Privacy Policy
1. Who we are
This Privacy Policy applies to the VendorIntel platform (the "Service"), including vendorintel.ai, vrm.vendorintel.ai, and app.vendorintel.ai, operated by VendorIntel ("VendorIntel," "we," "us," or "our"). For privacy questions contact privacy@vendorintel.ai.
2. Information we collect
2.1 Information you give us
- Account data: name, work email, password (stored hashed), company / franchise name, role, number of locations.
- Billing data: billing address and tax information. Payment card details are collected and stored by Stripe, our payment processor — we receive only a customer identifier and last-four digits, never the full card number.
- Lead & sales inquiry data: any information you submit on contact forms (location count, role, product interest, free-text messages).
- Operational data: vendor records, contracts, surveys, action plans, and other content you (or your team) enter into the platform ("Customer Data").
- Communications: emails and messages you send us.
2.2 Information we collect automatically
- Standard server log data: IP address, browser type, pages viewed, referrer.
- Authentication tokens: we store a short-lived session token (issued by Supabase Auth) in your browser's local storage to keep you signed in. This is used only to authenticate you against our own service and is not used for cross-site tracking.
- Preference storage: we store your environment selection (Sandbox / Live) and onboarding checklist progress locally in your browser and on our servers.
2.3 Information we do not collect
- We do not collect or store full payment-card numbers. All card processing happens on Stripe's PCI-compliant infrastructure; we receive only a customer identifier and last-four digits for display purposes.
- We do not use third-party advertising trackers.
- We do not sell your personal information.
3. How we use information
- To provide, secure, and improve the Service.
- To authenticate you and manage your account, subscription, and billing.
- To respond to sales inquiries and support questions.
- To send transactional emails (signup confirmation, password resets, billing receipts, trial-ending reminders, subscription notifications).
- To send occasional product updates and announcements (you can unsubscribe at any time).
- To generate aggregated, anonymized benchmarks and analytics (data that does not identify you or your organization).
- To comply with legal obligations and enforce our Terms of Service.
4. Legal basis (GDPR / UK GDPR users)
We process your data under the following legal bases: (a) contract — to deliver the Service you requested; (b) legitimate interests — operating and improving our business; (c) consent — for optional marketing emails, which you can withdraw at any time.
5. Sharing & sub-processors
We share data only with vendors who help us run the Service, under written data-processing terms:
- Supabase — database hosting, authentication, and API for account and Customer Data. Data resides in Supabase's cloud infrastructure.
- Stripe, Inc. — payment processing, subscription management, and billing. Stripe's own privacy policy applies to payment data.
- Genspark / Cloudflare — static site hosting and edge delivery.
- Google Fonts — typography (no account data shared).
- Email service providers — for transactional emails such as receipts and password resets.
We do not sell, rent, or trade your personal information.
6. Data retention
We keep account data and Customer Data while your account is active. After cancellation, we retain your data for approximately ninety (90) days to allow for reactivation, after which it may be permanently deleted. Billing records are retained for the period required by tax and accounting law (typically 7 years). Sales-inquiry records are kept for up to 24 months. You can request earlier deletion by emailing privacy@vendorintel.ai.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal data; to object to or restrict processing; and to lodge a complaint with your data-protection authority. California residents have rights under the CCPA/CPRA. To exercise any right, email privacy@vendorintel.ai. We will respond within 30 days.
8. Security
We use HTTPS everywhere, encrypted database storage at rest, encrypted authentication tokens, hashed passwords, and Row-Level Security (RLS) policies to ensure each customer can access only their own data. We follow industry best practices for security operations. Payment card data is handled exclusively by Stripe, which is PCI-DSS Level 1 certified.
While we work to protect your data, no online service is 100% secure. You are responsible for maintaining the confidentiality of your account credentials and for keeping your own backups of important data.
9. International transfers
Our service providers may process data in the United States and the European Union. Where required, we rely on Standard Contractual Clauses to protect transfers.
10. Children
The Service is intended for business users 18+. We do not knowingly collect data from anyone under 18.
11. Changes to this policy
We may update this policy. The "Effective Date" at the top tells you when it last changed. Material changes will be announced by email or in-app notice.
12. Contact
Privacy questions: privacy@vendorintel.ai
General inquiries: hello@vendorintel.ai