Skip to content
VVendorlogic
Product guidePricingSign inJoin public beta
← Back to Vendorlogic

Privacy policy

Last updated July 2026

On this page
  1. 1. Information we collect
  2. 2. How we use it
  3. 3. Information sharing
  4. 4. Data security
  5. 5. Data retention
  6. 6. Your rights
  7. 7. Third-party services
  8. 7a. Signature & audit metadata
  9. 8. Cookies & tracking
  10. 8a. GDPR (EU/EEA/UK)
  11. 9. Contact

1. Information we collect

Vendorlogic collects information you provide directly when creating an account, submitting credit applications, or responding to trade reference requests. This includes your name, email address, phone number, business details, and banking information relevant to credit evaluation.

2. How we use your information

We use collected information to:

  • Process and evaluate credit applications
  • Facilitate trade reference requests and responses
  • Communicate application status updates
  • Support optional AI-assisted and business-discovery features you choose to use
  • Improve our platform and user experience

3. Information sharing

We share application data only with the vendor you applied to and their authorized team members. Trade reference data is shared with the requesting vendor. We do not sell personal information to third parties. We share information with service providers only as needed to host, secure, operate, support, and improve the service, or when you choose to use an optional feature that requires an external provider.

4. Data security

Network connections use TLS. Hosted data is protected by provider-managed encryption at rest, and application access is restricted through role-based permissions. Passwords are stored as salted hashes rather than readable text.

5. Data retention

We retain application data for as long as your account is active or as needed to provide services. You may request account deletion through the account settings page, which deactivates your account and removes your password.

6. Your rights

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account
  • Export your application data

7. Third-party services

We use the following service providers. The information each provider receives depends on the feature being used:

  • Supabase — primary database and file storage.
  • Upstash — short-lived security, rate-limit, and service-protection records.
  • PostHog — opt-in product analytics. Automatic interaction capture and session replay are disabled.
  • Sentry — sanitized error diagnostics. Browser tracing and session replay are disabled.
  • Resend — transactional email delivery.
  • Stytch — optional SMS verification when you choose phone-based account recovery or sign-in.
  • BetterStack — external uptime monitoring; pings public health endpoints only.
  • Vercel — application hosting and Speed Insights performance telemetry.
  • LinkedIn — optional account sign-in when you choose the LinkedIn authentication method.
  • Anthropic — processes content submitted to optional AI-assisted features.
  • Apollo — optional business-contact discovery for authorized vendor users.
  • Google Places — optional public business and location search.
  • Firecrawl — optional retrieval of public company-website content for business discovery.

7a. Signature and audit metadata

When you electronically sign an application, decision, or trade reference, we record your typed name, signature image (drawn on a signature pad), the IP address from which you signed, and your browser user-agent string. This metadata is retained as proof of intent and is included in any signed PDF we generate.

We also maintain a security audit log of authentication events (sign-in, sign-out, impersonation, permission changes). The audit log stores a one-way hash of the IP address — not the raw IP — so we can detect anomalous patterns without retaining the original identifier.

8. Cookies and tracking

Vendorlogic uses cookies in three categories:

  • Essential — required for sign-in, CSRF protection, and session continuity. These are always set and cannot be disabled because the platform will not function without them.
  • Analytics — PostHog product analytics and Vercel performance telemetry. Off by default. Analytics does not load until you opt in through the privacy banner. You can change your choice at any time using the “Cookie preferences” link in the footer.
  • Marketing — none currently used.

We do not use third-party advertising cookies and do not sell or share data for advertising purposes.

Change your choice: use the “Cookie preferences” control in the footer to accept or reject optional analytics. Rejecting analytics does not affect essential sign-in and security cookies.

8a. EU / EEA / UK users (GDPR)

If you are accessing the platform from the European Union, the European Economic Area, or the United Kingdom, the GDPR (and the UK's equivalent regime) gives you the following rights with respect to personal data we hold about you:

  • Right of access to your personal data
  • Right to rectification of inaccurate data
  • Right to erasure (“right to be forgotten”), subject to legal-retention exceptions
  • Right to restrict or object to processing
  • Right to data portability — receive your data in a machine-readable format
  • Right to withdraw consent at any time for processing based on consent (e.g. analytics)
  • Right to lodge a complaint with a supervisory authority in your country of residence

The legal bases we rely on are: contract(processing required to provide the credit-application service you signed up for), consent (analytics cookies, optional features), and legitimate interest(security audit logs, fraud prevention).

To exercise any of these rights, email vinnie@vltest.net with the subject line “GDPR request”. We respond within 30 days as required by GDPR.

Note (beta): Vendorlogic is currently in beta and does not operate an EU data center. Personal data is processed in the United States by our hosting providers. The specifics of our international-transfer mechanism, Data Protection Officer designation, and EU representative are pending legal review and will be added to this policy before general availability in the EU.

9. Contact

For privacy-related questions or requests, contact us at vinnie@vltest.net.

V© 2026 Vendorlogic
PrivacyTermsSupportStatus
vinnie@vltest.net