Privacy Policy
Last updated: Oct 3, 2026
This policy explains what information Vendly keeps, why, and what you can ask us to do with it.
1. Two kinds of data
Your account: the details of the business that signs up and of the people who log in. [OPERATOR NAME] is responsible for this data.
Your customers' data: the names, phone numbers, debts and notes a business enters about its own customers. The business decides what to store. We only keep and process it on the business's behalf, to run the service for it.
2. What we collect
Login details: email address and password. Passwords are stored only in hashed form; we cannot read them.
Business details: name, settings such as the exchange rate and receipt language, and staff accounts.
What you record: products and their images, sales, stock changes, expenses, customers and debts.
Technical data: your IP address, used only in memory to limit repeated signups and not stored by us, and the standard request logs our hosting provider keeps.
3. Why we use it
To run the service, answer your support requests, keep the service and your account secure, and send you important messages about your account.
We do not sell data, show advertising, or use your data or your customers' data for marketing.
5. Who stores it for us
The app runs on Vercel, which also stores product images, and the database is hosted by Prisma. Their servers are in [REGION].
When the app hits an error, technical details about it (what failed, which page, your browser type) are sent to Sentry so we can fix it. They are tagged with your account and business ID numbers only, never your name, email or your business's records.
To stop automated sign-ups and password guessing, the sign-up and sign-in pages may run Cloudflare Turnstile. It checks signals from your browser and device to tell a person from a bot, and uses no cookies.
They store the data for us under their own security and confidentiality commitments, and may not use it for anything else. We will update this list before we add any new provider.
6. How we protect it
All traffic is encrypted (HTTPS). Passwords are hashed.
Each business's data is kept separate at two independent levels: in the application, and in the database itself, so one business can never see another's data.
7. How long we keep it
We keep your data while your account is open.
After an account is closed, the data stays available for 30 days so you can ask for a copy. We then delete it, and copies in backups are deleted within a further 90 days.
8. Your rights
You can ask us to show you, correct, give you a copy of, or delete your data. Email [CONTACT EMAIL] and we will answer within 30 days.
These rights follow Lebanon's Law No. 81 of 2018 on electronic transactions and personal data.
9. If you are a shop's customer
If a shop using our service holds your details (for example, a debt in your name), please contact that shop first: it decides what it keeps about you.
If you cannot reach the shop, email [CONTACT EMAIL] and we will help.
10. Children
The service is for businesses and is not meant for anyone under 18.
11. Changes and contact
If we change this policy in a significant way, we will tell account owners at least 30 days before it applies. The date at the top shows the latest version.
Questions about privacy: [CONTACT EMAIL].