VendMetric
Request a demo

Legal

Subprocessors

Effective August 9, 2026

VendMetric uses a small number of third-party providers to operate the platform. Each one is listed below with the data it handles. We update this page before adding a new subprocessor that processes Customer Data.

SubprocessorPurposeData handledLocation
VercelApplication hosting, content delivery, and cookieless traffic analyticsApplication traffic and request logs, and aggregate, cookieless page-view analytics (Vercel Web Analytics) that do not use cookies or identify visitors. Vendor documents are not stored on Vercel.United States
Plausible AnalyticsCookieless, aggregate website analyticsAggregate page views, referrers, and anonymous usage events. No cookies, no cross-site tracking, no data that identifies a visitor.European Union
SupabaseDatabase and encrypted document storageOrganization, user, vendor, and compliance records; uploaded vendor documents.United States (us-east-1)
AnthropicAI document extraction and anomaly review (compliance, contract, and warranty documents)Contents of uploaded vendor documents, processed to extract expiration dates, coverage amounts, and related metadata.United States
ResendTransactional email deliveryRecipient email addresses and the contents of reminder, invitation, and notification emails.United States
CloudmersiveMalware scanning of uploaded filesContents of uploaded files, transmitted for virus and malware analysis before storage. Files are scanned and not retained.United States
SentryApplication error monitoringTechnical details of software errors: the error message and stack trace, the URL and HTTP method of the failing request, and browser or server version information. Configured to exclude personal data: request bodies, cookies, query strings, authorization headers, and captured variables are removed before transmission, and identifiers such as taxpayer identification numbers are redacted. Vendor documents are never sent.United States
StripePayment processing for subscriptions and per-use servicesBilling contact information and payment details for subscription and per-use payments. Stripe collects payment details directly on its own hosted checkout; VendMetric does not receive or store full payment card numbers.United States
CobaltBusiness entity and registration verification, and TIN (taxpayer ID) matchingA vendor's business name and state of registration (for entity checks), or business name and taxpayer identification number (for TIN matching), submitted only when an organization or vendor requests and pays for a verification check.United States
OpenSanctionsSanctions and watchlist screeningA vendor's business name and country, submitted only when an organization or vendor requests and pays for a screening check.United States

Integrated but not enabled

These providers are built into VendMetric but are not switched on. No account is active, no credentials are configured, and no customer data has been sent to any of them. We list them here in advance so this page matches what is in our software, rather than waiting until the day one is turned on. Each moves into the table above, with advance notice, before it processes any customer data.

SubprocessorPurposeData handledLocation
Dropbox SignElectronic signature for contracts (not enabled)Would receive a contract document and the name and email address of each signer. Nothing is sent today: there is no account and the integration runs in simulation only.United States
Tax1099Taxpayer identification number matching (not enabled)Would receive a vendor's business name, taxpayer identification number, and mailing address for an IRS TIN-match check. Not in use: TIN matching is currently performed by Cobalt, listed above.United States
SAM.gov (U.S. General Services Administration)Federal exclusion and debarment screening (not enabled)Would receive a vendor's business name to check the U.S. federal exclusions list at contract award. Not enabled: exclusion checks currently run against simulated data only.United States

A note on AI processing

Document contents are sent to Anthropic solely to extract compliance metadata — expiration dates, coverage amounts, policy numbers, and document type — and, for imported contract documents and warranty documents, the equivalent terms and dates. Extracted values are always presented to a human reviewer in your organization before they affect a compliance record; VendMetric does not act on AI output without human confirmation.

Your documents are not used to train AI models. VendMetric uses Anthropic under its commercial terms, which state that Anthropic does not train its models on customer inputs or outputs. We do not enable any data-sharing option that would change this. Anthropic may retain data transiently for abuse monitoring, consistent with its published policies.

De-identified data and product development. To improve the product, we may use data derived from your account after it has been de-identified and aggregated, so that it no longer identifies you, your organization, or your vendors. That work uses structured fields such as document categories, date and coverage patterns, and score distributions. Your uploaded document files are never used for it, we do not try to re-identify this data, and we do not sell it.

A note on payments

When you or your organization pays for a subscription or an optional per-use service, Stripe collects your payment details directly on its own hosted checkout page. VendMetric never receives or stores your full payment card number. We receive limited billing metadata, such as your subscription plan and status, to operate your account.

A note on verification checks

Business entity, TIN-match, and sanctions/watchlist verification checks are optional and priced before you run them; nothing is sent to Cobalt or OpenSanctions unless an organization or vendor specifically requests and pays for a check. Results are evidence for a person to review, never an automated decision, and never affect the Vendor Intelligence Score (VIS™).

A note on error monitoring

When something breaks, our error monitoring provider receives the technical details needed to diagnose it: the error message, the stack trace, and the address of the failing request. It is deliberately configured not to receive personal data. Request bodies, cookies, query strings, authorization headers, and captured program variables are stripped before anything is sent, and identifiers such as taxpayer identification numbers are redacted wherever they might appear. Vendor documents are never transmitted.

Notification of changes

Customers who would like advance notice of subprocessor changes can request it at privacy@vendmetric.com.

See also our Privacy Policy, Terms of Service, and security posture.