Privacy Policy
Last updated: 6 October 2026
Who we are and our role
VendorStreet (“the Platform”) is an operating platform for farmers markets, experiences, and venues, operated by Ecropolis LLC.
Organizations that use VendorStreet — market operators, experience operators, and venue operators — use it to manage their own vendors, customers, guests, and attendees. For that data, the organization is the data controller and we are a data processor acting on its instructions. We do not decide the purposes for which an organization’s vendor or customer data is used, and we do not use it for our own purposes.
Where we process an organization’s own account details (staff logins, organization profile, billing status), we act as a controller.
What we process
About organization staff
Login email, display name, optional first/last name and phone number, a salted password hash (we never store the password itself), role, session records, and the date of terms acceptance.
About organizations
Legal and trade name, business address, contact person details, federal EIN (an organization-level tax identifier), plan and billing status, and Stripe billing identifiers.
About vendors (processed for the organization)
| Data | Why |
|---|---|
| Business name, description, public profile, website and social links | Vendor directory and market-facing profile |
| Contact name, email, phone, postal address | Operating the vendor relationship |
| Uploaded compliance documents (e.g. certificates of insurance, health permits) and their review status | Document requirements set by the organization. Files contain whatever the issuer put in them. |
| Electronic signature records: typed signature, date, IP address, and browser identifier | Evidence that a vendor acknowledged an organization’s rules or documents |
| Applications, bookings, attendance, invoices, credits, and sales reports | Market operations and billing |
About customers and guests (processed for the organization)
| Data | Why |
|---|---|
| Name, email, optional phone | Taking and managing a booking; the organization’s customer list |
| Booking details, payment status, refunds | Operating experience and venue bookings |
| Waiver acceptance date | Recording that a guest accepted the organization’s waiver before booking |
| Waitlist entries (name, email) | Notifying a guest when a spot opens |
| Feedback ratings and comments | Post-visit feedback the guest chooses to submit |
| Acquisition source (a short code identifying the link or promotion that led to a booking) | Telling the organization which of its promotions worked |
We do not store payment card details or bank account numbers — payment is collected on Stripe-hosted pages and the Platform stores only Stripe identifiers, amounts, and statuses. The Platform has no fields for government identifiers of individuals or for special-category data.
Connected calendar and video accounts
An appointments practice can connect a practitioner’s own Zoom, Google or Microsoft account so that bookings reach their calendar and video appointments get a meeting link. Each practitioner connects their own account, can disconnect it at any time, and the connection is used only for the purposes below. These are the practitioner’s own accounts with those companies, under their terms; we act on them only as the practitioner has approved.
Zoom
- What we store: the OAuth access and refresh tokens Zoom issues, the permissions granted, the practitioner’s Zoom user ID (used only to recognise a removal notice from Zoom), and, for each video appointment, the ID and join link of the meeting we created for it. Nothing else.
- What we do with it: create one meeting on the practitioner’s account when a video appointment is booked, move it when the appointment is rescheduled, and delete it when the appointment is cancelled. The join link is shared with the client who booked that appointment.
- What we never access: meeting content, recordings, transcripts, participants, chat, contacts, the practitioner’s profile, or any meeting we did not create. We never join a meeting.
- Deletion: disconnecting Zoom in VendorStreet deletes the stored tokens immediately. Removing VendorStreet in Zoom’s App Marketplace does the same: Zoom notifies us and we delete the connection. Join links are cleared from an appointment when it is cancelled.
Google Calendar and Google Meet
We ask only for permission to manage calendar events, not to read the whole calendar. We write an event for each appointment, and for a Google Meet appointment the meeting link is created on that event. We store the encrypted tokens and the IDs of the events we created.
Microsoft Outlook calendar
We write an event for each appointment, and read the practitioner’s calendar to keep times they are busy off the booking page. We keep only when they are busy, up to 120 days ahead, with each event’s ID so one read can be compared with the next — never what an event is called or who it is with — and we do not access mail or contacts. Disconnecting deletes the stored tokens and the busy times that connection brought in.
For all three, tokens are encrypted before they are stored (AES-GCM, with the key held outside the database) and are never returned by any listing in the Platform.
What we do not do
- We do not sell personal data. There is no mechanism to do so.
- We do not run advertising trackers, and we do not profile you across other websites. The Platform (app.vendorstreet.app) loads no advertising scripts, and fonts are self-hosted. It uses PostHog for product analytics, to see how the Platform is used and to find problems (see Cookies below). This marketing website uses Google Analytics for basic traffic measurement — European visitors are asked first, everyone else can opt out on the cookie banner — with advertising and cross-site features switched off (see Cookies below).
- We do not combine data across organizations. Every vendor and customer record belongs to a single organization, and each organization’s records are kept separate.
