Back to home

Legal

Privacy Policy

How Vendmint collects, uses and protects personal data, on what legal bases, who we share it with, and the rights you have under the GDPR.

Last updated: July 16, 2026

On this page

Who we are

Vendmint is a platform that lets you generate, maintain and manage online stores with the help of AI. The controller of the personal data described in this policy is Kacper Polak, correspondence address: Dmowskiego 60, 05-270 Marki, Poland.

For anything related to this policy, write to privacy@vendmint.com. We have not appointed a data protection officer; privacy@vendmint.com is the right address for all data-protection matters.

Two roles: controller and processor

Vendmint sits between three parties: us (the platform), you (the merchant building and hosting a store), and your end customers (people shopping in the stores you create). Our role under data-protection law depends on whose data it is.

  • For your account data (email, billing, the content you create) we are the controller and decide how it is used. This policy governs that.
  • For the personal data of your end customers flowing through your stores and forms, we are a processor acting on your instructions. That relationship is governed by our Data Processing Agreement, not this policy.

What data we collect

CategoryExamplesOur role
AccountEmail, password (stored only as an irreversible hash — we never see your password), account settingsController
SessionsCookies and session identifiers that keep you signed inController
Integration keysAccess keys for Shopify, WooCommerce and InPost, API keys for mailing providers (MailerLite, Mailchimp, Brevo) and form-webhook signing secrets (all stored encrypted)Controller
BillingPaddle customer and subscription IDs, plan, statusController
CreditsBalance plus a history of balance changes (when and why credits were added or spent)Controller
Store contentSection code, prompts, chat history, saved store styles, the store niche description you provideController
Product importsURLs of imported products and the normalized product contentController
Version historyEdit and undo events for sectionsController
Generation statisticsAI model used, amount of text processed, our cost of the operationController
MediaFiles and their WebP / AVIF variantsController
Custom domainsDomain names and verification statusController
Push notificationsIf you enable notifications: the endpoint address of your browser's push service, the subscription's encryption keys and the device's user agent (to tell your devices apart)Controller
Form submissionsFields submitted in your stores (may contain customer data); IP addresses stored only as an irreversible hash (SHA-256)Processor
Discount-code registryWhen you enable the automatic discount-code email for a form: the end customer's email address the code was sent to, the form name and the send date (prevents sending the code twice)Processor
Store statisticsVisits to your stores: device type, landing page, traffic source and the checkout stages reached. IP addresses are not stored — they only derive a fingerprint of the visit, whose key is random and discarded daily. These statistics use no cookiesProcessor
Orders in your storesOrder and delivery data of end customers (when you use payments and fulfilment)Processor
Logs and errorsStack traces and diagnostic logsController

Where the data comes from

  • Directly from you, when you activate your account, build a store or write to us.
  • Automatically, from your use of the service (logs, generation statistics).
  • From integrations you connect, such as Shopify, WooCommerce, Stripe and InPost.
  • From public sources you import product content from (for example AliExpress product pages), only when you run an import yourself.

Why we use it and on what basis

PurposeLegal basis (Art. 6 GDPR)
Providing the service: building, hosting and deploying your storesPerformance of a contract
Billing, credits and abuse preventionContract and legitimate interest
Security, abuse detection and platform stabilityLegitimate interest
Sending push notifications you enable yourself (for example about a paid order)Consent (you can withdraw it at any time)
Accounting and tax recordsLegal obligation

Administrative access and support

In justified cases — technical support, debugging, verifying an abuse report — platform administrators may access your account and act within it as you would (a support mode). Such a session is restricted to administrators, based on a cryptographically signed cookie, and expires automatically after at most one hour. We do not use this mode to browse your data without a reason.

Who we share data with

We use a small, vetted set of subprocessors to run the service (hosting, AI generation, payments, email, storage, monitoring). The full, maintained list with each provider's processing scope and location is on the Subprocessors page.

If you enable push notifications, the technical delivery is performed by your browser's push service (for example Google, Mozilla or Apple — depending on the browser you enable them in). The notification content is encrypted with your subscription's keys, so the push service provider cannot read it.

International transfers

Some subprocessors are based in the United States. When personal data leaves the European Economic Area, we rely on appropriate safeguards: standard contractual clauses and, where applicable, the EU-US Data Privacy Framework. The Subprocessors page shows the transfer mechanism for each provider.

How long we keep it

DataRetention
Form submissionsUntil you delete them or close your account
Sent discount-code registryUntil you delete the entry, an end customer's erasure request is fulfilled, or your account is closed
Store statistics14 months from the visit, then deleted automatically; the key linking one person's visits is discarded daily
Push notification subscriptionsUntil you disable notifications in the app or your browser, or delete your account; subscriptions that can no longer receive deliveries are removed automatically
Version history and chat historyUntil you delete the section, page or store, or close your account
Account dataUntil account deletion; data may persist in database backups for at most 30 more days, after which backups expire automatically
Billing and tax recordsAs required by law (typically 5 years)
Logs and diagnosticsRolling window, then deleted or anonymized

Your rights

Under the GDPR you have the right to access, rectify, erase, restrict and port your data, as well as the right to object to certain operations and to withdraw consent at any time.

To exercise any of these rights — including a copy (export) of your data or account deletion — write to privacy@vendmint.com and we will take care of it. We respond within one month.

Complaints

If you believe we have mishandled your data, you can lodge a complaint with a supervisory authority. In Poland that is the President of the Personal Data Protection Office (PUODO). We would appreciate the chance to resolve the matter with us first.

Cookies and tracking

We use only essential cookies (session, language and — only during a support session — the support-mode cookie). We use no analytics or marketing cookies. Full details, including the cookie table, are in the Cookie Policy.

Security

The integration keys you entrust to us — access to Shopify, WooCommerce and InPost, API keys for mailing providers (MailerLite, Mailchimp, Brevo) and form-webhook signing secrets — are stored only in encrypted form (AES-256-GCM), IP addresses from form submissions are stored only as an irreversible hash (SHA-256), and all connections are encrypted (TLS). See the Security page for more about our safeguards.

Children

Vendmint is a business tool and is not directed at anyone under 16. We do not knowingly collect children's data.

Automated decisions

We do not make decisions about you with legal or similarly significant effects based solely on automated processing. AI is used to generate store content at your request, not to profile you.

Changes to this policy

For material changes we update the date at the top, and for significant changes we notify you by email or in the app. Continued use after a change means you accept the updated policy.

Still have a question?

If anything here is unclear, we would rather explain it than leave you guessing.

Contact us