1. Who provides OrgAtlas
OrgAtlas is provided and sold by Suppl LLC. In this policy, “OrgAtlas,” “we,” “us,” and “our” refer to Suppl LLC and the OrgAtlas services it operates.
2. Information OrgAtlas handles
Account and licensing information
We request your email address to create and authenticate your account. Our account systems also maintain an internal user identifier, trial and entitlement state, subscription status, Stripe customer and subscription identifiers, and operational timestamps required to provide access and prevent billing or licensing errors. We do not ask for your name as part of the OrgAtlas account profile.
Billing information
Stripe hosts checkout, collects card and billing details, provides invoices, and manages payment-method changes and cancellation. OrgAtlas does not store your full card details. Stripe provides OrgAtlas with the identifiers and subscription state needed to determine access.
Technical request information
Hosting, authentication, email, and security providers may process ordinary technical request information such as IP address, browser or device information, timestamps, and security logs when you use the account service or website. We use this information to deliver, secure, diagnose, and protect the service.
Website cookies and tracking
The OrgAtlas marketing website uses Vercel Web Analytics to measure page views and understand which pages and referrers are useful. Vercel may process the page path, referrer, approximate country, browser, operating system, device type, and a privacy-preserving identifier derived from request data. Vercel Web Analytics does not use cookies or track visitors across different websites. It does not receive Salesforce workspace data, prompts, business rules, or source files.
We do not use advertising pixels, chat widgets, cross-site behavioral profiles, or targeted-advertising trackers. Essential hosting and security infrastructure may still process ordinary request logs.
Support information
If you contact support, we process the email, screenshots, files, descriptions, or other information you choose to send. Do not include secrets or customer data that are not necessary for the support request.
3. Your local Salesforce workspace
The OrgAtlas desktop application uses your computer as the working environment. Salesforce projects, retrieved source, generated org intelligence, code, local applications, reports, documents, and other work products remain in the local project or locations you control. OrgAtlas does not upload and store a cloud copy of that complete workspace in its account database.
4. Services you choose to connect
OrgAtlas is local software, but it is not an offline island. The desktop application can connect to:
- Salesforce using the authorization and permissions associated with the org you explicitly select.
- Your selected AI provider using the account, key, provider, and model you choose. Prompts and selected context sent for a task are handled under that provider's terms and privacy practices.
- OrgAtlas account services for authentication, entitlement, licensing, and supported protected services.
- Stripe for checkout, billing, invoices, and subscription management.
You should review the privacy terms of Salesforce, Stripe, and any AI provider you connect. OrgAtlas does not control those providers' independent data practices.
5. Protected CPQ validation
An optional protected CPQ product-validation feature sends a bounded product-catalog payload to an authenticated OrgAtlas endpoint for in-memory processing. The endpoint is designed not to persist the request payload. It records limited operational information such as a request identifier, product count, and rule-registry version. Do not use this feature if that processing boundary does not meet your requirements.
6. How we use information
- Authenticate accounts and return the user to the desktop application.
- Calculate trial, subscription, offline-access, and entitlement state.
- Process purchases, prevent duplicate subscriptions, and support billing recovery.
- Deliver authentication email and requested support.
- Measure aggregate marketing-website traffic and improve public content.
- Protect the service, investigate failures, and enforce applicable terms.
- Comply with legal obligations and resolve disputes.
We do not sell personal information or use the website for behaviorally targeted advertising.
7. Service providers and disclosures
We use service providers including Supabase for authentication and account data, Stripe for billing, Vercel for hosted application infrastructure and website analytics, and Resend for authentication email. We may disclose information when required by law, to protect users or the service, or as part of a corporate transaction subject to appropriate safeguards.
8. Retention and security
We retain account, subscription, security, and operational records for as long as reasonably necessary to provide the service, meet billing and legal obligations, prevent fraud, and resolve disputes. The exact period depends on the record and applicable requirements.
OrgAtlas uses measures appropriate to the data boundary, including server-owned entitlements, restricted billing access, encrypted desktop account tokens through the operating system's secure storage, and read-only Salesforce controls. No system can guarantee absolute security.
9. Legal bases and international processing
Where the GDPR or similar law applies, we process information to perform the product contract, respond to steps you request, meet legal obligations, and pursue legitimate interests in operating, securing, supporting, and improving OrgAtlas. Service providers may process information in the United States or other jurisdictions where they operate, subject to their applicable transfer safeguards.
10. Your choices and rights
You can manage billing and cancellation through the Stripe-hosted customer portal available from the OrgAtlas account application. Depending on where you live, you may have rights to access, correct, delete, receive, restrict, or object to processing of certain personal information. California residents may also request information about collection and disclosure and exercise applicable deletion or correction rights. OrgAtlas does not sell personal information or share it for cross-context behavioral advertising.
Use the OrgAtlas contact page to make a privacy request. We may need to verify the request and retain information when required by law. We do not currently respond separately to browser “Do Not Track” signals because the website does not use behavioral tracking.
11. Children
OrgAtlas is a professional business product and is not directed to children under 18.
12. Changes and contact
We may update this policy as the product, providers, or legal requirements change. The effective date will identify the current version. Privacy questions can be sent through the OrgAtlas contact page.
