Vendor Huddle is a web app for event coordinators. You build an event’s run of show, keep a vendor directory, and send each vendor and client a private link to their part of the plan. This policy says what we collect, why, who sees it, how long we keep it, and what you can do about it.
Effective date: 27 September 2026. Questions: privacy@ironpinelabs.com.
The short version
- We collect what you type into the app and what we need to run your account. Nothing else.
- We don’t sell your personal information today, and we run no ads. We may license aggregate market data — price ranges and demand patterns with no names, businesses or events in it. If selling personal information ever changes, we will tell you before it takes effect and give you a working way to opt out first.
- You own what you put in. Vendor and client details you enter stay under your control; we process them for you.
- Three companies handle data for us: Cloudflare (hosting and storage), Stripe (payments) and Resend (email).
- Product analytics (PostHog) runs on the planner side of the site, including its public pages, but never on the vendor page, the client page or the intake form. It contains no names, emails or event content, respects Global Privacy Control and Do Not Track, and has an off switch in the app.
- Vendor and client links expire on their own, 30 days after the event. Intake links expire after 14 days.
- Every email we send carries our postal address, and the ones that can reach somebody who never signed up carry a one-click unsubscribe that works immediately.
- To delete your account, email us. We don’t have a self-serve delete button yet.
Who we are
Ironpine Labs LLC (Florida, USA) runs Vendor Huddle at pilot.vendorhuddle.com. The service is a pilot: early access, offered in the United States only.
Two roles matter in this policy:
- Your own information — your account, your settings, your billing. For this, we decide how it is used, and this policy is the whole story.
- Information you enter about other people — vendors, clients and anyone named in an event. You decide why it is collected and who sees it. We store and process it on your behalf, only to provide the service to you, and only as this policy and our terms describe.
What we collect
Your account
- Name and email address. Sign-up needs both.
- Password, if you set one. We store a hash, never the password itself. You can sign in with an emailed link instead, and never set a password.
- Email verification status, and the short-lived codes behind verification, sign-in and password-reset links.
- Sessions. Each sign-in records when it started, when it expires, your IP address and your browser’s user-agent string.
- Sign-in attempt counts, keyed by address, so we can slow down password guessing and link spam.
There is no Google, Apple or other social sign-in. The only sign-in methods are email + password and an emailed link.
Your workspace and events
Everything you enter to run an event is stored so we can show it back to you and to the people you share it with:
- Workspace settings: your business name, whether you plan for clients or for yourself, your 12h/24h time preference.
- Events: name, date or date range, time zone, event type, venue name and address, client names, notes, status.
- Run-of-show cues: times, titles, locations, notes, which day, which vendors can see each cue, whether the client can see it, and done/pending status.
- Vendor directory: company, category, contact name, email, phone, notes, load-in, power needs, team size, and any certificate-of-insurance document you or the vendor upload (the file, its name, type, size and expiry date).
- Vendor assignments: a vendor’s role and arrival time on an event, and whether they have opened and reviewed their schedule.
- Messages: threads between you and a vendor or client, the cue each thread is about, and when you last read it.
- In-app notifications: a short copy of what happened (a new question, a submitted intake form, a client confirmation, a vendor review) and when you read it.
What vendors and clients send us
- Vendor intake form. A vendor you invite fills in their business name, category, contact name, phone, email, arrival time, load-in, power needs, team size and notes, and can upload a certificate of insurance (PDF, JPEG or PNG, up to 10 MB). None of this needs an account. It lands in your vendor directory.
- Vendor page. When a vendor opens their schedule link we record that it was opened, and if they tap “I’ve reviewed this” we record when. Questions they ask become messages to you.
- Client page. Same again: when it was first opened, when your client confirmed the plan, and any questions they ask.
We do not ask vendors or clients for anything beyond what the form or the page shows.
Billing
- Stripe identifiers: your Stripe customer ID, subscription ID, plan, status and current period end. Stripe creates the customer record with your name and email the first time you start a checkout.
- Your auto-renewal consent: the plan, price, billing interval, the exact sentence you agreed to, and when. California law requires us to keep proof of this.
