Surfular
ProductsSuppliersNew launches
Sign inBecome a supplier

© 2026 Surfular — The operating system for the global stone & surface industry

Privacy Policy

Privacy Policy

Last updated 3 August 2026

This policy is not finished.

The registered address and jurisdiction have not been set. Fill in src/config/legal.ts and have the text reviewed by someone qualified in your market before relying on it. This notice disappears once those fields are set.

Contents

  1. 1. Who we are
  2. 2. What we collect
  3. 3. Why we use it
  4. 4. Who we share it with
  5. 5. Cookies and local storage
  6. 6. How long we keep it
  7. 7. Your rights
  8. 8. Security
  9. 9. Changes
  10. 10. Contact

Surfular is a business-to-business marketplace for the stone and surface industry. This policy explains what personal data we collect, why, and what you can ask us to do about it. It is written to describe what the platform actually does — not to cover every hypothetical.

1. Who we are

Surfular operates Surfular at surfular.online. We are the data controller for the personal data described below.

Privacy enquiries: privacy@surfular.online

2. What we collect

When you create an account. Your name, email address and profile picture, handled on our behalf by our authentication provider (see section 4). We store your email, name, profile image and whether you use the platform as a buyer, a supplier or an administrator. We never see or store your password.

When you set up a company. Company name, description, business type, country, state, city and address, contact email, phone number, website and social links, plus optional facts about your operation such as year established, employee range, factory size, production capacity and export markets. Logos, banners and factory photographs you upload. This information is published on your public storefront — that is its purpose.

When you send an enquiry. Your name, email address, phone number, country, the company you represent, your requirement and your message, plus any files you attach. You do not need an account to send an enquiry. This is passed to the supplier you addressed it to.

When you request a quote (RFQ). Project name, the company and country you buy for, and your specification — material, colour, finishes, thickness, quantity, dimensions, budget, delivery country and timeline — along with any attachments. This is shared with the suppliers you select.

When you send messages. The content of your messages and any attachments, retained so both sides can read the thread.

As you use the site. We record product and company page views, catalogue downloads and searches so suppliers can see how their listings perform. Each event stores a one-way hash of your IP address using a secret key — we do not store raw IP addresses, and the hash cannot be turned back into an IP by anyone who obtains the database. We also store the browser user-agent string submitted with enquiries, to help us detect abuse.

Things you choose to save. Saved products, saved suppliers, saved searches, and a list of pages you recently viewed — all visible only to you.

Administrative records. When an administrator approves, verifies or suspends a company, we log who did it and what changed, so decisions about a business can be accounted for.

3. Why we use it

  • To run the marketplace — showing storefronts and listings, delivering enquiries and quotes to suppliers, and carrying messages between the two sides. This is the service you asked for.
  • To send transactional email — a welcome message, notification that an enquiry, quote or message arrived, and confirmation when a company is approved or verified. These are part of the service, not marketing.
  • To give suppliers audience statistics — aggregate counts of views, enquiries and downloads. Suppliers see totals, never a list of who visited.
  • To keep the platform usable — rate limiting and abuse detection, which is why we keep a hashed IP and user-agent against enquiries.
  • To review businesses before they go live — new companies are checked before appearing publicly, which is what the verified badge is for.

Where the law requires a legal basis, ours is performance of a contract for the account and marketplace functions, and legitimate interests for security, abuse prevention and aggregate audience measurement. We do not sell personal data, and we do not use it for advertising.

4. Who we share it with

Other users. Your company profile and listings are public by design. An enquiry or quote request is delivered to the suppliers you address it to, including your name, email, phone and country — that is how they reply to you. Messages are visible to the company you are talking to, which may mean more than one member of their staff.

We use a deliberately small number of external providers:

  • Clerk — account creation, sign-in and session security. They handle your credentials so we never store a password.
  • Resend — delivery of the transactional emails listed above. They process the recipient address and message content.

Everything else stays with us. The database and every file you upload are held on our own server in Europe, not on third-party storage. We use no advertising networks, no third-party analytics, and no tracking pixels.

We may disclose data where we are legally required to, or to establish or defend legal claims.

5. Cookies and local storage

We use no advertising or tracking cookies. What the site stores is:

  • A session cookie, set by our authentication provider, that keeps you signed in. Without it the site cannot tell who you are.
  • Your comparison shortlist and recent searches, kept in your browser’s local storage. These never reach our server; clearing your browser data removes them.
  • A short-lived marker that stops a page refresh counting as a second view.

Because none of this is used to profile you or follow you across other websites, we do not show a consent banner. If that changes, we will ask first.

6. How long we keep it

Account, company and listing data is kept for as long as your account is open. Enquiries, quote requests and message threads are kept while they remain commercially relevant to both sides, since a supplier needs their record of a deal as much as a buyer does.

Analytics events are aggregated into daily totals; the aggregates carry no identifier of any kind.

When you ask us to delete your account, we remove your personal data. Some records are retained where we must — for example an enquiry already delivered to a supplier remains their business record, and administrative logs are kept so decisions stay accountable.

7. Your rights

Depending on where you live, you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or provide it in a portable format. You can also complain to your national data protection authority.

Write to privacy@surfular.online and we will respond within one month. We may need to confirm your identity first, so that nobody else can make a request in your name.

You can edit most of your information yourself at any time from your account and company settings.

8. Security

Traffic to the site is encrypted in transit. Passwords are never held by us. IP addresses are stored only as a keyed one-way hash. Access to the production database is restricted to the operator, and backups are held outside the public web root so they cannot be fetched over the internet.

No system is perfectly secure. If a breach affects your personal data and presents a real risk to you, we will tell you and the relevant authority as the law requires.

9. Changes

We will update this page when the platform changes what it collects or how it is used, and revise the date at the top. Material changes will be signalled in the product rather than made quietly.

10. Contact

Privacy questions and requests: privacy@surfular.online
Anything else: hello@surfular.online

← Back to Surfular