Effective Date: April 2026 · Last Updated: April 9, 2026
Welcome to Vedex. This Privacy Policy explains how Vedex Inc. ("Vedex," "we," "us," or "our") collects, uses, discloses, and protects your personal information when you access or use our alternative data vendor intelligence platform available at vedex.io, including all associated APIs, dashboards, mobile experiences, and related services (collectively, the "Service").
Vedex provides a research and intelligence platform that enables professionals to discover, evaluate, and compare alternative data vendors across categories such as geolocation, satellite imagery, transaction data, web-scraped datasets, and more. Our Service aggregates publicly available information, user-contributed reviews, and proprietary enrichment data to create comprehensive vendor profiles.
By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with any part of this Privacy Policy, you should discontinue use of the Service immediately. This Privacy Policy applies to all users of the Service, including visitors who do not create an account, registered users, and enterprise clients.
We are committed to transparency regarding our data practices. This policy is designed to comply with applicable data protection laws, including the European Union General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and other relevant privacy legislation. Where a specific jurisdiction grants you additional rights, those rights are detailed in the relevant sections below.
Account Information. When you register for a Vedex account, we collect your full name, email address, organization or company name, job title, and password (stored in hashed form). If you sign in via a third-party authentication provider (such as Google or GitHub), we receive your name, email address, and profile image from that provider. You may optionally provide additional profile details such as your department, phone number, or LinkedIn URL.
Usage Data. We automatically collect information about how you interact with the Service. This includes the pages and vendor profiles you view, search queries you perform, filters you apply, vendors you add to watchlists or comparison boards, features you access, and the dates and times of your interactions. We record navigation paths, session durations, and interaction patterns such as clicks, scrolls, and hover events to understand how users engage with the platform.
Technical Data. When you access the Service, we automatically collect your IP address, browser type and version, operating system, device type, screen resolution, preferred language, time zone, and referring URL. We also collect device identifiers and may use browser fingerprinting techniques strictly for fraud prevention and security purposes.
Watchlist and Research Data. If you create watchlists, save vendor comparisons, bookmark vendor profiles, add notes, or build custom dashboards, we store this data in association with your account. This includes any tags, annotations, or ratings you assign to vendors. Research queries submitted to our agentic search system are logged to improve result quality and may be retained in anonymized form for model training.
Communication Data. When you contact our support team, submit feedback, respond to surveys, or participate in user research sessions, we collect the content of those communications along with associated metadata such as timestamps and communication channel. If you subscribe to newsletters or product updates, we store your email address and communication preferences.
API Usage Data. If you access the Service through our API, we collect API key identifiers, request endpoints, query parameters, request and response payloads (excluding sensitive credential fields), timestamps, response times, error codes, and rate limit consumption. This data is used for billing, rate limiting, debugging, and service optimization.
Cookie and Tracking Data. We use cookies and similar technologies to collect information as described in Section 4 of this policy. This includes session identifiers, authentication tokens, preference settings, and analytics data.
Providing and Operating the Service. We use your information to create and maintain your account, authenticate your sessions, deliver the features you request, display vendor profiles and search results, maintain your watchlists and saved research, and provide customer support. This processing is necessary for the performance of our contract with you.
Improving and Developing the Service. We analyze aggregated and anonymized usage patterns to understand which features are most valuable, identify usability issues, prioritize product development, and measure the effectiveness of new features. We may use anonymized search queries and research patterns to improve our vendor data enrichment pipelines and recommendation algorithms.
Personalization. We use your usage history, watchlists, and stated preferences to personalize your experience, including recommending relevant vendors, surfacing recently viewed profiles, tailoring search result rankings, and customizing dashboard layouts. You can control personalization through your account settings.
Payments and Billing. If you subscribe to a paid plan or purchase premium features, we use your information to process transactions, manage subscriptions, send invoices, and handle billing inquiries. Payment card details are processed directly by our payment processor and are never stored on our servers.
Service Communications. We send you transactional emails related to your account, including registration confirmations, password reset requests, subscription changes, security alerts, and important service updates. These communications are essential to the operation of the Service and cannot be opted out of while you maintain an active account.