- Renewal reminders sent and the IDs of Stripe events we have processed.
We never see or store your card number. Stripe handles the payment page and stores your payment method.
Automatically, when you use the site
- Server logs. Cloudflare keeps short-lived request logs (IP address, path, status, errors) that we use to keep the service running.
- Error reports. If a request fails, we may record the error with the request path and timing in those same Cloudflare logs. Vendor and client link tokens are scrubbed before an error is recorded.
- Web analytics and product analytics, described next.
If you have a vendor account
A vendor account is separate from a planner workspace, and it holds its own things:
- Your profile: business name, the services you offer, your base location and how far you travel, a description, photos and a price range. A published profile is public — that is what it is for.
- Availability: the dates you mark booked or open for work.
- Requests and bids: the requests you can see, the bids you place, your quoted price and the message you send with it, and whether the planner replied or accepted.
- Messages: conversations with a planner about a bid, before any hire.
- Reviews: what you write about a planner and what they write about you, plus the derived counts on your profile.
- Past-client references: if you name a past client so they can confirm they worked with you, we email them. We store a one-way hash of that address, not the address itself, and the confirmation link expires. Because of that, your own reference list shows you the domain you invited rather than the full address — we no longer hold it to show you. They can ignore the email, and we do not email them again about it or use their address for anything else. If they decline, or use the unsubscribe link, we keep that same hash on a do-not-email list so no vendor can invite that address again — which is the one thing we do with it, and the only way to honour a “stop” without keeping the address.
- Bid credits: a ledger of every credit granted, spent and refunded, and what each spend was for. It is a record of what you bought and used.
- Saved replies: snippets you write to reuse in bids.
If you connect a calendar
- Busy dates only. We read your calendar and keep which dates are busy. We do not keep, and do not want, event titles, guests, locations, notes or anything else in it. Whatever your calendar says about your other clients never reaches us.
- The connection itself: the calendar address you gave us, when we last read it successfully, and whether the last attempt failed.
- The feed we publish for you: a secret link whose contents are the dates you are booked, each labelled only “Booked”. No client name, no venue, no event name — so if that link ever escapes, it shows that you are busy, never who for.
If you use the business tools
Quotes, contracts, invoices, your crew’s call sheets and your enquiry form hold details about other people — your clients, your crew, whoever fills in your form. You decide what goes in and you are responsible for having the right to put it there; see the terms. We hold it for you, show it to nobody else, and delete it when you delete the record or your account.
- Your clients: the name, email, phone and notes you enter, and the bookings you record against them.
- Quotes: your line items — descriptions, quantities, prices and the total.
- Contracts and signatures: the contract text you write, and — when your client signs — their name, the email address they give, their IP address and browser, the moment they signed, their confirmation that they meant to sign and agreed to receive the records electronically, and a frozen copy of exactly what was on their screen, stored so it cannot be edited afterwards. That combination is what makes an electronic signature stand up as evidence under the federal ESIGN Act and Florida’s Uniform Electronic Transactions Act, which is the only reason we keep an IP address here at all. It is a record about your client rather than about you, and it goes when the contract or your account goes.
- Invoices and payments: amounts, dates and what you tell us you were paid. No card numbers and no bank details — no money for your work passes through us.
- Your crew: the name and the email or phone you enter, their role, and the dates you assign them. A call-time link carries only that person’s own role, time and place — never your client, your event or anyone else on the job.
- Enquiries: whatever somebody types into your enquiry form — their name, how to reach them, their message — and which source it came from. If you put the form on your own website, tell your visitors their details reach you through us.
Your insight page holds nothing of its own. It is worked out from the rows above at the moment you open it, and nothing new is collected or stored to produce it.
Analytics
Cloudflare Web Analytics
Cloudflare’s analytics beacon counts page views and load times. It sets no cookies, stores nothing in your browser, and does not identify you across sites.
Product analytics (PostHog)
We are adding PostHog, hosted in PostHog’s US cloud, to learn which parts of the app are used, where sign-up gets stuck, and whether paid plans work as intended. It is not switched on yet; this section takes effect when it is. The app enforces these rules:
- Where it runs. On the planner side of the site — including the public pages: the home page, pricing, sign-in, sign-up and the setup walkthrough — so it covers anonymous visitors as well as signed-in coordinators. It never loads on the vendor page, the client page or the vendor intake form. No PostHog code runs there at all.
