Vendrop
Chrome extension privacy policy
Last updated August 15, 2026
Purpose and scope
The Vendrop Chrome extension helps authorized Vendrop users maintain retailer catalog information, prepare supplier carts for Vendrop orders, and—only when the user explicitly starts it—sync recent retailer purchase history. It also automates the transport and report-registration steps when an authorized user starts a Cantaloupe connection through the SeedLive portal. This policy applies to the extension and the information it sends to the Vendrop service and supported providers.
Information handled
- Vendrop connection data: the connected organization identifier and name, the Vendrop service origin, and time-limited authorization tokens.
- Retailer product data: product names, product URLs and identifiers, images, prices, package quantities, availability, sale information, and the purchasing club or warehouse context shown on supported retailer pages.
- Order automation data: the Vendrop order identifier, supplier product links, requested case quantities, and progress or error status needed to prepare a cart.
- Optional purchase history: retailer order and line identifiers, product name, product URL or SKU, quantity, and purchase date. This is read and transmitted only after an authorized user affirmatively starts purchase-history sync.
- SeedLive setup state: whether the user-started Cantaloupe setup is on the SeedLive sign-in, portal, or Report Register step, plus the portal's direct Report Register menu-link URL. The extension supplies the Vendrop transaction ingest URL and API Username, leaves Password blank, tests and saves the transport, and creates the required reports. It does not read, store, or transmit the username or password entered into SeedLive.
The extension does not read unrelated websites, submit retailer checkout, collect payment-card details or SeedLive credentials, or sell data for advertising.
How information is used
Vendrop uses this information only to provide and improve the extension’s retailer workflow: maintaining catalog records, matching recent purchases to catalog products, preparing supplier carts, diagnosing failed jobs, and protecting the service from misuse. Data is not used for personalized, retargeted, or interest-based advertising.
Storage, transfer, and retention
The extension stores connection settings and job progress in Chrome extension storage on the user’s device. Privileged catalog authorization is time-limited and is not saved to Chrome Sync. SeedLive automation values are retained only in Chrome session storage while the user-started setup is running and are cleared after completion. Information sent to Vendrop and supported providers is transmitted over HTTPS in production.
Imported retailer purchase signals are limited to the most recent year and older signals are removed during subsequent syncs. Catalog and operational records are retained while needed to provide the Vendrop service or until they are deleted through Vendrop’s administrative or support processes, subject to legal, security, and backup requirements.
Sharing
Vendrop does not sell extension data. To operate the disclosed workflow, information may be processed by Vercel for application hosting, Clerk for authentication, Neon for PostgreSQL database hosting, Amazon Web Services for transaction queues or private storage, and PostHog only when product analytics is enabled. Product information and product images may be processed by configured catalog-analysis providers, which can include Anthropic, Google, Moonshot AI, OpenAI, and xAI. The extension also sends the user-requested configuration values or retailer actions to SeedLive, Sam's Club, and Costco as necessary to complete the workflow.
Information may also be disclosed when required by law or when necessary to investigate fraud, abuse, or security incidents. Vendrop does not permit people to read user data except with specific user consent for support, for security or legal reasons, or in an aggregated and de-identified form for internal operations.
User choices
Purchase-history sync is optional and starts only after an explicit user action. Users can stop future extension access by removing the extension and clearing its local data. To request access, correction, or deletion of information held by Vendrop, contact privacy@vendropapp.com.
Chrome Web Store Limited Use
Vendrop’s use and transfer of information received through the extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Changes and contact
Material changes to extension data practices will be disclosed before the changed practices take effect. Questions about this policy can be directed to privacy@vendropapp.com.
Extension troubleshooting and support guidance is available on the Vendrop extension support page.