VVendly

Draft template — replace bracketed placeholders and have this reviewed by a lawyer licensed in your operating jurisdictions (Nigeria's NDPR, UK/EU UK GDPR, US state privacy laws, Ghana's Data Protection Act) before relying on it.

Privacy Policy

Last updated: July 14, 2026

1. Overview

This Privacy Policy explains how Vendly ("we," "us," "our") collects, uses, and protects personal data when you use our point-of-sale and business management platform. It applies to business owners and staff who use Vendly directly (our "customers"), and to the end customers of those businesses whose data may pass through Vendly (for example, a customer placing a QR-code order at a restaurant using Vendly).

2. What we collect

Account and business data — business name, type, address, registration number, owner and staff names, emails, phone numbers, and hashed passwords or PINs.

Operational data — products, dishes, prices, stock levels, transactions, expenses, and — for pharmacy businesses — NAFDAC numbers, batch numbers, expiry dates, and prescription details you choose to record.

Your customers' data — names and phone numbers you add as customers, purchase history, WhatsApp opt-in status, and, for QR-code ordering, the name and phone number a diner provides when placing an order.

Payment data — where you accept card or transfer payments through Vendly, transaction amounts and references are stored; full card numbers are handled directly by our payment processor and never touch Vendly's own servers.

Technical data — device identifiers, IP address, and log data collected automatically for security and troubleshooting.

3. How we use it

  • To operate the core service — processing sales, tracking inventory, generating reports;
  • To send transactional emails (signup confirmation, password resets, receipts);
  • To send WhatsApp messages on your behalf, only to customers who have opted in;
  • To detect fraud, abuse, and security incidents;
  • To improve Vendly's features, using aggregated or de-identified data where possible;
  • To comply with legal obligations, including tax and financial recordkeeping requirements in your jurisdiction.

4. Who we share data with

We share data only as needed to run the service, with:

  • Supabase — our database and file storage provider;
  • Paystack — for processing card and bank transfer payments;
  • Meta — for delivering WhatsApp Business messages you send through Vendly;
  • Resend — for delivering transactional emails;
  • Law enforcement or regulators, where required by law.

We do not sell personal data. We do not share your business data with other Vendly tenants — each business's data is isolated.

5. Storage and security

Data is stored on Supabase infrastructure with encryption in transit. Access to your business's data is restricted to your authorized staff through role-based permissions, and to Vendly personnel only as needed for support or maintenance. Passwords are hashed and never stored in plain text. No system is perfectly secure, and we cannot guarantee absolute security of data transmitted to us.

6. Data retention

We retain your business data for as long as your account is active. After account closure, data is retained for [retention period, e.g. 30–90 days] to allow export or reactivation, after which it is deleted or anonymized, except where we are legally required to retain records for longer (for example, financial or pharmacy compliance records under applicable law).

7. Your rights

Depending on where you or your customers are located, you may have rights to access, correct, delete, or export personal data, and to object to or restrict certain processing:

  • Nigeria — rights under the Nigeria Data Protection Act;
  • United Kingdom — rights under UK GDPR;
  • United States — rights under applicable state privacy laws (for example, CCPA for California residents);
  • Ghana — rights under the Data Protection Act, 2012.

To exercise these rights, contact us at the address below. If you are an end customer of a business using Vendly (not a Vendly account holder yourself), please contact that business directly, as they control your data — we act on their instructions.

8. Cookies and local storage

Vendly uses cookies and browser local storage to keep you signed in, remember your selected location, and maintain session security. These are functional, not advertising, cookies — Vendly does not use third-party tracking or advertising cookies.

9. Children's data

Vendly is intended for business use by adults. We do not knowingly collect personal data from children. If you believe a child's data has been collected through Vendly, contact us and we will delete it.

10. International transfers

Vendly's infrastructure may process and store data outside your country. Where we transfer personal data internationally, we rely on appropriate safeguards required by applicable law (such as standard contractual clauses where required for UK/EU-originating data).

11. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email or in-app notice before they take effect.

12. Contact

Questions or data-rights requests can be sent to privacy@vendly.co [replace with your real contact address].