Privacy policy
Last updated:
VendorDesk (“VendorDesk”, “we”, “us” or “our”) respects your privacy and is committed to protecting the personal information we process.
This Privacy Policy explains how VendorDesk collects, uses, stores and protects personal information when you visit our website, use the VendorDesk application, communicate with us, or otherwise use our services.
VendorDesk provides software for facilities and property teams to request, collect, review and track vendor paperwork.
This Privacy Policy applies to information processed through the VendorDesk website, application and related services.
1. Who we are
VendorDesk
Privacy contact: info@vendordesk.co.za
VendorDesk is operated from the United Kingdom.
If you have questions about this Privacy Policy, how we process personal information, or want to exercise a privacy right, contact us at info@vendordesk.co.za.
2. Information we collect
The information we collect depends on how you use VendorDesk.
Account information
When you create a VendorDesk account, we may collect:
Name
Email address
Password credentials in securely protected form
Company information
User role and permissions
Authentication and session information
Company and building information
Customers may provide:
Company name
Building names
Building addresses
Building-related information
Internal users and team members
Vendor information
Customers may enter information about vendors they work with, including:
Vendor/company name
Contact name
Email address
Telephone number
WhatsApp number
Service or trade
Building assignments
Request history
Documents and paperwork
VendorDesk allows customers and vendors to upload documents.
These may include insurance certificates, policies, registration documents, training records and other paperwork selected by the customer.
Documents may contain personal information depending on their contents.
VendorDesk does not determine which documents a customer should legally require from a vendor. The customer decides what paperwork they wish to collect.
Usage and activity information
We may process information relating to your use of VendorDesk, including:
Pages and features accessed
Actions performed
Request activity
Document activity
Review activity
Audit and activity records
Dates and timestamps
Technical information needed to operate and secure the service
Website analytics
Our marketing website uses Framer Analytics to understand how visitors use the website.
This may include:
Pages viewed
Navigation and interaction information
General geographic location
Device and browser information
General usage information
We use this information to understand and improve the website and our services.
Subscription and payment information
VendorDesk uses Polar to provide subscription and payment functionality.
We may receive information such as:
Subscription status
Product or plan
Billing status
Transaction references
Customer identifiers
Subscription dates and status changes
Payment card details are handled by the payment provider rather than stored directly by VendorDesk.
3. How we collect information
We may collect information:
Directly from you
When you create an account
When you use VendorDesk
When you or your organisation add company, building or vendor information
When vendors respond to paperwork requests
When documents are uploaded
When you communicate with us
Automatically when you use our website or application
From service providers where necessary to provide our services
A VendorDesk customer may provide personal information about other people, such as employees, contractors, vendors or vendor contacts.
Where a customer provides such information to VendorDesk, the customer is responsible for ensuring that it is appropriate for them to provide that information and that they have an appropriate lawful basis for doing so.
4. How we use personal information
We may use personal information to:
Provide VendorDesk
Create and manage accounts
Provide access to VendorDesk
Manage companies and buildings
Manage vendors
Create and manage paperwork requests
Facilitate document uploads
Review and manage submissions
Track outstanding paperwork
Track expiry information
Maintain request and document history
Send reminders and notifications
Provide customer support
Authentication and security
Authenticate users
Maintain secure sessions
Protect accounts
Prevent unauthorised access
Detect and prevent abuse or fraud
Investigate security incidents
Maintain security and audit records
Service communications
Send password reset emails
Send vendor paperwork requests
Send submission notifications
Send replacement notifications
Send team invitations
Send service-related reminders
Respond to support requests
Payments and subscriptions
Create and manage subscriptions
Confirm payment status
Update subscription access
Process cancellation and subscription changes
Service improvement
Understand how the service is used
Identify problems
Improve functionality
Improve reliability and security
Develop the service
Legal and regulatory purposes
We may process information where reasonably necessary to:
Comply with applicable law
Respond to lawful requests
Establish, exercise or defend legal claims
Protect our rights, property or users
Investigate suspected unlawful activity
5. VendorDesk's role and customer-controlled information
VendorDesk is designed so that the customer decides what vendor information and paperwork they want to manage.
For example, a facilities or property company may decide:
“We need this paperwork from this vendor.”
The customer then enters the vendor into VendorDesk, creates a request and asks the vendor to provide the requested paperwork.
VendorDesk provides the software and infrastructure used to:
Send the request
Collect the paperwork
Store documents
Review submissions
Track status
Maintain history
Send reminders
VendorDesk does not independently determine:
What paperwork a vendor is legally required to provide
Whether a vendor is legally compliant
Whether a particular document is legally sufficient
Whether a vendor is authorised to perform a particular service
The customer remains responsible for determining its own paperwork requirements and how it uses information provided through VendorDesk.
6. Public vendor request links
VendorDesk can provide vendors with unique links through which they can respond to paperwork requests.
A vendor may be able to:
View the relevant request
Upload documents
Submit paperwork
A vendor does not necessarily need to create a VendorDesk account to respond to a request.
We use access controls and unique request links designed to prevent unauthorised access to requests and documents.
Customers are responsible for ensuring that information included in a request is appropriate for the intended recipient.
7. How we share information
We do not sell personal information.
We may share personal information with service providers that help us provide and operate VendorDesk.