- We do not use personal data to train machine learning models. The Platform’s AI-assisted features process only the text an organization’s staff types into them.
The Platform sends account and service email:
- To staff and vendors: verification, password reset, and invitation email; document-expiry reminders; compliance notices and operational announcements an organization sends to its vendors; platform service announcements.
- To guests: booking confirmations and reminders, waitlist notifications, and a post-visit feedback request.
We do not send third-party marketing. You can opt out of non-essential email — platform service announcements, an organization’s operational announcements to its vendors, and the post-visit feedback request sent to guests — at any time. Signed-in users can turn it off under Account settings → Email preferences, and every non-essential email includes an unsubscribe link, so guests can opt out even though they have no account. Essential email is always sent: verification, password reset, and invitations; booking confirmations, reminders, and waitlist notifications; document-expiry and compliance notices; and payment messages. You can also contact privacy@ecropolis.com. We do not send SMS.
Automated decisions
The Platform makes no automated decisions that produce legal or similarly significant effects.
Where data is stored
On Cloudflare’s global network (Workers, D1, KV, and R2). Data may be processed at Cloudflare data centers worldwide.
Sub-processors
| Sub-processor | Purpose |
|---|---|
| Cloudflare, Inc. | Application hosting, database, file storage, bot protection (Turnstile), and AI features |
| Stripe, Inc. | Payment processing and billing (Stripe-hosted checkout and connected accounts) |
| Twilio Inc. (SendGrid) | Transactional email delivery |
| Google LLC | Website traffic analytics (Google Analytics via Google Tag Manager), subject to the cookie choices described below |
| PostHog, Inc. | Product analytics and session replay for the Platform, processed in the United States |
We will give organizations notice before adding a sub-processor. The Platform contains an integration with a customer-intelligence system operated by Ecropolis; it is not currently enabled, and we will update this page before enabling it.
Security
Traffic is encrypted in transit, data is encrypted at rest by Cloudflare, passwords are stored as salted hashes, and every organization-owned record is scoped to that organization. Our Security Overview describes our measures in detail, including what we do not yet claim.
Retention
- Staff, vendor, and customer records are retained for the life of the organization’s account.
- Operational records are moved out of the live database to cold storage on a schedule: audit events after 400 days, notification records after 180 days, resolved payment-reconciliation records after 90 days.
- Abandoned draft bookings are deleted after 7 days.
- Financial records (invoices, payments) are retained for approximately 7 years for tax purposes.
- When an organization closes its account, we delete its data on written request, except records we are legally required to keep.
Your rights
If you are a vendor, customer, or guest of an organization that uses VendorStreet, that organization is the controller of your data — please direct access, correction, or deletion requests to it. We assist organizations in responding to such requests; requests we receive directly are referred to the organization concerned, and we act on verified requests the organization passes to us.
For data we control (organization accounts and staff logins), contact privacy@ecropolis.com.
Cookies
This website uses Google Analytics (via Google Tag Manager) to measure traffic. Which rules apply depends on where you appear to be. If you appear to be in the EEA, the UK or Switzerland, nothing is requested from Google and no analytics cookies are set until you accept via the cookie banner — decline, or simply ignore it, and no Google script loads at all. Everywhere else, analytics start on your first page view and the banner invites you to opt out; if you decline we stop analytics, switch Google Analytics off for this site, and delete the analytics cookies already set, so only that first page view was ever counted. We work out which applies from your browser's own time-zone setting — a rough guess that a VPN or a trip abroad will fool. We deliberately do not use the Geolocation API (which would prompt you) or an IP address lookup, and an unreadable time zone falls back to the stricter, consent-first rules. You can change your choice at any time using the Cookie settings link in the footer. We do not use advertising or cross-site tracking cookies.
The Platform (app.vendorstreet.app) sets a session cookie (HttpOnly, Secure) to keep you signed in, and a temporary cookie holding your email address during signup verification. Sign-in and registration forms use Cloudflare Turnstile for bot protection, which processes your IP address.
The Platform also uses PostHog for product analytics. It records the pages you visit, the controls you use, errors in your browser, and technical details such as browser type, screen size and an approximate location derived from your IP address; if you are signed in, this is associated with your account and organization. To diagnose problems it may record how a page was used (a session replay), with anything typed into a form masked first. Payment card details are entered on Stripe’s pages and are never captured. PostHog sets first-party cookies and uses your browser’s storage so that repeat visits are counted once. We do not sell this information or use it for advertising.
Changes
We will post changes here and update the date above. Material changes will be notified to organizations.
Contact
privacy@ecropolis.com — 8001 Valcasi Dr. Ste 101, Arlington, TX 76001, USA