100mL Trade Inc. (“100mL”, “we”, “us”) operates a business-to-business marketplace that connects hotels and hospitality groups with premium amenity brands. This policy explains what personal information we handle, why we handle it, who we share it with, and the choices you have.
100mL is a trade platform. Almost everyone whose information we hold is acting in a professional capacity — as a buyer for a property, as a member of a brand team, or as someone applying for a trade account. We do not sell to consumers and we do not build consumer advertising profiles.
Who this policy covers
This policy applies to everyone who interacts with 100mL, including:
- Hotel buyers and property teams with an approved trade account
- Brand partners and their team members selling through the marketplace
- Applicants who request access but are not approved
- Subscribers to our trade updates email
- Visitors to www.100mlhospitality.com who never create an account
It does not cover the independent privacy practices of the brands you buy from or the hotels you sell to. Once an order is approved, the counterparty handles your shipping and contact details under its own policy.
Information we collect
We collect only what the marketplace needs to operate.
- Account and identity: name, work email address, phone number, job role, and the organization you act for.
- Application information: company name, website, property count or product categories, order volumes, lead times, and any verification documents you name during the application. At MVP we record document file names in the application record; we do not store the files themselves.
- Authentication: password hashes (never plaintext passwords), one-time passcodes, linked Google or enterprise identity-provider identifiers, the sessions created after successful authentication, and sign-in attempt timestamps.
- Organization and team data: memberships, roles, invitations, and who invited whom.
- Property and shipping data: property names, addresses, and the shipping contact for each destination.
- Commercial activity: catalog browsing within the store, saved items, carts, order requests, approvals and declines, samples, invoices, ledger entries, and payouts.
- Banking and payment data — handled by Stripe, not by us. See “Payment and bank information” below.
- Communications: messages you send us through the support form, and the delivery status of the lifecycle emails we send you.
- Technical data: IP address, browser and device information, and pages viewed, collected in aggregate for security and performance.
How we use information
We use personal information to:
- Review trade applications and decide whether to approve an account.
- Authenticate you, keep your session alive, and enforce role-based permissions within your organization.
- Operate the marketplace: show approved catalogs and wholesale pricing, route order requests to the right brand, and move orders through approval, fulfillment, and delivery.
- Collect payment for approved orders, calculate sales tax, issue invoices, and pay brand partners.
- Send transactional and lifecycle email — sign-in codes, application decisions, order and invoice notifications, payout confirmations.
- Send marketing email where you have asked for it, and only until you unsubscribe.
- Provide support and respond to the requests you send us.
- Detect and prevent fraud, abuse, and automated sign-ups, and keep the platform secure.
- Meet our tax, accounting, and other legal obligations.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
Payment and bank information
100mL never sees or stores your full bank account number, card number, or tax identification number. Bank connections for hotel buyers run through Stripe Financial Connections, and brand payout onboarding runs through Stripe-hosted onboarding — you enter those details directly with Stripe.
What we retain is limited to references and non-sensitive descriptors we need to run the ledger: a Stripe customer or connected-account identifier, a payment-method identifier, the bank name and last four digits shown for recognition, mandate status, and the status of each charge, transfer, and reversal.
What the other side of a trade sees
A marketplace only works if counterparties can identify each other. When a hotel places an order request, the brand sees the ordering organization, the ordering contact’s name and work email, the order contents, and — after the brand approves the order — the shipping address and shipping contact for the destination property. Shipping details are deliberately withheld until approval.
When a brand approves, declines, ships, or delivers an order, the hotel sees the brand’s trading name and the status and any reason given. Brands never see another brand’s pricing, orders, or customers. Hotels never see another hotel’s activity. Team members see only the organization they belong to.
Service providers
We keep the vendor list deliberately short. Each provider is contractually limited to processing data on our instructions:
- Vercel — application hosting, file storage, and privacy-friendly analytics.
- Neon — the managed Postgres database that holds marketplace data.
- Stripe — payment collection, bank connections, sales-tax calculation, and brand payouts.
- Resend — delivery of one-time sign-in codes and password-reset links.
- Klaviyo — lifecycle and marketing email delivery and audience management.
- Cloudflare — Turnstile bot filtering on our public forms.
We may also disclose information to professional advisers, to authorities where the law requires it, and to an acquirer in the event of a merger, financing, or sale of the business — in which case this policy continues to apply until you are given notice of a replacement.
How long we keep information
- Trade accounts and their marketplace records: for as long as the account is active, and afterwards for as long as we need them for tax, accounting, and dispute-resolution purposes.
- Orders, invoices, and ledger entries: retained as financial records for the period required by applicable tax and accounting law.
- Rejected applications: retained so we can recognize and respond to a re-application, then deleted.
- Passwords: stored only as one-way hashes for the life of the approved account; reset tokens are single-use and expire after 30 minutes.
- One-time passcodes: retained as an approved-account fallback, stored hashed, and expire five minutes after issue.
- Sessions: 30-day sliding expiry; revoked immediately on sign-out.
- Marketing subscribers: until you unsubscribe, plus a suppression record so we do not email you again by mistake.
Security
Access to marketplace data is scoped to your organization by construction: every read is filtered by the membership on your verified session, and every write re-checks your role before it runs. Passcodes are hashed at rest, sessions are database-backed and revocable, and payment credentials never enter our systems. Traffic is encrypted in transit and data is encrypted at rest by our infrastructure providers.
No system is perfectly secure. If a breach affects your personal information, we will notify you and any required regulator within the timeframes the law sets.
Your privacy rights
Depending on where you live, you may have the right to request access to the personal information we hold about you, correction of inaccurate information, deletion, a portable copy, and to opt out of the sale or sharing of personal information. We do not sell or share personal information for advertising, so there is nothing to opt out of on that front.
To exercise a right, email privacy@100mlhospitality.com from the address on your account. We will verify your identity before acting and respond within the period the applicable law allows. We will not discriminate against you for making a request.
Some information cannot be deleted on request — completed orders, invoices, and ledger entries are financial records we are required to keep. Where that applies we will tell you what we retained and why.
Marketing choices
Marketing email is opt-in and double confirmed: you will not receive it unless you asked for it and clicked the confirmation link. Every marketing message carries an unsubscribe link that takes effect immediately.
Transactional messages — sign-in codes, application decisions, order and payment notices — are part of the service and cannot be unsubscribed from while your account is open.
International transfers
100mL is operated from the United States and our infrastructure providers process data in the United States. If you use the marketplace from outside the United States, your information will be transferred there. Where a transfer needs a safeguard under your local law, we rely on our providers’ standard contractual clauses.
Children
100mL is a trade platform for businesses. It is not directed to anyone under 18 and we do not knowingly collect information from children. If you believe a child has given us information, contact us and we will delete it.
Changes to this policy
We update this policy when our practices change. The revision date at the top always reflects the current version, and we will notify account holders by email before a material change takes effect.
Contact us
Privacy questions and data-rights requests: privacy@100mlhospitality.com. General support: support@100mlhospitality.com. 100mL Trade Inc. is incorporated in Delaware, United States.
100mL Trade Inc. · 139 Budlong Street, Hillsdale, MI 49242 · Incorporated in Delaware, United States.