Last updated: September 8, 2026 · Operator: Vendyr LLC · Coverage: Utah
This policy describes how Vendyr LLC (“Vendyr,” “we,” or “us”) handles information in the current Vendyr web application. It is written from implemented practices, not from a wish list of features. If a practice is not described here, do not assume we do it.
Authentication uses Google OAuth through Supabase Auth. Google’s own terms and privacy policy also apply to the sign-in. You can revoke Vendyr access from your Google account settings. Signing out of Vendyr ends the in-app session; access tokens are not guaranteed to fail immediately after account deletion.
We use cookies that are necessary to keep you signed in. Those session cookies are set by Supabase Auth (names typically begin with sb-). We do not currently run an analytics SDK, advertising pixels, or session replay. Blocking all cookies may prevent sign-in from working.
The browser may also hold limited local keys used by the app (for example leftover local profile or favorites keys), which are cleared on logout or account deletion.
Vendyr is a vendor-facing directory. Official listing information (hours, fees, location, application links, and similar market facts) is separate from an individual vendor’s experience report.
Vendyr does not process market applications, booth payments, vendor–organizer contracts, or acceptance decisions in the app. Those happen outside Vendyr, through links or contacts the listing provides.
We do not sell personal information, and we do not run advertising on Vendyr.
Information is processed by the services that actually host or authenticate the product:
If you follow an external market, Instagram, or website link, that destination receives whatever your browser sends under our referrer policy. We may also disclose information if required by law, to protect users or the service, or as part of a business transfer.
Account profile data is kept while the account is active. We do not currently publish a separate timed retention schedule for operational logs, backups, or rejected/superseded proof files.
If you delete your account, we remove the auth user, profile, favorites, private evidence, profile photos, pending or rejected photo suggestions, and other owned contribution rows. We keep legitimately public, market-owned listing assets: organizer listing photos and approved community listing photos. Approved photo-suggestion records that back those public copies are kept and anonymized (the contributor label becomes “Deleted contributor” and the user id is cleared). Private original suggestion files are deleted. Merged market listing facts may remain as directory information without your account attached.
You can delete your account from your profile. Deletion cannot be undone. Public market listing photos that belong to a market stay in the directory without your name, as described above.
You can download a machine-readable export of data Vendyr holds about your account from your profile. The export covers your profile and owned contribution records that the current export path reads.
In the current product you can edit your profile, export your data, and delete your account while signed in. We do not currently operate a separate privacy-request portal. If applicable law gives you additional rights, use the privacy contact below when a working address has been published. We may need to verify that a request comes from the account holder.
Vendyr is intended for adults exploring or running vendor businesses. It is not directed to children under 13. We do not knowingly collect information from children under 13. If you believe a child has created an account, contact us using the privacy contact below when it is published and we will delete the account.
Vendyr is operated from the United States. Supabase, Vercel, and Google may process information in the United States and in other countries where they operate. We do not currently publish a separate list of subprocessors beyond the destinations in section 6.
If we change this policy, we will update the “Last updated” date. Material changes may also be noted in the product. Continued use after an update means the revised policy applies to later use.
Privacy questions: privacy@vendyr.app Support: support@vendyr.app See also our Terms of Service.