- Who you are to it. Before you sign up, a random identifier with no name or email. After you sign in, our internal account ID, with your workspace as a group. The only profile details attached are your plan tier (free or pro) and which environment you are on.
- What it records. A fixed list of actions — sign-up, email verified, each walkthrough step, event created, cue added, vendor added, link copied, update sent, day-of view opened, print opened, plan limit hit, checkout started — each with a few fixed values (a method, a source, a count), and page views recorded as page templates with every record ID removed and no query strings. Two billing events (subscription started, subscription cancelled) are sent from our server when Stripe confirms them.
- Never sent: your email, name, phone, company name, vendor or client names, cue text, notes, or any other free text you typed. Automatic capture of page content is off; every event is hand-defined.
- Session replays mask every piece of text and every input, so a replay shows layout, navigation and clicks, not your data.
- Global Privacy Control and Do Not Track are honored. The app checks for either signal before PostHog loads; if one is set, it never loads for that visitor.
- An in-app switch. Signed-in coordinators can turn analytics off under Account → Plan & billing → “Product analytics”, whatever their browser says. The choice is remembered in that browser.
- No third-party scripts. PostHog’s code ships inside the app; nothing is fetched from PostHog’s servers at run time.
While it is on, PostHog keeps a random identifier, session state and your off-switch choice in a cookie or your browser’s local storage.
Emails we send
Resend delivers all of it. This is the whole list — there is nothing else.
To you, about your account:
- Email verification, sign-in links and password resets.
- A summary when something happens on an event — new questions, a submitted intake form, a client confirmation, a vendor review — at most one per event every 15 minutes. Also a one-off note if a vendor you invited for one category submits their form as another.
- A note when a review window opens, so you can leave a review before it closes.
- Yearly plan only: a renewal reminder about 30 days before your plan renews, as California law requires.
To your vendors — people whose address you typed in, who may have no Vendor Huddle account of their own:
- A schedule-update email when their times change, sent as “Your business name via Vendor Huddle” with a link to their schedule. It goes only to a vendor who has an email address and a live schedule link, once your changes have sat untouched for 10 minutes, and it is capped per day (see the terms). While vendor accounts are open, it also invites them to claim a free one.
- An intake invitation, when you ask them for their details.
- A note that you accepted their bid, if they bid on a marketplace request of yours.
To a past client you name. If you claim you worked an event together before joining Vendor Huddle, we email that person once to ask them to confirm it. We send it, not you, so it comes from us and carries our address. They can confirm, say it isn’t right, or ignore it; the link expires either way, and we store a hash of their address, not the address itself.
To us. Abuse reports and a weekly service summary, carrying only what identifies the thing reported.
Our address, and how to make us stop
Every email we send carries our postal address. The law asks that of anyone who emails you, and you should be able to tell who is writing to you without clicking anything.
The three emails that can reach somebody who never signed up — the schedule update, the bid-accepted note and the past-client reference request — each carry a one-click unsubscribe link. Click it and we stop: right away, for good, for that kind of email to that address. No account, no login, no form to fill in. Declining a reference request stops any further reference request to you as well.
When a vendor unsubscribes from schedule updates, we tell the coordinator in the app, not by email, so they know to reach that vendor another way. We would rather somebody got a phone call than quietly stopped hearing that their call time moved.
Account emails — verification, sign-in, password resets, billing and the activity summaries — carry no unsubscribe link, because they are how your account works rather than something we are promoting at you. You switch those off by closing your account.
No newsletters. We don’t sell your address, we don’t rent it out, and we never carry another company’s advertising to you. Two of the emails above do speak for Vendor Huddle itself — the schedule update invites a vendor to claim a free account, and the reference request has to explain who we are — and both of those can be unsubscribed from, as above.
How we use it
- To run the service: show you your events, deliver vendor and client pages, send the emails above, take payment.
