Support and usage privacy
Updated 19 September 2026. This notice covers how VendorDue protects store data, VendorDue support, account assistance and how VendorDue records use of the app.
How store data is protected
The database itself keeps each store's data apart. A request made for one store cannot read another store's rows, even if VendorDue's own code asks it to.
Names, email addresses, payout details, PayPal credentials, messages, notes, reasons and files are encrypted with a key that belongs to your store before they are saved. That key is encrypted in turn with a key the database never holds. A copy of the database or a backup, on its own, shows none of your team's or your vendors' contact names and emails, no password or payout detail and no message. Store names, vendor names as they appear on your products, product titles, order numbers and amounts are not encrypted, because VendorDue has to search them and add them up. The names among them are already public on your storefront.
This is not end-to-end encryption. VendorDue's servers open this data while they do the work you ask for, such as emailing a statement, paying a vendor or showing a report.
VendorDue does not keep your customers' names, email addresses or postal addresses. Shopify sends them with each order, and VendorDue drops them before saving anything.
Sending a payment, connecting PayPal or turning on automatic payments needs a passkey or a code from an authenticator app, used in the last five minutes. A new PayPal connection waits a day before it sends on its own. A vendor's new payout details wait two days. VendorDue emails the vendor and the store's owner, and the link in either email stops the change.
VendorDue checks every new password against passwords exposed in data breaches. It sends Have I Been Pwned only the first five characters of a one-way code made from the password, so the password itself never leaves VendorDue.
What you send to support
VendorDue support can read the text and screenshots you choose to submit, including information that would otherwise stay private in your workspace. This is an exception for support submissions. Mask names, amounts and any other details you do not want support to see before uploading a screenshot. Never include passwords, sign-in codes, payment credentials or recovery codes.
Screenshots are flattened after masking and re-encoded before storage. They are stored privately in VendorDue's Supabase project. Access requires an authorized support session. Submitted content is not sent to an external AI service.
Merchant support is shared with authorized members of that store. Vendor support belongs to the vendor account. Support opened with an email verification code belongs to that verified address and does not grant access to a merchant or vendor workspace. Internal support notes are not shared with requesters.
The form shows the account and diagnostic context attached to a request. Diagnostics may include the selected page, account role, store domain, language, timezone and last sync time. Support's account tools show setup and processing states and your store's totals per currency. They do not show individual orders, statement lines, what one vendor is owed or your conversations with vendors.
Email and account assistance
Support emails contain a request reference and a link. They do not contain your message, screenshots or internal notes. VendorDue uses Resend for delivery and records whether the provider accepted or delivered an email, rejected it, or returned an uncertain result.
Account recovery may require confirmation through the existing registered email and an independently authenticated Shopify store owner. Removing a lost sign-in method requires a warning and a waiting period of at least 24 hours. You can cancel a recovery request you do not recognize.
How the app is used
VendorDue records completed actions, such as a finished import, an approved payout period or an exported file, and the pages each signed-in person opens. A page record holds the page's name, how long it stayed on screen, the kind of device, the browser, the operating system and the country. Each record is tied to your store and to the store member or vendor account that opened the page.
These records never include item contents, customer details, amounts, search terms, message bodies, screenshots or sign-in secrets. No cookie is set for them, and VendorDue uses no session recording and no third-party advertising tracker. If you answer the question about how you heard of VendorDue, your answer is kept with your store.
Only the person who runs VendorDue sees these records. They see each store and its people by name, how each uses the app, and the store's sales, amounts owed and payments as totals per currency. VendorDue records each time they open a person's details or see people in a list or a search. VendorDue also receives the install, uninstall and billing events Shopify shares with app developers, including any reason given for uninstalling. To have your store's usage records deleted, contact support.
Retention and deletion
- Unsubmitted verified support drafts expire after one hour.
- Screenshots expire 90 days after a request closes. Unattached uploads expire after one hour.
- Closed support text and internal notes expire after 12 months.
- Encrypted email payloads are removed after 30 days. Account assistance and security audit records are retained for up to 365 days.
- After 30 days a page record no longer says who opened the page. Usage records are kept for 13 months. After that they become daily counts for each store, and the records are deleted.
- Anything you type about how you heard of VendorDue is deleted after 90 days. The option you picked stays.
- When a customer asks Shopify for their data, VendorDue emails your store's owner the order lines it holds for them. When a customer asks to be erased, there is nothing to erase, because VendorDue holds no customer details.
- When you uninstall VendorDue, Shopify asks for your store to be erased 48 hours later. Everything the store held is then deleted, including its people, vendors, files and its key. A record that the store was erased and Shopify's install and billing events for it are kept, without the store's name. The database's backups still hold the store for up to seven days, until they are replaced.
Retention cleanup runs at least daily, with up to 24 hours of scheduling delay. Failed file removals remain queued for retry and are monitored. Earlier redaction and deletion requests can be made through support. Data needed for the merchant's accounting and legal obligations is governed separately from this support notice.
For a privacy request, contact VendorDue support. We will respond as soon as possible.