Privacy
What we collect, and why.
VendLead is a directory of vending placement opportunities. This policy describes exactly what the service stores, which providers process it, and how to have it removed.
Last updated 30 August 2026
Information you give us
Creating an operator account stores:
- Your email address and password. The password is never stored in readable form; our authentication provider stores only a cryptographic hash of it.
- Your full name, business name, phone number, city, and state. These fields are required when you apply so the team can review the business and establish your operating market.
- A derived market centre and default search radius. The service resolves an approximate position from your city and state so it can rank opportunities by distance; it does not ask for or store your exact home address.
- A profile photo, if you choose to add one. This is optional.
Once approved, you can edit the account fields other than your sign-in email from profile settings. Pending members can complete missing application details on the waitlist. Suspended members can ask support to correct account information while protected settings are paused.
Open your profile settingsInformation created by using the service
- Saved searches and their alert frequency, so we can notify you when new opportunities match.
- Bookmarks and the opportunities you have unlocked.
- Purchase and subscription records — what was bought, when, its status, and the identifier our payment processor assigns you.
- Notification preferences, including whether you want email alerts at all.
Payment information
We never see or store your card details. Payments are handled entirely by Stripe, which collects card information directly and processes it under its own privacy policy. What we keep is the customer and transaction identifiers Stripe returns, plus whether a purchase succeeded — enough to know what access you are entitled to.
We also keep the event records Stripe sends us about your payments — refunds, payment failures, invoices, and disputes — so a purchase can be reconciled and a problem investigated. These can include billing details, the payment method type, and failure reasons; they never include full card numbers. They are retained for reconciliation and retry. There is no current scheduled deletion for these event records.
IP addresses and browser details
Two moments in the service write down the request itself — the IP address it came from and the browser user-agent string it sent — and not only what it did:
- Starting a checkout. The purchase record keeps the address and browser of the request that created it. We capture it here, inside your own request, rather than from the payment processor's later callback — that callback comes from Stripe's servers, so it would record Stripe's address instead of yours.
- A privileged administrative action. When someone with staff access changes a role, suspends or bans an account, refunds a purchase, or edits a listing, the audit record of that action keeps the address and browser of whoever took it.
We keep them for three reasons and no others: to spot fraud, such as several accounts operating from a single address; to answer a payment dispute, where evidence of who bought what, and from where, is what settles it; and to audit who did what inside the administrative console.
These records are kept indefinitely. We do not delete them on a schedule, and we are not going to name a shorter window than we actually apply: an audit record is a permanent account of a privileged action, and a purchase record has to outlive any dispute over it. If that ever changes, this page changes with it.
What this is not: ordinary browsing is not recorded this way. Cloudflare, as our host, processes request metadata including your IP address to deliver and protect the site, as every web host does, and our visit counter is cookieless and aggregate — but the application itself writes an address down only at the two moments above. None of it is used to build an advertising or behavioural profile, and none of it is shared for that purpose.
Who processes your data
We use a small number of providers, each for a specific purpose:
- Supabase — the database, sign-in system, and private file storage. Account and marketplace data live here, hosted in the United States.
- Stripe — payment processing and subscription billing.
- Resend — sending transactional email such as confirmation links, password resets, and opportunity alerts.
- Cloudflare — serving the site. Like any web host, it processes request metadata such as IP address for delivery, security, and abuse prevention. We also use Cloudflare Web Analytics to count visits. It sets no cookies and cannot follow you to other sites: it records the page you viewed, where you arrived from, your browser and country, and how quickly the page loaded. We see totals, never individuals.
- Google — only if you choose “Sign in with Google”. Google’s sign-in script runs on our sign-in and sign-up pages so the choice is there to make, and Google tells us your name, email address, and profile picture once you approve it. No other page loads it, and declining costs you nothing: email and password, or an emailed sign-in link, work the same.
What we do not do
- We do not sell or rent your personal information.
- We do not run advertising trackers, analytics cookies, or third-party marketing pixels. Exactly two scripts come from another company: Google's sign-in script, on the sign-in and sign-up pages only, and Cloudflare's cookieless visit counter. Neither one follows you off this site.
- We do not build advertising or behavioural profiles. The IP addresses and browser details described above are read to investigate fraud, payment disputes, and security incidents, and for nothing else.
- We do not send unrelated marketing. Opportunity alerts cover nearby published opportunities and searches you saved. Pending members can update alert choices on the waitlist, and active members can update them in profile settings.
Cookies
VendLead sets cookies for one reason: to keep you signed in and to protect that session. There are no advertising or analytics cookies. Clearing them signs you out.
Protected contact details
Opportunity listings include a location's contact details and, sometimes, private documents. Those are deliberately withheld until access is authorised by a purchase or an explicit permission. Documents are held in private storage and served only through short-lived links generated for an authorised request — never from a public address. If you are a location that has shared contact details with us, that same protection applies to your information too.
How long we keep it
Account information is kept while your account exists. Purchase and payment records are kept longer where financial and tax obligations require it, even after an account closes. Saved searches, bookmarks, and notifications are removed with the account.
Audit records of privileged administrative actions, and the IP address and browser details attached to those records and to purchases, are kept indefinitely, as the section above sets out. Deleting an account does not erase the audit trail of what staff did to it, because a record of a suspension that can be made to disappear is not an audit trail.
Your choices
- Active members can see and correct account information in profile settings. Pending members can complete missing application details on the waitlist; suspended members can ask support for a correction.
- Pending members can update alert choices on the waitlist, and active members can turn opportunity alerts off in profile settings without closing an account.
- Request a copy of your data, or ask support to close your account. Purchase, payment, and audit records may remain where accounting, dispute, fraud-prevention, or security obligations require them.
- Depending on where you live, you may have additional rights over access, correction, deletion, or portability. We apply these requests to everyone rather than only where legally required.
Children
VendLead is a business tool and is not directed at children. We do not knowingly collect information from anyone under 18.
Changes and contact
If this policy changes materially, we will update the date at the top of this page. For any privacy question, a copy of your data, or a deletion request, get in touch.
Open a private support request