Privacy notice
Last updated: April 27, 2026
This notice explains how NX Division ("NX Division", "we", "us"), operating under the trade name SupplyMatch, collects, uses, shares, and protects information when you visit the SupplyMatch website or use the platform.
Who we are
SupplyMatch is the trade name of NX Division, a business based in Alberta, Canada. We provide a directory and discovery platform that helps Canadian food-industry buyers and suppliers find each other. You can reach our privacy team through our contact page.
What this notice covers
This notice covers personal information we handle when you visit our website, create or use a SupplyMatch account, contact us, or otherwise interact with our services. It does not cover third-party websites or services we link to, which are governed by their own privacy practices.
Information we collect
We collect information you provide directly, information generated through your use of the platform, and limited technical information sent automatically by your browser. Specifically:
- Account information — name, work email, password (hashed), preferred language, and role (buyer or supplier). For two-factor authentication we also store a TOTP secret and recovery codes.
- Business profile information — organization name, business number, addresses, facility details, capabilities, certifications, contact details, and any other information you choose to add to your profile or listings.
- Communications — the content of messages, RFQs, supplier responses, contact-form submissions, and emails you send through or about the platform.
- Payment information — when paid features become available, billing details (cardholder name, card brand, last 4 digits, billing address, billing email) handled directly by Stripe. We do not store full card numbers; Stripe sends us only a token and limited metadata.
- Technical information — IP address, user-agent string, device and browser metadata, timestamps, page URLs, and basic interaction data, collected through server logs and analytics.
- Cookies and similar storage — see "Cookies and similar technologies" below.
How we use your information
We use the information described above to:
- Provide, maintain, and improve the SupplyMatch platform — including account creation, sign-in, two-factor authentication, supplier discovery, RFQ workflows, and matching.
- Send transactional and service emails (account verification, password resets, RFQ activity, and other operational notices) and respond to your inquiries.
- Process payments and manage subscriptions for any paid features you purchase.
- Detect, prevent, and respond to fraud, abuse, security incidents, and other prohibited or illegal activity.
- Comply with applicable laws and respond to lawful requests from authorities.
- Understand how the platform is used and improve product, performance, and reliability — using aggregated and de-identified analytics where practical.
Your consent
We rely on your consent — or another lawful basis under the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and Alberta's Personal Information Protection Act (PIPA) — to collect, use, and disclose your personal information. For most uses, your consent is implied by your use of the service for the purposes described above. You can withdraw consent at any time by contacting us; doing so may limit or end your ability to use the platform.
Cookies and similar technologies
We use cookies and similar storage to keep you signed in (session cookie), remember your language preference (a 'guest_locale' cookie), and operate analytics and security features. You can clear or block cookies in your browser; doing so may break parts of the service that rely on them.
Service providers we share information with
We rely on vetted third-party service providers who process information on our behalf. These currently include:
- Laravel Cloud — application hosting, database, and storage.
- Postmark — transactional email delivery (for example, account verification and password resets).
- Stripe — payment processing for paid features.
- Google Analytics — usage analytics.
- Sentry and Laravel Nightwatch — error monitoring, performance telemetry, and reliability data.
These providers are contractually limited to using your information only as needed to deliver the services we've engaged them for.
International transfers
Some of our service providers operate or store data outside Canada, including in the United States. Where that is the case, your information may be subject to the laws of those jurisdictions. We take reasonable steps to ensure providers protect your information at a level comparable to Canadian standards.
When we share information
We do not sell your personal information. We disclose personal information only to: (a) the service providers described above; (b) other SupplyMatch users when you choose to publish information on your public profile or contact them through the platform; (c) parties to a corporate transaction such as a merger, acquisition, or asset sale, with appropriate safeguards; and (d) authorities or other parties when required by law or to protect our rights, property, or safety.
How long we keep your information
We retain personal information for as long as your account is active and as needed to provide the service, comply with our legal obligations, resolve disputes, and enforce our agreements. When information is no longer needed, we delete or anonymize it.
Your rights
Subject to applicable law, you have the right to:
- Access the personal information we hold about you and request a copy.
- Request that we correct or update inaccurate information.
- Withdraw your consent to our processing, subject to legal or contractual restrictions.
- File a complaint with us, with the Office of the Privacy Commissioner of Canada (priv.gc.ca), or — if you are an Alberta resident — with the Office of the Information and Privacy Commissioner of Alberta (oipc.ab.ca).
To exercise any of these rights, reach us through our contact page.
Security
We use reasonable administrative, technical, and physical safeguards to protect personal information from loss, theft, and unauthorized access, disclosure, or alteration — including encryption in transit, hashed passwords, access controls, and operational monitoring. No system can be guaranteed completely secure, so we cannot promise absolute security.
Children
SupplyMatch is a business-to-business platform intended for users 18 years of age and older. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can delete it.
Changes to this notice
We may update this notice from time to time. When we do, we will revise the 'Last updated' date above. If we make material changes, we will provide additional notice (for example, by email or an in-platform notice) before the changes take effect.
Contact us
If you have questions or concerns about this notice or how we handle your information, please reach our privacy team through our contact page.