Skip to main content

Legal

Privacy Policy

Last updated: July 25, 2026 · VendorCAD · VendorCAD

1. Who we are

This Privacy Policy describes how VendorCAD (“VendorCAD,” “we,” “us,” or “our”), a Tennessee company based in Knoxville, Tennessee, USA, collects, uses, discloses, and protects personal information when you visit https://vendorcad.com, use the VendorCAD platform (the “Service”), or communicate with us.

VendorCAD is a B2B configure-to-order SaaS product. We act as a controller for our own marketing and account data, and typically as a processor for Customer Content that manufacturer customers upload or generate in their tenants (CAD sources, configurations, quotes, branding).

Contact for privacy requests: contact@vendorcad.com.

2. Scope

This Policy applies to our websites, the manufacturer App, published configurators and share links, demo environments, and related support channels.

It does not apply to third-party sites linked from the Service, or to CAD/vendor platforms (for example OnShape) that you connect under your own agreements with those providers.

3. Information we collect

We collect information in the following categories:

  • Account & organization data: name, work email, password (hashed), company name, tenant/slug, role, and billing contact details.
  • Sales & support leads: demo and contact form fields (name, email, company, product type, workflow notes, inquiry type, support category/priority).
  • Customer Content: product parameters, rules, CAD references, 3D/export assets, share-link activity, quote requests (including buyer contact details submitted to a manufacturer’s inbox), branding, and audit/activity logs necessary to operate the tenant.
  • Usage & device data: IP address, browser type, pages viewed, approximate location derived from IP, referrers, and product analytics events (when analytics cookies are enabled).
  • Security & integrity data: session identifiers, bot-protection tokens (e.g. Cloudflare Turnstile), and error/diagnostic events (e.g. Sentry).
  • Payment data: if you purchase through Stripe, payment method details are processed by Stripe; we receive limited billing metadata (plan, status, invoices), not full card numbers.

4. Sources

We collect information directly from you, automatically from your browser or device, from your organization’s administrators, and from service providers that help us operate the Service (see Subprocessors).

5. How we use information

We use personal information to:

  • Provide, secure, maintain, and improve the Service.
  • Authenticate users, manage tenants, and enforce access controls.
  • Respond to demos, sales inquiries, and support requests.
  • Process quote workflows on behalf of manufacturer customers.
  • Send transactional messages (account, security, quote notifications) and, where permitted, product updates or marketing emails (you may opt out of marketing).
  • Detect abuse, prevent fraud, and comply with law.
  • Analyze product usage in aggregate or with identifiers when analytics consent is granted.

7. How we share information

We do not sell personal information. We share information with:

  • Service providers / subprocessors that host infrastructure, email, payments, analytics, security, and error monitoring under contractual confidentiality and processing limits.
  • Your organization: administrators and teammates in your tenant can access Customer Content and user account metadata as permitted by role.
  • Buyers and sellers in published flows: quote submissions are delivered to the manufacturer tenant that operates the configurator.
  • Professional advisors and authorities when required by law, legal process, or to protect rights, safety, and the Service.
  • A successor entity in connection with a merger, acquisition, or asset sale, subject to continued protection consistent with this Policy.

8. Cookies and similar technologies

We use necessary cookies for authentication and security (for example, httpOnly session cookies). We use analytics technologies (such as PostHog and Microsoft Clarity) only after you accept analytics cookies via our consent banner, except where a lawful basis other than consent applies and is disclosed.

See our Cookie Policy for categories, retention, and how to change your choice.

9. Retention

We retain account and Customer Content for the life of the customer relationship and a reasonable period afterward for backups, disputes, and legal compliance. Lead and support records are retained as needed for sales and support follow-up. Analytics events follow provider retention defaults unless configured shorter. You may request deletion subject to legal holds and backup cycles.

10. Security

We implement administrative, technical, and organizational measures appropriate to a multi-tenant SaaS product, including encrypted transport (TLS), hashed passwords, httpOnly session cookies, access controls, and signed short-lived URLs for certain exports. No method of transmission or storage is 100% secure.

11. International transfers

We and our subprocessors may process data in the United States and other countries. Where required, we use appropriate transfer mechanisms (such as Standard Contractual Clauses) with processors.

12. Your rights

Depending on your location, you may have rights to access, correct, delete, or export personal information; object to or restrict certain processing; withdraw consent; and lodge a complaint with a supervisory authority.

California residents may have CCPA/CPRA rights to know, delete, correct, and opt out of “sale” or “sharing” for cross-context behavioral advertising. We do not sell personal information as defined by the CCPA. Analytics tools may involve “sharing” for limited advertising measurement; you can deny analytics cookies to limit this.

To exercise rights, email contact@vendorcad.com with “Privacy request” in the subject. We may need to verify your identity and, for tenant Customer Content, redirect you to your organization’s administrator when we act only as a processor.

13. Children

The Service is for business use and is not directed to children under 16. We do not knowingly collect personal information from children.

14. Manufacturer customers (processors)

If you are a manufacturer customer, you are responsible for providing appropriate notices and obtaining any required consents for buyer personal data collected through your published configurators and quote forms. Our Data Processing Addendum (DPA) describes our processor obligations for Customer Content.

15. Changes

We may update this Policy by posting a revised version with a new “Last updated” date. Material changes will be highlighted on this page or communicated to account admins when appropriate.

16. Contact

VendorCAD

Based in Knoxville, Tennessee, USA

Privacy: contact@vendorcad.com

General: contact@vendorcad.com

Website: https://vendorcad.com

These documents are provided for transparency and operational compliance. For signed enterprise paper (DPA, security questionnaire, or custom terms), contact contact@vendorcad.com.