VENDORGUARD

Privacy policy

Draft for operator review · Effective date: [EFFECTIVE DATE] · Operator: [VENDORGUARD LEGAL ENTITY]

Information we collect

We process account details, private vendor profiles, event submissions, outcome reports, optional verification evidence, saved analyses, and security logs to operate VendorGuard.

Public information and aggregates

Individual vendor financial results are not public. Event, category, and subcategory statistics require at least five qualifying vendors, with additional suppression where combinations could expose small groups.

Private evidence

Evidence is stored in private object storage. Authorized admins receive short-lived download links, and access is audited. Once verification is completed, evidence is scheduled for deletion after five business days. Non-file verification metadata may remain.

AI processing and retention

Inputs may be sent to our AI provider for extraction or analysis. Uploaded event packets and anonymous prompts are processed transiently and not stored by VendorGuard. Structured signed-in analyses are saved until deleted. We request non-storage from the AI API; provider operational retention may still apply. Inputs are not repurposed by VendorGuard for model training. AI usage metadata is retained for 30 days.

Service providers

Hosting, PostgreSQL, Supabase authentication, Cloudflare private storage and gateway, OpenAI, and optional analytics/error monitoring providers process data as needed to provide their services. Optional analytics must be configured and enabled with consent.

Account deletion

Account settings let you delete profile data, saved analyses, saved events, and evidence. De-identified outcome information may remain in aggregates when legally permitted. Contact the operator for unresolved deletion requests.

Age, security, and retention

Accounts are for adults 18 and older. We use access controls, private storage, audit logs, and data minimization; no system guarantees absolute security. Other operational records are retained as reasonably needed for security, legal, and product purposes.

Changes and contact

We may update this policy and notify users as required. Send privacy requests to [PRIVACY CONTACT EMAIL]. Legal counsel should review this draft before commercial launch.