Privacy Policy
Last updated: 12 July 2026
1. Introduction
Welcome to Vendor.onl ("we", "our", or "us"). We operate a SaaS platform that enables restaurants and food businesses to accept digital orders via QR codes. This Privacy Policy explains how we collect, use, and protect your information when you use our platform.
2. Information We Collect
We collect the following types of information:
- Business information: Business name, type, location, logo, and brand settings provided during signup.
- Account information: Name, email address, and password of the account owner and staff members.
- Order data: Orders placed by customers through your QR menu, including items ordered, prices, and payment status.
- Payment information: We use Paystack to process payments. We do not store card details — these are handled directly by Paystack.
- Usage data: Analytics about how your dashboard is used, including page views and feature usage.
3. How We Use Your Information
- To provide and operate the Vendor.onl platform
- To process orders and payments on your behalf
- To send transactional emails (order confirmations, password resets, staff invitations)
- To provide analytics and reporting about your business performance
- To improve our platform and fix technical issues
- To contact you about your subscription and account
4. Customer Data
When your customers scan your QR code and place orders, we collect their order details to facilitate the transaction. We do not use customer data for marketing purposes. Customer data is associated with your business account and is accessible only to you and your staff.
5. Data Sharing
We do not sell your data. We share data only with the following third parties as necessary to operate the platform:
- Supabase: Our database and authentication provider
- Paystack: Payment processing for online orders and subscriptions
- Resend: Transactional email delivery
- Vercel: Platform hosting and deployment
6. Data Retention
We retain your account and business data for as long as your account is active. Order history is retained for up to 2 years for accounting and analytics purposes. If you cancel your account, we will delete your data within 30 days upon request.
7. Security
We use industry-standard security measures including encrypted connections (HTTPS), hashed passwords, and row-level security on our database. However, no system is 100% secure and we cannot guarantee absolute security.
8. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and associated data
- Export your order history as CSV at any time from the Analytics page
To exercise these rights, contact us at privacy@vendor.onl
9. Cookies
We use a single session cookie to keep you signed in to your dashboard. We do not use advertising cookies or tracking cookies. Your customers' menu experience does not use cookies.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or by a notice on your dashboard. Continued use of the platform after changes constitutes acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy, please contact us at:
Vendor.onl
Email: privacy@vendor.onl
Website: https://vendor.onl