Privacy Policy

    What Harness Atlas collects, why, and how to get it changed or deleted.

    Last updated: 28 July 2026

    Who we are

    Harness Atlas is a directory of wire harness and cable assembly manufacturers, operated by Paweł Kowalczyk, Sarnia 2/37, 61-058 Poznań, Poland. For anything in this policy — including requests to access or delete your data — contact pawel@harnessatlas.com.

    We are the data controller for the personal data described below. Because we are established in Poland, the supervisory authority for complaints is the Polish Data Protection Authority (Urząd Ochrony Danych Osobowych, uodo.gov.pl).

    What we collect

    Most of the site can be browsed without giving us anything. We collect personal data when:

    • You request a quote. The form at /request-quote asks for your work email, and optionally your name, company, and details of what you are sourcing. We also record which page you arrived on and any campaign parameters in the link you followed (including a Google Ads click identifier, where present), so we can tell which advertising is working.
    • You send an RFQ. A request for quote records your name, email and — if you provide it — phone number and company, alongside the requirements you describe and which suppliers you sent it to.
    • You create an account. We store your email, the name you give us, and whether you signed up as a buyer or a supplier. Passwords are handled by our authentication provider and stored only as a cryptographic hash — we never see them. If you later add a phone number or company name to your profile, we store those too.
    • You claim or manage a company listing. We store the account that made the claim, the company it relates to, any message you send with it, and the listing details you submit — which may include names, roles, email addresses and phone numbers of your colleagues, if you enter them as contacts.
    • You use our public data service. Our endpoint for AI agents logs each request with the query made, the IP address it came from, and the identifying string sent by the software making the call. The address is removed after 30 days.

    Cookies and analytics

    We show a banner before loading any analytics. If you accept, we load Google Analytics 4 and HubSpot, which set their own cookies and record how the site is used. If you decline, neither is loaded and no analytics cookies are set.

    Regardless of your choice, we store a small number of items in your browser to make the site work: your cookie choice itself, your shortlist of suppliers, your sign-in session if you have an account, and interface preferences such as whether a panel is expanded. These are not used for tracking or advertising.

    Where you have accepted analytics, some of what we record is more specific than page views. Events for submitting an RFQ or a quote request include a reference number for that submission, which can be matched back to the contact details you gave us on the form. And when you search the directory, the words you typed are recorded along with how many results they returned — so please do not type anything into the search box you would not want recorded.

    You can change your mind at any time using Cookie settings at the bottom of any page. Switching to declined stops the analytics immediately and removes the cookies they had already set, in every tab you have open. Your choice is stored in the browser you made it in, so it is something only you can set or change — emailing us cannot action it, because we have no way to reach into your browser.

    Two things load from other organisations, which means they receive your IP address in order to serve them: map tiles from OpenStreetMap on the supplier map, and — only if you have accepted analytics — Google Analytics and HubSpot. Fonts and map icons are served from our own site. The map also asks your browser for your location so it can centre the view; that happens only if you allow it when your browser asks, and your position stays in your browser — it is never sent to us or stored.

    Who we share data with

    We share personal data only with service providers who process it on our instructions, and with suppliers you deliberately contact.

    • Suppliers you contact. When you send an RFQ, the suppliers you selected receive your enquiry and the contact details you entered — that is the point of sending it. Our notification emails contain a tracking image that tells us whether the email was opened, so we can tell you if a supplier has seen your request.
    • Hosting and database — Supabase (database, accounts, file storage; hosted in the EU) and Vercel (website hosting).
    • Email delivery — Resend, which sends the notifications described above.
    • Analytics and marketing — Google Analytics and HubSpot, only where you have accepted analytics cookies.

    Some of these providers are based outside the European Economic Area or may process data outside it. Where that happens, the processing is governed by each provider's standard data-processing terms. You can ask us for details of the arrangements with any of them.

    How long we keep it

    These periods are enforced automatically by a daily job, not by hand.

    • Your account — for as long as it exists. Deleting it removes your profile, sign-in and roles immediately.
    • Quote requests (the no-login form) — 24 months, then deleted. Sourcing projects run long, so a year-old enquiry can still be live; past two years it is not.
    • RFQs 36 months, then your name, email and phone number are removed. The request itself is kept, because the suppliers you sent it to received it and may have quoted on it.
    • Listing drafts 12 months after we review them. Drafts still waiting for review are kept.
    • Claim invitations 12 months, then the email address is removed. A record that we invited you to claim that company stays, because without it the next run would email you again about the same listing.
    • Logs from our public data endpoint — IP addresses are removed after 30 days. Where the address was the only thing identifying a caller, it is replaced with a one-way code so we can still count how many distinct callers there were, and the key behind that code is replaced on the same cycle, so the live database can no longer reverse older codes. Backups taken before a replacement still hold the old key until they expire. The request records themselves are kept.

    If you want your data removed sooner than any of these, ask us — see below.

    Your rights

    If you are in the EU or UK, you have the right to:

    • get a copy of the personal data we hold about you;
    • have inaccurate data corrected;
    • have your data deleted;
    • restrict or object to how we use it, including profiling for analytics;
    • receive data you gave us in a portable format;
    • withdraw consent at any time, without affecting what we did before you withdrew it — for analytics cookies, use Cookie settings in the footer, since that choice lives in your own browser.

    To delete your account yourself, use “Delete your account” on your dashboard — or on the pending-approval screen if your account has not been approved yet. It removes your profile, sign-in and roles straight away.

    For anything else, email pawel@harnessatlas.com and we will respond within one month. If you are unhappy with how we handle your request, you can complain to the Polish Data Protection Authority (uodo.gov.pl) or the authority in your own country.

    If your details appear in a company listing

    The directory describes manufacturing companies, and some listings include business contact details — a name, role, work email or work phone number — either published by the company itself, submitted to us by someone at that company, or compiled from publicly available business sources.

    We publish this on the basis of our legitimate interest in operating a business directory that buyers can actually use. If you would rather your details were not listed, email us and we will remove them. You do not need to explain why.

    Security

    Access to the database is restricted by row-level security rules, so accounts can only read the records they are entitled to. Passwords are stored as hashes by our authentication provider. Administrative functions are limited to a small number of accounts.

    No system is perfectly secure. If you believe you have found a vulnerability, please email us rather than disclosing it publicly, and we will work with you on it.

    Changes to this policy

    If we change how we use personal data, we will update this page and the date at the top. Where a change materially affects you, we will tell you directly — by email if we have your address, or through a notice on the site.