Legal
Privacy Policy
Effective September 16, 2026
This Privacy Policy explains how Vendor OS (“Vendor OS,” “we,” “us,” or “our”) handles information when you use the Vendor OS web application, Android application, and related services.
Information we collect
Account and organization information
We collect information you provide when creating or managing an account, including your name, username, email address, hashed password, email-verification status, invitation status, organization membership, role, permissions, preferences, and storage locations. If you choose Google or Apple sign-in, we also store the provider's stable account identifier and the verified email, display name, profile image, and private-relay status that the provider makes available. Vendor OS does not receive or store your Google or Apple password.
Card Inspection reports
Card Inspection performs capture-quality checks, alignment, centering measurement, enhanced views, and areas-to-review analysis on your device. If you choose to save an inspection report, Vendor OS uploads the untouched front/back captures, aligned copies, measurements, review decisions, and notes to private organization storage. These saved images are used to provide the report and are not added to a model-training dataset. Card Inspection does not predict a professional grading outcome.
Business and inventory information
Vendor OS stores the information you enter to operate your business, such as inventory records, catalog matches, prices, cost basis, sales, purchases, trades, events, expenses, notes, public inventory settings, and related transaction history. If you record customer or seller contacts, this may include their name, email address, phone number, preferences, and notes.
Payment integration information
When an organization connects Square or Stripe, we receive and store merchant and location identifiers, terminal identifiers, connection status, transaction and refund references, payout and reconciliation information, and encrypted authorization credentials needed to operate the connection. Square and Stripe process payment-card information. Vendor OS does not store full payment-card numbers or card security codes.
Camera and card-scanner information
The Android and iOS applications request camera or photo-library access only when you use a scanning feature. Card images are processed on your device. The scanner sends detected card text and identifiers to Vendor OS for catalog matching and records scan usage against applicable plan limits. Vendor OS retains structured scanner diagnostics for up to 90 days, including selected scan context, bounded OCR text and evidence, catalog candidates and confidence, device and processing details, and the result you confirm or correct. If you explicitly enable “Share scan photos,” Vendor OS also retains the original capture for up to 7 days and aligned or aligned card images and per-run diagnostic bundles for up to 90 days. Scanner diagnostic data is available only to authorized platform administrators and is used to troubleshoot and improve scanner accuracy. You can disable future photo sharing in the scanner, and retained diagnostics may be deleted by an administrator. You may also deliberately export a diagnostic ZIP for support.
Technical and usage information
We use session cookies and similar storage required for sign-in, security, and application operation. Our systems may process IP address, browser or device information, timestamps, request logs, error information, and feature-usage counts for security, reliability, troubleshooting, and enforcement of access or plan limits. We do not use this information for behavioral advertising.
How we use information
- Provide inventory, pricing, sales, purchasing, and trade tools.
- Authenticate users and administer organizations and permissions.
- Process vendor-directed payments, refunds, and reconciliation.
- Match scanned or entered products with catalog and pricing data.
- Send account verification, security, and password-reset email.
- Protect Vendor OS, prevent misuse, and troubleshoot failures.
- Comply with legal obligations and enforce our agreements.
How information is shared
We share information only as needed to provide Vendor OS, follow your instructions, protect the service, or comply with law. Service providers may include:
- Amazon Web Services for application hosting, database infrastructure, logs, and transactional email.
- Square and Stripe when your organization connects a merchant account or processes a payment.
- Google and Apple when you choose their sign-in service. They authenticate you and return the account details you authorize for Vendor OS.
- Catalog and pricing providers when Vendor OS requests product, market-price, or listing information. These requests are made by Vendor OS and do not require sending your account password or payment-card details.
We may also disclose information if required by law, to investigate fraud or security incidents, or as part of a merger, financing, acquisition, or transfer of the service, subject to appropriate safeguards. We do not sell personal information.
Public inventory
An organization owner can choose to publish a read-only inventory browser. Information intentionally enabled for that browser—such as item names, images, asking prices, and storage locations—can be viewed by anyone with its link. Vendor OS does not provide customer checkout through the public inventory browser.
Data security
We use administrative, technical, and organizational safeguards designed to protect information. These include encrypted network connections, hashed passwords, encrypted payment-provider credentials, access controls, and organization-based authorization. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.
Retention and deletion
We retain account and business information while it is needed to provide Vendor OS and for legitimate security, backup, dispute, accounting, and legal purposes. Retention periods depend on the type of information and why it is maintained. When information is no longer required, we delete or de-identify it where reasonably practicable. Some transaction, fraud-prevention, backup, or legal records may be retained after account deletion where permitted or required by law.
Structured scanner diagnostics, aligned and preprocessing images, and diagnostic bundles are deleted after 90 days. Shared original card captures are deleted after 7 days.
Saved Card Inspection reports and their evidence remain with the organization until the report or applicable account data is deleted, subject to backup, security, and legal retention needs.
You may request deletion of your Vendor OS account and associated data through our account deletion page. Organization records belonging to other users may be retained for that organization, and information that must be retained will be isolated from ordinary use.
Your choices
- Update available account and organization information in Settings.
- Link or remove Google, Apple, and email sign-in methods in Settings, provided at least one usable sign-in method remains.
- Disconnect Square or Stripe from payment settings.
- Disable public inventory sharing.
- Revoke camera permission through Android system settings.
- Disable scanner photo sharing while continuing to use on-device recognition and catalog matching.
- Request access or correction by contacting us. Request permanent account deletion directly through the account deletion page; contacting support is not required.
Children’s privacy
Vendor OS is a business tool and is not directed to children under 13. We do not knowingly collect personal information from children under 13. Contact us if you believe a child has provided personal information to Vendor OS.
Changes to this policy
We may update this policy as Vendor OS changes. We will update the effective date on this page and provide additional notice when required.
Contact us
For privacy questions or requests, email support.dev@vendoros.xyz.