Privacy policy

Last updated:

VendorDesk (“VendorDesk”, “we”, “us” or “our”) respects your privacy and is committed to protecting the personal information we process.

This Privacy Policy explains how VendorDesk collects, uses, stores and protects personal information when you visit our website, use the VendorDesk application, communicate with us, or otherwise use our services.

VendorDesk provides software for facilities and property teams to request, collect, review and track vendor paperwork.

This Privacy Policy applies to information processed through the VendorDesk website, application and related services.

1. Who we are

VendorDesk

Privacy contact: info@vendordesk.co.za

VendorDesk is operated from the United Kingdom.

If you have questions about this Privacy Policy, how we process personal information, or want to exercise a privacy right, contact us at info@vendordesk.co.za.

2. Information we collect

The information we collect depends on how you use VendorDesk.

Account information

When you create a VendorDesk account, we may collect:

  • Name

  • Email address

  • Password credentials in securely protected form

  • Company information

  • User role and permissions

  • Authentication and session information

Company and building information

Customers may provide:

  • Company name

  • Building names

  • Building addresses

  • Building-related information

  • Internal users and team members

Vendor information

Customers may enter information about vendors they work with, including:

  • Vendor/company name

  • Contact name

  • Email address

  • Telephone number

  • WhatsApp number

  • Service or trade

  • Building assignments

  • Request history

Documents and paperwork

VendorDesk allows customers and vendors to upload documents.

These may include insurance certificates, policies, registration documents, training records and other paperwork selected by the customer.

Documents may contain personal information depending on their contents.

VendorDesk does not determine which documents a customer should legally require from a vendor. The customer decides what paperwork they wish to collect.

Usage and activity information

We may process information relating to your use of VendorDesk, including:

  • Pages and features accessed

  • Actions performed

  • Request activity

  • Document activity

  • Review activity

  • Audit and activity records

  • Dates and timestamps

  • Technical information needed to operate and secure the service

Website analytics

Our marketing website uses Framer Analytics to understand how visitors use the website.

This may include:

  • Pages viewed

  • Navigation and interaction information

  • General geographic location

  • Device and browser information

  • General usage information

We use this information to understand and improve the website and our services.

Subscription and payment information

VendorDesk uses Polar to provide subscription and payment functionality.

We may receive information such as:

  • Subscription status

  • Product or plan

  • Billing status

  • Transaction references

  • Customer identifiers

  • Subscription dates and status changes

Payment card details are handled by the payment provider rather than stored directly by VendorDesk.

3. How we collect information

We may collect information:

  • Directly from you

  • When you create an account

  • When you use VendorDesk

  • When you or your organisation add company, building or vendor information

  • When vendors respond to paperwork requests

  • When documents are uploaded

  • When you communicate with us

  • Automatically when you use our website or application

  • From service providers where necessary to provide our services

A VendorDesk customer may provide personal information about other people, such as employees, contractors, vendors or vendor contacts.

Where a customer provides such information to VendorDesk, the customer is responsible for ensuring that it is appropriate for them to provide that information and that they have an appropriate lawful basis for doing so.

4. How we use personal information

We may use personal information to:

Provide VendorDesk

  • Create and manage accounts

  • Provide access to VendorDesk

  • Manage companies and buildings

  • Manage vendors

  • Create and manage paperwork requests

  • Facilitate document uploads

  • Review and manage submissions

  • Track outstanding paperwork

  • Track expiry information

  • Maintain request and document history

  • Send reminders and notifications

  • Provide customer support

Authentication and security

  • Authenticate users

  • Maintain secure sessions

  • Protect accounts

  • Prevent unauthorised access

  • Detect and prevent abuse or fraud

  • Investigate security incidents

  • Maintain security and audit records

Service communications

  • Send password reset emails

  • Send vendor paperwork requests

  • Send submission notifications

  • Send replacement notifications

  • Send team invitations

  • Send service-related reminders

  • Respond to support requests

Payments and subscriptions

  • Create and manage subscriptions

  • Confirm payment status

  • Update subscription access

  • Process cancellation and subscription changes

Service improvement

  • Understand how the service is used

  • Identify problems

  • Improve functionality

  • Improve reliability and security

  • Develop the service

Legal and regulatory purposes

We may process information where reasonably necessary to:

  • Comply with applicable law

  • Respond to lawful requests

  • Establish, exercise or defend legal claims

  • Protect our rights, property or users

  • Investigate suspected unlawful activity

5. VendorDesk's role and customer-controlled information

VendorDesk is designed so that the customer decides what vendor information and paperwork they want to manage.

For example, a facilities or property company may decide:

“We need this paperwork from this vendor.”

The customer then enters the vendor into VendorDesk, creates a request and asks the vendor to provide the requested paperwork.

VendorDesk provides the software and infrastructure used to:

  • Send the request

  • Collect the paperwork

  • Store documents

  • Review submissions

  • Track status

  • Maintain history

  • Send reminders

VendorDesk does not independently determine:

  • What paperwork a vendor is legally required to provide

  • Whether a vendor is legally compliant

  • Whether a particular document is legally sufficient

  • Whether a vendor is authorised to perform a particular service

The customer remains responsible for determining its own paperwork requirements and how it uses information provided through VendorDesk.

6. Public vendor request links

VendorDesk can provide vendors with unique links through which they can respond to paperwork requests.

A vendor may be able to:

  • View the relevant request

  • Upload documents

  • Submit paperwork

A vendor does not necessarily need to create a VendorDesk account to respond to a request.

We use access controls and unique request links designed to prevent unauthorised access to requests and documents.

Customers are responsible for ensuring that information included in a request is appropriate for the intended recipient.

7. How we share information

We do not sell personal information.

