Privacy policy

How MedTrade handles personal data across public discovery and workspace operations.

This policy explains what data MedTrade collects, how it is used across account, supplier, product, inquiry, and support flows, and what rights users may have under applicable law.

Effective date:

Quick view
Covers account, workspace, inquiry, and upload flows
Security, retention, and deletion explained
Cross-border processing addressed
Contact route: [email protected]

1. Scope

This Privacy Policy explains how MedTrade collects, uses, stores, shares, and protects personal data when individuals or organizations access the MedTrade platform, create accounts, publish supplier information, review products, send inquiries, or communicate with us through support and policy channels.

MedTrade operates a B2B medical equipment sourcing platform. The platform may expose public supplier profile data, product listing data, and inquiry-related business contact flows. This policy is intended to describe those real operating flows rather than act as a generic placeholder notice.

2. Data collected

Depending on how you use the platform, MedTrade may collect account data such as name, email address, login credentials or social-login identity information, organization and workspace data such as company profile details, team membership, role and permission data, and public catalog data such as supplier profile content, product listing content, category choices, brand references, and public proof or credential-related business materials.

We may also collect inquiry and communication data, including buyer-submitted inquiry content, supplier responses, operational workflow status, support requests, uploaded files or attachments, and technical or security data such as browser metadata, device information, IP-derived logs, session records, and activity logs needed to protect accounts and operate the service.

Where you purchase paid features such as inquiry credits or subscriptions, we collect billing and transaction records (for example, order identifiers, amounts, and payment status). Card details are processed by our payment provider and are not stored by MedTrade.

3. Data sources

We collect data directly from you when you register, sign in, complete forms, create or edit supplier profiles, upload product or credential materials, submit inquiries, or contact MedTrade. We also collect data from authorized organization operators who manage a supplier workspace and may add, edit, or govern organization-level information tied to other team members.

If you choose Google sign-in or another integrated identity flow, we collect the identity data returned by that provider to authenticate you and establish or reconnect your MedTrade account. We also collect data generated through platform usage, workflow events, and security or operational logging.

4. Processing purposes

MedTrade processes personal data to create and secure accounts, operate buyer and supplier workspaces, publish or unpublish public supplier and product information, route and preserve inquiry conversations, maintain platform integrity, support users, prevent abuse, enforce platform rules, and improve the reliability and usability of the service.

We may also process data to perform organization-level access control, maintain auditability of operator actions, investigate misuse, comply with legal obligations, defend legal claims, and retain records needed for dispute resolution, fraud prevention, or business continuity.

6. Sharing

MedTrade does not sell personal data. We may share data with infrastructure, hosting, storage, authentication, analytics, communications, email, or payment providers that help us operate the platform under appropriate contractual or operational safeguards. These provider categories may include cloud hosting and edge delivery, object storage, email delivery, usage analytics, identity providers, and payment processing.

Some data is intentionally visible to other users because that is part of the service itself. For example, public supplier profile data, product listing data, inquiry-routing information, and organization contact details may be surfaced to buyers, suppliers, or platform operators according to the product workflow and visibility settings. MedTrade may also disclose data when required by law, to protect the platform or its users, or in connection with a merger, acquisition, financing, or asset transfer.

7. Inquiry and contact flows

When you send an inquiry about a product or supplier through the platform, the contact details you submit (such as your email address or phone number) and the content of your inquiry are shared with the supplier that receives the inquiry so they can respond to you. This is the core purpose of the inquiry flow: buyers share business contact information with suppliers to start a commercial conversation, and suppliers may use that information to reply about the inquiry.

The platform may display public supplier contact options, including WhatsApp numbers. Clicking a WhatsApp contact link opens a conversation in the WhatsApp application, and the information you choose to share in that conversation is governed by WhatsApp’s own terms and privacy policy. MedTrade may log that a contact link was clicked (for example, click counts on a listing) for operational and analytics purposes; this log does not include the content of your WhatsApp conversation.

Public product images on the platform may carry a supplier watermark that includes the supplier’s name and a QR code linking back to the listing. This watermark is business data displayed on public media and is not processed as personal data.

8. Cookies and analytics

MedTrade uses strictly necessary cookies and similar technologies for session management, authentication, and platform security. These are required for the service to function.

We also use Google Analytics to understand aggregate usage of the platform, such as page views, traffic sources, and general behavior patterns. Google Analytics may process IP-derived location data and device information, and Google’s own privacy practices apply to data it processes on our behalf. Where applicable law (including the GDPR and ePrivacy requirements) requires consent for non-essential analytics cookies, MedTrade requests your consent before enabling them and honors your choice.

You can control or delete cookies through your browser settings, and you can learn about Google Analytics data practices and opt-out options in Google’s privacy documentation.

9. Transfers

Because MedTrade is an online platform, data may be processed in more than one country depending on our hosting, infrastructure, support, or service-provider stack. Where applicable, we rely on lawful transfer mechanisms and reasonable safeguards for cross-border processing.

10. Retention and security

We retain data for as long as reasonably necessary to operate the service, maintain account continuity, preserve inquiry and workflow history, support security investigations, enforce platform rules, satisfy legal obligations, and resolve disputes. Retention periods may vary depending on data type, workspace state, public visibility, operational need, and legal risk.

MedTrade uses technical and organizational measures designed to protect personal data, but no platform can guarantee absolute security. You are responsible for maintaining the confidentiality of your own login credentials and for controlling access inside your organization workspace.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, MedTrade will notify the relevant supervisory authority and affected individuals where required by applicable law, and will take reasonable steps to mitigate the impact of the breach.

11. Your rights

Subject to applicable law, you may have rights to request access, correction, deletion, restriction, portability, or objection, and to withdraw consent where consent is the basis for processing. You may also be able to update certain account or workspace information directly through the platform.

We will respond to privacy requests within the timeframes required by applicable law (typically one month), and we may ask you to verify your identity or clarify the scope of your request before acting on it.

When a request relates to organization-controlled data, MedTrade may need to distinguish between the rights of the individual requester and the rights or responsibilities of the organization that controls the relevant workspace content.

12. Children

MedTrade is a B2B platform and is not intended for children. Do not use the service to submit children’s data unless you are legally authorized to do so and such submission is necessary for a lawful business or compliance purpose.

13. Updates and contact

We may update this Privacy Policy as the platform evolves. Material updates will be reflected by a revised effective date and, where appropriate, by additional notice through the service.

For privacy questions, rights requests, or data-handling concerns, contact [email protected] or use the contact routes available on the platform. For users in the European Economic Area, you may also contact our Data Protection Officer at [email protected].

Related pages

Need platform rules or direct support instead?