- To keep it safe: rate-limit sign-ins and public links, detect abuse, investigate errors.
- To improve it: the aggregate analytics described above.
- To meet legal duties: billing records, renewal notices, responding to lawful requests.
We do not use your data to build advertising profiles, to train AI models, or for anything you would not expect from a scheduling tool.
Who we share it with
We do not sell personal information today, and we do not share it for advertising. We run no ads. We are not promising never to. If that changes, we will update this policy, tell the people it affects before it takes effect, and give you a working opt-out first — see Your rights and choices. We will not apply a change like that retroactively to information collected while this paragraph said otherwise.
Three companies process data for us, each only for the job listed:
| Service | What it does | What it holds |
|---|---|---|
| Cloudflare (USA) | Hosting, database, file storage, request logs, cookieless web analytics | Everything in this policy, on Cloudflare’s infrastructure |
| Stripe (USA) | Checkout, subscriptions, the billing portal | Your name, email, payment method, invoices; never seen by us in full |
| Resend (USA) | Sends our email | Recipient address, subject and body of each email we send |
| PostHog (USA, US cloud) — when switched on | Product analytics | Action events, templated page views and masked session replays from the planner side of the site; no names, emails or event content |
Beyond that, we share personal information only:
- With the people you choose. A vendor sees the cues you show them, and your business name on the emails we send them. A client sees the client page, with your business name on it.
- If the law requires it, such as a valid subpoena, and we will tell you unless we are legally barred.
- If the business changes hands. If Ironpine Labs is acquired or the product is sold, your data goes with it under this same policy, and we will tell you first.
Aggregate market data
Running a marketplace produces something genuinely useful that is nobody’s personal information: what event services actually cost, how demand moves through the year, and how often a request gets filled. We may publish or license that as aggregate, de-identified market data.
What that means, precisely:
- What it contains: statistics — price ranges by service type and area, seasonal demand, how many requests receive bids, typical response times.
- What it never contains: your name, your business name, contact details, client names, venues, event details, or anything that identifies a person or a business.
- Small numbers are suppressed. We only publish a figure when it draws on enough separate businesses that no single one can be worked out from it. A price range for a service type in a town with two vendors in it does not get published, because that is not really aggregate — it is those two vendors’ pricing with a label on it.
- No re-identification. We do not attempt it, and anyone we license the data to is contractually barred from attempting it or from combining it with other data to that end.
This is separate from the paragraph above about personal information. Aggregate market data is not personal information, and licensing it does not involve selling anything about you individually.
Cookies and browser storage
- Session cookie. One cookie keeps you signed in (
better-auth.session_token, marked Secure and HttpOnly). Signing out clears it. It is strictly necessary and has no opt-out. - Sign-up walkthrough draft. If you start building a plan before creating an account, the draft sits in your browser’s local storage until you finish signing up or clear it.
- PostHog, when on, keeps a random identifier, session state and your off-switch choice in a cookie or local storage, as described above. Global Privacy Control or Do Not Track stops it from loading at all; the in-app switch stops it for that browser.
No advertising cookies, no third-party tracking cookies, no cookie banner needed.
Links you share
Vendor pages, client pages and intake forms open with a private link and no password. Anyone holding the link can open the page, so treat each link like a key.
- Vendor links work until 30 days after the event date. You can revoke or regenerate one at any time.
- Client links work until 30 days after the event’s last day. You can revoke or regenerate one at any time.
- Intake links work for 14 days from when you create them, and you can revoke one sooner.
We store only a hash of each link’s secret, so a copy of our database does not reveal working links. For vendor links we also keep an encrypted copy, so “Copy link again” and the schedule-update email hand your vendor the same link rather than a new one.
How long we keep it
- Your account and everything in it: for as long as your account exists.
- Events, vendors, cues, messages, documents: until you delete them. An event archives itself 7 days after its last day, but archiving deletes nothing. Deleting an event removes its cues, assignments, links and messages. Deleting a vendor removes their record and their uploaded documents.
- Uploaded documents: a new certificate of insurance replaces the old file. Deleting the vendor deletes the file.
- Sessions: until they expire or you sign out.
