Privacy
Privacy Policy
Last updated 26 July 2026
VendiSite is a business tool for vending operators. Most of what it holds is information about businesses rather than about consumers, but it does hold personal data in a few specific places. This page says which, and what happens to it.
01Who this covers
Three groups of people interact with VendiSite, and the answers differ for each. Account holders are operators who sign in to the app. Field reporters are people who scan a flyer code and fill in the short form behind it. Business contacts are the named people at candidate locations whose work contact details appear in lead records.
02What we collect from account holders
- Your email address, and the name and profile identifier your provider returns if you sign in with Google or Facebook.
- Session cookies named vs_access and vs_refresh, which hold signed tokens that keep you logged in. They are strictly necessary for the app to work and are not used for advertising.
- The work you do in the app: scoring templates, target groups, imported records, notes, outreach you send, and the audit log of changes that produced a given score.
- Ordinary server logs, including IP address and user agent, kept for security and debugging.
We do not run advertising trackers or third-party analytics on the marketing site or in the app, and we do not sell personal data.
03What we collect from a flyer or booking link
A flyer code and a booking link are single-purpose URLs. Anyone holding one can use it without an account, so they are deliberately narrow in what they take.
- What you type into the form: the location description, address, city, state, postal code, an optional company name, what machines are already there, and the short survey about the site.
- The coordinates of the device, if and only if you grant the browser location permission. You can decline and type the location instead.
- Photographs you choose to attach, up to three, stored in our object storage under a key tied to that code.
- A salted, one-way hash of your IP address and user agent. It is used to spot duplicate and abusive submissions. It is not reversible and is not used to identify you.
A booking link records the slot you pick and the contact details you enter so the operator can keep the appointment.
04Business contact data in lead records
VendiSite builds candidate location records from public and licensed sources: business listings and mapping data, published job postings, building permit filings, local news, government open data, and economic development announcements. Where a record includes a named person, it is a work role and work contact details at a business, gathered for business-to-business outreach.
Account holders may also import their own contact records. When they do, they are responsible for having a lawful basis to hold and use them.
If you are a business contact and you want your details corrected or removed from our systems, write to [email protected] and we will action it.
05Outreach email and opting out
Outreach sent through VendiSite goes out via our email provider, which reports delivery, bounces, and complaints back to us so operators can see what happened to a message. Every outreach email carries a one-click unsubscribe link.
Unsubscribing adds the address to a suppression list that is enforced automatically. Once an address is suppressed it stays suppressed. That is the one case where we keep a record specifically so that we can stop contacting you.
06Who processes data on our behalf
We keep this list short on purpose. As of the date above, it is:
- Railway, for application hosting and the managed Postgres database.
- Brevo, for transactional and outreach email delivery and the delivery events that come back.
- Google, for optional sign-in and for places and mapping data.
- Meta, for optional Facebook sign-in.
- Our object storage provider, for photographs submitted through flyer codes.
Discovery sources such as OpenStreetMap, Geoapify, GDELT, Socrata portals, ArcGIS permit services, and job boards are read by us. They do not receive your data.
07How long we keep things
- Account and workspace data: for as long as the account is open, and then deleted on request.
- Suppression records: indefinitely, because deleting them would let contact resume.
- Field submissions and photographs: for as long as the associated lead record is useful to the operator.
- Server logs: a rolling short window for security and debugging.
08Your rights
Depending on where you live, you may have the right to ask for a copy of the personal data we hold about you, to have it corrected, to have it deleted, or to object to how it is used. Write to [email protected] and say what you want done. We will not charge you for it, and we will not ask you to explain why.
09Security
Access to the app requires a signed session. Flyer, booking, and unsubscribe links are authorized by a signed token rather than by an account, and are rate limited. Data in transit is encrypted. No system is perfectly secure, and we do not claim otherwise.
10Changes
If this policy changes in a way that affects what we collect or who we share it with, we will update the date at the top and, for account holders, say so in the app.
Questions about this document? Write to [email protected].
