VendorStreet
MarketsFarmers markets, artisan markets & vendor events ExperiencesTours, classes & workshops VenuesVenues & event spaces
Bookings Payments Customers Messaging Reporting API & Integrations See the full platform →
Pricing About
Log In Get Started
Markets Experiences Venues Platform Pricing About Get Started
VendorStreet

Privacy Policy

Last updated: 10 August 2026

Operator: Ecropolis LLC, 8001 Valcasi Dr. Ste 101, Arlington, TX 76001, USA
Contact: privacy@ecropolis.com
Applies to: vendorstreet.app (this website) and app.vendorstreet.app (the Platform)

Who we are and our role

VendorStreet (“the Platform”) is an operating platform for farmers markets, experiences, and venues, operated by Ecropolis LLC.

Organizations that use VendorStreet — market operators, experience operators, and venue operators — use it to manage their own vendors, customers, guests, and attendees. For that data, the organization is the data controller and we are a data processor acting on its instructions. We do not decide the purposes for which an organization’s vendor or customer data is used, and we do not use it for our own purposes.

Where we process an organization’s own account details (staff logins, organization profile, billing status), we act as a controller.

What we process

About organization staff

Login email, display name, optional first/last name and phone number, a salted password hash (we never store the password itself), role, session records, and the date of terms acceptance.

About organizations

Legal and trade name, business address, contact person details, federal EIN (an organization-level tax identifier), plan and billing status, and Stripe billing identifiers.

About vendors (processed for the organization)

DataWhy
Business name, description, public profile, website and social linksVendor directory and market-facing profile
Contact name, email, phone, postal addressOperating the vendor relationship
Uploaded compliance documents (e.g. certificates of insurance, health permits) and their review statusDocument requirements set by the organization. Files contain whatever the issuer put in them.
Electronic signature records: typed signature, date, IP address, and browser identifierEvidence that a vendor acknowledged an organization’s rules or documents
Applications, bookings, attendance, invoices, credits, and sales reportsMarket operations and billing

About customers and guests (processed for the organization)

DataWhy
Name, email, optional phoneTaking and managing a booking; the organization’s customer list
Booking details, payment status, refundsOperating experience and venue bookings
Waiver acceptance dateRecording that a guest accepted the organization’s waiver before booking
Waitlist entries (name, email)Notifying a guest when a spot opens
Feedback ratings and commentsPost-visit feedback the guest chooses to submit
Acquisition source (a short code identifying the link or promotion that led to a booking)Telling the organization which of its promotions worked

We do not store payment card details or bank account numbers — payment is collected on Stripe-hosted pages and the Platform stores only Stripe identifiers, amounts, and statuses. The Platform has no fields for government identifiers of individuals or for special-category data.

What we do not do

  • We do not sell personal data. There is no mechanism to do so.
  • We do not run advertising trackers, and we do not profile you across other websites. The Platform (app.vendorstreet.app) loads no third-party analytics or advertising scripts, and fonts are self-hosted. This marketing website uses Google Analytics for basic traffic measurement — European visitors are asked first, everyone else can opt out on the cookie banner — with advertising and cross-site features switched off (see Cookies below).
  • We do not combine data across organizations. Every vendor and customer record belongs to a single organization, and each organization’s records are kept separate.
  • We do not use personal data to train machine learning models. The Platform’s AI-assisted features process only the text an organization’s staff types into them.

Email

The Platform sends account and service email:

  • To staff and vendors: verification, password reset, and invitation email; document-expiry reminders; compliance notices and operational announcements an organization sends to its vendors; platform service announcements.
  • To guests: booking confirmations and reminders, waitlist notifications, and a post-visit feedback request.

We do not send third-party marketing. You can opt out of non-essential email — platform service announcements, an organization’s operational announcements to its vendors, and the post-visit feedback request sent to guests — at any time. Signed-in users can turn it off under Account settings → Email preferences, and every non-essential email includes an unsubscribe link, so guests can opt out even though they have no account. Essential email is always sent: verification, password reset, and invitations; booking confirmations, reminders, and waitlist notifications; document-expiry and compliance notices; and payment messages. You can also contact privacy@ecropolis.com. We do not send SMS.

