Meridian BFD, LLC
Privacy Policy
1. Introduction and Scope
Meridian BFD, LLC, a Delaware limited liability company ("Company," "we," "us," or "our"), provides a cloud-based software platform for procurement, purchasing, inventory, and related business-operations workflows (the "Service"), together with our websites located at www.meridianbfd.com and any other sites that link to this Privacy Policy (the "Sites").
This Privacy Policy explains how we collect, use, disclose, and protect personal information when you visit our Sites, use or interact with the Service, communicate with us, or otherwise engage with us in sales, marketing, support, or business activities. "Personal information" means information that identifies, relates to, or could reasonably be linked with an identified or identifiable individual.
The Service is a business-to-business product. The individuals whose personal information we handle are primarily business representatives: our customers’ personnel and authorized users, prospective customers, suppliers’ business contacts, and visitors to our Sites. We do not offer the Service to consumers for personal, family, or household use.
2. Our Two Roles: Business and Service Provider
We handle personal information in two distinct capacities, and your rights and our responsibilities differ between them:
As a business (controller). We decide how and why to process personal information relating to our Site visitors, prospects, and customer account contacts — for example, registration details, billing contacts, support communications, and Site usage data. This Privacy Policy primarily describes this processing.
As a service provider (processor) for Customer Data. When our customers use the Service, they submit or connect business records — purchase orders, invoices, receiving records, supplier contact details, product and inventory data, and documents and emails retrieved from systems and mailboxes the customer connects ("Customer Data"). We process Customer Data on the customer’s behalf and under its instructions, as described in our agreement with that customer, and the customer is responsible for its own privacy practices. If your information is contained in Customer Data — for example, you are an employee or supplier contact of one of our customers — please direct privacy questions and requests to that customer. We will support our customers in responding, as required by law and our agreements.
3. Information We Collect
3.1 Information You Provide to Us. We collect personal information that you provide directly, including: (a) account and registration information, such as name, business email address, phone number, employer, job title, and login credentials; (b) billing and transaction information, such as billing contact details and payment method details (payment card numbers are collected and processed by our third-party payment processor, and we do not store full card numbers); (c) communications, such as the contents of emails, support requests, chat messages, feedback, and survey responses, and, where permitted and disclosed, recordings or notes of sales and support calls; and (d) marketing and event information, such as information submitted through forms on the Sites, demo requests, or event registrations.
3.2 Information Collected Automatically. When you visit the Sites or use the Service, we and our service providers automatically collect certain information, including: (a) device and log information, such as IP address, browser type and version, operating system, device identifiers, pages viewed, features used, links clicked, referring pages, and date/time stamps; (b) approximate location inferred from IP address; and (c) information collected through cookies and similar technologies, as described in Section 7.
3.3 Information from Other Sources. We may receive personal information from other sources, including: (a) our customers, when they invite you as a user of the Service or list you as a contact; (b) third-party services that you or your organization connect to the Service, as described in Section 4; (c) service providers, such as analytics providers and payment processors; (d) business and marketing data providers and publicly available sources, such as company websites and professional profiles, used to maintain accurate business contact records; and (e) event partners and referral sources.
3.4 Customer Data Processed on Behalf of Customers. The Service processes Customer Data as configured by each customer, which may include personal information such as the names, business contact details, and communications of the customer’s personnel, suppliers, and other business contacts appearing in procurement documents (purchase orders, order confirmations, invoices, packing slips, price lists) and in messages retrieved from connected mailboxes. We process this information as a service provider/processor under Section 2, and it is not used for our own marketing.
4. Connected Accounts and Email Integrations
Customers may connect third-party systems to the Service — for example warehouse management, shipping, e-commerce, inventory, or accounting systems — and may designate specific email mailboxes from which the Service retrieves supplier and procurement-related documents. When a customer authorizes a connection, we access and process data from that system or mailbox only as needed to provide the features the customer has configured. Access can be revoked at any time through the Service or through the third-party service’s own settings.
Email integrations are limited by design: the Service accesses only the mailboxes a customer designates, and processes messages and attachments to identify and extract procurement-related documents and associated metadata for use in the customer’s account.
