Privacy Policy

Effective 2026-09-24

1. Who this policy covers

This Privacy Policy describes what information SupLoc collects from shoppers and merchants, and how it is used. Questions about this policy can be sent to support@suploc.shop.

2. Shoppers — search and location

You do not need to create an account or sign in to search SupLoc or view store listings.

If you choose “Use my location,” your browser provides SupLoc with your device's precise coordinates to run that search. SupLoc's application does not save those precise coordinates in its database or in the remembered-location cookie described below — they are used to compute that search and are not written to any shopper-related application record. This does not mean the underlying request is invisible to network and hosting infrastructure generally; see “Third parties and infrastructure” below for how request- and log-level information may be processed at that layer.

If you instead enter a ZIP code and choose to have SupLoc remember it, that ZIP code — along with the approximate coordinates and search radius derived from it — is stored in a first-party browser cookie (suploc_location) for up to one year, so your general area is remembered on your next visit. You can remove this cookie at any time using the “Clear” control next to your remembered location on the SupLoc homepage.

Your search query, category, sort order, and page number may appear in the page URL as you browse, but SupLoc does not use that URL state to create a shopper profile.

3. Merchants and account data

If you connect a store to SupLoc, we collect and use:

  • Sign-in identity. SupLoc uses Google sign-in for merchant accounts; we receive the basic profile information Google provides (name, email address).
  • Business and store data. Your business name, which you choose and can change at any time, and your store location details (address, contact information, and hours), which come from your connected Square account.
  • Square-authorized catalog, inventory, and location data. Product, inventory, and store location information your Square connection authorizes SupLoc to read, so it can be shown to shoppers.
  • Square OAuth credentials. Access and refresh tokens issued by Square when you connect, stored in encrypted form and used only to read the information above.
  • Synchronization and operational records. Records of sync activity and connection status, used to operate and troubleshoot your listing.
  • Terms acceptance records. A record of which version of the Terms of Service you accepted and when, kept as durable evidence of that acceptance.
  • Publication review records. New stores are reviewed before they are published to shoppers. SupLoc keeps a record of each decision to approve, decline, or withdraw your store's public listing, together with a limited factual snapshot of your store's listing readiness at the time of that decision (for example, whether your point-of-sale connection was active and how many store locations and in-stock products were eligible to be shown). These records do not copy your product or store listing text.

Store addresses may also be geocoded (converted to map coordinates) by a third-party service so your store can appear in nearby-location searches — see “Third parties and infrastructure” below.

4. Third parties and infrastructure

SupLoc relies on the following categories of third-party providers:

  • Google — merchant sign-in.
  • Square — merchant authorization and the catalog, inventory, and location integration. Product images shown on SupLoc may load directly from Square-hosted infrastructure when a listing is viewed, rather than being copied to SupLoc's own servers.
  • Geocodio — converts a merchant's store address into map coordinates for location-based search.
  • Vercel — hosts and runs the SupLoc application, and necessarily processes request and technical log information (such as IP address and request metadata) as part of serving the service.
  • Neon — hosts SupLoc's database.
  • Resend — delivers SupLoc's internal operational email, such as a notice to SupLoc that a new store is ready for publication review. These messages are sent to SupLoc, not to shoppers, and contain only the limited store information needed for that purpose, such as the store name, the connected point-of-sale provider, and summary counts of the store's listing readiness.

Each of these providers processes data under its own privacy policy in addition to this one. SupLoc does not send a shopper's precise device location to Google, Square, Geocodio, or Resend — it is used only within SupLoc's own request handling (which necessarily passes through SupLoc's hosting infrastructure, as described above) to compute search results.

5. Cookies and tracking

SupLoc uses:

  • a first-party remembered-location cookie (suploc_location), described above; and
  • authentication/session cookies for merchants who sign in to manage their store.

SupLoc does not currently use advertising cookies, and does not currently operate a behavioral analytics or tracking system. SupLoc does not sell or share personal information for cross-context behavioral advertising under its current product.

Do Not Track. SupLoc does not currently respond differently to a browser's Do Not Track signal, because SupLoc does not currently engage in cross-site behavioral advertising or tracking. SupLoc does not currently use third parties to track users over time across unrelated websites for advertising purposes.

6. Data retention

SupLoc retains information for as long as reasonably necessary to provide and secure the service, maintain operational and legal records, comply with applicable legal obligations, resolve disputes, and enforce our agreements.

When Square authorization for a connection is definitively revoked or ended, SupLoc removes the Square-derived product, inventory, and location content associated with that connection, consistent with the disconnection and data-handling description in the Terms of Service. Limited SupLoc-owned identity, account, and operational or legal records (such as your account, a stable store identifier, sync history, and Terms acceptance records) may continue to be retained where reasonably necessary and legally permitted, even after that content is removed.

If you delete a shop using “Delete shop” in your SupLoc dashboard, SupLoc removes that shop's publication review records, including related internal notification records, along with it. Internal notification emails that were already sent to SupLoc before the deletion are not recalled.

If you would like to request deletion of your account or associated data, contact support@suploc.shop; requests are handled in accordance with applicable law and the retention provisions described above.

7. Security

SupLoc uses reasonable technical and organizational safeguards to protect the information it stores, including safeguards for stored Square credentials. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.

8. Changes to this policy

This Privacy Policy is effective as of the date shown at the top of this page. If we make a material change to how SupLoc collects or uses information, we will update this page and its effective date.

9. Contact

Questions about this policy can be sent to support@suploc.shop. You may also request to access, correct, or delete information associated with you through that address, subject to applicable law and the retention provisions described in Section 6.