Legal

Privacy Policy

Effective Date:

We built Vendoors to keep company and vendor information in one controlled place. This Policy explains what personal information is involved, how we use it, and the choices you have.

1. Who We Are and Scope

Vendoors (the “Service”) is a business-to-business vendor management platform developed and operated by Winnovate Technologies (“Winnovate”, “we”, “us”, or “our”). This Privacy Policy explains how we handle personal information when you visit vendoors.tech, request a demo, or use the Service as a member of a subscribing company’s staff (“Client”) or as one of its vendors.

This Policy should be read together with our Terms and Conditions.

2. Our Role: Processor and Controller

  • On behalf of Clients (processor): Each Client operates its own isolated workspace. The vendor records, documents, invoices, RFQs, approvals and staff details in that workspace (“Client Data”) are controlled by the Client. We process Client Data only to provide the Service under the Client’s instructions. If you are a vendor or staff member with questions about how a particular company uses your information, please contact that company first.
  • For our own purposes (controller): We are responsible for the limited information we collect directly — website enquiries, demo requests, account sign-in and security data, and billing contacts for subscribing companies.

3. Information We Collect

  • Demo and contact requests: full name, work email, phone number, job title, company name, company size, country, and any message you choose to send.
  • Account information: name, email address, role, division and department, and the permissions assigned to you by your company administrator. Sign-in uses one-time codes sent to your email address — we do not store passwords.
  • Vendor information: company details, contact persons, areas of expertise, trade licence, tax and insurance details, and compliance documents that vendors upload during registration or later updates.
  • Operational records: invoices, purchase orders, RFQ submissions, quotations, payment status and proof-of-payment documents, approval decisions, comments and ratings entered in the Service.
  • Audit and email logs: a record of significant actions (who did what, and when) and of the notification emails the Service sends, kept so Clients can demonstrate accountability.
  • Technical data: IP address, browser and device information, and request logs needed to operate, secure and troubleshoot the Service.

The Service is not designed to collect sensitive categories of personal information (such as health or biometric data), and we ask Clients and vendors not to upload such data unless strictly required.

4. How We Use Information

We use personal information only to:

  • Provide, maintain and secure the Service and each Client’s workspace;
  • Authenticate users and protect against fraud, abuse and automated attacks;
  • Send workflow notifications — for example, when an approval is your turn or a status changes;
  • Respond to demo requests, enquiries and support tickets;
  • Administer subscriptions and communicate with Clients about their account;
  • Diagnose technical issues and monitor the performance of the platform; and
  • Comply with legal obligations.

We do not sell personal information, use Client Data for advertising, or mine Client Data for our own commercial purposes. Winnovate personnel do not open or view Client Data except when the Client explicitly authorises it to resolve an issue or implement a requested change.

5. How Information Is Shared

  • Within a workspace: information is visible to the Client’s staff according to the roles and permissions the Client configures. Vendors see only the information relevant to their own relationship with that Client.
  • Between companies: a vendor working with several companies has a separate relationship with each. One Client cannot see another Client’s data, or a vendor’s dealings with another Client.
  • Service providers: we rely on a small number of vetted providers who process data on our behalf under contractual confidentiality and security obligations — cloud hosting, database and file storage, transactional email delivery, and bot protection.
  • Legal requirements: we may disclose information where required by law, regulation or valid legal process, or to protect the rights, safety and security of our users and the Service.
  • Business transfers: if Winnovate is involved in a merger, acquisition or sale of assets, information may be transferred subject to this Policy.

6. Cookies and Similar Technologies

The Service uses strictly necessary cookies to keep you signed in, protect your session and remember the workspace you are using. We do not use advertising or cross-site tracking cookies.

Our sign-in and demo forms are protected by Google reCAPTCHA, which collects device and interaction information to tell people from bots. Its use is subject to Google’s Privacy Policy and Terms of Service.

7. Security

We protect information with measures appropriate to its sensitivity, including:

  • Logical isolation of every Client’s data within our database and storage;
  • Encryption in transit (TLS) and access-controlled, private cloud storage for uploaded documents;
  • Password-less sign-in with short-lived one-time codes and temporary session tokens;
  • Role- and permission-based access within each workspace; and
  • Audit trails of significant actions.

No system is completely secure. If we become aware of a security incident affecting personal information, we will notify affected Clients without undue delay and as required by applicable law.

8. International Transfers

Winnovate is based in Canada, and our Clients and their vendors operate in many countries. Information may be stored and processed in countries other than your own, including in the data centre regions of our cloud providers. Where we transfer information across borders, we rely on contractual and technical safeguards to ensure it remains protected in line with this Policy and applicable law.

9. Retention

  • Client Data is retained for the duration of the Client’s subscription. On termination, or on the Client’s written request, we permanently delete it from our active databases and storage within a commercially reasonable timeframe, as described in our Terms.
  • Demo and contact requests are kept for as long as needed to follow up and manage the relationship, and deleted on request.
  • Technical logs are kept only as long as needed for security and troubleshooting. We may keep anonymised, aggregated telemetry that no longer identifies anyone.

10. Your Rights

Depending on where you live, you may have the right to access, correct, delete or obtain a copy of your personal information, to object to or restrict certain processing, and to withdraw consent where processing is based on consent.

If your information is held in a Client’s workspace, please direct your request to that company, as it controls that data; we will assist the Client in responding. For information we hold as controller, contact us at support@winnovate.tech. We will respond within the timeframe required by applicable law. You may also have the right to complain to your local data protection authority — in Canada, the Office of the Privacy Commissioner of Canada.

11. Children

The Service is intended for businesses and is not directed at children. We do not knowingly collect personal information from anyone under the age of 16.

12. Changes to This Policy

We may update this Policy from time to time. We will update the effective date at the top of this page and, for material changes, notify Clients by email or within the Service. Continued use of the Service after an update means you accept the revised Policy.

13. Contact

For privacy questions or requests, please contact Winnovate Technologies at support@winnovate.tech.

© 2026 Winnovate Technologies. All rights reserved.