Draft template — replace bracketed placeholders and have this reviewed by a lawyer licensed in your operating jurisdictions (Nigeria's NDPR, UK/EU UK GDPR, US state privacy laws, Ghana's Data Protection Act) before relying on it.
Last updated: July 14, 2026
On this page
This Privacy Policy explains how Vendly ("we," "us," "our") collects, uses, and protects personal data when you use our point-of-sale and business management platform. It applies to business owners and staff who use Vendly directly (our "customers"), and to the end customers of those businesses whose data may pass through Vendly (for example, a customer placing a QR-code order at a restaurant using Vendly).
Account and business data — business name, type, address, registration number, owner and staff names, emails, phone numbers, and hashed passwords or PINs.
Operational data — products, dishes, prices, stock levels, transactions, expenses, and — for pharmacy businesses — NAFDAC numbers, batch numbers, expiry dates, and prescription details you choose to record.
Your customers' data — names and phone numbers you add as customers, purchase history, WhatsApp opt-in status, and, for QR-code ordering, the name and phone number a diner provides when placing an order.
Payment data — where you accept card or transfer payments through Vendly, transaction amounts and references are stored; full card numbers are handled directly by our payment processor and never touch Vendly's own servers.
Technical data — device identifiers, IP address, and log data collected automatically for security and troubleshooting.
Data is stored on Supabase infrastructure with encryption in transit. Access to your business's data is restricted to your authorized staff through role-based permissions, and to Vendly personnel only as needed for support or maintenance. Passwords are hashed and never stored in plain text. No system is perfectly secure, and we cannot guarantee absolute security of data transmitted to us.
We retain your business data for as long as your account is active. After account closure, data is retained for [retention period, e.g. 30–90 days] to allow export or reactivation, after which it is deleted or anonymized, except where we are legally required to retain records for longer (for example, financial or pharmacy compliance records under applicable law).
Depending on where you or your customers are located, you may have rights to access, correct, delete, or export personal data, and to object to or restrict certain processing:
To exercise these rights, contact us at the address below. If you are an end customer of a business using Vendly (not a Vendly account holder yourself), please contact that business directly, as they control your data — we act on their instructions.
Vendly is intended for business use by adults. We do not knowingly collect personal data from children. If you believe a child's data has been collected through Vendly, contact us and we will delete it.
Vendly's infrastructure may process and store data outside your country. Where we transfer personal data internationally, we rely on appropriate safeguards required by applicable law (such as standard contractual clauses where required for UK/EU-originating data).
We may update this Privacy Policy from time to time. Material changes will be communicated by email or in-app notice before they take effect.
Questions or data-rights requests can be sent to privacy@vendly.co [replace with your real contact address].