VendMetric
Request a demo

Legal

Privacy Policy

Effective August 9, 2026

This Privacy Policy explains how Enterprise Professional Systems, LLC ("we," "us"), operator of VendMetric™ (the "Service"), collects, uses, and discloses information in connection with the Service.

Reading this as a vendor? If a customer of ours invited you, the short version: your documents are visible only to you and the customer that requested them, nothing is shared between your customers without your direction, your uploaded documents are never used to train AI models, your account is free, and any paid option is optional and priced before you agree to it.

1. Information We Collect

  • Account information: name, email address, organization, and role, provided when you or your organization create an account. Vendors hold a single account that can serve multiple customer relationships. Where your organization has configured single sign-on or directory provisioning, your name, email address, directory identifier, and active status are provided to us by your organization's own identity provider, on your organization's instruction, and your organization's directory controls when your account is created, updated, or deactivated.
  • Vendor and document data: information a customer organization uploads or requests about its vendors, including contact details and compliance documents (such as certificates of insurance, licenses, and tax forms), which may contain personal information about vendor contacts.
  • Lien waiver documents: for organizations using our construction accounting features, signed lien waiver documents uploaded by the organization. These are legal documents and typically contain the signatory's name, title, and signature; where a waiver concerns a subcontractor or supplier further down the chain, it may contain information about individuals or businesses that are not otherwise users of the Service.
  • Payment and accounting records: for organizations using our accounting features, records the organization keeps about purchase orders, invoices, payments, and retained amounts ("retainage"). These contain payment reference numbers the organization chooses to record (for example a check number), never bank account credentials or payment card numbers.
  • Usage data: log data, device information, and interactions with the Service, including per-organization operational metrics that we compute to show organizations the Service's measured impact. Mutual working metrics — for example, how quickly each side of a customer–vendor relationship responds to the other — are computed from existing records and shown to both sides of that relationship; they are aggregated by organization side, never computed about a named individual.
  • API request logs: where an organization uses our public API, we log each request — including the requesting IP address, the API key used, the route accessed, and the number of records returned — for security monitoring and incident response. Requests with invalid or missing credentials are logged the same way. These logs are retained for 12 months (Section 6).
  • Billing information: when you or your organization pay for a subscription or an optional per-use service, our payment processor (currently Stripe) collects and processes your payment details directly. We receive and store limited billing metadata (for example, your subscription plan and status) but not your full payment card number.
  • Verification data: when a business entity or sanctions/watchlist verification check is requested and paid for, the vendor's business name and state of registration (for entity checks) or business name and country (for sanctions/watchlist checks) are sent to the relevant verification provider and the result is returned to the requesting organization. See Section 3.
  • Taxpayer identification numbers: compliance documents your organization collects (notably IRS Form W-9) contain a vendor's taxpayer identification number (TIN). A TIN is an EIN for a business or, for a sole proprietor, that individual's Social Security number. Where a TIN-match check is requested and paid for, the vendor's business name and TIN are transmitted to a third-party verification provider (see Section 3). We also use TINs and payment totals to prepare IRS Form 1099 candidate reporting for organizations using our accounting features.
  • Federal exclusion screening data: where an organization records a procurement as federally funded, we submit the vendor's business name to the U.S. General Services Administration's SAM.gov exclusions data to check whether the vendor is debarred or excluded from receiving federal funds. This runs only on federally-funded spend, never on commercial procurements.
  • Opportunity board information: organizations may choose to publish a procurement opportunity to a shared opportunity board visible to other VendMetric vendors. Where a vendor expresses interest in a posted opportunity, that vendor's business identity and verification status are disclosed to the posting organization. See Section 5.
  • Messages: messages exchanged between an organization and a vendor through the Service, which are attached to the specific record (such as a document request or solicitation) they concern.
  • Prospect information: if you contact us through our website (for example, the demo request form) without becoming a customer or vendor, we retain your submission (name, email, company, and message) to follow up, and delete it if no relationship develops (Section 6).
  • Communications: information you provide when you contact us, including through the demo request form.

2. How We Use Information

  • To provide, operate, and maintain the Service.
  • To process AI-based document extraction, classification, and anomaly review on behalf of the organization that requested the document, including warranty documents an organization uploads for analysis.
  • To scan every uploaded file for malware before storage.
  • To carry out a vendor's instruction to reuse a document for another of that vendor's customers (see Section 4).
  • To process subscription and per-use payments and to bill for optional paid services (Section 3).
  • To perform business entity or sanctions/watchlist verification checks that an organization or vendor has requested and paid for (Section 3).
  • To create, update, and deactivate user accounts on the instruction of an organization's identity provider, where the organization has configured single sign-on or directory provisioning.
  • To monitor and secure the Service, including logging API requests (with source IP addresses) so that unauthorized access or attempted access can be detected, investigated, and answered.
  • To send compliance reminders, digests, and account notifications.
  • To deliver Managed Services a customer has purchased, within that customer's workspace and on its instructions.
  • To respond to inquiries and provide customer support, and to follow up with prospective customers who contact us.
  • To improve and secure the Service.

