Vendrop
Privacy policy
Last updated August 24, 2026
Scope
This policy describes how Vendrop handles information in the Vendrop iOS app, website, and vending-operations service. The separate Chrome extension privacy policy covers information handled by the optional retailer extension.
Information we handle
- Account information: name, email address, authentication identifiers, organization, role, and team invitations. Authentication is provided by Clerk.
- Vending operations: business locations, machines, reader identifiers, products, slot layouts, inventory counts, restocks, optional cash-collected amounts, sales records, supply orders, and related operational notes.
- Photos: machine, product, card-reader, and restock photos that you choose to capture or upload for setup, identification, verification, and machine cover images.
- Device and diagnostics: push-notification tokens, app and operating-system versions, feature events, performance information, and crash or error details. Vendrop does not use an advertising identifier or collect precise device location from the iOS app.
- Subscription information: plan, entitlement, and billing status. Stripe processes payment details; Vendrop does not receive full payment-card numbers.
Camera, photos, and AI analysis
Camera and photo-library access is used only after you choose a photo workflow. Vendrop may send selected photos and the minimum necessary setup context to a configured analysis provider to identify a machine, map slots, match products, read a card-reader identifier, or check a restock. Automated results are presented as assistance and can be reviewed or corrected by the user.
Vendrop stores the optimized machine cover photo while the machine remains in the service. A separate analysis-review copy is retained for up to 45 days only when an analysis fails, is uncertain, or needs correction, then is deleted.
How information is used
Vendrop uses information to authenticate users, operate organization-scoped accounts, set up machines, connect transaction data, maintain inventory, prepare restocks and supplier orders, send requested notifications, provide support, prevent abuse, and improve reliability. Vendrop does not sell personal information or use it for third-party advertising or cross-app tracking.
Service providers and sharing
Information may be processed by vendors that help operate Vendrop, including Vercel for hosting, Clerk for authentication, Neon for database hosting, Amazon Web Services for private storage and queues, Sentry for crash diagnostics, PostHog when product analytics is enabled, Stripe for billing, and configured AI providers for the user-requested analysis described above. Transaction and setup information is shared with Cantaloupe or another connected provider only as needed to deliver the integration. Supplier data is sent to a retailer only when an authorized user starts the relevant workflow.
Vendrop may also disclose information when required by law, to protect users or the service, or with the user's specific direction. Organization members can access the organization's shared operational information according to their role.
Retention
Account and operational records are retained while needed to provide the service. Some sales, inventory, order, and billing records may be retained as necessary for security, accounting, dispute resolution, or legal obligations. Backups and provider logs expire on their normal schedules. Diagnostic retention is minimized, and the special 45-day photo-review limit is described above.
Your choices and deletion
You can manage notification permission in iOS Settings and correct many account or operational details in Vendrop. The iOS app's Settings screen includes a Delete Account action. Deleting the final account in an organization also deletes that organization's machines, photos, inventory, orders, and sales data. A deletion request that cannot complete immediately is queued for completion within 30 days.
To request access, correction, or deletion, or to ask a privacy question, contact privacy@vendropapp.com.
Security and children
Vendrop uses access controls, organization scoping, encrypted network transport, and restricted provider credentials to protect information. No internet service can guarantee absolute security. Vendrop is a business operations service and is not directed to children under 13.
Changes and contact
Material changes will be posted here with a revised date. For help using the app, visit the Vendrop support page. Privacy questions can be directed to privacy@vendropapp.com.