Marketing Communications. With your consent, we may send you newsletters, product announcements, feature highlights, and promotional offers. You can opt out of marketing communications at any time by clicking the unsubscribe link in any marketing email, or by adjusting your notification preferences in your account settings. We will never condition access to core Service features on your consent to marketing communications.
Analytics and Research. We use analytics tools to measure platform performance, generate internal reports on usage trends, and conduct market research. Analytics data is aggregated and anonymized wherever possible. We may publish aggregated, non-identifying statistics about alternative data market trends derived from platform usage patterns.
Security and Fraud Prevention. We process technical data, access logs, and behavioral signals to detect and prevent unauthorized access, abuse, scraping, account takeover attempts, and other fraudulent or malicious activity. This processing is necessary for our legitimate interest in maintaining the security and integrity of the Service.
Legal Compliance. We may process your information as necessary to comply with applicable laws, regulations, legal processes, or enforceable governmental requests, to enforce our Terms of Service, or to protect the rights, property, or safety of Vedex, our users, or the public.
We Do Not Sell Your Personal Information. Vedex does not sell, rent, or trade your personal information to third parties for their own commercial purposes. We have never sold personal information and have no plans to do so. This commitment applies to all categories of personal data we collect.
Service Providers. We share personal information with a limited number of trusted third-party service providers who process data on our behalf under strict contractual obligations. These providers include: Vercel (hosting, edge network delivery, and serverless compute); Supabase (database hosting, authentication, and real-time data services); PostHog (product analytics and session replay); Stripe (payment processing and subscription management); and email delivery services for transactional and marketing communications. Each provider is contractually required to process your data only as necessary to provide services to Vedex and in accordance with this Privacy Policy.
Legal Requirements. We may disclose your information if we believe in good faith that such disclosure is necessary to: (a) comply with applicable law, regulation, legal process, or enforceable governmental request; (b) enforce our Terms of Service, including investigation of potential violations; (c) detect, prevent, or address fraud, security, or technical issues; or (d) protect the rights, property, or safety of Vedex, our users, or the public as required or permitted by law. Where legally permitted, we will notify you of such requests.
Business Transfers. If Vedex is involved in a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of its assets, your personal information may be transferred as part of that transaction. In such an event, we will notify you via email and/or a prominent notice on the Service of any change in ownership or use of your personal information, as well as any choices you may have regarding your information.
Aggregated and De-identified Data. We may share aggregated, anonymized, or de-identified information that cannot reasonably be used to identify you with third parties for research, industry analysis, benchmarking, and market reporting purposes. For example, we may publish reports on alternative data market trends that include aggregate statistics derived from platform activity.
We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements. Our specific retention periods are as follows:
Account Data. We retain your account information (name, email, profile details, preferences) for the duration of your active account. If you request account deletion, we will delete or anonymize your personal data within 30 calendar days of your request, except where retention is required by law (for example, billing records may be retained for tax compliance). During the 30-day deletion window, your account will be deactivated and inaccessible.
Analytics Data. Event-level analytics data is aggregated into anonymized statistical summaries within 12 months of collection. Raw, identifiable analytics data is permanently deleted within 24 months. Aggregated statistical data that cannot identify individual users may be retained indefinitely for trend analysis and product improvement.
API Logs. Detailed API request and response logs are retained for 90 days to support debugging, abuse detection, and billing verification. After 90 days, logs are either deleted or reduced to aggregated usage metrics (total request counts, error rates, latency distributions) that do not contain identifiable information.
Communication Records. Support tickets and associated correspondence are retained for 24 months after resolution to enable follow-up support and quality assurance. Survey responses and feedback data are retained for 36 months in anonymized form.
Security Logs. Authentication events, access logs, and security incident records are retained for 12 months to support security investigations and compliance audits. These logs may be retained longer if they are relevant to an ongoing investigation.
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) and equivalent local legislation provide you with specific rights regarding your personal data. Vedex acts as the data controller for the personal data we collect through the Service. Our lawful bases for processing include: performance of a contract (to provide the Service), legitimate interests (security, fraud prevention, service improvement), consent (marketing communications, non-essential cookies), and legal obligation (compliance with applicable laws).
