Platform Privacy Policy
Effective date: August 25, 2026 · Document key: privacy_policy · Version: approved-2026-08-24-v7 · Operator: M2 AI, LLC, a Texas limited liability company · Brand: The Vendor Lineup · Website: https://www.vendorlineup.com · Scope: visitors, Customers, and Vendors · Launch geography: United States only, Texas-focused (Greater Houston)
Plain-language summary
- One policy covers everyone: people just browsing, Customers, and Vendors. Read the section for your role — Section 4 onward is organized that way.
- We use Supabase for database, email magic-link sign-in, and file storage; Vercel to host the app; Resend for application transactional email; Google Maps Platform for address and route functions; and Sentry for error/performance monitoring when configured. Twilio Verify remains configured through Supabase but is not used by any current launch application authentication path.
- Stripe is enabled in test mode only for test payment, Connect, Tax, and entitlement flows. The current release is not authorized to process real money.
- We don't use third-party advertising trackers or sell your data.
- Some practices described below require additional implementation or verification before the related feature is available.
1. Defined terms
| Term | Meaning |
| --- | --- |
| "Platform," "The Vendor Lineup," "we," "us," "our" | M2 AI, LLC, operator of The Vendor Lineup at https://www.vendorlineup.com. |
| "Visitor" | Anyone browsing the Platform's public pages without an account or verified contact. |
| "Customer" | A person who verifies an email address to message a Vendor, request or book a service, whether as a verified guest or account holder. |
| "Vendor" | An independent business with a Platform storefront and account. |
| "Service provider" / "processor" | A third party we use to operate the Platform, as described in Section 3. A provider may instead process some information under its own terms and legal role where disclosed. |
| "Verified guest" | A Customer who has verified an email address but has not created a persistent account. |
2. Who this policy covers, and how it's organized
This is one Platform Privacy Policy for Visitors, Customers, and Vendors, with role-specific sections where our collection or use of data differs. If a section does not say otherwise, it applies to everyone. Section 4 (Visitors), Section 5 (Customers), and Section 6 (Vendors) describe role-specific data practices; Sections 7–18 apply across roles.
We receive information directly from you, from the Customer or Vendor with whom you interact, automatically from your device and use of the Platform, and from the services in Section 3 when they return authentication, payment, delivery, route, security, or account-status records.
3. Services we use and current release status
The current preview build (per docs/build-spec-slice-1-houston-mini-donuts.md) actually uses:
| Service | Role | Status | | --- | --- | --- | | Supabase | Postgres database, email magic-link authentication, legacy authentication records, and file storage for Vendor media | Active; verified email is the only current launch authentication gate | | Twilio Verify (through Supabase phone auth) | Remains configured for the older Production phone-auth path; no current Preview launch application path requests or validates an SMS code | Configured but inactive in the current launch application; final authentication-provider disablement and configuration cleanup remain post-promotion gates | | Vercel | Hosts and serves the application, including server functions and request logs controlled by Vercel | Active | | Stripe | Test payment credentials, PaymentIntents/SetupIntents, test Tax calculations, Connect onboarding and test payout state, and test Billing/entitlement records | Active in test mode only; no real-money processing authorized | | Resend | Delivers fixed application transactional-email templates and returns delivery identifiers/errors | Application adapter and Preview configuration active; one controlled Preview delivery and its authenticated link were proved | | Google Maps Platform (Places API (New), Address Validation API, Routes API) | Address validation/normalization and one-way route distance. Raw addresses are sent to Google for a request; the route cache stores keyed HMAC hashes and distance, not raw addresses | Server integration active; final end-to-end route-pricing proof pending | | Sentry | Error and performance monitoring. Default PII sending is disabled, session replay is disabled, and production trace sampling is configured at 10% | Active when the environment DSN is configured; final Preview event/source-map proof pending |
We do not use third-party advertising trackers or ad pixels, and we do not sell personal data or share it for cross-context behavioral advertising. The current build's own analytics are limited to a first-party journey_event record of funnel steps (ZIP entry, category/service selection, storefront view, configuration and checkout steps, booking confirmation, onboarding steps) that carries only ids and enumerated values — no free-text personal information.
In addition to the role-specific disclosures below, we may disclose information: to service providers acting for us; to Stripe and other recipients that process information under their own terms where necessary for a transaction; to the Customer or Vendor involved in the same inquiry or Booking; to professional advisers subject to confidentiality; to comply with law, legal process, or enforceable government requests; to protect rights, safety, security, and prevent fraud; or in connection with a proposed or completed financing, merger, acquisition, reorganization, or sale of all or part of the business, subject to appropriate confidentiality and notice requirements. We may use or disclose aggregated or deidentified information that is not reasonably linkable to a person and that we maintain in deidentified form.
4. Visitors
You can browse public search results, vendor storefronts, packages, policies, availability indicators, and estimated pricing without creating an account, verifying contact information, or passing a sign-in wall. Browsing the Platform does not, by itself, collect your name, email, or phone number. Standard web request data (such as IP address, for security, rate-limiting, and fraud purposes) is processed as part of operating the site; see Section 11.
