Privacy Notice
This notice describes what personal data Magemcy handles, why, and what you can do about it. It covers the website, the application, and the vendor marketplace.
On this page 12 sections
Who we are
Magemcy is a procurement, e-tendering and vendor-management platform operated by Magemcy, based in Florida, United States.
For anything in this notice, write to our privacy contact or use the contact form.
When we are the controller, and when we are the processor
This distinction decides who you should ask about what, so it is worth being precise:
- We are the controller for your account and billing details, for anything you send us through the website, and for the data we need to run and secure the service.
- We are the processor for the business data a customer puts into their own workspace, their vendor registry, tenders, purchase orders and invoices. That customer decides what goes in and why. If your details are in a company’s private vendor registry because you supply them, that company is the controller, and a request about that record should go to them. We will help them answer it, and we will point you to them if you ask us.
Customers acting as controllers are covered by our Data Processing Addendum.
What we collect
Grouped by where it comes from rather than by legal category, because that is how you can actually check it.
When you create an account
Your email address, display name, and whether you are a buyer or a vendor. Sign-in itself is handled by Google Firebase Authentication, which holds your password (hashed, we never see it) or your Google identity, whether your email is verified, and sign-in timestamps.
When you use a company workspace
Your role, the workspace you belong to, and the records you create: vendors, ratings, invitations to quote, bids, purchase orders, invoices and projects. Vendor records can include commercial registration numbers, tax numbers, certificate expiry dates and contact people, because that is what procurement requires.
When you register as a vendor
Your company profile: name, country, website, brands, categories, service countries, branch offices, logo, and contact name, email and phone. Premium and marketplace-listed profiles are searchable by other signed-in users; the public marketplace shows a reduced profile with contact details removed until someone signs in.
When you apply for a company workspace or a vendor account
What the application asks for: the company’s legal name, country, website, industry and size, its registration and tax numbers with their expiry dates, ISO and other certificates, the registration, tax and certificate documents you upload, and the name, job title, phone and email of the person submitting. Before a workspace or vendor account opens, we verify the application: we read those documents and consult public sources about the business (business registries, its website, sanctions lists and news), including with automated tools, and a member of our team decides. The research report is seen only by that team, never by other customers, and the decision and its reason are recorded against the reviewer who made it.
When you contact us or use the website assistant
What you write, plus context we read from the request itself: IP address, approximate location derived from it, browser, operating system and device type, referring page, language, and the page you were on. Details you type into the chat, and the conversation itself, are stored so we can review misuse and answer you if you later ask what was said.
We collect this context because it is what makes a contact form usable, it separates a real enquiry from an automated one, not because we profile you. We do not use it for advertising.
When we send you email
Delivery records, including the recipient address, the subject, the rendered message and its delivery status. That is how a failed invitation or approval email can be retried instead of silently lost.
Support
Your messages, the page you were on when you wrote, and your browser’s user-agent string, so support can reproduce what you saw.
Why we use it, and on what legal basis
| What we do | Why | Legal basis (UK/EU GDPR) |
|---|---|---|
| Run your account and workspace | To provide the service you asked for | Performance of a contract |
| Verify a company or vendor before opening its account | So that the businesses buying and selling on the platform are real and identifiable | Legitimate interests, and your consent to the document analysis given when you submit |
| Send transactional email (invitations, approvals, verification) | The service does not work without it | Performance of a contract |
| Invite the suppliers a customer lists to register | A customer who uploads its supplier registry can have those suppliers invited to register, so that its requests, orders and payments reach them through the platform. This is one business-to-business email to an address the customer holds, sent in the customer's name; it carries a one-click unsubscribe, and an address that opts out is never invited again | Legitimate interests (the customer's, in reaching its own suppliers; ours, in a marketplace both sides use), balanced by the single message and the opt-out |
| Take payment | Subscriptions, and card payments a buyer makes on a vendor's invoice, through Stripe | Performance of a contract |
| Open a vendor's payout account | A vendor who wants to be paid by card is onboarded by Stripe Connect; Stripe collects the identity and bank details the law requires, and we store only whether the account can take payments and the country it is in | Performance of a contract / legal obligation (Stripe's) |
| Answer your enquiry | You asked us something | Legitimate interests |
| Rate-limit, detect abuse, keep the service up | Preventing misuse of a free, public endpoint | Legitimate interests |
| Keep an audit trail of platform actions | Accountability, and dispute resolution | Legitimate interests / legal obligation |
| Improve the product | Aggregate, non-identifying usage understanding | Legitimate interests |
| Non-essential cookies or analytics, if we ever add them | Only with your consent | Consent |
Where we rely on legitimate interests, we have weighed them against your interests, and you can object, see your rights.
