Privacy Policy

Effective date: August 10, 2026. Last updated: August 6, 2026. Version: 2.0

VendoIQ, Inc. (“VendoIQ,” “we,” “us,” or “our”) provides a voice-enabled sales productivity platform. Sales professionals use the VendoIQ mobile app to dictate notes about their work and photograph business cards and event badges; those captures sync to the VendoIQ web application, where their organization manages the resulting lead records. This Privacy Policy explains what information we collect, how we collect it, how we use and share it, how long we keep it, and the choices and rights you have.


This Privacy Policy applies to the VendoIQ mobile applications for iOS and Android, the VendoIQ web application, vendoiq.com, and all related services (together, the “Services”).

Who we are and how to reach us

Legal entity

Address

Privacy contact

Security contact

Legal notices

Support

VendoIQ, Inc., a Delaware corporation

1400 Arrowhead Drive, Brentwood, TN 37027, United States

privacy@vendoiq.com

security@vendoiq.com

legal@vendoiq.com

support@vendoiq.com

1) The most important things to know

Four facts about how VendoIQ works matter more than anything else in this policy, so we state them up front rather than burying them.


  1. Your dictation is transcribed on your own device, and we never store the audio. When you dictate, the app converts your speech to text using your device’s own on-device speech recognition. It is configured to use on-device recognition only—it will not fall back to Apple’s or Google’s network speech services. Separately, to improve accuracy, the app may send the recording directly from your device to Microsoft Azure AI Speech for a second transcription pass. That transmission goes from your phone to Microsoft, never through VendoIQ’s servers, and Microsoft processes it in memory without storing it. VendoIQ never receives or stores your voice audio. A working copy sits in your device’s temporary cache, is deleted the moment a transcript comes back, and is otherwise swept the next time you open the app—within 24 hours. That cache is excluded from iCloud, iTunes, and Google device backups.


  2. We do not use your content to train AI models. Not your audio, not your transcripts, not your notes, not your photos. Section 4 explains this in full, including what we would do before that ever changed.


  3. We never analyze faces or voices biometrically. The Services do not perform facial recognition, facial detection, face matching, face grouping, or any extraction of facial geometry from photographs. The Services do not perform speaker identification, speaker separation, voice enrollment, or any other process that produces a voiceprint. We do not create, collect, or store biometric identifiers of any kind.


  4. VendoIQ is a dictation and capture tool, not a conversation recorder. The Services are designed for you to dictate your own notes and photograph the things in front of you—a business card, a badge, a product. The Services are not designed to record other people’s conversations, and using them that way is prohibited by our Terms of Service. Recording only ever occurs while you have the app open and have deliberately started a capture; the app cannot record in the background.

2) Information we collect

2.1 Information you or your employer provide

Category

Specific data

How we collect it

Account and identity information

Name, business email address, job title, employer, role, conference assignments, user identifier

Your workspace administrator, during account setup. There is no

self-registration — VendoIQ accounts are created for you by your organization

Voice input

Audio of your dictation

Your device microphone, when you affirmatively start a dictation

Transcripts and notes

The text produced from your dictation, together with any edits, tags, tasks, opportunities, and records you create

Generated from your voice input on your device; edited by you

Photographs

Images you capture in the app — business cards, event badges, nametags, and anything else you choose to photograph

Your device camera only

Information extracted from photographs

Text read from an image — a name, job title, company, email address, phone number, or postal address on a business card or badge

Text recognition applied to the images you capture (Section 6)

Support and communications

Support tickets, emails, and the contents of your messages to us

You

Billing information

Billing contact name, business email, invoice and payment records

Your employer’s authorized billing contact

2.2 Information collected automatically

Category

Specific data

Purpose

Device and app information

Device model, operating system version, app version, language, time zone

Operate the app and diagnose device-specific defects

Server log data

IP address, request timestamps, error codes

Security, debugging, availability, abuse prevention

Usage data

Features used, capture counts, sync events, session timestamps

Operate and support the Services

We do not collect location data of any kind. The app requests no location permission on either platform, and photographs are re-encoded before upload, which removes embedded EXIF metadata including GPS coordinates.


We do not use advertising identifiers, cross-app tracking, or advertising SDKs, and we do not participate in cross-context behavioral advertising. The mobile apps contain no analytics, advertising, attribution, session-replay, or crash-reporting software development kits of any kind. Any crash information we receive comes from Apple and Google through their own developer consoles, under a setting you control on your device—it is their collection, not ours.

