Privacy policy
Last updated 7 August 2026
Vendor Squeezer exists so a business leader can see what they are responsible for without asking anyone. The same standard applies here: this page says what we actually collect, which services touch it, and what you can ask us to do with it.
Marked placeholders, not invented facts
Vendor Squeezer is in early access and the operating entity behind it, its registered address, and the governing jurisdiction are not settled yet. Anything that depends on those decisions appears here as a placeholder such as [OPERATING ENTITY], and nothing has been invented to fill the gap. This page is updated and re-dated once those details are confirmed. Everything that does not depend on them describes what the product actually does today.
Who this applies to
This policy covers the public Vendor Squeezer website, the early access product, and any email you send us in connection with either. The operator is [OPERATING ENTITY], at [REGISTERED ADDRESS].
What we collect
If you leave your email on the marketing site. We store the email address, the company name if you give one, the page you submitted from, a short label for which call to action it was, and the time. That is the whole record. Submitting again from a different page updates the row you already have rather than creating a second one.
If you create an account. Sign-in is handled by WorkOS AuthKit. We receive your name, email address, profile picture if your identity provider supplies one, and which organization and role you belong to. We never see your password.
What you put into the product. Vendors, contracts, renewal dates, notice periods, costs, notes, and any documents you upload or forward. This is your material. We do not sell it, we do not share it with other customers, and we do not use it to train machine learning models.
Product analytics. If analytics are enabled for the deployment you are using, PostHog records which pages are viewed and which features are used, plus a few named events such as submitting the early access form. This is about how the product is used, not about the contents of your contracts.
Ordinary server logs. IP address, browser user agent, requested URL, and timestamps, kept for security and debugging.
What we do not collect
No payment details, because the product is free during early access. No advertising identifiers, no ad network pixels, and no data sold or brokered to anyone. We do not buy contact lists.
Services that process data for us
- WorkOS for authentication, organization membership, and roles.
- Convex as the application database and backend, including storage for the files you upload.
- PostHog for product analytics, where enabled.
- Brandfetch for vendor logos. Your browser requests the logo directly from their CDN, so they see the vendor domain being displayed and your IP address. They do not receive your identity or anything from the contract.
- An email delivery provider so that an early access signup reaches a person who reads it. Only the fields listed above are included.
- [HOSTING PROVIDER] for serving the site and the application.
Each of these processes data on our instruction in order to run the service. Where any of them stores data outside your own country, the transfer basis is set out under [GOVERNING LAW] once the operating entity is confirmed.
Cookies
Signing in sets a session cookie through WorkOS AuthKit. It is required to stay signed in and cannot be turned off while using the application. PostHog sets analytics cookies where analytics are enabled. There are no advertising cookies on this site.
How long we keep things
Early access signups are kept until early access closes or until you ask us to remove yours, whichever is first. Account and product data are kept while your organization uses the product and are deleted on request. Server logs are kept for a short operational window and then rotated out.
What you can ask for
Write to [CONTACT EMAIL] and you can ask for a copy of what we hold about you, a correction, or a deletion. Removing an early access signup needs nothing more than the email address you used. Depending on where you live you may have further statutory rights; those are listed here once the operating entity and its jurisdiction are confirmed.
Security
Traffic is served over HTTPS, and access to an organization's records is scoped to the members of that organization at the backend, not only in the interface. We do not currently hold a formal security certification, and this page will not claim one before it is true.
Children
Vendor Squeezer is a tool for people doing their job. It is not directed at children and we do not knowingly collect data from them.
Changes to this policy
When this policy changes in a way that matters, the date at the top changes with it and account holders are told by email. Filling in a placeholder is such a change.