VendorClue · information & policy
Privacy Policy
Personal data used to operate VendorClue, respond to requests and provide optional email features.
- Market scope
- unspecified
- Basis
- Published editorial version
- Author
- VendorClue
Document version 1.0. Reviewed 2026-10-05. Effective 2026-10-05. Native CMS revision and publication history are retained separately for this document.
Browsing and infrastructure. Cloudflare serves the website through Workers and stores application records in D1 and published media in R2. Requests necessarily expose network and request information such as IP address, requested URL and browser headers to the infrastructure provider. Operational logs and security controls can process this information to deliver the service, diagnose failures and prevent abuse. Do not put confidential information in URLs.
Readers and saved items. Reading public pages does not require an account. Saved product references use sessionStorage in your browser tab; VendorClue does not provide cloud synchronization for this feature. Calculator inputs describe a buying scenario, not payroll, accounting records or financial accounts. Do not enter personal or confidential business information into a scenario.
Administration. Payload CMS authentication is for authorized staff, not readers. Staff email addresses, authentication records, document versions and editorial audit entries support access control and publication accountability. CMS content and uploaded source evidence may contain information about authors or suppliers; staff must minimize personal data and have a valid reason to include it.
Optional email. When a form is available, a request stores the submitted email address, optional first name, requested topics, source page family, consent-text version, request and confirmation timestamps and contact status. Double opt-in requires the recipient to confirm before topic preferences become active. A request to email one calculator or comparison result does not subscribe the recipient to updates.
Email delivery records contain the purpose, template version, provider message identifier, status and timestamps. Confirmation and unsubscribe tokens are stored as hashes. Delivery events can include the recipient, sender and subject while passing through Cloudflare Queues; the application event table retains event identifiers, type, message identifier and timestamps, not the full event body. Bounces, complaints and suppression events prevent further inappropriate sends.
Bot protection. When an email form is enabled, Cloudflare Turnstile evaluates browser and device signals and returns a token for server-side verification. The application checks the hostname and action and does not treat a browser-only success as authorization to send. Cloudflare describes its own processing of detection signals in its Turnstile Privacy Addendum.
Consent and Google. Google publisher and consent bootstrap code loads on eligible public pages. Google receives network information when its code is requested even though VendorClue GA4 and ad-serving flags are off. The external consent-message preview remains unverified; VendorClue does not claim that a working choice dialog is available. Browser consent choices, where available, are separate from email topic preferences. Legal pages exclude publisher tags and analytics. Accepting Google consent does not subscribe you to email; rejecting it does not block a requested transactional message. Email unsubscribe does not change Google consent.
Purposes and legal bases. We use necessary request and security data to operate a reliable information service and prevent abuse, on the basis of our legitimate interests. Optional research preferences require consent and double opt-in. A specifically requested result email or response uses only the information necessary to fulfil your request, on the basis of our legitimate interest in providing the service you asked for. We process rights requests and legally required records to fulfil applicable legal obligations. Consent can be withdrawn independently of browser advertising choices.
Recipients and transfers. Cloudflare provides hosting, storage, security and transactional email infrastructure. Its DPA covers processing on customer instructions; its separate policies also cover its own purposes. For Turnstile, Cloudflare acts as processor for protecting customer sites and as controller for improving bot detection. Google’s publisher/advertising services use its applicable controller terms. Outbound supplier destinations are independent services. See Third parties for links. We do not promise EU-only processing; provider safeguards include the applicable contractual transfer mechanisms described in their published terms.
Retention policy v1. Unconfirmed requests and consumed/expired confirmation tokens have a 7-day target; result-only contacts and delivery records 30 days unless separately subscribed or needed for suppression; delivery history/events 90 days. Active preferences remain until withdrawal, with review after 24 months without a confirmed interaction. Minimal consent, withdrawal and suppression evidence has a 3-year target after withdrawal. Unsubscribe links are valid for at most 365 days, with expired-record removal targeted within 7 days. Resolved support correspondence has a 12-month target; minimal rights-request records 3 years. Holds and applicable legal obligations can require limited longer retention. Queue and DLQ retention is configured to 4 days. Security logs target 30 days subject to actual provider retention; backups target a rolling 30 days. Automatic email cleanup is not enabled: these targets guide operator review and authorized deletion, and do not guarantee automatic removal on a particular date. Token expiry is not record deletion.
Your choices and rights. Optional email consent can be withdrawn without changing the lawfulness of earlier processing. Unsubscribe disables preferences even when sending is disabled; it does not erase every audit or suppression record. Clearing browser storage removes saved items. Where applicable, you may request access, correction, erasure, restriction, portability or object to processing, and complain to a competent data-protection authority. See Data rights & deletion for the request process.
VendorClue does not use the calculator to make a legally binding or similarly significant decision about you. The service is general software information and is not directed at children. Do not submit special-category personal data or identity documents through general correspondence. Material changes require a new reviewed document version.
Requests and controller. Contact privacy@magoflow.com for access, correction, deletion, restriction, portability, objection or consent withdrawal. We may request proportionate verification. You can complain to a competent authority; our operator is established in Poland, where the supervisory authority is the President of the Personal Data Protection Office (UODO): https://uodo.gov.pl/ . Support and factual corrections use the support contact below; legal notices use the legal contact below. These are the current monitored VendorClue contact addresses; Magoflow is the mailbox domain, not the product domain.
Operator: IT SERVICES MAREK PIETKIEWICZ, Polish sole proprietorship, NIP 5542598947, REGON 341623872. Address: ul. Irysowa 16, 86-031 Osielsko, Poland. Jurisdiction: Poland. VendorClue is the service name of this operator.
Support and editorial corrections: support@magoflow.com. Privacy and data rights: privacy@magoflow.com. Legal notices: legal@magoflow.com.