ALL VISITORS AND ACCOUNT HOLDERS · UPDATED OCTOBER 6, 2026
Privacy Policy
1. Information Vendiaro handles
Depending on the feature you use, Vendiaro may handle:
- Account and profile data: email address, username, display name, password hash/session data held by the authentication provider, email-confirmation status, profile photo, and security events.
- Agreement and application data: versions and timestamps for terms accepted; seller type, public business/display name, introduction, shipping region, inventory categories/source/volume, inspection and data-wiping process, experience, sourcing-record readiness, fulfillment readiness, and response targets.
- Listing and safety data: title, description, price, category, condition, seller-provided device details, photos, screening signals, staff review history, reports, and listing status. Current AI screening sends structured listing text and metadata (including photo count) to Groq when enabled; it does not send the photo files in the current implementation.
- Buyer settings, if checkout is used: billing and delivery name/address, contact phone if supplied, order, shipment, support, and refund/dispute information. For a direct charge, checkout may create a Customer record in the seller's connected Stripe account to prefill saved addresses; the seller/payment provider will receive order and fulfillment details. Full card numbers are handled by Stripe, not stored in Vendiaro's database.
- Seller payment verification, if enabled: information the seller submits directly to Stripe or another selected payment provider, such as identity, entity, bank/payout, and tax details. Vendiaro receives status and account references needed to operate the marketplace; the provider may process additional information under its own notice.
- Support and safety submissions: information you choose to include in an email or form, plus reports, appeal evidence, and relevant account/listing/order records.
- Technical and abuse-prevention data: IP address, browser/device and request information, cookie/session data, logs, CAPTCHA/Turnstile results, and event data used by Vercel, Supabase, Cloudflare, payment/email providers, and security tools to operate the service and prevent abuse.
Do not send passwords, full payment-card numbers, authentication codes, or government ID images in public listings, messages, or ordinary email.
2. Why the information is used
Vendiaro uses information to create and secure accounts; confirm email and recover access; display profiles and listings; assess seller applications; screen and review listings; prevent, investigate, and respond to abuse; process and document orders, payments, delivery, refunds, or disputes if those features are activated; comply with law and payment-provider rules; answer support and privacy requests; maintain backups and records; and improve reliability and accessibility.
Automated screening can surface risk indicators for human review. It does not make an autonomous final decision to verify, accuse, reject, or publish a person or product. Vendiaro does not use the current listing-screening AI to analyze the actual images.
3. What may be public or shared
Public visitors may see a username, display name, profile photo, approved seller/shop description, listing text/photos, public city/state for local pickup, and information that law requires Vendiaro to disclose for certain sellers. Do not put private contact, home-address, serial, IMEI, payment, or identity data in a public field.
Vendiaro may share information with:
- Service providers that host or operate needed features: Supabase (auth, database, storage), Vercel (hosting), Cloudflare Turnstile (abuse checks), Resend (transactional email), Groq (structured listing text/metadata for AI advisory screening when enabled), Stripe (payment, identity, and payouts if enabled), and USPS or another shipping provider if a label feature is enabled. Provider names and scope must be kept current in the live notice.
- Transaction participants: if a paid order is enabled, the seller and the seller's connected Stripe account may receive the buyer's name, shipping address, billing/contact details submitted at checkout, and order information necessary to process and fulfill it. The buyer receives seller identity/disclosures required by law. The seller should not receive buyer payment credentials or unrelated account settings.
- Authorities, advisers, and other parties when reasonably necessary to comply with law, respond to valid legal process, investigate fraud or safety issues, protect users or rights, resolve a transaction, or enforce agreements.
- A successor in connection with a merger, financing, sale, or transfer of business assets, subject to applicable privacy law and appropriate safeguards.
Vendiaro does not currently sell personal information for money or use it for cross-context behavioral advertising. If that practice changes or a privacy law treats a later use differently, Vendiaro must provide any required notice and choice before that use.
4. Cookies and similar technologies
Vendiaro and its service providers use essential cookies/session tokens to authenticate users, prevent abuse, protect forms, and keep the service functioning. Providers may use their own technical identifiers for security and service delivery. This pilot does not intentionally run third-party behavioral advertising. The live implementation and notice must be reviewed before adding analytics, marketing pixels, or non-essential tracking.
5. Retention and deletion
Vendiaro retains information for as long as reasonably needed for the purpose collected, account operation, safety, transactions, legal or tax records, dispute handling, security, and enforcement. Some records may be retained where the law permits or requires it.
6. Security
Vendiaro uses role-based access, database access policies, server-side secrets, and service providers with security controls. No internet system is perfectly secure. Do not reuse passwords, share authentication codes, or email sensitive data. If Vendiaro discovers a security incident, it will investigate, contain it, preserve evidence, and provide notices required by applicable law.
7. Your choices and privacy requests
You may edit public profile data and profile photo in account settings. You may remove saved billing/delivery information through settings when that feature is available. To request access, correction, deletion, or information about data sharing, email vendiaro.shop@gmail.com from the account email and describe your request. Vendiaro may reasonably verify your identity and may retain data needed for legal duties, safety, fraud prevention, transaction records, or another lawful exception.
Some state privacy laws give residents additional rights, such as access, correction, deletion, portability, or opting out of certain sale, sharing, or targeted-advertising uses. Whether a law applies depends on the current business and statutory thresholds. Vendiaro will honor applicable rights and will not unlawfully discriminate against someone for exercising them. Add state-specific instructions and appeal contacts after counsel confirms which laws apply.
8. Children's information
Vendiaro accounts are for people 18 and older. The marketplace is not directed to children. If you believe a child provided personal information, contact vendiaro.shop@gmail.com so Vendiaro can review and take appropriate action.
9. International processing and provider terms
Vendiaro is based in Arizona and is designed initially for U.S. users. Providers may process information in other locations under their service terms. Before serving other countries, Vendiaro must assess applicable privacy, consumer, tax, transfer, and data-localization requirements and update this notice.
10. Changes and contact
Questions or reports: vendiaro.shop@gmail.com.