Public search-oriented pages can expose stable category and launch-market information without revealing your specific query. Search terms, dates, exact addresses, saved items, and any account or Booking activity remain private and are not designed to be indexable by search engines. Hosting, security, and error systems may also process request time, page or route, browser/device type, referring page, cookie or session identifiers, and diagnostic data. Verify the exact categories against deployed Vercel, Supabase, and Sentry request/event payloads before publication.
5. Customers
What we collect
- Verified contact: an email address verified through a secure magic link via Supabase Auth, required before you first message a Vendor, save work across devices, submit a Request to Book or Custom Quote, or proceed through checkout. Legacy verified mobile numbers may remain in existing authentication or identity records, but the current launch application does not ask Customers to verify a mobile number or use SMS to sign in.
- Event details: the information you provide to discover, configure, or book a service — event ZIP, date, time, guest count, exact address (collected only once needed for eligibility, pricing, or fulfillment), and category-specific requirements.
- Messages: the content of your Platform messages with a Vendor, including any structured requests, quotes, or change proposals.
- Booking and payment records: the itemized Booking snapshot (service, package, price, policy, agreement versions, tax/fee allocation evidence), Stripe customer/payment/setup intent references, payment-method references used for an authorized later balance, and payment state. We do not store your full card or bank account number. Stripe handles those credentials. The current release uses test mode only.
- Account information, if you create one: profile details, saved event configurations, and notification preferences.
- First-party analytics events: the
journey_eventrecords described in Section 3, which do not include free-text personal information.
Why we use it
To operate and authenticate your account or guest session, protect account access and reduce fraud, connect you with Vendors you choose to contact or book, process and administer your Booking, send required transactional notices, provide support, and improve the Platform through the limited first-party analytics described above.
Who receives it
- The Vendor you message, request, or book with receives the event and contact information needed to respond to your inquiry and fulfill an accepted Booking — not more. Before booking, your direct contact details are not shared with the Vendor except through Platform messaging; a documented, approved exception applies to sharing raw contact details before confirmation. After confirmation, the Vendor receives the operational contact information needed to fulfill the event.
- Service providers and transaction recipients described in Section 3 that host, secure, or operate parts of the Platform or process the transaction. Stripe may process payment, identity, fraud, tax, and Connect information under Stripe's own legal obligations and terms as well as when acting for us.
- We do not sell your personal information to third parties or share it for cross-context behavioral advertising, and we do not disclose it to unrelated third parties for their own direct marketing.
6. Vendors
What we collect
- Business and identity information: legal business identity, authorized representative identity, private business contact information and location (including a required operational phone number that is not used as a sign-in factor), and service-area information.
- Tax and payout information: identity, bank-account information, and taxpayer certification collected through Stripe's hosted Connect onboarding flow in test mode. Stripe receives the details; we retain Stripe account identifiers and readiness/status evidence rather than full bank-account or tax-form contents.
- Storefront content: logo, media, business description, packages, pricing, and policies you choose to publish.
- Storefront media: logos and images uploaded for Vendor storefronts. Credential-document uploads and public credential badges are not enabled in the current release. If introduced, they require a separate data, security, verification, retention, notice, and appeal review before collection.
- Booking, payment, and messaging records related to the Bookings you accept and fulfill.
Why we use it
To operate the required Platform account gate, publish and operate your storefront, process Bookings and payouts, prevent fraud and abuse, and enforce this policy, the Vendor Agreement, and the Fee and Payout Disclosure. Optional credential badges are not enabled and are not a current collection purpose.
Who receives it
- Customers see your published storefront content and, after a Customer's booking or inquiry, the operational contact information needed for fulfillment. Your private business location and banking details are not shown publicly. Credential-document uploads and public badges are not enabled.
- Processors and service providers described in Section 3, including Stripe for test-mode identity, payout-readiness, tax, and payment functions.
- We do not sell your business or customer data to third parties.
7. Cookies and similar technology
We do not use third-party advertising cookies or pixels. Supabase authentication uses cookies or similar storage needed to keep a session secure. The application may also use limited local/session storage needed to preserve an in-progress journey. Sentry session replay is disabled. Complete and verify a browser storage/network inventory on the exact deployed candidate before publication; add a consent mechanism if the final inventory or launch geography requires one.
8. Messaging and moderation
Platform messages between Customers and Vendors are stored to preserve the record of what was asked or promised for a Booking. Authorized personnel may access a message only when reasonably needed for support, safety, security, fraud prevention, moderation, dispute resolution, or legal compliance. Access should be role-limited and logged where appropriate. Messages are not shared with parties outside your inquiry or Booking except for those purposes or as otherwise described in this policy. Confirm and test support-role access, access logging, attachment handling, and moderation operations before making this commitment public.
9. Notify-me / demand-registration signups
Where the Platform lets you register interest in a ZIP code or service that is not yet available, we collect the email address, ZIP code, service interest, and submission time needed to manage that request. This is a request for a future availability email, not consent to unrelated marketing. Set and implement a retention period and unsubscribe/suppression process before sending availability notices.
