Privacy Policy
VendBuddy is a software platform for vending machine operators. This policy describes what data we collect when you use vendbuddy.io, how we use it, and your rights over it.
Privacy at a glance
The full policy is below. Here is the short version first.
| Category | Do we collect it? | Do we sell it? | Shared with |
|---|---|---|---|
| Contact info (email, name) | Yes, at signup | No | Supabase, Resend, Stripe |
| Payment info | No — handled entirely by Stripe | No | Stripe |
| Business/usage data you create (leads, routes, contracts, notes) | Yes | No | Supabase (storage only) |
| Location/ZIP searches | Yes | No | Apollo.io, Census/mapping APIs, Supabase |
| Questions you ask the AI Growth Coach | Yes | No | Anthropic (Claude API) — see § 3 below |
| Device/IP, analytics events | Yes | No | Google Analytics, Meta, Cloudflare |
| Property manager machine requests (name, email, phone, property address) | Yes, if you submit the form at /property-managers | Not sold — shared with up to 2 paying operators, see § 2a | Up to 2 vending operators near your property, Supabase, Resend |
| Precise geolocation, contacts, camera/mic | No — never requested | — | — |
| Data used to train third-party AI models | No | — | — |
1. What we collect
Account data (when you sign up)
- Email address
- Password (stored only as a salted hash; we never see or store plaintext passwords)
- If you sign in with Google: your Google-verified email and display name
Usage data (as you use the product)
- ZIP codes and locations you search in the Lead Finder
- Machines, routes, pipeline records, contracts, and notes you create inside the app
- Business profile information you choose to add (company name, ZIP, service area)
- IP address, browser user-agent, and an anonymous device fingerprint (used for fraud prevention and anti-abuse rate limiting)
- Referral codes if you arrived through a partner link
Billing data
Credit card and bank details are handled entirely by Stripe — they never touch our servers. We store only: your plan, credits remaining, Stripe customer ID, and payment status.
Analytics and advertising
- Google Analytics (pageviews, session length, referring source)
- Meta Pixel and Meta Conversions API (PageView, Lead, and Purchase events to measure ad performance)
- Cloudflare Turnstile (invisible CAPTCHA tokens to block bot signups)
2. How we use your data
- To deliver the features you signed up for (lead lookup, route planning, contract generation, and related tools)
- To send service emails (verification codes, billing notices, critical product updates)
- To improve the product based on aggregate usage patterns
- To prevent fraud, abuse, and credit-farming
- To measure the performance of advertising campaigns that refer users to VendBuddy
We do not sell your personal data, and we do not share it with advertising networks beyond the analytics and attribution uses described above. The one place we deliberately share personal data with a third party who pays us is the property-manager referral flow described immediately below — we call that out explicitly rather than bury it, because it is the exception.
2a. Property manager machine requests — how referrals work
If you are a property manager and you submit the form at /property-managers, this section applies to you. It does not apply to operator accounts.
What we collect on that form
- Your name, email address, and phone number
- The property name, street address, city, state, and ZIP
- Property type, approximate daily foot traffic, unit or employee count, and any notes you write
- Your consent record: the exact wording of the consent text shown to you, its version, the page URL, the timestamp, your IP address, and your browser user-agent
Who we share it with, and what they pay us
- We share the above with at most two vending operators whose service area covers your property at the time you submit. That limit is what the consent checkbox states, and the system enforces it.
- Those operators pay VendBuddy for a subscription that includes receiving referrals like yours. We are compensated when we refer a location. This is disclosed on the form itself.
- The operator set is fixed at the moment you submit. Operators who join our network later are not given your details.
- If no operator covers your area, we share your details with nobody, we tell you so by email, and we hold the request until an operator covers your area — at which point we contact you before introducing anyone.
- We do not sell, rent, or list property-manager contact details to anyone outside that flow, and we do not add you to marketing lists you did not ask for.
Calls and texts
- Submitting the form means an operator may call you at the number you provided about your request.
- Text messages, autodialed calls, and prerecorded messages require the separate, optional checkbox on the form. It is unchecked by default, ticking it is never required to submit the form or to be matched, and you can reply STOP to any message to opt out. Message and data rates may apply.
- We do not certify, license-check, or insure-check operators. Ask any operator for proof of insurance and references before signing anything.
Retention and your choices
- We retain the request and its consent record for 5 years. Telephone-consumer claims run four years and do-not-call requests must be honoured for five, so the record has to outlive both.
- Reply to any email from us, or write to [email protected], to have your request deleted or to be added to our do-not-contact list. We will not be able to recall details already passed to an operator, but we will stop sharing further and tell you who received them.
3. AI-powered features
VendBuddy uses artificial intelligence in two places:
- Growth Coach — an AI chat assistant (in-app and as a public widget on the site) that answers vending-operator questions using Anthropic’s Claude API. The text of your question is sent to Anthropic to generate a response.
- AI Discovery — an AI-assisted feature inside the Lead Finder that helps surface and summarize candidate business leads from the data described in Section 1, also using Anthropic’s Claude API.
Under Anthropic’s commercial API terms, the questions and data we send are not used to train Anthropic’s models. We do not use your account data, leads, or business records to train any AI model ourselves. If a signed-in account asks a question, we log it (see Section 5) so we can debug issues and improve the feature — the public widget does not require an account and is logged without identifying information beyond what you typed.
4. Who we share data with
We use third-party processors to run the service. Each receives only the minimum data needed for their role:
- Supabase — database hosting (stores your account and product data)
- Resend — transactional email delivery
- Stripe — payment processing
- Apollo.io — B2B contact enrichment for leads you look up
- US Census Bureau + mapping APIs — location and demographic data
- Meta (Facebook) and Google Analytics — ad attribution and product analytics
- Cloudflare Turnstile — CAPTCHA / bot protection
- Railway — server infrastructure
5. Your rights
- Access: request a copy of everything we have on file by emailing [email protected]
- Correct: update your details in the app or by email
- Delete: request full deletion of your account — see our Data Deletion page
- Portability: request your data in a machine-readable format
- Opt out of marketing email: use the unsubscribe link in any marketing message; service emails (billing, verification) will still be delivered
6. Data retention
- Active accounts: data is retained for as long as the account is open
- Deleted accounts: data is removed from primary systems within 30 days of the deletion request
- Backups: data is purged from backup systems within 90 days
- Analytics and server logs: retained for up to 13 months, then aggregated or deleted
- Billing records required for tax and accounting: retained for 7 years as required by applicable law
7. Cookies and similar technologies
We use a small number of cookies:
vb_session_token— keeps you signed in (required for the app to function)_ga,_gid— Google Analytics_fbp,_fbc— Meta Pixel for ad attribution
You can block cookies in your browser settings, but the app will not function without vb_session_token.
8. Children
VendBuddy is a business tool not directed at children. We do not knowingly collect data from anyone under 18.
9. International users
VendBuddy is operated from the United States. If you use the service from outside the US, your data is processed in the US. By using the service you consent to that transfer.
10. Changes to this policy
We will notify active users by email at least 30 days before any material change takes effect. The Last updated date at the top of this page always reflects the most recent revision.
11. Contact
Privacy questions, requests, or complaints: [email protected]