← Back to VendorLens
Privacy Policy
Effective date: July 20, 2026 · Last updated: July 20, 2026
Larraondo Labs LLC, a Florida limited liability company doing business as
VendorLens (“we,” “us”), is the controller responsible for the personal data described in
this policy. VendorLens provides a vendor pre-screening web application. In short: we
collect the minimum needed to run your account and searches, we do not sell your
data, and the vendor information we show comes from public sources and authoritative
registries. AI processing is optional and limited to the structured findings.
What we don’t collect. VendorLens screens only publicly
available information about vendors. We don’t ask for or store sensitive personal
data (no Social Security or government ID numbers, financial-account numbers, or health
data), we don’t connect to your bank or your internal systems, and full
payment-card details are handled by Stripe — never stored by us.
1. Information we collect
- Account & identity: name, work email, and organization. We sign you in with a one-time email link (magic link); we do not ask you to create a password.
- Your searches: vendor names/domains and industry you enter, and the comparisons/RFPs you generate.
- Vendor research data: publicly available information about the third-party vendors you search, from each vendor’s own website and authoritative public sources. Primarily company/product data; news or legal results may mention individuals and are shown as “verify” items with their source.
- Usage & device data: log data, IP, browser, feature usage, used for security, rate-limiting, debugging, and analytics.
- Billing data: handled by our payment processor; we do not store full card numbers. For team plans we store the company email domain you provide at checkout, so everyone at that domain gets covered by the plan.
2. How we use it
To provide and secure the service; authenticate you and enforce plan limits; generate pre-screens and RFPs; prevent abuse; comply with law; and improve the product (aggregated/de-identified where feasible).
3. Legal bases (GDPR)
Contract, legitimate interests (security, abuse prevention, product improvement), consent (where required), and legal obligation.
4. Sub-processors & data sources
- Hosting/edge & database: Cloudflare. Payments: Stripe. Sign-in email: our transactional email provider (sends your one-time login link only).
- Optional AI: Anthropic receives only the structured findings to rewrite wording; not your credentials; not used to train models under our terms.
- Public research sources (about searched vendors, not about you): the vendor’s own website, FedRAMP Marketplace, CSA STAR, GovRAMP, Common Criteria portal, the Visa Global Registry of Service Providers, openFDA, CourtListener, Have I Been Pwned, CISA KEV, Google News, GLEIF (legal-entity index), SEC EDGAR, Wikidata, domain registries (RDAP), public DNS records, the U.S. Consolidated Screening List (trade.gov), the UN Security Council, UK OFSI and EU consolidated sanctions lists (we keep a weekly copy of each), government cloud-program lists (such as ISMAP and ANSSI SecNumCloud), and similar. Federal-contract pricing (USAspending.gov) is looked up directly from your browser.
A current sub-processor list is available on request and for Team/Enterprise via the DPA.
5. Sharing
We do not sell personal information. We share only with the processors above, for legal/safety reasons, or in a corporate transaction (with notice). Vendor results are shown only to you and your organization’s authorized users.
6. Retention
Account data: life of your account plus a limited legal window. Searches/comparisons: until you delete them or close your account. Logs: a limited rolling window.
7. Your rights
Subject to your location (GDPR/UK GDPR/CCPA/CPRA and others): access, correction, deletion, portability, restriction/objection, and to opt out of “sale”/“sharing” (we do neither). Contact us at hello@getvendorlens.com to exercise these; we verify identity. No discrimination for exercising rights.
8. Security
Encryption in transit; least-privilege access; passwordless email sign-in (no stored passwords);
rate-limiting; SSRF protections on all outbound fetches. Single sign-on (SSO) and MFA are available on
request for Team/Enterprise. No method is 100% secure; report issues below.
9. Cookies
Strictly-necessary cookies for authentication/security, and (with consent where required) analytics.
10. Children
Not directed to children under 16; we do not knowingly collect their data.
11. International transfers, changes & contact
Data may be processed in the US and other countries with appropriate safeguards (e.g., SCCs). We post changes here with an updated date. Questions, privacy requests, or security reports: hello@getvendorlens.com.
Controller and contact details:
Larraondo Labs LLC d/b/a VendorLens
St. Cloud, Florida, USA
hello@getvendorlens.com
Accuracy note: VendorLens pre-screens are informational, drawn from public sources, and are not a certification, recommendation, or security assessment. Verify findings before relying on them.