Legal
Privacy Policy
What we collect, why we collect it, and who it is shared with — described against what the platform actually does.
Last updated: September 2026
1. Introduction
This Privacy Policy explains what information Vendio collects when you use our marketplace, storefronts and vendor tools, why we collect it, who we share it with, and the choices you have.
Vendio connects buyers with local vendors. Some information necessarily moves between the two of you so an order can be fulfilled, and this policy is explicit about where that happens.
2. Account information
When you create an account we collect your name, email address and password, and your phone number if you provide one. Passwords are never stored in readable form.
We record whether your email address has been verified, and we keep a limited security record of sign-in activity on your account, described under technical and security information below.
3. Buyer information
If you save delivery addresses, we store the recipient name, phone number, address lines, city, region, postal code, country, and any delivery notes you add, along with which address you have marked as default.
We store the carts you build and the orders you place, including the items ordered, quantities, prices, delivery fee, total, fulfilment method, the payment method you selected, and any note you leave for the store.
4. Guest checkout information
Some stores let you order without creating an account. When you order as a guest we collect the contact name, phone number and email address you enter, and store them with the order so the vendor can prepare it and contact you about it.
Guest orders are not linked to a personal account, so you will not be able to sign in later and see them in an order history.
5. Vendor and store information
If you open a store, we collect the information needed to publish and operate it: your store name, description, category, and the public contact details you choose to display, which may include a public address, email address and phone number. Anything you mark as public is visible to shoppers.
We store your store's operating settings, such as currency, timezone, whether you offer pickup and delivery, your delivery fee, which payment methods you accept, and your storefront colours.
If you provide bank transfer details for buyers to pay you directly, those details are encrypted where we store them.
We keep an activity record for each store showing which team member took which action, so store owners can see who changed what.
6. Order information shared between buyers and vendors
Fulfilling an order requires the vendor to know who the order is for and how to reach you. When you place an order, the vendor receives your name, the contact phone number and email address associated with the order, the items and totals, your chosen fulfilment and payment method, any note you left, and — for delivery orders — the delivery address you selected.
We cannot offer the Service without this exchange. If you would prefer a vendor not to hold your delivery address, choose pickup where the store offers it.
Vendors are independent businesses and are responsible for how they handle the information they receive about their customers.
7. Content you upload
We store the images and text you upload, including product images, product descriptions, store logos and banner images. Product and store media is held in third-party object storage on our behalf.
Anything you publish to a storefront or to the marketplace is publicly accessible. Please do not include personal information in product images or descriptions that you do not want to be public.
8. Support requests
When you contact support we receive the name, email address, category and message you submit, plus an order or store reference if you include one. We use it to answer you and to investigate the issue, and it reaches us by email.
9. Technical and security information
To keep accounts secure we record authentication events — such as sign-in attempts, password resets and email verification — together with whether the attempt succeeded, the IP address it came from, and the browser user agent string. We also count failed sign-in attempts so an account can be temporarily locked after repeated failures.
We keep session records so you stay signed in and so sessions can be expired or revoked. Session tokens are stored hashed, not in readable form.
Like any internet service, our hosting and email providers process technical information such as IP addresses in the course of delivering the Service.
11. How we use information
- To create and maintain your account and keep you signed in.
- To publish vendor storefronts and show stores and products in the marketplace.
- To take, route and track orders, and to keep buyers and vendors updated on order status.
- To send transactional email such as email verification, password resets, order updates and team invitations.
- To answer support requests and investigate problems reported to us.
- To protect the Service — detecting and responding to suspicious sign-in activity, fraud, abuse and breaches of our Terms.
- To operate, maintain and improve the Service, including diagnosing faults.
- To meet legal obligations that apply to us.
13. How long we keep information
We keep account, store and order information for as long as your account or store is active, and afterwards where we still need it — for example to keep an accurate record of orders that were placed, to resolve disputes, or to meet a legal obligation.
Some records expire on their own: sessions expire and can be revoked, and email verification and password reset tokens are short-lived by design.
We have not set fixed retention periods for every category of information, and we would rather say so than publish a schedule we do not yet apply.
14. Security
We take reasonable measures to protect information, including hashing passwords, storing session tokens hashed rather than in readable form, encrypting vendor bank transfer details where we store them, serving the Service over encrypted connections, restricting staff access within a store to the permissions the store owner grants, and rate-limiting sensitive endpoints.
No online service can be completely secure, and we cannot guarantee that information will never be accessed without authorisation. Please use a strong, unique password and tell us if you think your account has been compromised.
15. Your choices and rights
You can review and update your name, phone number and saved addresses from your account settings, and vendors can update their store information from the vendor dashboard.
Account deletion is not yet self-service. If you would like your account closed or your information deleted, contact us and we will handle the request, subject to any information we need to keep for legal or record-keeping reasons.
If you want a copy of the information we hold about you, or want to raise a concern about how we handle it, contact us at support@vend-io.com.
16. Children
The Service is not directed to children, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will take appropriate steps.
17. Changes to this policy
We may update this policy as the Service develops. When we do, we will change the "Last updated" date at the top of this page, and we will take reasonable steps to bring significant changes to your attention.
18. Contact
If you have questions about this policy or about how your information is handled, contact us at support@vend-io.com, or through our contact page.
