Who we are
Vendmint is a platform that lets you generate, maintain and manage online stores with the help of AI. The controller of the personal data described in this policy is Kacper Polak, correspondence address: Dmowskiego 60, 05-270 Marki, Poland.
For anything related to this policy, write to privacy@vendmint.com. We have not appointed a data protection officer; privacy@vendmint.com is the right address for all data-protection matters.
Two roles: controller and processor
Vendmint sits between three parties: us (the platform), you (the merchant building and hosting a store), and your end customers (people shopping in the stores you create). Our role under data-protection law depends on whose data it is.
- For your account data (email, billing, the content you create) we are the controller and decide how it is used. This policy governs that.
- For the personal data of your end customers flowing through your stores and forms, we are a processor acting on your instructions. That relationship is governed by our Data Processing Agreement, not this policy.
What data we collect
| Category | Examples | Our role |
|---|---|---|
| Account | Email, password (stored only as an irreversible hash — we never see your password), account settings | Controller |
| Sessions | Cookies and session identifiers that keep you signed in | Controller |
| Integration keys | Access keys for Shopify, WooCommerce and InPost, API keys for mailing providers (MailerLite, Mailchimp, Brevo) and form-webhook signing secrets (all stored encrypted) | Controller |
| Billing | Paddle customer and subscription IDs, plan, status | Controller |
| Credits | Balance plus a history of balance changes (when and why credits were added or spent) | Controller |
| Store content | Section code, prompts, chat history, saved store styles, the store niche description you provide | Controller |
| Product imports | URLs of imported products and the normalized product content | Controller |
| Version history | Edit and undo events for sections | Controller |
| Generation statistics | AI model used, amount of text processed, our cost of the operation | Controller |
| Media | Files and their WebP / AVIF variants | Controller |
| Custom domains | Domain names and verification status | Controller |
| Push notifications | If you enable notifications: the endpoint address of your browser's push service, the subscription's encryption keys and the device's user agent (to tell your devices apart) | Controller |
| Form submissions | Fields submitted in your stores (may contain customer data); IP addresses stored only as an irreversible hash (SHA-256) | Processor |
| Discount-code registry | When you enable the automatic discount-code email for a form: the end customer's email address the code was sent to, the form name and the send date (prevents sending the code twice) | Processor |
| Store statistics | Visits to your stores: device type, landing page, traffic source and the checkout stages reached. IP addresses are not stored — they only derive a fingerprint of the visit, whose key is random and discarded daily. These statistics use no cookies | Processor |
| Orders in your stores | Order and delivery data of end customers (when you use payments and fulfilment) | Processor |
| Logs and errors | Stack traces and diagnostic logs | Controller |
Where the data comes from
- Directly from you, when you activate your account, build a store or write to us.
- Automatically, from your use of the service (logs, generation statistics).
- From integrations you connect, such as Shopify, WooCommerce, Stripe and InPost.
- From public sources you import product content from (for example AliExpress product pages), only when you run an import yourself.
Why we use it and on what basis
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Providing the service: building, hosting and deploying your stores | Performance of a contract |
| Billing, credits and abuse prevention | Contract and legitimate interest |
| Security, abuse detection and platform stability | Legitimate interest |
| Sending push notifications you enable yourself (for example about a paid order) | Consent (you can withdraw it at any time) |
| Accounting and tax records | Legal obligation |
Administrative access and support
In justified cases — technical support, debugging, verifying an abuse report — platform administrators may access your account and act within it as you would (a support mode). Such a session is restricted to administrators, based on a cryptographically signed cookie, and expires automatically after at most one hour. We do not use this mode to browse your data without a reason.
International transfers
Some subprocessors are based in the United States. When personal data leaves the European Economic Area, we rely on appropriate safeguards: standard contractual clauses and, where applicable, the EU-US Data Privacy Framework. The Subprocessors page shows the transfer mechanism for each provider.
How long we keep it
| Data | Retention |
|---|---|
| Form submissions | Until you delete them or close your account |
| Sent discount-code registry | Until you delete the entry, an end customer's erasure request is fulfilled, or your account is closed |
| Store statistics | 14 months from the visit, then deleted automatically; the key linking one person's visits is discarded daily |
| Push notification subscriptions | Until you disable notifications in the app or your browser, or delete your account; subscriptions that can no longer receive deliveries are removed automatically |
| Version history and chat history | Until you delete the section, page or store, or close your account |
| Account data | Until account deletion; data may persist in database backups for at most 30 more days, after which backups expire automatically |
| Billing and tax records | As required by law (typically 5 years) |
| Logs and diagnostics | Rolling window, then deleted or anonymized |
Your rights
Under the GDPR you have the right to access, rectify, erase, restrict and port your data, as well as the right to object to certain operations and to withdraw consent at any time.
To exercise any of these rights — including a copy (export) of your data or account deletion — write to privacy@vendmint.com and we will take care of it. We respond within one month.
Complaints
If you believe we have mishandled your data, you can lodge a complaint with a supervisory authority. In Poland that is the President of the Personal Data Protection Office (PUODO). We would appreciate the chance to resolve the matter with us first.
Security
The integration keys you entrust to us — access to Shopify, WooCommerce and InPost, API keys for mailing providers (MailerLite, Mailchimp, Brevo) and form-webhook signing secrets — are stored only in encrypted form (AES-256-GCM), IP addresses from form submissions are stored only as an irreversible hash (SHA-256), and all connections are encrypted (TLS). See the Security page for more about our safeguards.
Children
Vendmint is a business tool and is not directed at anyone under 16. We do not knowingly collect children's data.
Automated decisions
We do not make decisions about you with legal or similarly significant effects based solely on automated processing. AI is used to generate store content at your request, not to profile you.
Changes to this policy
For material changes we update the date at the top, and for significant changes we notify you by email or in the app. Continued use after a change means you accept the updated policy.
Related documents
Still have a question?
If anything here is unclear, we would rather explain it than leave you guessing.