Privacy Policy
Last updated: June 8, 2026
At Vendor Ghosted, we are committed to protecting your privacy. This Privacy Policy describes how we collect, use, and safeguard your personal information when you use our invoice follow-up service.
1. Information We Collect
To deliver our services, we collect information that you explicitly provide, as well as data from connected platforms:
- Account Information: When you register via Clerk, we receive your email address, identifier, and billing records.
- Google API & Gmail Data: When you authorize your Google account via OAuth 2.0, we store encrypted tokens to interact with the Gmail API on your behalf. We access email threads strictly within the context of followed-up invoices to detect client replies and prevent subsequent chasers.
- Invoice Records: We store invoice records you import or forward, including client names, client emails, balances, currencies, and due dates.
- Writing Tone Samples: We store sample emails you provide to guide our synthesis engine in matching your communication style.
2. How We Use Information
We use the data collected strictly for the following operational objectives:
- To synthesize and schedule personalized follow-up sequences.
- To send authenticated replies directly from your Google Workspace address.
- To detect inbound responses from clients and halt pending queue jobs.
- To process subscription billing via Stripe.
- To maintain system reliability and integrity.
3. Data Sharing and Subprocessors
We do not sell, license, or monetize your personal data. Data is shared exclusively with verified infrastructure partners required to operate the application:
- Clerk: Authentication, session handling, and identity infrastructure.
- Stripe: Payment processing and subscription management. Payment credentials are handled directly by Stripe.
- Cloud AI Infrastructure: Enterprise models deployed via Azure OpenAI to synthesize style drafts. Your email data is processed in stateless sessions and is never used to train public foundation models.
- Cloud Database & Hosting: Managed PostgreSQL and caching systems with encryption at rest and in transit.
4. Google API User Data Policy Compliance
Vendor Ghosted's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use your Gmail data for advertising or marketing profiling.
5. Security Controls
All sensitive credentials and Google OAuth refresh tokens are encrypted at rest using industry-standard AES-256-GCM encryption. All traffic between your browser, our servers, and third-party APIs is enforced over TLS 1.3 encryption.
6. Data Retention and Account Deletion
You retain full ownership of your data. You may disconnect Google Workspace at any time in your Settings panel, which permanently revokes and wipes your stored OAuth tokens. Upon account termination, all active records, drafts, and invoices are permanently deleted from our active database.