Legal
Privacy Policy
Last updated: July 25, 2026 · VendorCAD · VendorCAD
1. Who we are
This Privacy Policy describes how VendorCAD (“VendorCAD,” “we,” “us,” or “our”), a Tennessee company based in Knoxville, Tennessee, USA, collects, uses, discloses, and protects personal information when you visit https://vendorcad.com, use the VendorCAD platform (the “Service”), or communicate with us.
VendorCAD is a B2B configure-to-order SaaS product. We act as a controller for our own marketing and account data, and typically as a processor for Customer Content that manufacturer customers upload or generate in their tenants (CAD sources, configurations, quotes, branding).
Contact for privacy requests: contact@vendorcad.com.
2. Scope
This Policy applies to our websites, the manufacturer App, published configurators and share links, demo environments, and related support channels.
It does not apply to third-party sites linked from the Service, or to CAD/vendor platforms (for example OnShape) that you connect under your own agreements with those providers.
3. Information we collect
We collect information in the following categories:
- Account & organization data: name, work email, password (hashed), company name, tenant/slug, role, and billing contact details.
- Sales & support leads: demo and contact form fields (name, email, company, product type, workflow notes, inquiry type, support category/priority).
- Customer Content: product parameters, rules, CAD references, 3D/export assets, share-link activity, quote requests (including buyer contact details submitted to a manufacturer’s inbox), branding, and audit/activity logs necessary to operate the tenant.
- Usage & device data: IP address, browser type, pages viewed, approximate location derived from IP, referrers, and product analytics events (when analytics cookies are enabled).
- Security & integrity data: session identifiers, bot-protection tokens (e.g. Cloudflare Turnstile), and error/diagnostic events (e.g. Sentry).
- Payment data: if you purchase through Stripe, payment method details are processed by Stripe; we receive limited billing metadata (plan, status, invoices), not full card numbers.
4. Sources
We collect information directly from you, automatically from your browser or device, from your organization’s administrators, and from service providers that help us operate the Service (see Subprocessors).
5. How we use information
We use personal information to:
- Provide, secure, maintain, and improve the Service.
- Authenticate users, manage tenants, and enforce access controls.
- Respond to demos, sales inquiries, and support requests.
- Process quote workflows on behalf of manufacturer customers.
- Send transactional messages (account, security, quote notifications) and, where permitted, product updates or marketing emails (you may opt out of marketing).
- Detect abuse, prevent fraud, and comply with law.
- Analyze product usage in aggregate or with identifiers when analytics consent is granted.
6. Legal bases (EEA/UK)
Where the GDPR or UK GDPR applies, we rely on: (a) contract performance (providing the Service); (b) legitimate interests (securing and improving the Service, B2B sales follow-up, fraud prevention — balanced against your rights); (c) consent (non-essential cookies/analytics, and marketing where required); and (d) legal obligation.
9. Retention
We retain account and Customer Content for the life of the customer relationship and a reasonable period afterward for backups, disputes, and legal compliance. Lead and support records are retained as needed for sales and support follow-up. Analytics events follow provider retention defaults unless configured shorter. You may request deletion subject to legal holds and backup cycles.
10. Security
We implement administrative, technical, and organizational measures appropriate to a multi-tenant SaaS product, including encrypted transport (TLS), hashed passwords, httpOnly session cookies, access controls, and signed short-lived URLs for certain exports. No method of transmission or storage is 100% secure.
11. International transfers
We and our subprocessors may process data in the United States and other countries. Where required, we use appropriate transfer mechanisms (such as Standard Contractual Clauses) with processors.
12. Your rights
Depending on your location, you may have rights to access, correct, delete, or export personal information; object to or restrict certain processing; withdraw consent; and lodge a complaint with a supervisory authority.
California residents may have CCPA/CPRA rights to know, delete, correct, and opt out of “sale” or “sharing” for cross-context behavioral advertising. We do not sell personal information as defined by the CCPA. Analytics tools may involve “sharing” for limited advertising measurement; you can deny analytics cookies to limit this.
To exercise rights, email contact@vendorcad.com with “Privacy request” in the subject. We may need to verify your identity and, for tenant Customer Content, redirect you to your organization’s administrator when we act only as a processor.
13. Children
The Service is for business use and is not directed to children under 16. We do not knowingly collect personal information from children.
14. Manufacturer customers (processors)
If you are a manufacturer customer, you are responsible for providing appropriate notices and obtaining any required consents for buyer personal data collected through your published configurators and quote forms. Our Data Processing Addendum (DPA) describes our processor obligations for Customer Content.
15. Changes
We may update this Policy by posting a revised version with a new “Last updated” date. Material changes will be highlighted on this page or communicated to account admins when appropriate.
16. Contact
VendorCAD
Based in Knoxville, Tennessee, USA
Privacy: contact@vendorcad.com
General: contact@vendorcad.com
Website: https://vendorcad.com
These documents are provided for transparency and operational compliance. For signed enterprise paper (DPA, security questionnaire, or custom terms), contact contact@vendorcad.com.