Legal

Privacy Notice

Last updated: July 29, 2026 · Version 2.0

At a glance

We use the data needed to operate accounts, RFQs, quotes, messages, payments, support, security, and compliance. We do not sell personal data. You may limit secondary purposes and exercise your ARCO rights by email.

1. Data Controller

Strike Gaming Center, S.A.S. de C.V. (hereinafter the "Controller") operates the service under the trade name ProveedorMX and through the domain proveedormx.lat. The Controller processes personal data collected through the platform and its associated services in accordance with the Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP) and its Regulations.

Legal name
Strike Gaming Center, S.A.S. de C.V.
Mexican tax ID (RFC)
SGC1804048X1
Registered address
Calle José Morelos 1120, Jardines de Santa Catarina, Santa Catarina, Nuevo León, C.P. 66362, México
Privacy and ARCO rights
soporte@proveedormx.lat

2. Personal Data We Collect

2.1 Identification and contact data:

  • Full name
  • Email address
  • Phone number (optional)

2.2 Company data (legal entity):

  • Legal name and trade name
  • RFC (Federal Taxpayer Registry)
  • Tax and commercial address
  • City, state, and country
  • Company website
  • Logo and corporate images
  • Banking data needed for payments, refunds, reconciliation, or verification (for example, bank and CLABE)
  • Tax documents, receipts, certifications, factory evidence, or supplier verification information

2.3 Operational and commercial data:

  • Technical specifications of requests for quotation (RFQs)
  • Quotes, prices, and commercial terms
  • Purchase order information
  • Message history on the platform
  • Sample requests and shipping addresses

2.4 Payment data:

Credit or debit card data is processed directly by Stripe through its PCI-DSS-certified infrastructure. ProveedorMX does not store, transmit, or have access to full payment card data. We only retain the Stripe session identifiers needed to reconcile payments, refunds, disputes, fees, and operational tracking.

2.5 Browsing and technical data:

  • IP address and approximate location
  • Browser type and operating system
  • Pages visited and actions on the platform (aggregated analytics)
  • Session tokens (stored in a PostgreSQL database)

2.6 Waitlist:

If you join the waitlist, we collect only your email address and the source of the registration (e.g., the website banner).

Sensitive data: we do not request it in the ordinary course of the service. Users must avoid uploading it in RFQs, messages, or documents. If strictly necessary, consent and enhanced safeguards will be applied as required by law; unsolicited sensitive information may be deleted or restricted.

3. Processing Purposes

3.1 Primary purposes (necessary for the service):

  • Create, authenticate, and manage user accounts via email OTP
  • Facilitate commercial connection between buyers and suppliers through RFQs
  • Process quotes, purchase orders, and payments
  • Manage the internal messaging system tied to active RFQs
  • Verify the identity and operational capacity of registered suppliers
  • Coordinate product sample requests
  • Send transactional notifications related to your activity (new quotes, messages, payment confirmations)
  • Comply with applicable legal, tax, and regulatory obligations

3.2 Secondary purposes (optional - they do not affect the core service):

  • Sending newsletters, platform updates, and supplier offers
  • Aggregated statistical analysis to improve the platform
  • Internal market research (without individual identification)

If you do not want your data to be used for secondary purposes, you may state so by sending an email to soporte@proveedormx.lat with the subject "Objection to secondary purposes". This refusal will not affect access to the service.

4. Consent and Permitted Processing

  • Consent: may be express or implied after this Notice is made available, depending on the data and purpose
  • Legal relationship: we process data needed to create and maintain the account, provide requested functions, and perform the relationship with the User
  • Legal duties and valid requests: information may be retained or disclosed for tax duties, prevention of unlawful acts, legal claims, or valid authority instructions
  • Secondary purposes: the User may refuse or object without losing the core service; non-essential analytics is enabled only following the User’s choice where applicable

5. Transfers and Data Processors

ProveedorMX does not sell or transfer personal data to third parties for their own commercial exploitation. To operate the Platform, we use processors and, in certain flows, third parties acting under their own terms:

ProviderPurposeCountry
Neon (AWS)PostgreSQL database storageInternational
VercelHosting and execution of the web applicationInternational
Stripe, Inc.Card payment processingInternational
ResendSending transactional emailsInternational
Cloudflare R2Secure storage and delivery of uploaded filesInternational
UpstashRequest rate limiting and abuse preventionInternational
GoogleGoogle sign-in and optional analytics, when configuredInternational

Processors receive only the data needed for their services and are subject to contractual and confidentiality duties. Processing or storage may occur outside Mexico. A disclosure that constitutes a transfer to a third party will rely on consent or a legal exception, and the recipient will be subject to the applicable purposes and duties.