4.1 Google User Data. Where a customer connects a Google account (for example, a Gmail mailbox used to receive supplier documents), our use of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. In particular: (a) we only use Google user data to provide and improve the user-facing features of the Service that the customer has configured; (b) we do not transfer Google user data to third parties except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition with notice; (c) we do not use Google user data for advertising; (d) we do not allow humans to read Google user data unless the customer or affected user has given consent, it is necessary for security purposes or to comply with law, or the data has been aggregated and anonymized for internal operations; and (e) we do not use Google user data to develop, improve, or train generalized artificial-intelligence or machine-learning models.
5. How We Use Personal Information
We use personal information for the following purposes:
To provide and operate the Service and Sites — creating and administering accounts, authenticating users, providing features (including document capture, three-way matching, and price-change monitoring as configured by the customer), hosting Customer Data, and providing customer support.
To process transactions — billing, payment processing, and account management.
To communicate with you — responding to inquiries, sending service and administrative messages (such as security notices, receipts, and changes to terms or policies), and, subject to your choices, sending marketing communications about our products, features, and events.
To improve and develop our products — understanding how the Service and Sites are used, troubleshooting, analytics, research, and developing new features, including using aggregated or de-identified data that no longer identifies any individual or customer.
To provide AI-assisted features — as described in Section 6.
For security and fraud prevention — monitoring, detecting, investigating, and preventing security incidents, fraud, abuse, and violations of our terms.
For legal and compliance purposes — complying with applicable law and legal process, enforcing our agreements, establishing and defending legal claims, and protecting the rights, safety, and property of our users, ourselves, and others.
In connection with corporate transactions — evaluating or carrying out a merger, acquisition, financing, reorganization, or sale of assets.
We do not use personal information for automated decision-making that produces legal or similarly significant effects about individuals.
6. AI Features
The Service includes features that use machine learning and large language models — for example, extracting structured data from supplier documents, suggesting matches among purchase orders, receipts, and invoices, and detecting supplier price changes. To provide these features, relevant Customer Data (such as a document being processed) may be transmitted to third-party AI providers acting as our subprocessors.
We only use AI providers that are contractually prohibited from using our customers’ data to train their generalized or foundation models, and AI providers are bound by confidentiality and data-protection obligations. AI-generated output is produced for the customer whose data was processed and is treated as that customer’s data. AI output can be inaccurate or incomplete; the Service is designed so that users review consequential output before acting on it.
7. Cookies and Similar Technologies
We and our service providers use cookies, pixels, local storage, and similar technologies on the Sites and the Service to operate and secure them, remember preferences and sessions, and understand usage. We group these technologies as follows:
Strictly necessary — required for the Sites and Service to function (for example, authentication and security cookies). These cannot be disabled through our controls.
Functional — remember choices you make, such as login state and interface preferences.
Analytics — help us understand how visitors and users interact with the Sites and Service so we can improve them.
You can control cookies through your browser settings, which typically allow you to refuse or delete cookies; doing so may affect the availability and functionality of the Sites and Service. Where we use third-party analytics providers, you can also use any opt-out tools those providers offer. We describe our treatment of Global Privacy Control signals in Section 15. We do not currently use third-party advertising cookies or engage in cross-context behavioral advertising; if that changes, we will update this Privacy Policy and provide any legally required notices and opt-outs.
8. How We Disclose Personal Information
We disclose personal information in the following circumstances:
Service providers and subprocessors. We use third parties to perform services on our behalf, such as cloud hosting and infrastructure (our production environment is hosted with Amazon Web Services in the United States), payment processing, email delivery, communications and support tools, analytics, and AI providers as described in Section 6. Service providers are permitted to use personal information only to perform services for us and must protect it.
At the customer’s direction; integrations. We disclose Customer Data to third-party services that a customer connects to the Service (for example, a warehouse management or accounting system), as configured by the customer. The third party’s handling of that data is governed by its own terms and privacy policy.
Within a customer’s account. Information about users of a customer’s account (such as names and activity within the Service) may be visible to that customer’s administrators and other authorized users.
