Privacy Policy

Last updated: February 21, 2026

1. Introduction

Kiricode OÜ (registry code pending), registered at Saaruste tee 24, Sausti küla, Harjumaa, 75415, Estonia ("we", "us", or "Kiricode") is the data controller for personal data collected through vendorm8.com (the "Service").

This Privacy Policy explains how we collect, use, store, and protect your personal data when you use the Service. It applies to all users of vendorm8.com, including visitors, trial users, and paying subscribers.

2. Information We Collect

2.1 Information You Provide Directly

  • Account information: Name, email address, and password (stored as a bcrypt hash, never in plain text)
  • Organization information: Organization name, billing email address, and timezone
  • Vendor data: Vendor records including company names, categories, statuses, and notes
  • Vendor contacts: Names, email addresses, and phone numbers of vendor contacts
  • Contracts: Contract details including names, values, dates, and terms
  • Uploaded files: Contract documents and related files (up to 10 MB per file)
  • Feedback: Messages submitted through the in-app feedback feature
  • Waitlist entries: Email addresses submitted through the waitlist form

2.2 Information Collected Automatically

  • Session data: IP address, user agent, and session timestamps
  • Audit logs: Records of entity changes within the Service, including JSON diffs of modifications
  • Analytics data: Page views and usage patterns via Google Analytics (only with your consent — see Section 4)

2.3 Information from Third Parties

  • Stripe: Payment confirmation and subscription status. We do not store credit card numbers or full payment details locally; all payment processing is handled by Stripe.

3. How We Use Your Information

PurposeData UsedLegal Basis (GDPR)
Provide the ServiceAccount, org, vendor, contract, and file dataContract performance (Art. 6(1)(b))
Process paymentsBilling email, Stripe subscription dataContract performance (Art. 6(1)(b))
Send transactional emailsEmail address, nameContract performance (Art. 6(1)(b))
Send contract renewal remindersEmail address, contract datesContract performance (Art. 6(1)(b))
Maintain audit logsUser ID, entity changes, timestampsLegitimate interest (Art. 6(1)(f))
AnalyticsPage views, usage patterns (anonymized)Consent (Art. 6(1)(a))
Security and fraud preventionIP address, session dataLegitimate interest (Art. 6(1)(f))
Respond to support and feedbackEmail, feedback contentLegitimate interest (Art. 6(1)(f))
Legal complianceAs required by lawLegal obligation (Art. 6(1)(c))

4. Cookies & Tracking Technologies

Essential Cookies

These cookies are strictly necessary for the Service to function and cannot be disabled.

CookiePurposeExpiry
better-auth.session_tokenSession authentication7 days

Analytics Cookies (Consent Required)

These cookies are only set after you provide consent via our cookie banner. They help us understand how visitors use the Service so we can improve it.

CookiePurposeExpiry
_gaGoogle Analytics — distinguishes users2 years
_gidGoogle Analytics — distinguishes users24 hours

You can change your cookie preferences at any time by clearing your browser cookies and revisiting the site, which will re-display the consent banner.

5. Data Sharing & Sub-processors

We do not sell, rent, or trade your personal data. We share data only with the following categories of service providers ("sub-processors") who assist us in operating the Service:

Sub-processorPurposeData Protection
RailwayInfrastructure hostingEU region
StripePayment processingPCI-DSS compliant, EU-US DPF certified
ResendEmail deliveryDPA available
Google AnalyticsUsage analytics (consent required)EU-US DPF certified

We may also disclose your data if required to:

  • Comply with applicable laws, regulations, or legal processes
  • Protect the rights, property, or safety of Kiricode OÜ, our users, or others
  • Facilitate a merger, acquisition, or sale of assets (you will be notified of any such transfer)

6. International Data Transfers

Your data is primarily stored in the European Union (Railway EU region). Some sub-processors are located in the United States. Where personal data is transferred outside the EU/EEA, we ensure adequate safeguards are in place, including:

  • EU-US Data Privacy Framework (DPF): Stripe and Google are certified under the EU-US Data Privacy Framework
  • Standard Contractual Clauses (SCCs): Where DPF certification is not available, we rely on European Commission-approved Standard Contractual Clauses

7. Data Retention

Data TypeRetention Period
Account dataDuration of subscription + 90 days
Organization and business dataDuration of subscription + 90 days
Session data7-day expiry per session; records retained until account deletion
Audit logsDuration of subscription + 90 days
Uploaded filesDuration of subscription + 90 days
FeedbackUntil account deletion
Waitlist entriesUntil launch or upon request
Stripe eventsRetained for billing dispute resolution

8. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • Bcrypt password hashing
  • HMAC-signed session tokens
  • HTTPS/TLS encryption for all data in transit
  • Database encryption at rest
  • Security headers (Helmet) and CORS policies
  • Input validation and sanitization
  • Multi-tenant row-level data isolation
  • Role-based access control (RBAC)
  • Mandatory email verification
  • File upload size limits (10 MB per file)

While we strive to protect your data, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security.

9. Your Rights Under the GDPR

If you are located in the European Economic Area (EEA), you have the following rights regarding your personal data:

  • Right of Access: Request a copy of the personal data we hold about you
  • Right to Rectification: Request correction of inaccurate data (available via account settings or by contacting us)
  • Right to Erasure: Request deletion of your personal data by contacting support@vendorm8.com
  • Right to Restriction: Request that we restrict the processing of your personal data
  • Right to Data Portability: Receive your data in a structured, machine-readable format. CSV export is available for vendor data; comprehensive data export is on our roadmap.
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Where processing is based on consent (e.g., analytics cookies), you may withdraw consent at any time

We will respond to valid requests within 30 days. To exercise any of these rights, contact us at support@vendorm8.com.

You also have the right to lodge a complaint with your local data protection authority. Our supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon): www.aki.ee.

10. Your Rights Under the CCPA

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: Request information about the categories and specific pieces of personal data we have collected
  • Right to Delete: Request deletion of your personal data
  • Right to Opt-Out of Sale: We do not sell your personal data
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights

11. Children's Privacy

The Service is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected personal data from a child under 16, we will take steps to delete that information promptly. If you believe a child has provided us with personal data, please contact us at support@vendorm8.com.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. For material changes, we will provide at least 30 days' notice via email to the address associated with your account. The "Last updated" date at the top of this page indicates when this policy was last revised.

13. Contact

If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:

Kiricode OÜ

Saaruste tee 24, Sausti küla

Harjumaa, 75415, Estonia

Email: support@vendorm8.com

Supervisory authority: Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) — www.aki.ee