AI features
Magemcy uses AI in two places, and both send text to Google’s Gemini API to do it, or to OpenAI when Gemini is unavailable or an attachment is a Word or PowerPoint file:
- Bid evaluation: when a buyer runs a compliance evaluation, the tender specification and the selected vendor’s technical response are sent for analysis. The buyer is asked to confirm this before it happens.
- Gero, the assistant: the message you type, plus reference material about the product. The assistant on this website has no access to any account.
These requests are made with storage disabled, so neither provider retains them to train models. Each may still hold request content for its own abuse monitoring: Google for up to 55 days (or the shorter window we configure), OpenAI for up to 30 days. Screenshots you attach in the assistant are kept in your own storage folder for the same 30 days as the conversation log, and on a support request for as long as the request exists. Nothing you send is used to train a model.
Gero is an AI assistant and says so in the conversation. Its answers are informational and are not an offer, a quote or a contract. Full detail is on our AI disclosure.
How long we keep it
| What | How long |
|---|---|
| Your account and workspace data | While the account exists. Deleting it removes it, subject to the exceptions below |
| Website contact submissions, including IP and device context | 24 months |
| Website assistant conversations | 30 days |
| In-app assistant conversations | 30 days |
| Abuse and security events | 90 days |
| Email delivery records | 90 days |
| Rate-limit counters | 2 days |
| Vendor registration invitations (the invited address and its outcome) | 180 days |
| Account application answers and documents | While the account exists; a declined application until you delete the account |
| Account-verification research reports | 2 years, so a decision can be revisited |
| Card payment records (payment, refund and dispute references on an invoice) | 7 years, as financial records |
| Platform audit records | Up to 7 years, for accountability |
These periods are enforced automatically rather than by policy alone: each record carries its own expiry and is removed when it passes.
We may keep some records longer where we have to, to resolve a dispute, meet a tax or accounting obligation, or enforce our terms.
International transfers
We are based in the United States and our providers are principally in the United States, so if you are outside the US your data will be transferred there. Where that transfer is from the EEA, the UK or Switzerland, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum) with each provider, together with the technical measures described on our security page.
We have not appointed a representative in the EU or the UK under Article 27. If you are in either and want to raise something, write to our privacy contact and we will answer directly.
Your rights
Depending on where you live, you can ask us to:
- tell you what we hold about you, and give you a copy;
- correct anything inaccurate;
- delete it;
- restrict or object to how we use it, including anything based on legitimate interests;
- give you a portable copy, or send one to someone else;
- withdraw consent, where consent is what we relied on.
Californians have specific rights, including the right to know, delete, correct and opt out of sale or sharing, set out on our Notice to California Residents. We do not sell or share personal information as those terms are defined, and we honour Global Privacy Control signals.
Some of this you can do yourself, immediately: export your data or delete your account from Settings, and delete a website chat from inside the chat itself. Otherwise use Your Privacy Choices. We answer within 30 days (45 for California requests), and we may need to verify who you are first.
If we get it wrong, you can complain to your data protection authority. We would rather you came to us first.
Security
Each company’s workspace is isolated from every other one, enforced on the server rather than in the interface. Data is encrypted in transit and at rest. Card details go straight to Stripe and never reach us. Approval links sent by email are single-use, expiring and bound to one approver and one document. Our security page has the detail, including how to report a vulnerability.
No service is perfectly secure. If a breach affects you and the law requires us to tell you, we will, without undue delay.
Children
Magemcy is a business tool and is not directed at anyone under 16. We do not knowingly collect data from children. If you believe a child has given us data, tell us and we will delete it.
Changes to this notice
When we change this notice we update the date at the top. If a change materially affects how we use your data, we will tell account holders by email or in the app before it takes effect.
This notice describes what the product actually does today. If you find something here that does not match your experience of the service, tell us, we would rather fix the discrepancy than defend it.
Questions about this policy?
A person reads every message. Get in touch and we’ll answer. Or ask Gero, our AI assistant, to walk you through what this page says - his answers explain, they don’t bind.