These may include providers for:
Cloud hosting
Database infrastructure
File storage
Transactional email
Subscription and payment processing
Website analytics
Security and technical infrastructure
We may also disclose information where reasonably necessary to:
Comply with applicable law
Respond to lawful requests
Protect VendorDesk, customers or others
Detect or investigate fraud, abuse or security incidents
Establish, exercise or defend legal claims
Complete a corporate transaction involving VendorDesk
We do not share customer or vendor information with unrelated third parties for their own marketing purposes.
8. Service providers and infrastructure
VendorDesk currently uses third-party providers including:
Vercel
Used for application hosting and infrastructure.
Vercel Blob
Used to store uploaded documents and other files.
Neon / PostgreSQL
Used for application database infrastructure.
Resend
Used to deliver transactional email.
Polar
Used for subscriptions and payment-related services.
Framer
Used for the VendorDesk marketing website and Framer Analytics.
These providers may process information on our behalf or as part of providing their services.
Third-party providers may have their own privacy policies and terms.
9. Data storage and international transfers
VendorDesk is operated from the United Kingdom, but some information is processed or stored outside the UK and South Africa.
Based on our current infrastructure:
Our production database is hosted using AWS US East 2 (Ohio) through our database infrastructure.
Our Vercel Blob storage is operated in Northern Virginia, USA.
Application requests may be processed through Vercel infrastructure, including Washington, D.C. / Northern Virginia, USA.
Other service providers may process information in additional countries depending on their infrastructure.
This means personal information may be transferred to and processed in countries outside the country in which you are located.
Where required by applicable data protection law, we will use appropriate safeguards for international transfers.
Our infrastructure and third-party providers may change over time, in which case this Privacy Policy may be updated.
10. Data security
We use reasonable technical and organisational measures designed to protect personal information against unauthorised access, loss, misuse, disclosure, alteration or destruction.
Measures may include:
Secure authentication
Password hashing
HTTP-only secure sessions
Tenant isolation
Server-side access controls
Encrypted connections
Private document storage
Restricted document access
Audit logging
Rate limiting
Security controls around public request links
Access restrictions based on company membership and permissions
No internet-based service can guarantee absolute security.
11. Data retention
We retain information for as long as reasonably necessary for the purposes for which it is processed and for legitimate operational, security, contractual and legal purposes.
VendorDesk may retain:
Account information
Request history
Document history
Replaced or historical documents
Audit records
Subscription information
This is because VendorDesk is designed to maintain an ongoing history of vendor paperwork and activity.
When information is no longer reasonably required, we may delete, anonymise or otherwise securely dispose of it, subject to applicable legal, contractual, security and operational requirements.
At present, VendorDesk does not publish a fixed number of days for deletion following account closure. Retention may therefore depend on the circumstances and the nature of the information involved.
12. Your rights
Depending on where you are located and which laws apply, you may have rights concerning your personal information.
These may include rights to:
Request access to personal information we hold about you
Request correction of inaccurate information
Request deletion where applicable
Object to certain processing
Request restriction of processing
Withdraw consent where processing is based on consent
Request information about how your information is processed
Lodge a complaint with a relevant data protection authority
Some rights are subject to legal limitations and exceptions.
To exercise a privacy right, contact:
We may need to verify your identity before processing certain requests.
13. Information provided by a VendorDesk customer
If your personal information has been provided to VendorDesk by one of our customers, such as when a facilities company adds you as a vendor contact or requests paperwork from you, that customer may determine why your information is being collected and used.
In those circumstances, you may also need to contact that customer regarding certain requests relating to your information.
VendorDesk will work with the relevant customer where appropriate.
14. Cookies and analytics
Our application may use technologies necessary for authentication, security and core functionality.
Our marketing website uses Framer Analytics for website analytics.
We use analytics to understand general website usage, including:
Pages visited
Navigation
General geographic location
General technical information
We use this information for website and service improvement.
15. Marketing communications
VendorDesk currently uses email primarily for product and transactional communications, including account, subscription, authentication and paperwork-related notifications.
We do not currently operate a separate promotional marketing mailing list as part of the VendorDesk service.
If this changes, we will update our practices and this Privacy Policy as appropriate.
16. Children
VendorDesk is a business service intended for organisations and adults.
We do not intentionally target children through the service.
If you believe a child has provided personal information to VendorDesk inappropriately, contact:
17. Account closure and deletion
If you stop using VendorDesk, information may remain stored for a period depending on the type of information, the customer's account status, contractual obligations, security requirements and applicable law.
Customers may contact us regarding account closure and data deletion.
Some information may need to be retained after account closure for legitimate security, legal, accounting or dispute-resolution purposes.
18. Changes to this Privacy Policy
We may update this Privacy Policy as VendorDesk changes.
This may occur when:
We introduce new features
Our data processing changes
We introduce or replace service providers
Infrastructure or processing locations change
Applicable legal or regulatory requirements change
We will update the Last updated date when material changes are made.
19. Complaints
If you have concerns about how VendorDesk handles personal information, please contact us first:
We will investigate reasonable privacy concerns and try to resolve them.
Depending on your location and applicable law, you may also have the right to lodge a complaint with the relevant data protection authority.
20. Contact
For privacy questions, data requests or concerns:
VendorDesk
Email: info@vendordesk.co.za