Legal

Privacy Policy

Last updated: August 18, 2026 · Effective: August 18, 2026

VendorLockbox operates a vendor management and NCUA compliance platform for credit unions and community banks. This Privacy Policy explains how we collect, use, share, and protect information when you or your institution uses our services.

Information we collect

Account information

When you sign up we receive your name, email address, and (through our identity provider WorkOS) an authenticated user identifier. When you complete onboarding you supply your institution's name, institution type (credit union or community bank), approximate asset size, and optionally your NCUA charter number and next scheduled exam date.

Vendor and compliance data

You upload records about your third-party vendors, contracts, compliance documents (for example SOC 2 reports, insurance certificates, and business continuity plans), due diligence reviews, risk assessments, and incidents. This content is owned by you and is stored and processed on your behalf.

Usage data

We collect information about how you interact with the service, including pages viewed, features used, timestamps of key actions, and error events. We use this information to operate, secure, and improve the service.

Payment information

Payment card details are collected and processed directly by Stripe, our payment processor. We never see or store your full card number. We do store a Stripe customer identifier and the subscription identifier associated with your account, along with the last four digits and expiration month of the card on file for display purposes.

Cookies and similar technologies

We use a small number of cookies for authentication (set by WorkOS), product analytics (set by PostHog), and to remember in-app preferences such as dismissed banners. See Cookies below for details.

How we use information

  • To operate, maintain, secure, and improve the service.
  • To create your account, authenticate you, and enforce plan limits.
  • To send transactional messages, including renewal alerts, document expiry notifications, billing notices, trial reminders, and important service announcements.
  • To bill you for paid subscriptions through Stripe.
  • To generate the exam readiness reports, vendor inventories, and other outputs you request.
  • To detect, prevent, and respond to security incidents, fraud, and abuse.
  • To comply with applicable laws and enforce our Terms of Service.

Who we share information with (subprocessors)

We rely on the following subprocessors to deliver the service. Each is bound by contractual obligations to protect your data:

  • WorkOS (San Francisco, California, USA). Identity, authentication, and session management.
  • Stripe (San Francisco, California, USA). Payment processing, subscription billing, and invoicing.
  • Resend (San Francisco, California, USA). Transactional email delivery.
  • PostHog (San Francisco, California, USA). Product analytics and feature usage tracking.
  • Microsoft Azure (Redmond, Washington, USA). Application hosting, database storage, and file storage for uploaded documents.

The current list of subprocessors, along with links to their security documentation, is available on our Security page. We do not sell your personal information to any party, and we do not share your data with third parties for advertising purposes.

We may also disclose information when required by law, subpoena, or valid legal process, or when necessary to protect the rights, property, or safety of VendorLockbox, our customers, or others.

Data retention

We retain your account and vendor data for as long as your account is active. If you cancel your subscription, your data remains available for 30 days so you can export it. After 30 days we delete your operational data on request. Anonymized usage statistics, financial transaction records required by law, and log entries needed for security auditing may be retained for a longer period.

You may request deletion of your account and associated data at any time by emailing [email protected]. We will complete the deletion within 30 days of a verified request, subject to any legal retention obligations.

Your rights

Regardless of your location, we honor the following rights:

  • Access. Request a copy of the personal information we hold about you.
  • Correction. Ask us to correct information that is inaccurate or incomplete.
  • Deletion. Request that we delete your account and personal information.
  • Portability. Request a machine-readable export of your data. Vendor and organization data can also be exported at any time through the in-app CSV export.
  • Objection and restriction. Ask us to stop or limit certain uses of your information.
  • Complaint. Lodge a complaint with your local supervisory authority if you believe your rights have been violated.

To exercise any of these rights, contact [email protected]. We may need to verify your identity before responding.

Cookies

We use only the following categories of cookies:

  • Session cookies set by WorkOS to keep you signed in. Deleting these will sign you out.
  • Product analytics cookies set by PostHog to identify your session and record feature usage in aggregate.
  • Preference cookies set by VendorLockbox to remember dismissed banners and other in-app choices.

We do not use advertising cookies and we do not permit cross-site tracking by third parties.

Security

We use industry-standard security controls to protect your data, including encryption in transit (TLS 1.2 or higher), encryption at rest, principle of least privilege for internal access, and multi-tenant data isolation with organization-scoped access control. A detailed description of our security program is available on our Security page.

International data transfers

Our subprocessors are based in the United States. If you access the service from outside the United States, your information may be transferred to, stored in, or processed in the United States. Where required by applicable law, we implement appropriate safeguards such as the Standard Contractual Clauses.

Children

VendorLockbox is a business-to-business service intended for institutional use. It is not directed to children under 13, and we do not knowingly collect personal information from children.

Changes to this policy

We may update this policy from time to time. If we make material changes we will notify you by email and post a notice inside the application. The effective date at the top of this page reflects the most recent update.

Contact

Questions about this policy, or requests to exercise your rights, should be sent to [email protected].

VendorLockbox
Attn: Privacy
Redmond, Washington, USA