We do not use Customer Data to train general-purpose AI models, and our AI providers are contractually prohibited from doing so. Uploaded document files are never used to train any AI model.

De-identified and aggregated data. We may create and use data derived from Customer Data that has been de-identified and aggregated so that it no longer identifies, and cannot reasonably be used to identify, you, your organization, your vendors, or any individual, in order to develop, evaluate, and improve the Service. This work is performed on structured, de-identified fields; uploaded document files themselves are not used for this purpose. We do not attempt to re-identify de-identified data, we do not sell it, and we do not disclose it in any form that identifies a customer or vendor.

3. AI, Payment, Verification, and Screening Processing

  • AI extraction. Documents uploaded to VendMetric are processed by third-party AI providers (currently Anthropic) to extract metadata such as expiration dates and coverage amounts, and to flag anomalies for human review. Document categories processed this way include compliance documents, imported contract documents, and warranty documents. This processing powers the Service's document intelligence features and nothing else.
  • Malware scanning. Every user-supplied file is transmitted to a malware scanning provider (currently Cloudmersive) and scanned before it is stored. Files that fail scanning are rejected and not retained.
  • Payment processing. Subscription and per-use payments are processed by our payment processor (currently Stripe), which collects payment details directly on its own hosted checkout page. We never receive or store your full payment card number.
  • Business entity and sanctions/watchlist verification. Where an organization or vendor requests and pays for a check, we send the vendor's business name and location to a verification provider (currently Cobalt for business entity checks, and OpenSanctions for sanctions/watchlist screening) and return the result to the requesting organization. These checks are evidence for a person's review; a possible match is never treated as a confirmed finding, and results never affect the Vendor Intelligence Score (VIS™).
  • TIN matching. Where an organization or vendor requests and pays for a check confirming a vendor's taxpayer identification number against IRS records, we send the vendor's business name and TIN to a verification provider (currently Cobalt). A result of "matched," "not matched," or "unavailable" is returned to the requesting organization.
  • Federal exclusion screening. For procurements an organization marks as federally funded, we check the vendor's business name against SAM.gov exclusions data. Unlike other checks in this Section, a confirmed exclusion does block an award or payment in the Service, because federal law prohibits awarding federal funds to an excluded party. An inconclusive or unavailable result never blocks anything.
  • Document integrity analysis. We inspect technical metadata embedded in uploaded files (for example, creation and modification timestamps and originating software) to flag possible signs of alteration. These are indicators for a person to review, never conclusions about authenticity or intent, and no such flag is reported to anyone outside the organization that holds the document.
  • Compliance and payment gates configured by your organization. The Service enforces rules an organization configures for itself: an award or payment can be blocked when a required document is missing or expired, or (for organizations that enable it) when a required lien waiver has not been provided. These gates apply the organization's own configured requirements — they are not third-party judgments — and the path past any of them is a documented exception recorded by a person in that organization, with a stated reason, preserved in the audit trail.
  • Human decisions. AI output and verification results are advisory. A person in the requesting organization approves or rejects documents and interprets verification results. The sole exception is a confirmed federal exclusion, described above; organization-configured gates always have a documented human exception path.

4. Vendor Accounts and Document Reuse

Vendors keep one account across all customers they serve on VendMetric.

  • Within each customer relationship, a vendor's documents are visible only to that vendor and that customer.
  • A vendor may direct the Service to reuse a document already provided to one customer to satisfy another customer's request. Only then is a copy (with its extracted metadata) created in the second customer's workspace, where it is reviewed under that customer's own requirements. The event is recorded in both customers' audit trails.
  • Customers never gain access to each other's workspaces or records, and we do not share a vendor's information between customers except at the vendor's direction as described here.

