VendorStreet
MarketsFarmers markets, artisan markets & vendor events ExperiencesTours, classes & workshops VenuesVenues & event spaces
Bookings Payments Customers Messaging Reporting API & Integrations See the full platform →
Pricing About
Log In Get Started Free
Markets Experiences Venues Platform Pricing About Get Started Free
VendorStreet

Privacy Policy

Last updated: 19 July 2026

Operator: Ecropolis LLC, 8001 Valcasi Dr. Ste 101, Arlington, TX 76001, USA
Contact: privacy@ecropolis.com
Applies to: vendorstreet.app (this website) and app.vendorstreet.app (the Platform)

Who we are and our role

VendorStreet (“the Platform”) is an operating platform for farmers markets, experiences, and venues, operated by Ecropolis LLC.

Organizations that use VendorStreet — market operators, experience operators, and venue operators — use it to manage their own vendors, customers, guests, and attendees. For that data, the organization is the data controller and we are a data processor acting on its instructions. We do not decide the purposes for which an organization’s vendor or customer data is used, and we do not use it for our own purposes.

Where we process an organization’s own account details (staff logins, organization profile, billing status), we act as a controller.

What we process

About organization staff

Login email, display name, optional first/last name and phone number, a salted password hash (we never store the password itself), role, session records, and the date of terms acceptance.

About organizations

Legal and trade name, business address, contact person details, federal EIN (an organization-level tax identifier), plan and billing status, and Stripe billing identifiers.

About vendors (processed for the organization)

DataWhy
Business name, description, public profile, website and social linksVendor directory and market-facing profile
Contact name, email, phone, postal addressOperating the vendor relationship
Uploaded compliance documents (e.g. certificates of insurance, health permits) and their review statusDocument requirements set by the organization. Files contain whatever the issuer put in them.
Electronic signature records: typed signature, date, IP address, and browser identifierEvidence that a vendor acknowledged an organization’s rules or documents
Applications, bookings, attendance, invoices, credits, and sales reportsMarket operations and billing

About customers and guests (processed for the organization)

DataWhy
Name, email, optional phoneTaking and managing a booking; the organization’s customer list
Booking details, payment status, refundsOperating experience and venue bookings
Waiver acceptance dateRecording that a guest accepted the organization’s waiver before booking
Waitlist entries (name, email)Notifying a guest when a spot opens
Feedback ratings and commentsPost-visit feedback the guest chooses to submit
Acquisition source (a short code identifying the link or promotion that led to a booking)Telling the organization which of its promotions worked

We do not store payment card details or bank account numbers — payment is collected on Stripe-hosted pages and the Platform stores only Stripe identifiers, amounts, and statuses. The Platform has no fields for government identifiers of individuals or for special-category data.

What we do not do

  • We do not sell personal data. There is no mechanism to do so.
  • We do not run advertising or analytics trackers. Neither this website nor the Platform loads third-party analytics or advertising scripts, and fonts are self-hosted.
  • We do not combine data across organizations. Every vendor and customer record belongs to a single organization, and each organization’s records are kept separate.
  • We do not use personal data to train machine learning models. The Platform’s AI-assisted features process only the text an organization’s staff types into them.

Email

The Platform sends account and service email:

  • To staff and vendors: verification, password reset, and invitation email; document-expiry reminders; compliance notices and operational announcements an organization sends to its vendors; platform service announcements.
  • To guests: booking confirmations and reminders, waitlist notifications, and a post-visit feedback request.

We do not send third-party marketing. To opt out of non-essential email, contact privacy@ecropolis.com. We do not send SMS.

Automated decisions

The Platform makes no automated decisions that produce legal or similarly significant effects.

Where data is stored

On Cloudflare’s global network (Workers, D1, KV, and R2). Data may be processed at Cloudflare data centers worldwide.

Sub-processors

Sub-processorPurpose
Cloudflare, Inc.Application hosting, database, file storage, bot protection (Turnstile), and AI features
Stripe, Inc.Payment processing and billing (Stripe-hosted checkout and connected accounts)
Twilio Inc. (SendGrid)Transactional email delivery

We will give organizations notice before adding a sub-processor. The Platform contains an integration with a customer-intelligence system operated by Ecropolis; it is not currently enabled, and we will update this page before enabling it.

Security

Traffic is encrypted in transit, data is encrypted at rest by Cloudflare, passwords are stored as salted hashes, and every organization-owned record is scoped to that organization. Our Security Overview describes our measures in detail, including what we do not yet claim.

Retention

  • Staff, vendor, and customer records are retained for the life of the organization’s account.
  • Operational records are moved out of the live database to cold storage on a schedule: audit events after 400 days, notification records after 180 days, resolved payment-reconciliation records after 90 days.
  • Abandoned draft bookings are deleted after 7 days.
  • Financial records (invoices, payments) are retained for approximately 7 years for tax purposes.
  • When an organization closes its account, we delete its data on written request, except records we are legally required to keep.

Your rights

If you are a vendor, customer, or guest of an organization that uses VendorStreet, that organization is the controller of your data — please direct access, correction, or deletion requests to it. We assist organizations in responding to such requests; requests we receive directly are referred to the organization concerned, and we act on verified requests the organization passes to us.

For data we control (organization accounts and staff logins), contact privacy@ecropolis.com.

Cookies

This website sets no cookies. The Platform sets a session cookie (HttpOnly, Secure) to keep you signed in, and a temporary cookie holding your email address during signup verification. Sign-in and registration forms use Cloudflare Turnstile for bot protection, which processes your IP address.

Changes

We will post changes here and update the date above. Material changes will be notified to organizations.

Contact

privacy@ecropolis.com — 8001 Valcasi Dr. Ste 101, Arlington, TX 76001, USA
⟨EU/UK representative, if required⟩


Related: Security Overview · Data Processing Addendum

Secure & Reliable

Your data is protected and always private.

Local Team, Real Support

We're here when you need us.

Built by Operators

We understand your real-world challenges.

Growing With You

A platform that scales as you grow.

VendorStreet

The operating platform for real-world businesses.

Solutions

Markets Experiences Venues

Platform

Bookings Payments Messaging Reporting API & Integrations

Company

About Pricing Security Contact
© 2026 Ecropolis LLC. All rights reserved. Made in Texas Privacy · DPA · Terms