Privacy Policy
Last updated: 19 July 2026
Who we are and our role
VendorStreet (“the Platform”) is an operating platform for farmers markets, experiences, and venues, operated by Ecropolis LLC.
Organizations that use VendorStreet — market operators, experience operators, and venue operators — use it to manage their own vendors, customers, guests, and attendees. For that data, the organization is the data controller and we are a data processor acting on its instructions. We do not decide the purposes for which an organization’s vendor or customer data is used, and we do not use it for our own purposes.
Where we process an organization’s own account details (staff logins, organization profile, billing status), we act as a controller.
What we process
About organization staff
Login email, display name, optional first/last name and phone number, a salted password hash (we never store the password itself), role, session records, and the date of terms acceptance.
About organizations
Legal and trade name, business address, contact person details, federal EIN (an organization-level tax identifier), plan and billing status, and Stripe billing identifiers.
About vendors (processed for the organization)
| Data | Why |
|---|---|
| Business name, description, public profile, website and social links | Vendor directory and market-facing profile |
| Contact name, email, phone, postal address | Operating the vendor relationship |
| Uploaded compliance documents (e.g. certificates of insurance, health permits) and their review status | Document requirements set by the organization. Files contain whatever the issuer put in them. |
| Electronic signature records: typed signature, date, IP address, and browser identifier | Evidence that a vendor acknowledged an organization’s rules or documents |
| Applications, bookings, attendance, invoices, credits, and sales reports | Market operations and billing |
About customers and guests (processed for the organization)
| Data | Why |
|---|---|
| Name, email, optional phone | Taking and managing a booking; the organization’s customer list |
| Booking details, payment status, refunds | Operating experience and venue bookings |
| Waiver acceptance date | Recording that a guest accepted the organization’s waiver before booking |
| Waitlist entries (name, email) | Notifying a guest when a spot opens |
| Feedback ratings and comments | Post-visit feedback the guest chooses to submit |
| Acquisition source (a short code identifying the link or promotion that led to a booking) | Telling the organization which of its promotions worked |
We do not store payment card details or bank account numbers — payment is collected on Stripe-hosted pages and the Platform stores only Stripe identifiers, amounts, and statuses. The Platform has no fields for government identifiers of individuals or for special-category data.
What we do not do
- We do not sell personal data. There is no mechanism to do so.
- We do not run advertising or analytics trackers. Neither this website nor the Platform loads third-party analytics or advertising scripts, and fonts are self-hosted.
- We do not combine data across organizations. Every vendor and customer record belongs to a single organization, and each organization’s records are kept separate.
- We do not use personal data to train machine learning models. The Platform’s AI-assisted features process only the text an organization’s staff types into them.
The Platform sends account and service email:
- To staff and vendors: verification, password reset, and invitation email; document-expiry reminders; compliance notices and operational announcements an organization sends to its vendors; platform service announcements.
- To guests: booking confirmations and reminders, waitlist notifications, and a post-visit feedback request.
We do not send third-party marketing. To opt out of non-essential email, contact privacy@ecropolis.com. We do not send SMS.
Automated decisions
The Platform makes no automated decisions that produce legal or similarly significant effects.
Where data is stored
On Cloudflare’s global network (Workers, D1, KV, and R2). Data may be processed at Cloudflare data centers worldwide.
Sub-processors
| Sub-processor | Purpose |
|---|---|
| Cloudflare, Inc. | Application hosting, database, file storage, bot protection (Turnstile), and AI features |
| Stripe, Inc. | Payment processing and billing (Stripe-hosted checkout and connected accounts) |
| Twilio Inc. (SendGrid) | Transactional email delivery |
We will give organizations notice before adding a sub-processor. The Platform contains an integration with a customer-intelligence system operated by Ecropolis; it is not currently enabled, and we will update this page before enabling it.
Security
Traffic is encrypted in transit, data is encrypted at rest by Cloudflare, passwords are stored as salted hashes, and every organization-owned record is scoped to that organization. Our Security Overview describes our measures in detail, including what we do not yet claim.
Retention
- Staff, vendor, and customer records are retained for the life of the organization’s account.
- Operational records are moved out of the live database to cold storage on a schedule: audit events after 400 days, notification records after 180 days, resolved payment-reconciliation records after 90 days.
- Abandoned draft bookings are deleted after 7 days.
- Financial records (invoices, payments) are retained for approximately 7 years for tax purposes.
- When an organization closes its account, we delete its data on written request, except records we are legally required to keep.
Your rights
If you are a vendor, customer, or guest of an organization that uses VendorStreet, that organization is the controller of your data — please direct access, correction, or deletion requests to it. We assist organizations in responding to such requests; requests we receive directly are referred to the organization concerned, and we act on verified requests the organization passes to us.
For data we control (organization accounts and staff logins), contact privacy@ecropolis.com.
Cookies
This website sets no cookies. The Platform sets a session cookie (HttpOnly, Secure) to keep you signed in, and a temporary cookie holding your email address during signup verification. Sign-in and registration forms use Cloudflare Turnstile for bot protection, which processes your IP address.
Changes
We will post changes here and update the date above. Material changes will be notified to organizations.
Contact
privacy@ecropolis.com — 8001 Valcasi Dr. Ste 101, Arlington, TX 76001,
USA
⟨EU/UK representative, if required⟩