5. Data Sharing

We do not sell personal information. We may share information with:

  • Service providers who process data on our behalf (hosting, database and storage, AI processing, malware scanning, email delivery, payment processing, and verification screening), each listed on our subprocessor page.
  • Other users within your organization, as determined by your organization's configured roles.
  • The customer that requested a document, in the case of vendor submissions; and a second customer of the same vendor, only at the vendor's direction (Section 4).
  • The other side of a customer–vendor relationship, in the case of mutual working metrics (Section 1): a customer's aggregate response-time metrics are visible to the vendor in that relationship, and vice versa. These are aggregated by organization side and are never about a named individual.
  • Our personnel, when acting inside a customer workspace to deliver purchased Managed Services or requested support; such access is visible in the customer's team list and recorded in its audit trail. Internal access for customer setup assistance is granted to a single named staff member for a single named customer at a time, is revocable, and is recorded — including who granted it and when. Our sales and support personnel may also see account-level billing and subscription status to serve your account, without access to your Customer Data.
  • Other organizations and vendors on the shared opportunity board, but only where someone chose to publish or respond. A vendor's expression of interest discloses its business identity and verification status to the posting organization; publicly visible listings show the opportunity and the posting organization, not the identities of vendors who responded.
  • Third-party systems your organization authorizes through our public API. Access is limited to the issuing organization's workspace, keys expire, and their use is logged. Where you direct data to a third-party system this way, that system's own terms and privacy practices govern what happens to it.
  • Authorities, where required by law.

6. Data Retention, Export, and Deletion

We retain account and vendor data for as long as the relevant account is active, and as needed to comply with legal obligations, resolve disputes, and enforce agreements.

  • Export. Organizations can generate vendor audit packages and export audit history from within the Service. A complete export of an organization's records and documents is available on request and on termination.
  • Deletion. On written request, or within 30 days of account termination, we delete the organization's Customer Data from our production systems. Backups are purged on their normal rotation.
  • Audit history. Audit events are append-only by design and cannot be edited. They are retained for the life of the organization's account — they are evidence the organization may need years later — and are removed only when the organization's data is deleted in full.
  • Stated retention periods. In addition to the above: API request logs are retained for 12 months and then automatically deleted; outbound email records for 24 months; operational error reports for 90 days; sign-in throttle records (which store IP addresses only in hashed form) for 24 hours; and prospect submissions for up to 12 months.
  • Security logs and account deletion. API request logs that are attributable to an organization are deleted with that organization's data. Request logs that are not attributable to any organization — for example, requests made with invalid or missing credentials — are security records about the request itself and are retained on the 12-month schedule above regardless of any account's deletion.
  • Vendor accounts. A vendor may request closure of their vendor account at any time; documents already provided to a customer remain part of that customer's records until deleted by that customer or on that customer's account deletion.

7. Subprocessors

We use a small number of third-party service providers to operate the Service. Each is listed, with the data it handles, on our subprocessor page. We will update that page before adding a new subprocessor that processes Customer Data. Single sign-on and directory provisioning involve your organization's own identity provider, which acts for your organization, not for us.

8. Data Processing Addendum

Business customers who require a Data Processing Addendum (DPA) can obtain the current version from an organization administrator's Settings within the Service, or request one at privacy@vendmetric.com. The DPA is provided to customers rather than published publicly; our subprocessor list, security overview, and this Privacy Policy remain public.

9. Data Security

We use industry-standard measures to protect information, including encryption in transit and at rest, role-based access control, tenant isolation covered by automated tests that run on every code change, database-enforced append-only audit logging, malware scanning of every upload, and deny-by-default database access policies. Two-factor authentication is available to customer staff accounts, and an organization can require it for all of its staff. Recovery from backup has been exercised and measured, not assumed. No system is completely secure, and we cannot guarantee absolute security. Our current controls are described on our security page.

10. Cookies and Local Storage

We do not use advertising, analytics, or cross-site tracking cookies, and we do not display a cookie consent banner because there is nothing optional to consent to. The only data stored on your device is what the Service needs to function:

  • Session cookies (application only): authentication cookies that keep you signed in. They are essential to the Service and expire automatically.
  • Preference storage (application only): your browser's local storage remembers small preferences, such as whether you have completed an in-app guided tour. This data never leaves your device.
  • Security check (contact form only): our demo request form uses Cloudflare Turnstile to block automated spam. Cloudflare may set technical state strictly for that security purpose. See the Cloudflare privacy policy for details.
  • Payment checkout (paid actions only): when you choose to pay for a subscription or an optional service, you are directed to our payment processor's own hosted checkout page, which may set its own cookies under its privacy policy. We do not receive those cookies.

Traffic measurement. We use privacy-preserving, cookieless analytics (Vercel Web Analytics and Plausible Analytics) to count aggregate page views and see which pages and referring links bring visitors. Neither sets cookies, tracks you across sites, or collects information that identifies you — which is why no consent banner is required.

11. Your Rights

Depending on your jurisdiction, you may have rights to access, correct, or delete your personal information. Vendor contacts whose information was uploaded by a customer organization may contact us, and we will assist or route the request to the responsible organization as appropriate. Contact privacy@vendmetric.com to make a request.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated to account administrators, and the effective date above will be revised.

13. Contact

Questions about this policy can be sent to privacy@vendmetric.com.