vendorghosted
Sign in Get Started

Privacy Policy

Last updated: June 8, 2026

At Vendor Ghosted, we are committed to protecting your privacy. This Privacy Policy describes how we collect, use, and safeguard your personal information when you use our invoice follow-up service.

1. Information We Collect

To deliver our services, we collect information that you explicitly provide, as well as data from connected platforms:

  • Account Information: When you register via Clerk, we receive your email address, identifier, and billing records.
  • Google API & Gmail Data: When you authorize your Google account via OAuth 2.0, we store encrypted tokens to interact with the Gmail API on your behalf. We access email threads strictly within the context of followed-up invoices to detect client replies and prevent subsequent chasers.
  • Invoice Records: We store invoice records you import or forward, including client names, client emails, balances, currencies, and due dates.
  • Writing Tone Samples: We store sample emails you provide to guide our synthesis engine in matching your communication style.

2. How We Use Information

We use the data collected strictly for the following operational objectives:

  • To synthesize and schedule personalized follow-up sequences.
  • To send authenticated replies directly from your Google Workspace address.
  • To detect inbound responses from clients and halt pending queue jobs.
  • To process subscription billing via Stripe.
  • To maintain system reliability and integrity.

3. Data Sharing and Subprocessors

We do not sell, license, or monetize your personal data. Data is shared exclusively with verified infrastructure partners required to operate the application:

  • Clerk: Authentication, session handling, and identity infrastructure.
  • Stripe: Payment processing and subscription management. Payment credentials are handled directly by Stripe.
  • Cloud AI Infrastructure: Enterprise models deployed via Azure OpenAI to synthesize style drafts. Your email data is processed in stateless sessions and is never used to train public foundation models.
  • Cloud Database & Hosting: Managed PostgreSQL and caching systems with encryption at rest and in transit.

4. Google API User Data Policy Compliance

Vendor Ghosted's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use your Gmail data for advertising or marketing profiling.

5. Security Controls

All sensitive credentials and Google OAuth refresh tokens are encrypted at rest using industry-standard AES-256-GCM encryption. All traffic between your browser, our servers, and third-party APIs is enforced over TLS 1.3 encryption.

6. Data Retention and Account Deletion

You retain full ownership of your data. You may disconnect Google Workspace at any time in your Settings panel, which permanently revokes and wipes your stored OAuth tokens. Upon account termination, all active records, drafts, and invoices are permanently deleted from our active database.

Privacy Inquiries

For questions or privacy requests, contact our compliance team directly at:

privacy@vendorghosted.com

© 2026 Vendor Ghosted. Built for freelancers and independent agencies.

Home  ·  Terms  ·  support@vendorghosted.com