2.3 Information about people who are not VendoIQ users

VendoIQ processes personal information about individuals who do not themselves use the Services. This happens in three ways:


  • When a user dictates about someone. If a user dictates a note that names a customer, a prospect, or any other person, and describes what they said, what they need, or how to follow up with them, that person's information becomes part of the note.

  • When a user photographs something that identifies someone. A business card, an event badge, or a nametag contains that person's name, employer, job title, and contact details.

  • When information is retrieved from an event lead-retrieval service, or added to a record. See Section 2.4.


A user should provide personal information about another person only where authorized to do so, or where it is reasonable to expect that the information would be shared in a professional business context—a business card handed over at a trade show, or a badge the attendee is wearing openly at a business event. Photograph a person only with that person's knowledge and agreement.


When we process this information, we do so on behalf of the user's employer, which decides what information is collected, how it is used, and how long it is kept. If you are an individual whose information appears in a VendoIQ customer's workspace and you want to access, correct, or delete it, please contact that company directly. If you contact us at privacy@vendoiq.com, we will refer your request to the relevant customer and assist them in responding.

2.4 Event lead-retrieval services

This is the one place where information about a person reaches us from somewhere other than that person or the user who met them, so we set it out separately.


What lead retrieval is. At most trade shows and conferences, the event organizer appoints a lead-retrieval provider. Attendees are issued a badge carrying a barcode, QR code, or contactless chip that links to the registration record they completed when they signed up for the event. Exhibitors license the organizer’s lead-retrieval service for that show. When an attendee agrees to have their badge scanned at a booth, the provider returns the business contact details that attendee gave the organizer at registration — typically name, job title, company, business email address, and business telephone number.


Lead retrieval is the standard way exhibitors collect leads at events, and it exists for the benefit of both sides: attendees give their details once, at registration, instead of repeating them at every booth, and exhibitors get an accurate record instead of transcribing a business card by hand. Attendees agree to it as part of the event’s registration terms, and they choose at each booth whether to let their badge be scanned.


How VendoIQ works with it. Where your organization has licensed lead retrieval from an event organizer and chooses to connect it, the Services submit the badge identifier a user scans to that event’s provider and record the attendee details it returns.


  • It is entirely optional. VendoIQ does not require lead retrieval. The Services work fully without it — a user can capture a business card, photograph a badge, or dictate a note instead. If your organization does not want to use lead retrieval, nothing in the Services depends on it.

  • It only ever runs at an event your organization is exhibiting at, using credentials the event organizer issues to your organization.

  • The provider changes from event to event and is chosen by the organizer, not by VendoIQ. We do not select, contract with, or pay these providers.

  • The connection is limited to that event and to the period the organizer keeps it open. It is not a standing connection, and it cannot be used to look anyone up outside that event.

  • We will tell you which provider was used for any given event on request.


What we do not do. We do not search for, look up, or compile information about individuals independently of an interaction. We do not scrape or crawl public sources or social networks. We do not build lists. There is no path in the Services by which a user can look up a person they have not met.


We do not build a contact database of our own. Every person record in VendoIQ is scoped to a single customer’s workspace. There is no shared or global contact database, no cross-customer person index, and no cross-customer cache of looked-up information. We do not aggregate records across customers, do not sell or license them, do not use them for our own marketing or lead generation, and do not offer them to anyone else. Information added under this Section is excluded from any dataset used to develop our technology.


If you are the person whose record was completed this way. You may not be a VendoIQ user and may never have heard of us. Email privacy@vendoiq.com to ask what information we hold about you, where it came from, and to request correction or deletion. You do not need an account. Because we act on our customer’s instruction, we will also refer your request to the customer whose workspace holds the record and assist them in responding. You may also contact the original provider directly, as event lead-retrieval providers maintain their own opt-out mechanisms.

3) How we use information

Purpose

What this means in practice

Provide the Services

Authenticate you, transcribe your dictation, create and store your captures and lead records, sync them to the VendoIQ web application, and make your workspace work

Support you

Respond to your questions, diagnose problems, and restore service

Keep the Services

secure

Detect and investigate unauthorized access, fraud, abuse, and technical attacks; maintain audit logs

Maintain and improve the Services

Monitor reliability and performance, fix defects, and understand which features are used

Bill and administer

accounts

Issue invoices, process payments, and maintain financial records

Comply with law

Meet legal and regulatory obligations, respond to lawful requests, and establish, exercise, or defend legal claims

We do not use your information for advertising, marketing profiling, or any purpose unrelated to providing the Services to you and your employer.

