VendorStreet
MarketsFarmers markets, artisan markets & vendor events ExperiencesTours, classes & workshops VenuesVenues & event spaces
Bookings Payments Customers Messaging Reporting API & Integrations See the full platform →
Pricing About
Log In Get Started Free
Markets Experiences Venues Platform Pricing About Get Started Free
VendorStreet

Data Processing Addendum

Last updated: 19 July 2026

Between: Ecropolis LLC (“Processor”) and the organization using VendorStreet (“Controller”)
Effective: on creation of a VendorStreet organization account

1. Roles

The Controller determines the purposes and means of processing its vendors’, customers’, and guests’ personal data. The Processor processes that data only on the Controller’s documented instructions, which are given by creating an account, configuring the Platform’s settings, and using its features.

Creating an account constitutes an instruction to process personal data for the purposes described in §3.

2. Subject matter and duration

Processing lasts for the term of the Controller’s account, plus the retention periods in §7, after which data is deleted.

3. Nature and purpose of processing

  • Operating markets: vendor applications, booth assignment, attendance, document compliance, invoicing, and sales reporting.
  • Operating experiences and venues: bookings, schedules, capacity, waivers, waitlists, reminders, and feedback.
  • Presenting vendors, customers, and their history to the Controller’s staff.
  • Sending the service email described in the Privacy Policy, including operational notices the Controller composes for its vendors.
  • Processing payments through Stripe on the Controller’s behalf.

4. Categories of data and data subjects

Data subjects: the Controller’s staff, vendors, customers, guests, and attendees.

Personal data: names, email addresses, phone numbers, postal addresses (vendors), vendor business profiles and uploaded compliance documents, electronic-signature records (typed signature, IP address, browser identifier), booking and payment status records, waiver acceptance records, feedback, and activity history.

Not processed: payment card details or bank account numbers (payments are collected on Stripe-hosted pages), government identifiers of individuals, and special-category data as defined by GDPR Article 9. The Processor has no facility to store these.

5. Processor obligations

The Processor shall:

  1. Process personal data only on documented instructions, including for international transfers.
  2. Ensure personnel with access are bound by confidentiality.
  3. Implement the technical and organisational measures in §6.
  4. Not engage a sub-processor without notice to the Controller (§8).
  5. Assist the Controller in responding to data subject requests (§9).
  6. Assist with security, breach notification, and impact assessments, taking into account the nature of processing and the information available.
  7. Delete data on termination, per §7.
  8. Make available the information needed to demonstrate compliance.

6. Technical and organisational measures

MeasureWhat is actually implemented
Encryption in transitTLS on all endpoints
Encryption at restProvided by Cloudflare for database, key-value, and file storage
Credential protectionPasswords stored as salted PBKDF2-SHA256 hashes (100,000 iterations); platform API secrets held as deployment secrets, not in code or the database
Access controlRole-based access; server-side sessions delivered as HttpOnly, Secure cookies; bot protection and rate limiting on authentication flows
Tenant isolationEvery Controller-owned record carries the organization identifier; queries are organization-scoped; cross-organization isolation is covered by automated tests
Payment isolationCard data never touches the Platform; Stripe webhook messages are cryptographically verified
AuditabilityWrites to Controller data are recorded in an audit log with actor and before/after state
Retention enforcementAutomated daily archival of aged operational records, with archives verified readable before originals are removed
Environment separationProduction, staging, and development use separate databases and storage

Not currently claimed: the Processor holds no third-party security certification (SOC 2, ISO 27001), does not commission independent penetration testing, and does not currently offer multi-factor authentication for user accounts. The Controller should weigh this.

7. Retention and deletion

Staff, vendor, and customer records are retained for the term of the Controller’s account. Aged operational records are moved to cold storage on a schedule: audit events after 400 days, notification records after 180 days, resolved payment-reconciliation records after 90 days. Abandoned draft bookings are deleted after 7 days. Financial records (invoices, payments) are retained for approximately 7 years to meet tax obligations.

On termination of the account, the Processor will, at the Controller’s written request, delete or return the Controller’s personal data within 30 days, save for records the Processor is legally required to retain.

8. Sub-processors

Sub-processorPurposeLocation
Cloudflare, Inc.Hosting, database, file storage, bot protection, AI featuresGlobal network
Stripe, Inc.Payment processing and billingGlobal
Twilio Inc. (SendGrid)Transactional email deliveryUnited States

The Processor will give notice before adding or replacing a sub-processor, and the Controller may object by closing its account.

9. Data subject requests

Requests from the Controller’s data subjects received directly by the Processor are referred to the Controller. On the Controller’s verified instruction, the Processor will report the records held for a data subject, or delete them, within 30 days — except records tied to an unpaid invoice or records the Processor is legally required to retain.

10. Personal data breach

The Processor shall notify the Controller without undue delay and no later than 72 hours after becoming aware of a personal data breach affecting the Controller’s data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken.

11. International transfers

Data is processed on Cloudflare’s global network. Where transfers leave the EEA or UK, the parties rely on ⟨Standard Contractual Clauses / UK Addendum — confirm with counsel⟩.

12. Audit

The Processor shall make available information necessary to demonstrate compliance and allow for audits by the Controller or an appointed auditor, on reasonable notice and no more than once per year unless required by a supervisory authority.

13. Liability and term

⟨To be aligned with the Terms of Service — counsel to complete.⟩


Related: Privacy Policy · Security Overview

Secure & Reliable

Your data is protected and always private.

Local Team, Real Support

We're here when you need us.

Built by Operators

We understand your real-world challenges.

Growing With You

A platform that scales as you grow.

VendorStreet

The operating platform for real-world businesses.

Solutions

Markets Experiences Venues

Platform

Bookings Payments Messaging Reporting API & Integrations

Company

About Pricing Security Contact
© 2026 Ecropolis LLC. All rights reserved. Made in Texas Privacy · DPA · Terms