Professional advisors. We may disclose personal information to lawyers, accountants, auditors, insurers, and other advisors under obligations of confidentiality.
Legal, safety, and enforcement. We may disclose personal information if we believe disclosure is required by law, regulation, or legal process; to respond to lawful requests by public authorities; or to protect the rights, property, or safety of our users, ourselves, or others, including to enforce our agreements and to detect, investigate, and prevent fraud or security issues.
Corporate transactions. If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of some or all of our assets, personal information may be disclosed to the parties involved and transferred as part of the transaction, subject to this Privacy Policy or successor notice.
With consent. We may disclose personal information with your consent or at your direction.
Aggregated or de-identified information. We may disclose information that has been aggregated or de-identified so that it no longer reasonably identifies any individual or customer, and we maintain and use such data only in that form and do not attempt to re-identify it, except as permitted by law to test de-identification.
WE DO NOT SELL PERSONAL INFORMATION, AND WE DO NOT SHARE PERSONAL INFORMATION FOR CROSS-CONTEXT BEHAVIORAL ADVERTISING. WE HAVE NOT DONE SO IN THE PRECEDING TWELVE (12) MONTHS.
9. Data Retention
We retain personal information for as long as necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law. In deciding how long to keep information, we consider the nature and sensitivity of the information, the purposes for which we process it, our legal and contractual obligations, applicable statutes of limitations, and the need to maintain business and financial records.
As a general matter: account and billing records are retained for the life of the customer relationship and thereafter as needed for tax, accounting, and legal purposes; support and sales communications are retained while relevant to the relationship; and Site analytics data is retained in identifiable form only as long as needed for the purposes described above. Customer Data is retained and deleted in accordance with our agreement with the customer — by default, customers may export Customer Data during the subscription and for sixty (60) days after termination, after which we may delete it from production systems and, in the ordinary course of our backup cycles, from backups. When we no longer need personal information, we delete it, de-identify it, or securely isolate it from further processing until deletion is possible.
10. Security
We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. These include encryption of data in transit and at rest, role-based access controls and least-privilege practices, logging and monitoring, and vendor security review. However, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential and for using available security features, such as strong passwords and multi-factor authentication. If you believe your account or any personal information has been compromised, please contact us at admin@meridianbfd.com. If we determine that a breach of security has affected your personal information, we will notify you and applicable regulators as required by law.
11. Your Privacy Rights and Choices
11.1 Marketing Choices. You may opt out of marketing emails at any time by using the unsubscribe link in the email or by contacting us at admin@meridianbfd.com. We will continue to send service and administrative messages related to your account or our ongoing business relationship.
11.2 Account Information. Users of the Service can review and update certain account information through the Service, or by asking their account administrator or contacting us.
11.3 U.S. State Privacy Rights. Depending on where you live, state privacy laws (including in California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws) may give you rights with respect to personal information we handle as a business, subject to conditions and exceptions, including the rights to: (a) know and access the personal information we have collected about you, including the categories collected, the sources, the purposes, and the categories of third parties to whom it was disclosed; (b) correct inaccurate personal information; (c) delete personal information; (d) obtain a portable copy of personal information; (e) opt out of the sale of personal information, the sharing or processing of personal information for targeted advertising, and certain profiling (as described in Section 8, we do not sell personal information or process it for targeted advertising); and (f) not receive discriminatory treatment for exercising your rights. Many of these laws apply only to individuals acting in a consumer capacity and may not apply to personal information processed in an employment or business-to-business context; we honor the rights that apply to you under the law of your state.
11.4 Exercising Your Rights. To exercise any of these rights, contact us at admin@meridianbfd.com with the nature of your request and enough information for us to verify your identity, which we may do by matching information you provide against information we hold, or through your authenticated account. An authorized agent may submit a request on your behalf with proof of authorization, and we may still require you to verify your identity. We will respond within the time required by applicable law (generally forty-five (45) days, with a permitted extension where reasonably necessary, in which case we will notify you). If we decline a request, we will explain why, and where applicable law provides an appeal process, you may appeal by replying to our decision or contacting admin@meridianbfd.com, and we will inform you of the outcome; if your appeal is denied, you may contact your state attorney general.