4) Artificial intelligence, model training, and de-identified data

This section states our position precisely, because vague language here is not useful to anyone.

What is true today

We do not use your content to train AI models. As of the effective date of this Privacy Policy, VendoIQ does not use your voice audio, transcripts, notes, photographs, extracted contact information, or lead records to train, retrain, fine-tune, or otherwise develop any artificial intelligence or machine learning model—ours or a third party's.


Our vendors do not train on your content either. Microsoft does not use audio submitted to Azure AI Speech, or prompts and outputs submitted to Azure OpenAI, to train its foundation models.


We never analyze faces. The Services do not perform facial recognition, facial detection, face matching, face clustering or grouping, or any extraction of face geometry, faceprints, or face templates. We do not use photographs for identity verification.


We never create voiceprints. The Services do not perform speaker identification, speaker verification, speaker diarization, or voice enrollment. No feature of the Services produces a voiceprint or any other voice-derived biometric identifier.

What may change, and what we commit to before it does

We intend, in the future, to use customer content to develop and improve our own technology. What we want to learn from is how sales professionals describe their own work—the language they use for follow-ups, tasks, escalations, next steps, and objections, and the shape of a sales process. We are interested in patterns of work, not in the people that work was done with. We are not trying to build a database of individuals, and business contact information added under Section 2.4 is not part of what we would train on.


Our agreements with business customers permit this on a limited basis, using only de-identified data. We are not exercising that right today.


Before we begin any model training on customer content, we commit to all of the following:

  1. We will update this Privacy Policy and change the "Last updated" date.

  2. We will give advance notice—in the app, by email, or both—before the change takes effect. We will not begin training on data we already hold on the strength of a silently amended policy.

  3. We will obtain any consent or authorization required at that time from the affected business customer or individual.

  4. We will disclose which model providers receive what data, and update our subprocessor list accordingly.

  5. Voice audio will remain excluded. We do not use, and will not use, voice audio to train speech models.

  6. Facial and voice biometric analysis will remain excluded.

  7. Business contact information added under Section 2.4 will remain excluded.

  8. Before any transcript or note is used, we will remove names and other identifying details of the people described in it. We train on how the work is described, not on who it concerned.

Our commitment on de-identified data

If and when we use de-identified data, we take reasonable measures to ensure that it cannot be associated with any individual, consumer, or household. We publicly commit to maintain and use de-identified data in de-identified form and not to attempt to re-identify it, except solely to determine whether our de-identification measures are effective. We contractually obligate any recipient of de-identified data to comply with the same restrictions.


What this commitment covers, and what it does not. It applies to the de-identified dataset described above — a separate derived dataset from which identifiers have been removed. It means we will not take that dataset and work backwards to determine whose records it was built from. It is a different operation from the record completion described in Section 2.4, which works on a record that is identified from the moment it is created and is never de-identified. The two are held and used separately.

AI features in the product today

Where the Services use artificial intelligence to transcribe, extract, or structure your content, that processing is performed by Microsoft Azure under an enterprise agreement, with Microsoft acting as our service provider. Specifically: Microsoft Azure AI Speech transcribes dictation, and Microsoft Azure OpenAI extracts structured contact fields from transcripts and from card and badge images.


AI-generated output can contain errors, omissions, and inaccuracies. You are responsible for reviewing and verifying AI-generated content before relying on it or synchronizing it into your business systems.

5) Microphone, camera, and device permissions

The VendoIQ app requests the following permissions, and no others. Each is requested at the point the corresponding feature is used, and you can decline or revoke any of them in your device settings.

Permission

Why we request it

What happens if you decline

Microphone

To capture your dictation

Dictation is unavailable; you can still type notes and use the rest of the app

Speech recognition

To let your device convert your dictation to text locally

Dictation is unavailable

Camera

To photograph business cards and event badges

Photo capture is unavailable; all other features work

We never ask for your photo library. The app takes photos in the moment, through the camera, and that is all. It does not read, browse, index, or request access to the photos already on your device. Neither app declares a photo-library permission.


We do not collect location. No location data of any kind. The app requests no location permission on either platform. Photographs are re-encoded before upload, which removes embedded EXIF metadata including GPS coordinates.


Recording begins only when you start it, and stops when you leave. The app does not listen in the background and does not capture audio when you have not started a dictation.

