Privacy Policy
Effective Date: June 30, 2026
VendorLeak is a vendor risk assessment tool built for security and procurement teams. This policy explains plainly what data we collect, why, and how we protect it. We wrote it to be readable — not to bury things in legalese.
We do not sell your data. Ever.
Your vendor lists, scan results, and account information are never sold, rented, or shared with advertisers, data brokers, or any third party for commercial purposes. Full stop.
What we collect
We collect only what we need to run the service:
- Account info. Your email address and the name of your workspace. If you sign in with Google, we receive your email and name from Google — nothing else.
- Vendor data. The vendor names and URLs you submit for scanning or monitoring.
- Scan results. Risk scores, verdicts, and policy summaries generated for your vendors — stored in your workspace and visible only to you and your team.
- Usage logs. Basic logs (pages visited, API calls, timestamps, browser type) used to keep the service running reliably and detect abuse. Not used for advertising.
- Billing info. Your subscription status. We never see or store your full card number — that lives with Stripe, our payment processor.
- Gmail integration (optional). If you use our Gmail scanning feature, we request read-only OAuth access to identify sender domains in your inbox. We never read, store, or transmit email bodies or message content. The token is used only during the scan and is not persisted on our servers.
We use essential cookies for session management only. No advertising cookies, no behavioral tracking.
How we use it
- To create and manage your account and team workspace.
- To run vendor scans, generate risk reports, and power monitoring alerts.
- To send transactional emails — account verification, billing receipts, and important service notices. We do not send marketing emails without your consent.
- To keep the service secure and prevent abuse.
- To comply with legal obligations.
We do not use your data to train AI models. Vendor policy text submitted for analysis is sent to our AI provider solely to generate your immediate result — it is not retained by the AI provider for training under our agreement.
Who can see your data
Your data is yours. It is isolated to your workspace using row-level security — other organizations on VendorLeak cannot see your vendors, scores, or team members.
We share data with a small number of infrastructure providers who process it on our behalf to operate the service. Each is bound by a data processing agreement:
| Provider | What they handle |
|---|---|
| Supabase | Database, authentication, and storage |
| Stripe | Payment processing and subscription management |
| Vercel | Application hosting and content delivery |
| OpenAI | AI inference for vendor policy analysis (not retained for training) |
We may also disclose data if required by law — for example, a valid court order or government request. Where legally permitted, we will notify you before complying.
How we protect it
- All data is encrypted in transit (TLS 1.2+) and at rest.
- Row-level security enforces strict isolation between organizations.
- Passwords are hashed — we never store them in plain text.
- Sessions use short-lived tokens. Rate limiting is applied to all API endpoints.
If you find a security vulnerability, please report it to team@vendorleak.com before public disclosure. We take every report seriously and respond quickly.
Data retention & deletion
We keep your data for as long as your account is active. When you delete your account or cancel your subscription, all of your data — account info, vendor lists, scan history — is permanently deleted from our active systems within 60 days. Encrypted backups are purged within 30 days after that.
To delete your account, go to account settings or email team@vendorleak.com. We’ll take care of it promptly.
Your rights
You can always:
- Access a copy of your data — just ask.
- Correct anything that’s wrong or out of date.
- Delete your account and all associated data at any time.
- Export your data in a machine-readable format where technically feasible.
- Opt out — we don’t sell data, so there’s nothing to opt out of. But if you want to stop receiving any emails from us, just ask.
California residents (CCPA). You have the right to know what we collect, request deletion, and opt out of the sale of personal information. We do not sell personal information.
EEA/UK residents (GDPR). We process your data on the legal basis of contract performance and legitimate interest. You have the right to lodge a complaint with your local data protection authority.
To exercise any right, email team@vendorleak.com. We respond within 30 days.
Changes to this policy
If we make material changes, we’ll notify you by email at least 14 days before they take effect. Minor clarifications may be updated without notice. The effective date at the top of this page always reflects the latest version.
Questions?
VendorLeak
Email: team@vendorleak.com
We aim to respond to all privacy inquiries within 2 business days.
For the full legal terms governing your use of the service, see our Terms of Service.
© 2026 VendorLeak. All rights reserved.