Privacy Policy

Last updated: September 4, 2026

This policy explains what information VendorFlow collects and how it's used. VendorFlow is written and reviewed by the business owner, not a law firm — if you have specific legal or compliance questions (for example, about student-data laws in your state), please consult an attorney.

What VendorFlow is

VendorFlow is a web application that helps charter-school vendors (tutors, service providers, and similar businesses) manage their rosters, certificates, invoices, and payments. This policy covers the information VendorFlow collects from vendors who use the service, and the limited information vendors enter about their own students and families in order to run their business.

Information we collect

When you create a VendorFlow account, we collect:

As you use VendorFlow, you may also enter information about your own students and their families, such as: student names, parent/guardian names and email addresses, class rosters, certificates, and payment records. This information is entered by you (the vendor) in order to run your own business through VendorFlow, and is stored on your behalf — VendorFlow does not independently collect this information from students or parents.

Payment information

Subscription payments are processed by Stripe, a third-party payment processor. VendorFlow does not receive or store your credit card number, bank account number, or other full payment card details — Stripe handles that directly. VendorFlow does receive limited billing metadata from Stripe, such as your subscription status, trial and renewal dates, and whether a subscription is active or canceled, in order to manage your account access.

How we use information

We do not sell your information, or the information you've entered about your students and families, to third parties. We do not use your data to serve advertising.

Where your data is stored

VendorFlow stores account and business data using Google Firebase (Firestore and Authentication) and runs its backend on Cloudflare Workers. Transactional emails (reminders, receipts, and similar messages) are sent through Resend. Subscription billing is handled by Stripe. Each of these providers has its own security practices and privacy policy governing how it handles data on our behalf.

Student and family information

If you use VendorFlow to track students, parents, or guardians associated with your own business, you are responsible for having the appropriate basis and permissions to collect and store that information, and for complying with any laws that apply to your business (for example, laws protecting student education records, or laws about collecting information from minors). VendorFlow provides the tools to store and manage this information securely on your behalf, but does not independently verify or take responsibility for how you collect it.

Data retention

We retain your account information for as long as your account is active, and for a reasonable period afterward in case you wish to reactivate it or need a copy of your records. If you'd like your account and associated data deleted, contact us at the email below.

Your choices

You can review and update most of your business information directly within VendorFlow, under Business Profile. To request a copy of your data, or to request deletion of your account, email us at the address below.

Security

We use industry-standard practices to protect your information, including encrypted connections (HTTPS) and access controls on our databases. No system can be guaranteed 100% secure, but we take reasonable steps to protect your data.

Changes to this policy

We may update this policy from time to time. If we make material changes, we'll update the "Last updated" date above.

Contact us

Questions about this policy, or requests regarding your data, can be sent to support@myvendorflow.com.