Privacy Policy

Last updated: 9 August 2026

This policy explains what personal data VendorDeck collects, why we collect it, and what rights you have. It covers the VendorDeck web application at vendordeck.org and the Trust Centre pages we host on behalf of our customers.

Who we are

VendorDeck is the data controller for personal data collected through our website and application. For Trust Centre content that our customers publish, our customer is the controller and VendorDeck acts as a processor on their behalf.

What we collect

Account data

When you create an account we collect your email address and, if you sign in with Google, the profile information Google returns (name, email, profile picture). If you sign up with email and password we store a hashed password — never the password itself.

Trust Centre content

We store the company details, MVSP checklist answers, policy documents and files you upload. You control whether this is published publicly.

Access requests

When someone requests access to a customer's Trust Centre documents, we record their email address, the time of the request and which documents were made available. This is shared with the Trust Centre owner — that is the purpose of the feature.

Payment data

Payments are processed by Stripe. We do not receive or store card numbers. We store your subscription status, plan and Stripe customer identifier.

Usage data

We use a self-hosted Umami instance for analytics. Umami does not use cookies for tracking and does not collect personally identifiable information. Non-essential cookies are only set with your consent via the cookie banner.

Why we can use your data

  • Contract — to provide the account, Trust Centre and subscription you signed up for.
  • Legitimate interests — to keep the service secure, to prevent abuse, and to understand aggregate usage.
  • Consent — for non-essential cookies and any marketing email. You can withdraw consent at any time.
  • Legal obligation — to keep records we are required to keep, such as for tax.

Subprocessors

We share data with the following providers so we can run the service:

ProviderPurpose
RailwayApplication and database hosting
StripeSubscription payments
SendGridTransactional email (verification, access links)
Amazon Web Services (S3)Document and file storage
GoogleOptional single sign-on

Some of these providers process data outside the UK. Where they do, transfers rely on the UK International Data Transfer Addendum or equivalent safeguards.

How long we keep it

Account and Trust Centre data is kept while your account is active. If you delete your account we remove your personal data within 30 days, except where we are required to retain records (for example, invoices for tax purposes, which are kept for six years). Access request records are retained for as long as the associated Trust Centre exists.

Your rights

Under UK GDPR you have the right to access your data, to have it corrected or erased, to restrict or object to processing, and to receive it in a portable format. To exercise any of these, contact us at the address below.

You also have the right to complain to the Information Commissioner's Office at ico.org.uk.

Security

Data is encrypted in transit using TLS and at rest by our hosting and storage providers. Access to production systems is restricted to personnel who need it. If a breach affects your rights and freedoms we will notify you and the ICO as required.

Contact

Privacy questions and rights requests: privacy@vendordeck.org.

Security vulnerability reports: see our security.txt.