Site information
Privacy Notice
This notice describes the limited personal information used to provide verified-email access, operate saved research engagements, collect feedback, and protect the site.
Effective July 25, 2026Who operates this site
This site is operated by VendorSignal LLC.
Information the site handles
- Registration and membership data: email address, optional display name, access role and status, administrator action history, and registration or sign-in timestamps. The submitted email receives the verification code; entering that code verifies control of the mailbox.
- Sign-in and security data: one-time-code challenge records, hashed codes and session tokens, session and expiration timestamps, and hashed rate-limit identifiers derived from an email address or network address. A secure cookie maintains the authenticated session. Hosting and security providers may also process request and security-log data.
- Evaluation activity: evaluation-session identifiers, application and research-corpus versions, and session start, last-seen, and end times.
- Feedback: ratings, free-text comments, friction notes, page context, follow-up preference, and administrator triage fields. Feedback is associated with the verified member who submitted it.
- Device-local progress: the research checklist can store completion state in the browser. That state remains on the device unless the browser clears it.
How the information is used
The information is used to verify mailbox control, provide and secure access, prevent abuse, maintain evaluation sessions, understand whether the research is useful, respond to feedback, administer the pilot, troubleshoot problems, and maintain the reliability and security of the service.
The site does not use personal information for targeted advertising or sell it. If those practices change, this notice must be updated before the change takes effect.
Cookies and local storage
The site sets a necessary authentication cookie after a successful sign-in. The cookie contains a random session value; the stored server record contains its hash. The cookie is used to keep the member signed in and is not used for advertising. Hosting and security services may use additional strictly necessary security storage. The research checklist uses optional browser local storage.
Service providers and sharing
Saved working engagements contain the context, product decisions, reasons, action plans, evidence references and collaborator email addresses you enter, along with a saved research snapshot. They are stored in the application database and are private to the owner until named collaborators are added. Named collaborators can view and edit the entire engagement; the owner controls access and deletion. Sharing a link does not grant access to someone who is not named. No collaboration invitations are emailed, and this feature does not send engagement content to an external AI service. If you upload an exported brief to another service, that service handles it under its own terms.
OpenAI Sites and Cloudflare provide application hosting, edge delivery, database, and security functions. Plunk processes the destination email address and one-time code to deliver sign-in messages. When feedback is stored, Plunk also delivers an administrative notification containing the feedback record identifier, checkpoint, and application surface. That notification excludes the member identity, ratings, comments, and friction notes. These providers process information as needed to perform their services. Information may also be disclosed when required by law, to protect the service or its users, or as part of a properly managed business transfer.
Following an external source link takes the visitor to another organization's site, which has its own privacy practices.
Retention
- Saved working engagements remain until their owner deletes them or the operator handles a deletion request. They are not included in the feedback cleanup schedule. Saving a revision replaces the previous saved engagement and evidence snapshot; the service does not provide a complete edit history. Removing a collaborator stops future application access but cannot recall a copy they already downloaded.
- One-time codes expire after 10 minutes. Authentication sessions expire after no more than 30 days and after 7 days without activity.
- Expired challenges, sessions, and rate-limit records are removed through administrator-run cleanup; removal is not currently automatic. Never-verified registration records have a short operational retention period and are removed after their challenge retention window.
- Feedback and unreferenced evaluation records become eligible for administrator-run cleanup after 90 days.
- Verified membership records are not included in the 90-day cleanup and are maintained separately for access administration and security history.
- Provider logs and backups may follow provider-specific retention schedules.
Security and international processing
The site uses access controls, hashed authentication secrets, request limits, and other safeguards intended to protect the information it handles. No online service can guarantee absolute security. Service providers may process information in locations where they operate.
Your choices and requests
You may ask about, correct, or request deletion of personal information associated with you. The operator may need to verify the requester's identity and will handle requests as required by applicable law. You can decline to submit optional feedback or request follow-up. Do not put client, incident, credential, contract, deployment, or other confidential information in feedback.
Children
This business research site is not directed to children under 13, and children should not submit personal information to it.
Privacy and correction contact
Email info@vendorsignal.io for a privacy request, factual correction, or rights-holder concern.