Privacy Policy
1. Scope & Dual Privacy Roles
This Privacy Policy applies to the Vendray e-commerce platform and edge services engineered and operated by Netrocos, LLC ("Netrocos", "Vendray", "we", "us", or "our"). Under data protection frameworks (including the GDPR and CCPA/CPRA), Vendray operates in two distinct legal capacities:
- Data Controller: For the personal data of our direct B2B customers—store owners, merchants, staff users, and platform website visitors. We determine the purposes and means of processing this account and billing information.
- Data Processor / Service Provider: For the personal data of shoppers and end-consumers who place orders, browse catalogs, or register accounts on independent merchant storefronts. The Merchant is the Data Controller; Netrocos, LLC processes end-consumer data strictly on the Merchant's instructions to provide checkout, inventory decrements, and order fulfillment tracking.
2. Information We Collect as Data Controller
When you register as a Merchant or interact with Vendray, we collect:
- Account Information: Name, business entity name, email address, store slug, and currency preference.
- Security Credentials: Cryptographic password hashes computed using modern Web Crypto PBKDF2 with unique cryptographic salt iterations. Plaintext passwords are never stored.
- Billing Records: Stripe Customer ID, Stripe Subscription ID, and subscription tier. We do not store raw credit card numbers or CVVs.
- Support Communications: Emails and inquiries submitted to platform support.
3. Customer Information We Process for Merchants
When an end-consumer interacts with a merchant's storefront, we process data on behalf of that merchant, including: buyer email address, customer name, shipping address, order items, quantities, applied discounts, and fulfillment tracking numbers. If customer portal accounts are enabled by the merchant, customer email and hashed access credentials are kept for order lookup.
4. Payment Information & PCI Security
All storefront checkouts and merchant platform subscriptions are executed using direct TLS 1.3 encrypted connections to Stripe, Inc., a certified PCI-DSS Level 1 Service Provider. Customer card credentials are tokenized directly within Stripe's infrastructure. Vendray retains only masked payment intent references and order settlement status.
5. Edge Infrastructure & Technical Telemetry
Because Vendray runs on a serverless edge network across 330+ global cities, our edge Workers process transient technical telemetry: IP address, approximate city/country, Cloudflare Ray ID, HTTP headers, and rate-limiting counters to thwart DDoS attacks and bot scraping. This telemetry is processed under our legitimate interest to safeguard system security and is purged or aggregated in standard log cycles.
6. Cookies & Edge Storage
Vendray employs a privacy-first cookie policy: essential session cookies/JWT tokens solely for merchant admin authentication (session_token), and browser localStorage to preserve shopping cart contents. We do not inject behavioral advertising cookies or third-party marketing trackers into storefronts.
7. Sub-Processors & Data Sharing
We do not share your personal data with third parties except with trusted sub-processors necessary to operate the platform:
- Cloudflare, Inc.: Edge compute (Workers), D1 SQLite, KV cache, R2 storage, DDoS shield (Global / USA / EU).
- Stripe, Inc.: Payment processing, subscription billing, and merchant payouts (USA / Global).
8. Data Retention & Deletion
We retain merchant account data as long as your store is active. When you cancel or request deletion, Netrocos, LLC purges your catalog data, orders, and customer records from primary active databases within thirty (30) days, except where retention is legally mandated for tax, accounting, or audit compliance.
9. Merchant Independent Privacy Duties
Because B2B Merchants act as independent Data Controllers for their store's shoppers, Merchants must publish a clear, easily accessible Privacy Notice on their storefront disclosing what customer data is gathered and how it is processed, and ensure compliance with applicable data protection statutes.
10. Your Rights Under GDPR (EU & UK)
If you reside in the European Economic Area (EEA) or the United Kingdom, you possess statutory rights under GDPR Articles 15 through 22, including rights of access, rectification, erasure ("Right to be Forgotten"), restriction of processing, data portability, objection, and lodging complaints with your supervisory authority.
11. Your Rights Under California Law (CCPA/CPRA)
California residents have the right to know what personal information is collected, the right to request deletion, and the right to non-discrimination. Netrocos, LLC does not sell or share personal information for cross-context behavioral advertising.
12. Data Security & Cryptography
Netrocos, LLC applies defense-in-depth security standards: end-to-end TLS 1.3 encryption, PBKDF2 Web Crypto password hashing with high iteration counts, and strict multi-tenant database isolation parameters on Cloudflare D1.
13. International Transfers
Personal data may be transferred to and processed across Cloudflare's global edge network. When transferring data internationally from the EEA, UK, or Switzerland, Netrocos, LLC relies on European Commission Standard Contractual Clauses (SCCs).
14. Privacy Inquiries & Data Officer
For questions or requests to exercise your data rights, contact:
Product: Vendray E-Commerce Platform
Privacy Email:
privacy@vendray.com / legal@netrocos.comWebsite:
https://vendray.netrocos.dev