Automated decisions

The Platform makes no automated decisions that produce legal or similarly significant effects.

Where data is stored

On Cloudflare’s global network (Workers, D1, KV, and R2). Data may be processed at Cloudflare data centers worldwide.

Sub-processors

Sub-processorPurpose
Cloudflare, Inc.Application hosting, database, file storage, bot protection (Turnstile), and AI features
Stripe, Inc.Payment processing and billing (Stripe-hosted checkout and connected accounts)
Twilio Inc. (SendGrid)Transactional email delivery
Google LLCWebsite traffic analytics (Google Analytics via Google Tag Manager), subject to the cookie choices described below

We will give organizations notice before adding a sub-processor. The Platform contains an integration with a customer-intelligence system operated by Ecropolis; it is not currently enabled, and we will update this page before enabling it.

Security

Traffic is encrypted in transit, data is encrypted at rest by Cloudflare, passwords are stored as salted hashes, and every organization-owned record is scoped to that organization. Our Security Overview describes our measures in detail, including what we do not yet claim.

Retention

  • Staff, vendor, and customer records are retained for the life of the organization’s account.
  • Operational records are moved out of the live database to cold storage on a schedule: audit events after 400 days, notification records after 180 days, resolved payment-reconciliation records after 90 days.
  • Abandoned draft bookings are deleted after 7 days.
  • Financial records (invoices, payments) are retained for approximately 7 years for tax purposes.
  • When an organization closes its account, we delete its data on written request, except records we are legally required to keep.

Your rights

If you are a vendor, customer, or guest of an organization that uses VendorStreet, that organization is the controller of your data — please direct access, correction, or deletion requests to it. We assist organizations in responding to such requests; requests we receive directly are referred to the organization concerned, and we act on verified requests the organization passes to us.

For data we control (organization accounts and staff logins), contact privacy@ecropolis.com.

Cookies

This website uses Google Analytics (via Google Tag Manager) to measure traffic. Which rules apply depends on where you appear to be. If you appear to be in the EEA, the UK or Switzerland, nothing is requested from Google and no analytics cookies are set until you accept via the cookie banner — decline, or simply ignore it, and no Google script loads at all. Everywhere else, analytics start on your first page view and the banner invites you to opt out; if you decline we stop analytics, switch Google Analytics off for this site, and delete the analytics cookies already set, so only that first page view was ever counted. We work out which applies from your browser's own time-zone setting — a rough guess that a VPN or a trip abroad will fool. We deliberately do not use the Geolocation API (which would prompt you) or an IP address lookup, and an unreadable time zone falls back to the stricter, consent-first rules. You can change your choice at any time using the Cookie settings link in the footer. We do not use advertising or cross-site tracking cookies.

The Platform (app.vendorstreet.app) sets a session cookie (HttpOnly, Secure) to keep you signed in, and a temporary cookie holding your email address during signup verification. Sign-in and registration forms use Cloudflare Turnstile for bot protection, which processes your IP address.

Changes

We will post changes here and update the date above. Material changes will be notified to organizations.

Contact

privacy@ecropolis.com — 8001 Valcasi Dr. Ste 101, Arlington, TX 76001, USA
⟨EU/UK representative, if required⟩


Related: Security Overview · Data Processing Addendum

Secure & Reliable

Your data is protected and always private.

Local Team, Real Support

We're here when you need us.

Built by Operators

We understand your real-world challenges.

Growing With You

A platform that scales as you grow.

VendorStreet

The operating platform for real-world businesses.

Solutions

Markets Experiences Venues

Platform

Bookings Payments Messaging Reporting API & Integrations

Company

About Pricing Security Contact
© 2026 Ecropolis LLC. All rights reserved. Made in Texas Privacy · DPA · Terms · Cookie settings

We use analytics cookies to understand how this site is used. Decline to opt out — we'll remember your choice. See our Privacy Policy.