Right of Access. You have the right to request a copy of the personal data we hold about you. We will provide this information in a structured, commonly used, and machine-readable format (JSON or CSV) within 30 days of your verified request. You may submit one free access request per 12-month period; additional requests may be subject to a reasonable administrative fee.
Right to Rectification. You have the right to request correction of inaccurate personal data or completion of incomplete personal data. You can update most account information directly through your account settings. For data that cannot be self-edited, contact us and we will make corrections within 30 days.
Right to Erasure. You have the right to request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, you withdraw consent, you object to processing and there are no overriding legitimate grounds, or the data has been unlawfully processed. Certain data may be exempt from erasure where retention is required for legal compliance, exercise of legal claims, or public interest.
Right to Restrict Processing. You have the right to request restriction of processing in certain circumstances, including when you contest the accuracy of your data, when processing is unlawful but you prefer restriction over erasure, when we no longer need the data but you need it for legal claims, or when you have objected to processing pending verification.
Right to Data Portability. You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller without hindrance. This right applies to data you have provided to us, processed on the basis of consent or contract, and carried out by automated means.
Right to Object. You have the right to object to processing of your personal data based on our legitimate interests. Upon receiving your objection, we will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms. You have an absolute right to object to direct marketing at any time.
Right to Withdraw Consent. Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing conducted prior to withdrawal. You can withdraw consent for marketing communications via the unsubscribe link, and for cookies via the cookie settings panel.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) provides you with specific rights regarding your personal information. This section describes those rights and how to exercise them. For purposes of this section, "personal information" has the meaning defined in the CCPA/CPRA.
Right to Know. You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you in the preceding 12 months, the categories of sources from which we collected that information, the business or commercial purpose for collecting it, and the categories of third parties with whom we shared it. You may submit a verifiable consumer request up to two times in a 12-month period.
Right to Delete. You have the right to request deletion of personal information we have collected from you, subject to certain exceptions. We may deny your deletion request if retaining the information is necessary for us or our service providers to complete a transaction, provide the Service, detect security incidents, comply with a legal obligation, or engage in research in the public interest.
Right to Opt-Out of Sale or Sharing. Vedex does not sell your personal information as defined by the CCPA/CPRA. We do not share your personal information for cross-context behavioral advertising purposes. Because we do not engage in these activities, there is no need for a "Do Not Sell or Share My Personal Information" opt-out mechanism; however, we respect the Global Privacy Control (GPC) signal as a valid opt-out preference where applicable.
Right to Correct. You have the right to request correction of inaccurate personal information that we maintain about you. You can correct most information directly through your account settings, or you can submit a request to us.
Right to Non-Discrimination. We will not discriminate against you for exercising any of your CCPA/CPRA rights. We will not deny you the Service, charge different prices or rates, provide a different level or quality of service, or suggest that you will receive any of these as a result of exercising your rights.
Authorized Agents. You may designate an authorized agent to submit requests on your behalf. To do so, you must provide the agent with written permission signed by you, and we may require you to verify your own identity directly with us and confirm that you provided the agent with permission to submit the request.
To exercise your CCPA/CPRA rights, please contact us at [email protected]. We will verify your identity before processing your request by matching information you provide against our existing records. We will respond to verifiable consumer requests within 45 calendar days of receipt, with the possibility of a 45-day extension if reasonably necessary.
Vedex is headquartered in the United States, and our primary data processing facilities are located in the United States. When you use the Service, your personal data may be transferred to, stored in, and processed in the United States and other countries where our service providers operate. These countries may have data protection laws that differ from the laws of your jurisdiction.
Transfers from the EEA, UK, and Switzerland. When we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland to the United States or other countries that have not received an adequacy decision from the European Commission or UK Secretary of State, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission (Commission Implementing Decision (EU) 2021/914) as our primary transfer mechanism. We have executed SCCs with all relevant sub-processors that receive EEA personal data.
Adequacy Decisions. Where the European Commission or other relevant authority has issued an adequacy decision for a recipient country, we may rely on that adequacy decision as a lawful transfer mechanism. We monitor changes to adequacy decisions and update our transfer mechanisms accordingly.