11.5 Requests Concerning Customer Data. If your personal information is contained in Customer Data that we process on behalf of a customer, we may not be able to act on your request directly. In that case, we will refer your request to the relevant customer and support its response as required by law and our agreement with that customer.
12. Notice to California Residents
This Section provides additional information for California residents under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"). It applies to personal information we handle as a business, and not to Customer Data we process as a service provider, nor to information exempt from the CCPA (such as certain business-to-business or employment-related information, to the extent exempt). In the preceding twelve (12) months, we have collected the categories of personal information described in the table below, from the sources and for the purposes described in Sections 3 and 5. We disclose each category to the service providers and other recipients described in Section 8. We do not sell personal information and do not share personal information for cross-context behavioral advertising, and we have no actual knowledge of selling or sharing the personal information of consumers under sixteen (16) years of age.
| Category (CCPA) | Examples we may collect | Sold or shared? |
| Identifiers | Name, business email address, phone number, IP address, account username | No |
| Customer records (Cal. Civ. Code § 1798.80(e)) | Billing contact details; payment method details held by our payment processor | No |
| Commercial information | Subscription history, plan details, transactions with us | No |
| Internet or other electronic network activity | Log data, pages viewed, features used, interactions with the Sites and Service | No |
| Geolocation data | Approximate location inferred from IP address | No |
| Professional or employment-related information | Employer, job title, business role | No |
| Sensitive personal information | Account log-in credentials (used only to authenticate and secure accounts) | No |
| Inferences | Limited product-usage analytics (we do not build advertising profiles about individuals) | No |
We use and disclose sensitive personal information only for purposes permitted by the CCPA, such as providing the Service and maintaining security, and we do not use it to infer characteristics about individuals; accordingly, we do not offer a "Limit the Use of My Sensitive Personal Information" control. We retain each category of personal information as described in Section 9. California residents may exercise the rights described in Section 11, including the rights to know, access, correct, and delete personal information, through the methods described there. California’s "Shine the Light" law (Civil Code § 1798.83) permits California residents to request certain information regarding disclosure of personal information to third parties for their direct marketing purposes; we do not disclose personal information to third parties for their direct marketing purposes.
13. International Use and Data Transfers
We are based in the United States, and the Sites and Service are hosted and operated in the United States. We primarily offer the Service to businesses in the United States. If you access the Sites or Service from outside the United States, you understand that your personal information will be transferred to, stored in, and processed in the United States and other jurisdictions where our service providers operate, which may have data protection laws different from those of your jurisdiction. Where required by applicable law, we implement appropriate safeguards for cross-border transfers, and we will supplement this Privacy Policy (including with a GDPR/UK addendum) before offering the Service in jurisdictions that require additional disclosures.
14. Children’s Privacy
The Sites and Service are intended for business users and are not directed to children. We do not knowingly collect personal information from anyone under eighteen (18) years of age, and in no event from children under sixteen (16). If you believe a child has provided us personal information, please contact us at admin@meridianbfd.com and we will delete it as required by law.
15. Do Not Track and Global Privacy Control
Some browsers transmit "Do Not Track" signals; because no common industry standard for interpreting them has been adopted, we do not respond to them. Where required by applicable law, we treat recognized opt-out preference signals, such as the Global Privacy Control (GPC), as a valid request to opt out of the sale or sharing of personal information for the browser or device sending the signal; because we do not sell or share personal information as described in Section 8, such signals do not change how we currently process personal information.
16. Third-Party Sites and Services
The Sites and Service may contain links to, or interoperate with, third-party websites and services, including systems our customers choose to connect. This Privacy Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party site or service you use.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make changes, we will post the updated policy with a revised "Last Updated" date. If the changes are material, we will provide additional notice before they take effect — for example, by email to account contacts or by a prominent notice on the Sites or in the Service. Your continued use of the Sites or Service after the effective date of an updated Privacy Policy means the update applies to you, to the extent permitted by law.
18. How to Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, contact us at:
Meridian BFD, LLC
Attn: Privacy
1402 Riverside Dr., Cincinnati, OH 45202
Email: admin@meridianbfd.com