Privacy Policy
Last updated: 18 July 2026
1. Who we are
Vendify operates the Vendify website (vendifyevents.com) and mobile application (collectively, the “Service”). We are a UK-based platform that connects customers with event service providers. Vendify is the data controller for the personal information described in this policy.
Contact us at info@vendifyevents.com or via our contact page.
2. What data we collect
Information you give us
- Account registration: name, email address, and account role (customer or business owner).
- Business listings: business name, description, category, location (address and map pin coordinates), photos, pricing, and contact details you choose to display publicly.
- Messages and enquiries: the content of messages you send to businesses or customers through the platform.
- Reviews: written reviews and star ratings you submit.
- Profile information: any additional details you add to your account.
Information collected automatically
- Usage data: pages visited, features used, and search queries — used to improve the Service.
- Device and technical data: IP address, browser type, and operating system — used for security and fraud prevention.
- Location searches: if you use the map feature and type a location, that search term is processed to show nearby vendors. We do not access your device’s GPS without your explicit permission.
- Cookies: we use essential cookies to keep you logged in. See Section 7 for details.
- Push notification token: if you grant notification permission on our mobile app, we store a device token to send you booking and message alerts. You can withdraw this permission in your device settings at any time.
3. How we use your data
- To create and manage your account.
- To display business listings and enable customers to find and contact vendors.
- To deliver messages and enquiries between customers and businesses.
- To send transactional emails (account alerts, enquiry notifications).
- To detect and prevent fraud, abuse, or security incidents.
- To improve the Service.
- To comply with our legal obligations.
Our legal basis for processing under UK GDPR is contract performance (to provide the Service you signed up for), legitimate interests (security and service improvement), and legal obligation where applicable.
We do not sell your personal data.
4. Who we share data with
When you send a message or enquiry to a business, your name, message content, and any contact details you include are shared with that business. This is the core function of the Service.
We use the following trusted third-party providers:
- Supabase — database and user authentication.
- Vercel — website and app hosting.
- Cloudinary — image storage and delivery.
- Resend — transactional email delivery.
- Google — if you sign in with Google, we receive your name and email via Google OAuth.
- OpenStreetMap — map tiles. No personal data is sent to OpenStreetMap.
We do not share your data with advertisers or data brokers.
5. Data retention
- Account data: retained while your account is active. When you delete your account, your personal data is removed. You can do this directly from your dashboard.
- Messages and enquiries: retained for up to 2 years from the date they were sent, then deleted.
- Technical and usage logs: retained for a limited period for security and fraud prevention purposes, then deleted.
If you have questions about specific data or want to request early deletion, contact us at info@vendifyevents.com.
6. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your data — you can do this directly from your dashboard, or contact us.
- Restrict or object to certain processing.
- Portability — receive your data in a portable format.
To exercise any of these rights, email info@vendifyevents.com. We will respond within 30 days. You also have the right to lodge a complaint with the UK Information Commissioner’s Office at ico.org.uk.
7. Cookies
We use essential cookies to keep you logged in and maintain your session. We do not use advertising cookies or share cookie data with advertisers. For more detail, see our Cookie Policy.
8. Security
All data is transmitted over encrypted HTTPS connections. Passwords are hashed and never stored in plain text. We take reasonable technical and organisational measures to protect your data, but no internet service can guarantee absolute security.
9. Children’s privacy
The Service is not directed at children under 13. We do not knowingly collect personal data from anyone under 13. If you believe a child under 13 has provided us with personal data, please contact us and we will delete it promptly.
10. Changes to this policy
We may update this policy from time to time. The “last updated” date at the top reflects the most recent revision. For significant changes, we will notify registered users by email.