It has no background-audio capability: capture stops when you switch away from the app or lock your device. A clear on-screen indicator is displayed for the entire time audio is being captured.


Audio on your device. While you dictate, the recording is written to your device’s temporary cache — the area both iOS and Android set aside for disposable files and exclude from iCloud, iTunes, and Google device backups. It is deleted the moment the transcript returns, and immediately if you discard the capture. Any remaining file is swept the next time you open the app, within 24 hours of recording. Logging out or deactivating your account erases the entire audio folder. If you never reopen the app, the file is removed by your device’s own cache management. At no point is the audio uploaded to VendoIQ.

6) Photographs

Because the camera is open-ended by design — you can point it at anything — this section sets out plainly what we do and do not do with the images you capture.

What we do
  • Photographs are taken in the app, never pulled from your library. The app has no ability to read, browse, or index the photos already on your device.

  • We remove location metadata. Every image is re-encoded before upload, which removes embedded EXIF data including GPS coordinates. We do not know where a photograph was taken.

  • We store your photographs in our cloud. Unlike voice audio, images are retained. They are stored in our Microsoft Azure environment in the United States, in private storage that is not publicly accessible, encrypted in transit and at rest. They are visible to you, to others in your workspace with permission to view the associated record, and to your workspace administrators.

  • We read text from images, in two stages. While you are lining up the shot, your device reads the text on screen locally using Google ML Kit — that step never leaves your phone. When you capture the image, a reduced-size copy is uploaded to our Microsoft Azure environment, where a Microsoft Azure OpenAI vision model extracts the contact fields — name, title, company, email, phone, address — so the record can be created without retyping.

  • Microsoft may briefly retain submitted content to detect misuse of its AI services. Under Microsoft’s standard configuration for Azure OpenAI, content submitted to the service — which here includes the card and badge images themselves — may be retained for a limited period and examined, by automated systems and where necessary by authorized Microsoft personnel, solely to detect and prevent abuse of the service. Microsoft does not use this content to train its models. We are pursuing Microsoft’s exemption from this monitoring; if and when it is approved, we will update this paragraph.

What we do not do
  • We do not perform any facial analysis. No facial recognition, no facial detection, no face matching, no face grouping, no extraction of face geometry, no faceprints, no face templates. We do not collect biometric identifiers or biometric information from your photographs.

  • We do not use your photographs to build our own contact database. Contact records created from images you capture belong to your employer’s workspace. Every record is scoped to a single customer. We do not aggregate them into any cross-customer dataset, sell them, license them, use them for our own marketing, or use them to enrich any product we offer to anyone else.

  • We do not contact the people in your photographs. We will not email, call, or message a person whose details you captured, except at your specific direction through a feature you have used deliberately.

  • We do not scan your photographs for advertising, profiling, or analytics.

Your responsibility for what you photograp

You choose what to point the camera at, and we cannot police that in advance. Before you photograph a person, or anything that identifies a person, obtain that person’s knowledge and agreement. Do not photograph and upload:


• children, or anyone who has not agreed to be photographed;

• government identification documents, passports, driver’s licences, or payment cards;

• medical, health, or financial records;

• confidential or proprietary information belonging to a third party — including whiteboards, screens, documents, or prototypes at another company’s premises, where you do not have permission to capture them;

• anything unlawful.


Section 7 of the Terms of Service makes these obligations binding.

Reporting a photograph

If a photograph in a VendoIQ workspace should not be there — because it is of you and you did not agree to it, because it contains confidential or unlawful content, or for any other reason — email privacy@vendoiq.com. Workspace administrators can delete any image in their workspace, and we will act on reports we receive.

7) How we share information

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We have not sold or shared personal information for these purposes in the preceding twelve months.


We disclose information only as follows:

Recipient

What they receive

Why

Your employer and

workspace

administrators

Your account details, your captures and transcripts, your usage and sync activity

They own the workspace and

the content created in it

Microsoft — Azure

Hosting, database, and image storage for all Service data

Cloud infrastructure

Microsoft — Entra External ID

Your name, business email address, role, and organization

Authentication and identity

Microsoft — Azure AI Speech

Dictation audio, sent directly from your device, for transcription in memory

Speech-to-text

Microsoft — Azure

OpenAI

Transcript text, and card and badge images, for structured field extraction

Contact extraction

Event lead-retrieval providers

The badge identifier a user scans at an event

Retrieval of your organization's entitled attendee records, as described in Section 2.4(a)

