Vendor Vault ("we", "us") respects your privacy. This Policy explains what we collect and why.
To provide the Service, send transactional email (receipts, invites, password resets, verification), keep the platform secure, and improve performance. We do not sell your data. We do not use it to train AI models.
You can export all your data from /billing, request deletion of your account (purges everything within 30 days), or contact us with any request at support@vendorvaultonline.com.
If you're in the EU/UK, you have GDPR rights of access, rectification, erasure, restriction, portability, and objection. If you're in California, you have CCPA rights of know, delete, and non-discrimination.
We keep your data while your account is active. After deletion, we purge it within 30 days, except as required by law (e.g. tax records may need to be retained longer).
Passwords are bcrypt-hashed. OAuth tokens are stored encrypted at rest in our database. We use TLS in transit. No system is 100% secure — please report any vulnerabilities to security@vendorvaultonline.com.
Vendor Vault is not directed at children under 16. We do not knowingly collect data from them.
If we change this Policy materially, we'll email you. Continued use means acceptance.
Questions? support@vendorvaultonline.com