Supplementary Measures. In addition to SCCs, we implement supplementary technical and organizational measures to protect transferred data, including encryption in transit and at rest, pseudonymization where feasible, access controls limited to personnel who require access for service delivery, and contractual obligations prohibiting sub-processors from accessing data beyond what is necessary for service provision. We conduct transfer impact assessments to evaluate the legal landscape in recipient countries.
You may request a copy of our Standard Contractual Clauses by contacting us at [email protected].
We take the security of your personal information seriously and implement appropriate technical and organizational measures designed to protect it against unauthorized access, alteration, disclosure, or destruction. While no system can guarantee absolute security, we strive to use commercially reasonable measures that meet or exceed industry standards.
Encryption. All data transmitted between your browser and our servers is encrypted using TLS 1.3 with strong cipher suites. Data at rest, including database contents and backups, is encrypted using AES-256 encryption. API keys and authentication tokens are stored using one-way cryptographic hashing with unique salts. Encryption keys are managed through dedicated key management infrastructure with automatic rotation.
Access Controls. Access to personal data is restricted to authorized personnel who require it for their job functions. We enforce the principle of least privilege across all systems. Employee access to production systems requires multi-factor authentication and is logged and audited. We conduct regular access reviews to ensure permissions remain appropriate.
Security Assessments. We conduct regular security assessments, including vulnerability scanning, dependency auditing, and code review processes. Our infrastructure is monitored continuously for suspicious activity, and we maintain intrusion detection capabilities across our production environment.
Incident Response. We maintain a documented incident response plan that includes procedures for identifying, containing, investigating, and remediating security incidents. In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected individuals and relevant supervisory authorities in accordance with applicable law, including within 72 hours for GDPR reportable breaches.
Compliance Goals. Vedex is actively working toward SOC 2 Type II certification to provide independent assurance of our security controls. We continuously evaluate and improve our security posture in response to evolving threats and industry best practices.
The Service is designed for use by business professionals and is not directed at, marketed to, or intended for use by children under the age of 16. We do not knowingly collect personal information from children under 16 years of age. We have implemented account registration processes that are designed for professional users and do not target minors.
If we become aware that we have inadvertently collected personal information from a child under 16, we will take immediate steps to delete that information from our systems. If you are a parent or guardian and believe your child under 16 has provided personal information to Vedex, please contact us at [email protected] so we can promptly delete the information.
In jurisdictions where the age of digital consent is higher than 16, we comply with the applicable local age threshold. We do not condition participation in any activity on the collection of more personal information than is reasonably necessary for that activity.
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or business operations. When we make changes, we will revise the "Last Updated" date at the top of this policy.
Material Changes. For material changes that significantly affect your rights or how we process your personal information, we will provide at least 30 days' advance notice before the changes take effect. Notice will be provided via email to the address associated with your account and through a prominent notification on the Service (such as a banner or in-app notification). Material changes include, but are not limited to: new categories of personal information collected, new purposes for data processing, changes to data sharing practices, and changes to your rights or how to exercise them.
Non-Material Changes. For non-material changes such as clarifications, formatting updates, or minor wording adjustments that do not substantively alter our data practices, we may update this policy without prior notice. We encourage you to review this policy periodically.
Your continued use of the Service after the effective date of any updated Privacy Policy constitutes your acceptance of the revised policy. If you do not agree with the changes, you should discontinue use of the Service and request deletion of your account.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us using the information below. We aim to respond to all inquiries within 5 business days.
If you are located in the EEA and have concerns about our data processing practices that we are unable to resolve, you have the right to lodge a complaint with your local data protection supervisory authority. A list of EEA supervisory authorities is available at edpb.europa.eu.
If you are a California resident, you may also contact the California Attorney General's office for information about your rights under the CCPA/CPRA.
This Privacy Policy is effective as of April 1, 2026. This policy supersedes all prior versions of our privacy policy. The terms of this policy apply to all information collected by the Service on or after the effective date.
For information about how we handled personal data prior to this effective date, please refer to the archived versions of our privacy policy, which are available upon request by contacting [email protected].