We may also share information with counterparties when needed for an RFQ, quote, order, delivery, or dispute; with advisers or acquirers in a confidential reorganization; and with authorities acting within valid powers. Stripe may process certain data as an independent controller under its own notices and terms.

6. Data Visible to Third Parties

Registered suppliers agree that the following information may be publicly visible in the Platform directory: company name, general description, city, verification, production capabilities, and packaging types. The contact's personal data (the representative's name and email) is not displayed publicly and is only accessible to counterparties with an active RFQ or an initiated conversation.

7. Retention Period

  • Account data: during the relationship and afterward while needed for closure, security, claims, and legal duties
  • Transaction and payment records: 5 years (tax period under the CFF)
  • Messages and RFQs: while needed to operate the matter, handle disputes, prevent abuse, and defend rights, subject to applicable legal periods
  • Sent email records (logs): for the operational or security period defined by each provider and, where retained by us, only while needed
  • Waitlist: until the data subject requests deletion or until the public launch of the Platform, whichever comes first
  • Session data: automatically deleted when the session expires

8. Information Security

We implement technical and administrative security measures that include:

  • Encryption in transit via HTTPS/TLS on all communications
  • Authentication via a one-time verification code (OTP), with no static passwords
  • Data storage in a PostgreSQL database with access restricted by rotating credentials
  • Role-based access control in the application (buyer, supplier, administrator)
  • No storage of payment card data in our systems
  • Logging of critical operations (payment creation, verification changes, administrative access)

No internet-connected system can guarantee absolute security. In the event of a security breach that significantly affects your property or moral rights, ProveedorMX will notify you without unreasonable delay through your registered email, in accordance with the information available and applicable law.

9. ARCO Rights and Withdrawal of Consent

As the owner of personal data, you have the right to:

  • Access: know what personal data we hold about you and what we use it for
  • Rectification: request the correction of incorrect or incomplete data
  • Cancellation: request the deletion of your data when it is no longer necessary, subject to legal retention obligations
  • Objection: object to the processing of your data for specific purposes
  • Withdrawal of consent: withdraw your consent for secondary purposes at any time

To exercise any of these rights, send an email to soporte@proveedormx.lat with the subject "ARCO Rights", including:

  • Your full name and the email registered on the platform
  • A clear description of the right you wish to exercise
  • Documents needed to verify identity or representation. Ask for a secure channel first; do not email a complete ID unless requested. Data not needed for verification may be redacted

We will respond within a maximum of 20 business days from receipt of the complete request. If the request is granted, we will make it effective within the following 15 business days.

Withdrawal is not retroactive. Cancellation may be subject to blocking and legal exceptions when data is needed for a contract, tax duties, legal claims, security, investigations, or third-party rights. If the data is essential, the service may not be able to continue.

When technically feasible and where it does not affect third-party rights, trade secrets, security, investigations, legal compliance, or transaction records, we may provide a structured copy of certain account data in CSV or JSON format.

10. Cookies and Tracking Technologies

We use cookies or local storage strictly needed for session, security, language, currency, and preferences. Optional measurement loads only after the User’s choice where non-essential technologies are used:

TypePurposeRequired
Session and securityMaintain the user's authenticated sessionYes
PreferencesRemember language, currency, and interface preferencesYes
AnalyticsVercel measurement and optional Google analytics when the User accepts itNo
Local storageRemember dismissal of the waitlist notice and the analytics choiceNo

We do not use advertising or retargeting cookies. Users may accept or reject optional analytics in the preferences notice and delete cookies in the browser. Rejection does not prevent core functions, although session, security, and language cookies are needed for certain flows.

11. Minors

The Platform is intended exclusively for persons over 18 years of age acting on behalf of legal entities or as individuals with business activity. ProveedorMX does not intentionally collect personal data from minors. If we detect that a minor has provided data without the consent of their guardian, we will proceed to delete it immediately.

12. Data Protection Authority

If an ARCO request was not handled correctly, you may initiate the applicable procedure before the competent federal authority. Under the current LFPDPPP, federal functions fall within the scope of the Secretariat for Anti-Corruption and Good Governance and the competent units or successors as applicable. A data protection request is subject to statutory requirements and deadlines. The official website is gob.mx/buengobierno.

13. Changes to the Privacy Notice

ProveedorMX reserves the right to update this Privacy Notice. Any modification will be published at www.proveedormx.lat/privacidad with the new update date. Material changes will be communicated by email, in-account notice, or a visible notice. Where a new purpose requires consent, it will be requested before the purpose begins; continued use does not replace express consent when the law requires it.

14. Contact

For any inquiry related to this Privacy Notice or the processing of your personal data:

Email: soporte@proveedormx.lat
Suggested subject: "Privacy Notice" or "ARCO Rights"