Privacy Policy
VendorInspect ("we", "our", or "us") operates vendorinspect.com. This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information.
1. Information We Collect
We collect the following categories of information:
- Vendor URLs you submit — the website address you enter to run an inspection.
- Vendor name — the official vendor name you provide at checkout.
- Email address — collected at checkout and when you request a report link to be resent, used to deliver your report.
- Payment information — handled entirely by Lemon Squeezy; we never see or store your card details.
- Usage data — anonymised analytics (page views, browser type, country) collected via Google Analytics (GA4).
2. How We Use Your Information
- To generate and deliver your vendor due diligence report.
- To send you a magic link so you can retrieve your report later.
- To respond to support requests you initiate via our contact form.
- To improve the service through aggregated, anonymised usage analytics.
We do not use your data for advertising, profiling, or sell it to third parties.
3. Data Storage & Retention
Reports and associated email addresses are stored in Supabase (hosted in US East). We retain report data for 90 days after generation, after which it is automatically deleted. You can request earlier deletion by contacting us.
4. Third-Party Services
We use the following sub-processors:
- Supabase — report storage (EU region).
- Resend — transactional email delivery.
- Lemon Squeezy — payment processing and checkout.
- Google Analytics (GA4) — anonymised usage analytics. IP anonymisation is enabled.
- Anthropic / Claude API — AI analysis engine. Submitted vendor URLs and names are sent to Anthropic's API to generate your report. Anthropic's usage policies apply.
5. Cookies
We use the following cookies:
- Google Analytics cookies (_ga, _gid) — analytics, expires after 2 years / 24 hours respectively.
- Lemon Squeezy cookies — set during the checkout process to maintain your session.
No cookies are used for advertising or cross-site tracking.
6. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data.
- Object to or restrict processing.
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, contact us at the address below.
7. Data Transfers
All sub-processors (Supabase, Anthropic, Resend, Lemon Squeezy) operate in the United States. If you are located in the EEA or UK, your data will be transferred to and processed in the US. We rely on applicable data transfer mechanisms for such transfers.
8. Children's Privacy
VendorInspect is a business-to-business service and is not directed at individuals under 18. We do not knowingly collect data from children.
9. Changes to This Policy
We may update this policy from time to time. We will update the "Last updated" date at the top of this page. Continued use of the service after changes constitutes acceptance of the revised policy.
10. Contact
Questions about this policy? Contact us via the Contact Support link in the footer, or write to us at privacy@vendorinspect.com.