Last updated July 28, 2026

Privacy Policy

This configurable template explains how VendorEpoch handles personal information. It has not been reviewed by an attorney and does not claim certification.

What we collect

We collect account email, optional display name, organization membership, notification preferences, billing entitlement identifiers, watchlist configuration, audit events, and security metadata reduced to keyed hashes where practical. Explicit signup also records the acknowledged legal document, action, version, source, completion time, originating magic-link reference, and a keyed hash of the completion IP address. We do not collect or store payment-card data.

Why we process it

We use this information to authenticate users, provide requested monitoring and reports, operate subscriptions, prevent abuse, diagnose service state, honor privacy requests, and meet documented legal obligations.

Lifecycle evidence

Official vendor documents, sanitized snapshots, evidence excerpts, and lifecycle claims are public product data, not customer data. Customer asset context remains tenant-scoped.

Cookies and analytics

A necessary secure-session cookie supports signed-in use. Protected production owner diagnostics use a separate necessary eight-hour cookie bound to the current user and session and scoped to owner pages; session revocation invalidates it, while sign-out or account deletion clears it. Abuse prevention uses keyed server-side identifiers rather than a tracking cookie. When enabled, first-party server-side analytics store only a fixed successful-event name, applicable account and organization UUIDs, bounded enum/boolean properties, and a 390-day expiry in VendorEpoch's PostgreSQL database. There is no browser analytics script or analytics cookie. Cross-context behavioral advertising and paid marketing are disabled by default.

Retention

Active account records persist while needed to provide the service. Signup acknowledgement evidence remains during the 30-day account-deletion recovery window and is removed with the eventual user purge. Raw watchlist CSV files are parsed in memory and are not retained; sanitized filename, content hash, counts, and row-error metadata remain with the organization until its deletion. Expired sessions, reports, delivery logs, analytics, and audit events follow documented retention schedules.

Your choices

Authenticated users can export account data, including signup acknowledgement evidence, and request deletion without contacting support. Newsletter subscribers can unsubscribe in one click and adjust preferences. Billing records follow separately stated tax and accounting boundaries.

Disclosures

We disclose data only to configured subprocessors needed to host, bill, deliver email, store backups, measure service health, or respond to valid legal process. We do not sell personal information.

Security

Controls include secure cookies, server-side tenant authorization, encryption in transit, encrypted provider secrets, rate limits, signed webhooks, audit events, and tested backup procedures. No system can guarantee absolute security.

Contact

Privacy requests: [email protected]. Security reports: [email protected]. Legal identity and address: [Owner legal identity required], [Owner business address required].