Privacy
What happens to your bill of materials.
A BOM is one of the most sensitive documents a manufacturer has. This page describes exactly what MapleBOM does with one.
Who operates MapleBOM
MapleBOM is an independent project built and run by Tyson Hamilton, a Canadian software engineer. There is no team behind it, no company you have not heard of, and nobody else with access to what you send. When you write to hello@maplebom.ca, that is who reads it and who replies.
Uploaded BOMs are not retained
When you upload a CSV at /upload, it is read into the web process's memory, parsed, analyzed, and rendered into the page returned to you. When that request ends, the data is released. Specifically:
- The file is never written to disk, not even as a temporary file while it is being read.
- The file contents are never written to the database. A private-beta workspace can store a BOM, but only one you explicitly saved there — see below. Nothing uploaded here reaches it, whether or not you have an account.
- Your analysis is not saved. There is no report history and no share link, because there is nowhere for a report to live. Reloading means uploading again. Having a private-beta account changes none of this: a public upload is never attached to an account, then or later.
- The downloadable worklist and call list are built in memory alongside the page and embedded in it, so your browser saves a file it already had. No copy is kept here, and the download never contacts our server — we know only that a download happened, not what was in it.
- Nothing is sent to a third party. The site loads no external scripts, fonts, images or trackers, and the analysis calls no external service.
What we do record
We record enough to know whether this product is worth building:
- Page and funnel events — which pages were viewed, that an upload happened, and whether it succeeded. For an upload we store summary counts only: number of components, number of suppliers, whether origin and cost columns were present, and how long the analysis took. No part numbers, no descriptions, no supplier names, no prices.
- A first-party session cookie holding a random value, so that a single visit's events can be counted as one visit. It identifies nobody and is not shared.
- Details you type into the request form — your name, work email, company, role, approximate BOM size and what you are trying to solve. That is the whole point of the form, and it is stored.
- Anything you send through the contact form — your name, email, optional company and your message, stored so that it can be answered. Contact messages are kept separately from analysis requests.
- Standard web server request logs, including your browser's user agent and the page you came from.
If you create a private-beta account
MapleBOM is testing a private workspace, reachable only at
/app. It is a separate, deliberate choice: nothing about
the public analyzer above creates an account or changes if you have one.
If you do sign in, we store:
- Your email address, because a sign-in link is how you get in. There is no password to store.
- Your workspace and its name, which is taken from your email domain until renaming exists.
- Your open sign-in sessions, held as a hash rather than as anything usable, plus the browser user agent so you can recognise a session you do not remember starting.
- That a sign-in link was requested for an address, for up to 24 hours, so the same address cannot be mailed repeatedly by somebody who does not own it.
No IP address is stored against any of that. Limiting how often one computer can request sign-in links is done in memory and written nowhere, precisely so that asking to sign in does not create a record of who asked and from where.
If an email to your address permanently bounces, or you mark one as spam, we record the address on a do-not-mail list and stop sending to it. That list exists so we do not keep mailing people who do not want it.
Bills of materials you save
A private workspace can now store a BOM, and this is the only place in
MapleBOM where a file is kept. It happens when you tick a box on
/app/w/…/save saying so, and never otherwise:
- The original file, exactly as uploaded. Byte for byte, including anything our parser would otherwise clean up, with its SHA-256 so you can check a download against it. You can download it back at any time.
- What our parser made of it — how many component rows, how many suppliers, how many rows it could not use, and which build of the parser produced those numbers.
- The product name you gave it, and who uploaded it.
Nothing is deleted when you save a new version: versions are kept so that what you saw on a date stays recoverable.
How long you can reach them. While your workspace is open, and for 30 days after a trial or paid period ends. After that the workspace closes and files stop being served — they are not deleted, and we will reopen it on request so you can export them. Deletion happens when you ask for it.
What we cannot promise. Asking for deletion removes your data from the live database. Database backups are taken by our hosting provider and we have not yet established how long they retain them or how deletion propagates, so we will not claim every copy disappears the moment you ask. We have to close that gap before this beta accepts anyone's real production data.
A file you upload at /upload is never saved, whether or not you have an account, and is never attached to one afterwards. Those are separate paths in the code and the public one still keeps nothing.
Nothing is deleted automatically. If a trial or a paid period ends, the workspace stays readable for 30 days so you can export what is in it, and after that it is closed rather than erased. We will not remove your data without telling you first, and there is no state in which you cannot ask for it back or ask us to delete it.
Ask and your account is deleted, along with the workspace and every session: hello@maplebom.ca. Deletion is by request today, handled by a person rather than a button.
None of it is sold, shared, or added to a mailing list. If you would like anything you have sent deleted, ask and it will be — one message to hello@maplebom.ca is enough, and you do not have to give a reason.
What we do not claim
MapleBOM is an early-stage experiment run by a small team. We are not going to describe security properties we have not built:
- There is no certification, audit or formal compliance programme behind this site — no SOC 2, no ISO, and no third party has reviewed any of this.
- The public analyzer has no accounts and nothing stored behind one. The private beta does: sign-in links, sessions held as hashes, and any BOM you saved. That is protected by the sign-in link reaching your inbox and nothing stronger — there is no two-factor authentication and no single sign-on yet. If your email account is compromised, so is your workspace.
- The application runs on Railway, a third-party hosting platform, which serves traffic over HTTPS. The web process holds nothing between requests.
- The database is managed by that same provider, so leads, contact messages and analytics events are held on their infrastructure.
- We make no claim of Canadian data residency. MapleBOM is built in Canada, which is a statement about who writes it and who it is for — not about which country a server sits in. If residency matters to you, ask before sending anything and we will tell you where things actually run.
If your organisation's policy prohibits uploading a BOM to a third-party website, do not upload one. Run the sample analysis instead, and if the output is useful, get in touch — a sanitized BOM, with part numbers and prices scrambled, is enough to show you the same thing.
The analysis itself
We do not enrich your BOM against outside sources, and we do not guess. If your file does not establish a country of origin, the report says Unknown / Unverified. We never infer origin from a supplier's location, a manufacturer's headquarters or a company's nationality.
Questions
Write to hello@maplebom.ca or use the contact form. If any of the above is unclear, or you think a sentence on this page overstates what the software actually does, that is worth telling us.
Uploads are limited to 25 MB. This page describes the current implementation and will be updated if the implementation changes.