Your order system and buyer list reside on this platform. The following is an overview of how that data is protected, without claiming certifications we do not hold.
Each supplier's data is isolated from every other supplier's. Buyers only see the catalogs, orders, and prices assigned to them. Isolation is enforced with account-scoped access controls at multiple layers.
Buyer portals are scoped to each supplier account and buyer profile. No buyer can access another buyer's orders, catalog, or pricing — including buyers on the same account.
Payment processing runs through Stripe. SupplyDesk never stores card numbers — they go directly to Stripe and stay there. PCI compliance is handled by Stripe's certified infrastructure.
SupplyDesk runs on managed cloud infrastructure with uptime monitoring. We use encryption in transit and at rest, and backups are in place to protect against data loss.
QuickBooks sync is optional and uses only the permissions required for the integration features you enable. This access is not used to read or store your full accounting history, bank transactions, payroll records, tax filings, payment accounts, or general ledger data. QuickBooks data is never sold or used for advertising, and connection credentials are encrypted at rest.
If an issue arises — an outage, a sync failure, or a data question — you can email us directly and receive a response from our team. There is no unmonitored ticket queue. Enterprise accounts are assigned a dedicated contact; all other plans reach the same support team without a guaranteed response window.
For security-specific questions, contact hello@supplydesk.ca.