We may share personal information with service providers that help us provide and operate VendorDesk.

These may include providers for:

  • Cloud hosting

  • Database infrastructure

  • File storage

  • Transactional email

  • Subscription and payment processing

  • Website analytics

  • Security and technical infrastructure

We may also disclose information where reasonably necessary to:

  • Comply with applicable law

  • Respond to lawful requests

  • Protect VendorDesk, customers or others

  • Detect or investigate fraud, abuse or security incidents

  • Establish, exercise or defend legal claims

  • Complete a corporate transaction involving VendorDesk

We do not share customer or vendor information with unrelated third parties for their own marketing purposes.

8. Service providers and infrastructure

VendorDesk currently uses third-party providers including:

Vercel

Used for application hosting and infrastructure.

Vercel Blob

Used to store uploaded documents and other files.

Neon / PostgreSQL

Used for application database infrastructure.

Resend

Used to deliver transactional email.

Polar

Used for subscriptions and payment-related services.

Framer

Used for the VendorDesk marketing website and Framer Analytics.

These providers may process information on our behalf or as part of providing their services.

Third-party providers may have their own privacy policies and terms.

9. Data storage and international transfers

VendorDesk is operated from the United Kingdom, but some information is processed or stored outside the UK and South Africa.

Based on our current infrastructure:

  • Our production database is hosted using AWS US East 2 (Ohio) through our database infrastructure.

  • Our Vercel Blob storage is operated in Northern Virginia, USA.

  • Application requests may be processed through Vercel infrastructure, including Washington, D.C. / Northern Virginia, USA.

  • Other service providers may process information in additional countries depending on their infrastructure.

This means personal information may be transferred to and processed in countries outside the country in which you are located.

Where required by applicable data protection law, we will use appropriate safeguards for international transfers.

Our infrastructure and third-party providers may change over time, in which case this Privacy Policy may be updated.

10. Data security

We use reasonable technical and organisational measures designed to protect personal information against unauthorised access, loss, misuse, disclosure, alteration or destruction.

Measures may include:

  • Secure authentication

  • Password hashing

  • HTTP-only secure sessions

  • Tenant isolation

  • Server-side access controls

  • Encrypted connections

  • Private document storage

  • Restricted document access

  • Audit logging

  • Rate limiting

  • Security controls around public request links

  • Access restrictions based on company membership and permissions

No internet-based service can guarantee absolute security.

11. Data retention

We retain information for as long as reasonably necessary for the purposes for which it is processed and for legitimate operational, security, contractual and legal purposes.

VendorDesk may retain:

  • Account information

  • Request history

  • Document history

  • Replaced or historical documents

  • Audit records

  • Subscription information

This is because VendorDesk is designed to maintain an ongoing history of vendor paperwork and activity.

When information is no longer reasonably required, we may delete, anonymise or otherwise securely dispose of it, subject to applicable legal, contractual, security and operational requirements.

At present, VendorDesk does not publish a fixed number of days for deletion following account closure. Retention may therefore depend on the circumstances and the nature of the information involved.

12. Your rights

Depending on where you are located and which laws apply, you may have rights concerning your personal information.

These may include rights to:

  • Request access to personal information we hold about you

  • Request correction of inaccurate information

  • Request deletion where applicable

  • Object to certain processing

  • Request restriction of processing

  • Withdraw consent where processing is based on consent

  • Request information about how your information is processed

  • Lodge a complaint with a relevant data protection authority

Some rights are subject to legal limitations and exceptions.

To exercise a privacy right, contact:

info@vendordesk.co.za

We may need to verify your identity before processing certain requests.

13. Information provided by a VendorDesk customer

If your personal information has been provided to VendorDesk by one of our customers, such as when a facilities company adds you as a vendor contact or requests paperwork from you, that customer may determine why your information is being collected and used.

In those circumstances, you may also need to contact that customer regarding certain requests relating to your information.

VendorDesk will work with the relevant customer where appropriate.

14. Cookies and analytics

Our application may use technologies necessary for authentication, security and core functionality.

Our marketing website uses Framer Analytics for website analytics.

We use analytics to understand general website usage, including:

  • Pages visited

  • Navigation

  • General geographic location

  • General technical information

We use this information for website and service improvement.

15. Marketing communications

VendorDesk currently uses email primarily for product and transactional communications, including account, subscription, authentication and paperwork-related notifications.

We do not currently operate a separate promotional marketing mailing list as part of the VendorDesk service.

If this changes, we will update our practices and this Privacy Policy as appropriate.

16. Children

VendorDesk is a business service intended for organisations and adults.

We do not intentionally target children through the service.

If you believe a child has provided personal information to VendorDesk inappropriately, contact:

info@vendordesk.co.za

17. Account closure and deletion

If you stop using VendorDesk, information may remain stored for a period depending on the type of information, the customer's account status, contractual obligations, security requirements and applicable law.

Customers may contact us regarding account closure and data deletion.

Some information may need to be retained after account closure for legitimate security, legal, accounting or dispute-resolution purposes.

18. Changes to this Privacy Policy

We may update this Privacy Policy as VendorDesk changes.

This may occur when:

  • We introduce new features

  • Our data processing changes

  • We introduce or replace service providers

  • Infrastructure or processing locations change

  • Applicable legal or regulatory requirements change

We will update the Last updated date when material changes are made.

19. Complaints

If you have concerns about how VendorDesk handles personal information, please contact us first:

info@vendordesk.co.za

We will investigate reasonable privacy concerns and try to resolve them.

Depending on your location and applicable law, you may also have the right to lodge a complaint with the relevant data protection authority.

20. Contact

For privacy questions, data requests or concerns:

VendorDesk
Email: info@vendordesk.co.za