← Back to VendorLens

Privacy Policy

Effective date: July 20, 2026 · Last updated: July 20, 2026

Larraondo Labs LLC, a Florida limited liability company doing business as VendorLens (“we,” “us”), is the controller responsible for the personal data described in this policy. VendorLens provides a vendor pre-screening web application. In short: we collect the minimum needed to run your account and searches, we do not sell your data, and the vendor information we show comes from public sources and authoritative registries. AI processing is optional and limited to the structured findings.

What we don’t collect. VendorLens screens only publicly available information about vendors. We don’t ask for or store sensitive personal data (no Social Security or government ID numbers, financial-account numbers, or health data), we don’t connect to your bank or your internal systems, and full payment-card details are handled by Stripe — never stored by us.

1. Information we collect

2. How we use it

To provide and secure the service; authenticate you and enforce plan limits; generate pre-screens and RFPs; prevent abuse; comply with law; and improve the product (aggregated/de-identified where feasible).

3. Legal bases (GDPR)

Contract, legitimate interests (security, abuse prevention, product improvement), consent (where required), and legal obligation.

4. Sub-processors & data sources

A current sub-processor list is available on request and for Team/Enterprise via the DPA.

5. Sharing

We do not sell personal information. We share only with the processors above, for legal/safety reasons, or in a corporate transaction (with notice). Vendor results are shown only to you and your organization’s authorized users.

6. Retention

Account data: life of your account plus a limited legal window. Searches/comparisons: until you delete them or close your account. Logs: a limited rolling window.

7. Your rights

Subject to your location (GDPR/UK GDPR/CCPA/CPRA and others): access, correction, deletion, portability, restriction/objection, and to opt out of “sale”/“sharing” (we do neither). Contact us at hello@getvendorlens.com to exercise these; we verify identity. No discrimination for exercising rights.

8. Security

Encryption in transit; least-privilege access; passwordless email sign-in (no stored passwords); rate-limiting; SSRF protections on all outbound fetches. Single sign-on (SSO) and MFA are available on request for Team/Enterprise. No method is 100% secure; report issues below.

9. Cookies

Strictly-necessary cookies for authentication/security, and (with consent where required) analytics.

10. Children

Not directed to children under 16; we do not knowingly collect their data.

11. International transfers, changes & contact

Data may be processed in the US and other countries with appropriate safeguards (e.g., SCCs). We post changes here with an updated date. Questions, privacy requests, or security reports: hello@getvendorlens.com.

Controller and contact details:
Larraondo Labs LLC d/b/a VendorLens
St. Cloud, Florida, USA
hello@getvendorlens.com

Accuracy note: VendorLens pre-screens are informational, drawn from public sources, and are not a certification, recommendation, or security assessment. Verify findings before relying on them.