The business systems your employer connects

The lead records your organization directs the Services to synchronize

Only where your organization has enabled an integration

Service providers

Only the information necessary for their function

Payment processing, email delivery, customer support

Apple and Google

App distribution; device-level diagnostics under a setting you control

To distribute the app

Professional advisers

As needed

Legal, accounting, insurance, and audit

Government or legal requesters

As legally required

To comply with law, respond to

lawful requests, or protect

rights and safety

A successor entity

As part of the transaction

In a merger, acquisition, financing, or sale of assets, subject to this policy

Our commitment regarding third parties. Every third party with whom we share user data — including our cloud, AI, and support vendors, and any parent, subsidiary, or affiliated entity that has access to user data — is contractually required to provide the same or equal protection of user data as is stated in this Privacy Policy. Our service providers may use the data only to perform services for us and may not use it for their own purposes.


Current subprocessors are listed at https://www.vendoiq.com/subprocessors. We provide our business customers with 30 days’ notice before engaging a new subprocessor.

8) Where information is processed

All customer data is processed and stored by VendoIQ in the United States.


If you access the Services from outside the United States, your information will be transferred to and processed in the United States, which may have different data-protection laws than your country. Where we process personal data subject to the EU or UK GDPR and transfer it to the United States, we rely on the Standard Contractual Clauses approved by European Commission Decision 2021/914 of 4 June 2021, with our business customer acting as data exporter and VendoIQ as data importer.

9) How long we keep information

Data

Retention

Voice audio on VendoIQ’s servers

Never received. Audio goes from your device directly to our speech-to-text provider and is never uploaded to VendoIQ

Voice audio on your device

Deleted the moment the transcript returns; otherwise swept the next time you open the app, within 24 hours of recording. Erased entirely on logout or deactivation. Excluded from device backups

Transcripts, notes, tasks, opportunities, and lead records

Kept for as long as your organization’s subscription is active, and afterwards only as long as needed for the purpose it was collected for, to resolve disputes, or to meet a legal obligation. Available for export for 30 days after termination. Deleted within 60 days of your organization’s deletion request

Card and badge images

Kept while the associated lead record is retained, and deleted when your organization deletes that record or its workspace. We are building a scheduled deletion process to shorten this; when it is in place we will state the period here

Account and profile data

Kept while the account is active; deleted when the account is deleted (Section 11)

Record of a deletion request

When an individual account is deleted, we keep a limited internal record of the request — the account identifier, email address, name, and the date it was completed — so that we can demonstrate the request was honored. This record is not used for any other purpose

Security and audit logs

Retained. Audit records are designed to outlive the accounts they

describe so that we can investigate security incidents and

demonstrate compliance

Database backups

Point-in-time recovery snapshots are retained for 7 days and then expire automatically. Backups cannot be edited selectively and are not restored into active use except in a disaster-recovery event

Support records

Kept while needed to support you and to resolve any related dispute

Billing, invoice, and tax records

7 years, as required by tax and accounting law

We retain information after a deletion request only where we are legally required to do so, or where it is necessary for security, fraud prevention, or resolving a dispute. We disclose that fact here so that it is not a surprise.

10) Security

We maintain the following measures to protect customer data:


  • Encryption in transit — TLS 1.2 or higher for all connections to our services and storage.

  • Encryption at rest — all stored data, including card and badge images, is encrypted at rest using Microsoft Azure platform encryption.

  • Private storage — image storage containers are private and not publicly accessible. Images are served only through short-lived, read-only, individually scoped access links.

  • Database isolation — our production database is not reachable from the public internet. Access is restricted to our own Azure services and named administrative addresses, over TLS, using Microsoft Entra identity authentication. Password-based database authentication is disabled.

  • Access control — role-based access on a need-to-know basis; every customer-facing request is scoped to a single customer’s data.

  • Logging and monitoring — audit logs of access to and actions on production systems containing customer data.

  • Incident response — a maintained incident response plan, with notification to affected business customers within 48 hours of confirming a security incident affecting their data.


No system is perfectly secure. You are responsible for protecting your credentials and for notifying us at security@vendoiq.com if you believe your account has been compromised.

11) Your choices and rights

11.1 Controls available to everyone
  • Delete your account and data. You can request deletion of your VendoIQ account at https://www.vendoiq.com/delete-account, or from Settings → Delete Account in the app. The web page works without logging in and without reinstalling the app. We complete verified deletions within 30 days. Section 11.2 explains exactly what is deleted and what is retained.

