresh credentials are encrypted and held server-side. The Procurement Agent may search and read relevant messages, threads and attachments to reconstruct supplier history, detect quotation replies and perform actions you request.
Mailbox content may be processed by our application, Google or Microsoft, and AI service providers used for the requested procurement workflow. Supplier-history discovery retains normalized procurement evidence rather than raw message bodies. When a message is matched to an active RFQ reply, InsourceAI retains relevant original reply text, information identifying the source message and any separate translation so buyers can review the evidence behind quote extraction. A translation never replaces the original reply.
3. How we use personal data
- create and secure accounts and workspaces;
- parse BOMs and procurement documents;
- identify and rank suppliers from authorized sources;
- maintain a consented shared supplier network and show active supplier profiles to authenticated buyer workspaces for relevant procurement matching;
- provide Supplier Priority visibility for eligible subscriptions and maintain related service records;
- draft, send and monitor buyer-approved RFQs;
- extract, review and compare supplier quotations;
- provide market benchmarking and procurement recommendations;
- maintain audit, security, abuse-prevention and usage records.
4. Human approval and AI processing
InsourceAI uses automated and AI-assisted processing to classify mailbox evidence, extract procurement data, personalize and translate draft communications, translate supplier replies and make recommendations. Supplier-network matching uses recorded specialisations and consent status; a match does not represent an endorsement or guarantee. Part numbers and commercial values are checked for preservation during translation. No supplier RFQ is sent until a buyer reviews and approves the exact recipient-specific subject, body and attachment protected by the product's approval controls.
5. Service providers and overseas processing
We use third-party AI-processing, cloud-hosting, data-storage and authorized market-data services, as well as connected services from Google or Microsoft. These providers may process the information needed to perform the relevant service. Data may therefore be processed outside Singapore. We take reasonable steps intended to ensure transferred personal data receives a standard of protection comparable to that required under Singapore’s Personal Data Protection Act 2012 (“PDPA”).
6. Retention
We retain personal data only for as long as reasonably necessary for the stated purposes, contractual or security needs, dispute resolution, audit requirements and applicable law. Account deletion removes authentication access and connected-mailbox credentials; some company procurement records may be retained with the former user reference removed where reasonably necessary for audit, contractual or business-record purposes.
7. Security
We use measures intended to protect personal data, including encrypted mailbox-credential storage, workspace access controls, restricted access to sensitive records, protected service credentials and approval checks for outgoing supplier messages.
8. Access, correction, withdrawal and deletion requests
Subject to applicable law, you may ask to access or correct personal data, withdraw consent where consent applies, disconnect a mailbox, or request deletion of data that we no longer need for legal or business purposes. A supplier may also request correction of its shared profile or withdraw from supplier-network matching by contacting our privacy contact; we will stop new matching after processing a valid request, subject to records we must retain.
9. Cookies
The application uses essential authentication/session cookies and similar technologies required to keep users signed in and protect the service.
10. Children
The Procurement Agent is a business service and is not intended for children.
11. Changes
We may update this policy as the service or legal requirements change. We will publish the revised version and effective date here.
12. Data Protection Officer / privacy contact
For privacy enquiries, access or correction requests, or withdrawal of consent, contact privacy@insourceai.sg.