- Auto-renewal consent records: at least three years, or one year after your subscription ends, whichever is longer, as California law requires. We keep these even after deleting the rest of your account, without your account identifier attached.
- Stripe records: Stripe keeps invoices and payment records under its own retention rules and the tax laws that apply to it.
- Email delivery logs (Resend) and request logs (Cloudflare): short-lived, under each provider’s retention.
Deleting your account. There is no self-serve delete button yet. Email privacy@ironpinelabs.com from your account address and we will delete your account and everything in it, except the consent records above. We aim to complete deletion within 30 days and will confirm when it is done. Cancel any Pro subscription first (in Plan & billing), or tell us and we will cancel it for you.
Your rights and choices
Wherever you are in the United States, you can ask us to:
- Access the personal information we hold about you, and get a copy.
- Correct anything inaccurate. Most of your data you can edit yourself in the app.
- Delete your account and data, as described above.
- Opt out of analytics — the in-app switch, or Global Privacy Control or Do Not Track in your browser. We do not sell personal information or run targeted advertising today, so there is nothing else to opt out of yet; if that ever changes, the same controls will cover it and we will tell you before it starts.
- Unsubscribe from any email that isn’t part of running your account, using the link in it — see our address, and how to make us stop. You don’t need to email us to do this, and you don’t need an account.
Email privacy@ironpinelabs.com. To protect your account we will ask you to write from the email address on it, or to confirm from inside the app. We answer within 45 days. If we refuse a request, we will say why, and you can ask us to reconsider. We will never treat you differently for exercising a right: no worse service, no different price.
Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon and other states with consumer privacy laws have these rights in law; we extend them to everyone in the US. You may also use an authorized agent; we will ask for proof that they act for you.
If you are a vendor or client
If a coordinator entered your details or sent you a link, the coordinator controls that data. To correct or remove it, ask the coordinator: their business name is on the client page, the intake form and every email you receive. If you would rather talk to us, email privacy@ironpinelabs.com and we will pass the request on, or act on it ourselves where we can.
To stop schedule-update emails, use the unsubscribe link at the bottom of any one of them — it works on the first click and needs no account. You can also ask the coordinator to remove your address or revoke your link, or email us and we will do it. However you do it, we tell the coordinator in the app that you have opted out, so they know to reach you another way rather than assuming you saw a change you never got.
The same goes if a vendor sent you a quote or a contract to sign, gave you a call-time link for a job, or you filled in their enquiry form: that vendor decides what is held about you, and their business name is on the document. Ask them first. If you would rather come to us, email privacy@ironpinelabs.com — we will pass it on, or act on it ourselves where we can. If you signed something, tell us and we will send you the copy of what you signed and when.
Children
Vendor Huddle is not for anyone under 16. We do not knowingly collect personal information from children. If you believe a child has an account, email us and we will delete it.
Security
- Every connection uses TLS. Session cookies are Secure and HttpOnly.
- Passwords are stored as salted hashes. Private links are 160-bit random secrets, stored hashed.
- Every record is tied to one workspace, and every request is checked against it. One coordinator cannot reach another’s data.
- Uploaded documents live in a private bucket with no public URL. They are streamed only to the signed-in coordinator who owns the workspace, as a download, after the file’s contents (not its name) have been checked to be a PDF, JPEG or PNG.
- Sign-ins, public links and public forms are rate-limited. Stripe webhooks are signature-checked.
No system is perfectly secure. If a breach affects your data, we will tell you by email as soon as we can, and notify regulators where the law requires.
International use
Vendor Huddle is offered in the United States and runs on US infrastructure. If you use it from elsewhere, your data is transferred to and processed in the US.
Changes to this policy
If we change what we collect, how we use it, or who we share it with, we will update this page, bump the date at the top, and email you or show a notice in the app before the change takes effect. Small edits (typos, clarifications, contact details) get a new date only. The two-sided marketplace we are building is not covered by this policy; it will get its own update before it launches.
Contact
Ironpine Labs LLC
2435 US-19 S, Suite 510
Holiday, FL 34691
USA
Privacy: privacy@ironpinelabs.com
Everything else: hello@ironpinelabs.com