Vendora OS — Privacy Policy
This policy explains what Vendora OS LLC ("Vendora," "we," "us"), a California limited liability company based in San Diego, collects and how we use it. It covers two things: our website at vendoraos.com, and the Vendora OS platform used by the businesses we serve ("Merchants") and their staff. It is part of our Terms of Service.
The Short Version
We collect what's needed to run a point-of-sale and business-management service, and not more. We don't sell personal information. We don't run advertising trackers — our website uses no cookies at all. Your business data belongs to you, you can export it, and when you leave we delete it after a wind-down window.
1. What We Collect
If you visit vendoraos.com: the site is static and sets no cookies and no third-party trackers or analytics. If you submit the contact form, we collect what you type (name, business name, email, phone, message) plus your IP address and browser type, which we use for spam prevention and rate limiting.
If your business uses the platform:
- Business account information — store name, address, phone, email, tax settings, logo, and configuration.
- Onboarding and underwriting information — the details a payment processor requires to approve your store for card acceptance, such as legal entity and ownership information, tax identification numbers, and your settlement bank account. We collect this to pass it to the processor (see §3); we don't use it for anything else.
- Staff information — names, roles, sign-in PINs, schedules, time-clock punches, and wage rates the owner enters for scheduling and payroll estimates.
- Business records — sales and refunds, inventory and supplies, expenses, supplier invoices (including invoice photos you scan), reservations, and reports derived from them.
- Your customers' information — customer names and contact details, loyalty balances, and gift-card records that you or your staff enter or collect through the Service. This data is collected on your behalf and under your direction (see §4).
- Payment information — card payments are handled by our payment processing partners on certified devices. Vendora does not receive or store full card numbers. We store transaction records (amounts, dates, card brand and last four digits, processor transaction identifiers).
- Technical data — sign-in events, IP addresses, device/browser type, and error logs, used for security and to keep the Service working.
2. How We Use It
- To provide and operate the Service: running your register, syncing your inventory, generating your reports, sending your receipts.
- To onboard and support you, including submitting your merchant application to a payment processor.
- For security: verifying sessions, rate-limiting abuse, investigating suspicious activity, and maintaining an activity log your owners can review.
- To improve the product, using aggregated or de-identified data that doesn't identify you or your customers.
- To communicate with you about the Service (support, notices about changes to pricing, features, or these policies; we don't spam).
We do not sell personal information, and we do not use your data — or your customers' data — for third-party advertising.
3. Service Providers We Share With
We share data only with the providers needed to run the Service, under agreements limiting their use of it:
- Hosting — our servers and database run in a United States data center in Hillsboro, Oregon, operated by Hetzner (a German company, Hetzner Online GmbH). Your business data is stored in the United States.
- Payment processing — card acceptance is provided by third-party payment processors, acquirers, and payment facilitators and their sponsor banks. Our processing partners are North American Bancard and Stripe, and we may add, replace, or move to another processor as our payments platform evolves; if we do, this policy continues to describe how that data is handled, and we'll name a new partner here. These partners receive the merchant information needed to underwrite and board your store (including the onboarding and underwriting information in §1) and the transaction data needed to authorize, process, settle, and reconcile your card sales, to handle disputes and chargebacks, and to detect and prevent fraud. Cardholder data — the card number and security code entered on a certified reader or payment page — goes directly to the processor and never to Vendora's servers. Their handling of all of this is governed by their own agreements and privacy policies with you.
- Email delivery — transactional email (receipts, notifications, lead responses) and email campaigns you send are delivered through our email provider (Resend).
- Text messaging — if your store sends SMS campaigns, the message and the recipient's phone number are delivered through our SMS provider (Twilio).
- AI processing — when you scan a supplier invoice, the image is sent to our AI provider (Anthropic) solely to extract the invoice's contents for you; we don't permit its use for anything else, including training.
- Advertising platforms — if you connect a Google, Meta, or TikTok advertising account, we use the access you grant to read your campaign, spend, and performance data so it can appear in your reports. We do not send your sales records, your customers' personal information, or audience lists to those platforms.
- E-commerce and other integrations you connect — if you connect a store or tool such as Shopify, we exchange the data that integration needs (for example products, inventory levels, and orders) with it, on your instruction.
We may also disclose information if the law requires it, to protect the safety or rights of Vendora, our merchants, or others, or as part of a sale or reorganization of our business (in which case this policy continues to apply to previously collected data).
4. Your Customers' Data (for Merchants)
When your store collects customer information through the Service — a loyalty signup, an emailed receipt, a reservation — you are responsible for that relationship: telling your customers how you use their information and honoring their requests. We process that data on your behalf and on your instructions, and we don't use it to market to your customers or share it with other merchants. If one of your customers contacts us directly about their data, we'll refer them to you and assist you in honoring the request.
5. Retention and Deletion
We keep your data while your account is active. If your account is terminated, you may export your data for thirty (30) days, after which we delete it from our production systems, except records we're required to keep for legal, tax, or dispute purposes. Encrypted backups rotate out automatically on a fixed schedule (currently fourteen days). Website lead-form submissions are kept while relevant to a sales conversation and deleted on request. Records held by a payment processor — transactions, disputes, and underwriting files — are retained under that processor's own policy and legal obligations, not ours.
6. Security
Data moves between your devices and our servers over encrypted connections (TLS). Access is scoped by business — each merchant's data is isolated to its own account — and staff access within your store is limited by the roles and PINs you assign. Card data is handled by certified payment devices and processors, not by Vendora's servers. No system is perfectly secure, and we can't guarantee absolute security, but if a breach affects your data we will notify you as required by law.
7. Your Choices and Rights
Email mateo@vendoraos.com to access, correct, export, or delete information we hold about you or your business, and we'll honor reasonable requests regardless of whether a specific privacy law compels us to. California residents: we don't sell or share personal information as defined by the CCPA/CPRA, and we honor the rights it provides where it applies to us.
8. Children
The Service and website are for businesses and their staff, and are not directed at children under 16. We don't knowingly collect children's personal information.
9. Changes to This Policy
We may update this policy as the Service and our providers change. For material changes we'll give at least thirty (30) days' notice by email to the address on file or by notice in the app — the same notice we give for changes to the Terms of Service — and the new version applies from the effective date stated in the notice. Non-material updates (such as naming a new service provider) take effect when posted. The current version, with its version number and effective date, always lives at vendoraos.com/privacy, and we may ask you to accept a new version when you next sign in.
10. Contact
Vendora OS LLC — San Diego, California
mateo@vendoraos.com