Privacy Policy
Last updated: 10 August 2026
Who we are and our role
VendorStreet (“the Platform”) is an operating platform for farmers markets, experiences, and venues, operated by Ecropolis LLC.
Organizations that use VendorStreet — market operators, experience operators, and venue operators — use it to manage their own vendors, customers, guests, and attendees. For that data, the organization is the data controller and we are a data processor acting on its instructions. We do not decide the purposes for which an organization’s vendor or customer data is used, and we do not use it for our own purposes.
Where we process an organization’s own account details (staff logins, organization profile, billing status), we act as a controller.
What we process
About organization staff
Login email, display name, optional first/last name and phone number, a salted password hash (we never store the password itself), role, session records, and the date of terms acceptance.
About organizations
Legal and trade name, business address, contact person details, federal EIN (an organization-level tax identifier), plan and billing status, and Stripe billing identifiers.
About vendors (processed for the organization)
| Data | Why |
|---|---|
| Business name, description, public profile, website and social links | Vendor directory and market-facing profile |
| Contact name, email, phone, postal address | Operating the vendor relationship |
| Uploaded compliance documents (e.g. certificates of insurance, health permits) and their review status | Document requirements set by the organization. Files contain whatever the issuer put in them. |
| Electronic signature records: typed signature, date, IP address, and browser identifier | Evidence that a vendor acknowledged an organization’s rules or documents |
| Applications, bookings, attendance, invoices, credits, and sales reports | Market operations and billing |
About customers and guests (processed for the organization)
| Data | Why |
|---|---|
| Name, email, optional phone | Taking and managing a booking; the organization’s customer list |
| Booking details, payment status, refunds | Operating experience and venue bookings |
| Waiver acceptance date | Recording that a guest accepted the organization’s waiver before booking |
| Waitlist entries (name, email) | Notifying a guest when a spot opens |
| Feedback ratings and comments | Post-visit feedback the guest chooses to submit |
| Acquisition source (a short code identifying the link or promotion that led to a booking) | Telling the organization which of its promotions worked |
We do not store payment card details or bank account numbers — payment is collected on Stripe-hosted pages and the Platform stores only Stripe identifiers, amounts, and statuses. The Platform has no fields for government identifiers of individuals or for special-category data.
What we do not do
- We do not sell personal data. There is no mechanism to do so.
- We do not run advertising trackers, and we do not profile you across other websites. The Platform (app.vendorstreet.app) loads no third-party analytics or advertising scripts, and fonts are self-hosted. This marketing website uses Google Analytics for basic traffic measurement — European visitors are asked first, everyone else can opt out on the cookie banner — with advertising and cross-site features switched off (see Cookies below).
- We do not combine data across organizations. Every vendor and customer record belongs to a single organization, and each organization’s records are kept separate.
- We do not use personal data to train machine learning models. The Platform’s AI-assisted features process only the text an organization’s staff types into them.
The Platform sends account and service email:
- To staff and vendors: verification, password reset, and invitation email; document-expiry reminders; compliance notices and operational announcements an organization sends to its vendors; platform service announcements.
- To guests: booking confirmations and reminders, waitlist notifications, and a post-visit feedback request.
We do not send third-party marketing. You can opt out of non-essential email — platform service announcements, an organization’s operational announcements to its vendors, and the post-visit feedback request sent to guests — at any time. Signed-in users can turn it off under Account settings → Email preferences, and every non-essential email includes an unsubscribe link, so guests can opt out even though they have no account. Essential email is always sent: verification, password reset, and invitations; booking confirmations, reminders, and waitlist notifications; document-expiry and compliance notices; and payment messages. You can also contact privacy@ecropolis.com. We do not send SMS.
Automated decisions
The Platform makes no automated decisions that produce legal or similarly significant effects.
Where data is stored
On Cloudflare’s global network (Workers, D1, KV, and R2). Data may be processed at Cloudflare data centers worldwide.
Sub-processors
| Sub-processor | Purpose |
|---|---|
| Cloudflare, Inc. | Application hosting, database, file storage, bot protection (Turnstile), and AI features |
| Stripe, Inc. | Payment processing and billing (Stripe-hosted checkout and connected accounts) |
| Twilio Inc. (SendGrid) | Transactional email delivery |
| Google LLC | Website traffic analytics (Google Analytics via Google Tag Manager), subject to the cookie choices described below |
We will give organizations notice before adding a sub-processor. The Platform contains an integration with a customer-intelligence system operated by Ecropolis; it is not currently enabled, and we will update this page before enabling it.
Security
Traffic is encrypted in transit, data is encrypted at rest by Cloudflare, passwords are stored as salted hashes, and every organization-owned record is scoped to that organization. Our Security Overview describes our measures in detail, including what we do not yet claim.
Retention
- Staff, vendor, and customer records are retained for the life of the organization’s account.
- Operational records are moved out of the live database to cold storage on a schedule: audit events after 400 days, notification records after 180 days, resolved payment-reconciliation records after 90 days.
- Abandoned draft bookings are deleted after 7 days.
- Financial records (invoices, payments) are retained for approximately 7 years for tax purposes.
- When an organization closes its account, we delete its data on written request, except records we are legally required to keep.
Your rights
If you are a vendor, customer, or guest of an organization that uses VendorStreet, that organization is the controller of your data — please direct access, correction, or deletion requests to it. We assist organizations in responding to such requests; requests we receive directly are referred to the organization concerned, and we act on verified requests the organization passes to us.
For data we control (organization accounts and staff logins), contact privacy@ecropolis.com.
Cookies
This website uses Google Analytics (via Google Tag Manager) to measure traffic. Which rules apply depends on where you appear to be. If you appear to be in the EEA, the UK or Switzerland, nothing is requested from Google and no analytics cookies are set until you accept via the cookie banner — decline, or simply ignore it, and no Google script loads at all. Everywhere else, analytics start on your first page view and the banner invites you to opt out; if you decline we stop analytics, switch Google Analytics off for this site, and delete the analytics cookies already set, so only that first page view was ever counted. We work out which applies from your browser's own time-zone setting — a rough guess that a VPN or a trip abroad will fool. We deliberately do not use the Geolocation API (which would prompt you) or an IP address lookup, and an unreadable time zone falls back to the stricter, consent-first rules. You can change your choice at any time using the Cookie settings link in the footer. We do not use advertising or cross-site tracking cookies.
The Platform (app.vendorstreet.app) sets a session cookie (HttpOnly, Secure) to keep you signed in, and a temporary cookie holding your email address during signup verification. Sign-in and registration forms use Cloudflare Turnstile for bot protection, which processes your IP address.
Changes
We will post changes here and update the date above. Material changes will be notified to organizations.
Contact
privacy@ecropolis.com — 8001 Valcasi Dr. Ste 101, Arlington, TX 76001,
USA
⟨EU/UK representative, if required⟩