  • Withdraw consent and revoke permissions. You can revoke microphone, speech recognition, and camera permissions at any time in your device settings. Revoking microphone access stops all audio capture immediately.

  • Access and correct your information. You can view and edit your profile and your captures in the app. For anything else, contact privacy@vendoiq.com.

  • Opt out of non-essential email. Use the unsubscribe link in any marketing email, or contact privacy@vendoiq.com. We will still send you service and security messages about your account.

11.2 What account deletion actually does

VendoIQ accounts are created by an organization for its own staff, and the leads captured through those accounts are that organization’s business records. So deletion works in two parts, and we would rather be precise than reassuring.


Deleted:

  • your account and sign-in identity;

  • your profile — name, email, role, and conference assignments;

  • your personal notes.


Retained by your organization, with your identity removed:

  • the leads and contacts you captured, and the transcripts, card images, tasks, and

opportunities associated with them. These belong to your organization as its business

records. Your authorship is removed from them and they are reassigned to your

organization. Requests to delete those records must come from your organization,

which controls them.


Retained by us:

  • a limited internal record that your deletion request was made and completed, as described in Section 9. This record contains your account identifier, email address, and name. We keep it so that we can demonstrate the request was honored, and for no other purpose. It means that, while the lead records themselves no longer identify you, your deletion is not erased from our internal audit trail. The accurate word for this is pseudonymization, not anonymization, and we prefer to say so.


Deletion of your account and personal data cannot be undone.

11.3 If your account is managed by your employer

If you use VendoIQ through an employer’s workspace, your employer controls the workspace and the content in it. Your employer may access your captures, transcripts, and usage activity, and may retain or delete workspace content independently of your individual account. Requests about workspace content should go to your employer first.

We will assist our business customers in responding to those requests as required by our agreement with them and by law.

11.4 United States state privacy rights

Depending on your state of residence, you may have the right to know what personal information we collect and how we use and disclose it; to access, correct, or delete it; to obtain a portable copy; to opt out of sale, sharing, targeted advertising, and certain profiling; and to not be discriminated against for exercising these rights.


We do not sell personal information, do not share it for cross-context behavioral advertising, and do not use it for targeted advertising or for profiling that produces legal or similarly significant effects. There is accordingly nothing to opt out of, and we honor Global Privacy Control signals as a matter of course.


To exercise a right, email privacy@vendoiq.com. We will verify your identity before responding, and we will respond within the period required by applicable law. You may use an authorized agent; we will require proof of authorization. If we deny your request, you may appeal by replying to our response with the word “Appeal.”


California. Under the CCPA, in the preceding twelve months we collected the categories of personal information described in Section 2 — identifiers, professional and employment information, commercial information, audio and visual information, internet and device activity, and inferences derived from the foregoing — for the business purposes in Section 3, from the sources in Section 2, and disclosed them to the categories of recipients in Section 7. Where we process personal information on behalf of a business customer, we act as that customer’s service provider and do not retain, use, or disclose that information for any purpose other than performing the services, or outside the direct business relationship, as required by the CCPA.

11.5 EEA, UK, and Switzerland

Where the GDPR or UK GDPR applies and our business customer is the controller, direct your requests to that customer. Where VendoIQ is the controller of your information — for example, information about our own website visitors, prospects, and billing contacts — our legal bases are performance of a contract, our legitimate interests in operating and securing our business, compliance with legal obligations, and, where required, your consent. You have the right to lodge a complaint with your supervisory authority.

12) Children

The Services are business software sold to organizations and are not directed to children. You must be at least 18 years old to use the Services. We do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has provided us personal information, contact privacy@vendoiq.com and we will delete it.

13) Third-party services and links

Where your organization authorizes an integration with a third-party business system, that system is controlled by its provider and governed by its own terms and privacy policy, not by this one. Disconnecting an integration does not delete data that has already been written into that system; you must delete it there.

14) Changes to this policy

We may update this Privacy Policy. If we make a material change, we will notify you before it takes effect by posting the updated policy with a new effective date and, where the change materially affects how we handle your information, by notifying you in the app or by email.

15) Contact us

VendoIQ, Inc. 1400 Arrowhead Drive Brentwood, TN 37027 United States


© 2025. All rights reserved. VendoIQ

© 2025. All rights reserved. VendoIQ

© 2025. All rights reserved. VendoIQ