10. Analytics
The current build's analytics are limited to the first-party journey_event table described in Section 3: funnel-step records (which screen, which action) that use ids and enumerated values, not free text, and are not shared with a third-party analytics or advertising vendor. Any future addition of a third-party analytics tool is explicitly described in PRODUCT.md as requiring separate approved privacy review before implementation, and this document will be updated before that happens — it does not authorize such use today.
11. Vendor-sourced links, QR codes, and attribution (when this feature is enabled)
Vendor-sourced short links, QR attribution, and Sponsored attribution are not enabled in the current release, so the Platform does not currently collect those attribution records. Enabling them requires a separate privacy review, notice update, retention rule, consent classification, and implementation proof. This approved text does not authorize that future collection.
12. Data retention
We retain personal data only as long as reasonably needed for the purpose described, including account security, an active request or Booking, payment and tax records, support, fraud prevention, dispute evidence, and legal obligations. The current implemented route-distance cache expires after 30 days and stores HMAC address fingerprints and distance rather than raw addresses. Messages are append-only Booking/inquiry records. Acceptance, booking snapshot, payment, webhook, notification, entitlement, and audit records do not yet have an approved deletion schedule. Stripe, Supabase, Vercel, Twilio, Resend, Google, and Sentry also retain information under their own service configurations and legal obligations.
Closing an account or requesting deletion does not erase active bookings, money movement, disputes, security evidence, tax records, or records we must preserve. Approve and implement a category-by-category schedule, including account/auth data, Vendor records, messages, event addresses, unsuccessful checkout stages, webhooks, Sentry events, email logs, notify signups, and backups, before public launch.
13. Your choices and rights
You can review and correct available account fields and notification preferences. Optional marketing consent, if introduced, must remain separate from terms acceptance and transactional notices.
Subject to identity verification and lawful exceptions, you may ask us to: confirm whether we process your personal data; provide access or a portable copy; correct inaccuracies; delete data; or review a denial of a prior request. Where applicable, an authorized agent may submit a request with legally sufficient proof of authority. You may also state that you do not want personal data used for targeted advertising, sold, or used for qualifying profiling; we do not currently conduct those activities. We will not discriminate against you for making a request. We will respond within the period required by applicable law and explain any permitted extension, denial, and appeal method. These choices are offered to U.S. users as an operating commitment without representing that every state statute applies to M2 AI, LLC, every person, or every record. Implement a monitored request method, authorized-agent and identity verification, response timing, search/export/deletion, appeal, and request log before publication.
14. Security
We use measures designed for the current product, including authenticated and scoped database access, row-level and server-side authorization, rate limits on email magic-link requests and selected messaging actions, signature-checked webhooks, server-only third-party provider credentials, restricted file types/sizes, no Platform storage of full card or bank-account numbers, and Sentry configuration that disables default PII and session replay. No system is perfectly secure; this is not a warranty or certification claim. If a legally reportable incident occurs, we will provide notices required by applicable law. Complete the incident-response owner, processor escalation paths, evidence preservation, and jurisdictional notification runbook before public launch.
15. Children's privacy
The Vendor Lineup is a general-audience marketplace for adults. A person must be at least 18 to create an account, submit a request, or make or accept a Booking. The Platform is not directed to children under 13, and we do not knowingly collect their personal information. If we learn that we collected personal information from a child under 13, we will disable the account or flow and delete the information unless we must preserve a limited record by law or for safety/security. Add and test the 18-or-older age registration/attestation and a monitored report-and-delete process consistent with the attorney-approved audience and coverage assumptions. A material change in audience, age flow, geography, or COPPA/Texas SCOPE Act assumptions requires renewed legal approval. Terms alone do not establish compliance.
16. US-only launch and applicable state law
The initial launch is United States only, focused on Texas (Greater Houston). The Texas Data Privacy and Security Act may apply depending on M2 AI, LLC's status, processing, and exemptions; when applicable it addresses privacy notices, consumer requests and appeals, processor contracts, sensitive data, and certain assessments. Some records and people, including Vendor representatives acting in a commercial context, may be treated differently under applicable law. This approved text adopts the core request categories as an operating commitment but does not make a blanket compliance certification. Attorney approval applies to the described launch scope and data practices; any material change in processing, audience, geography, processor contracts, or sensitive-data use requires renewed privacy/legal review.
17. Changes to this policy
We may update this policy as our data practices change. We will post a new version and effective date and provide advance notice of a material change by email, an in-Platform notice, or both when applicable law or the nature of the change requires it. We will not treat a policy update alone as consent to a materially different use when consent is legally required. The public policy must show both an effective date and a last-updated date.
18. Contact
Privacy questions and requests, including access, correction, deletion, portability, and appeal requests, may be emailed to hello@vendorlineup.com or mailed to M2 AI, LLC, 2240 Murphy Road, Suite 4020, Missouri City, Texas 77459. Legal correspondence and general support questions may use the same contacts. This contact information is not a consent to a method of formal service of process that applicable law does not otherwise permit. Implement and test the monitored privacy intake, identity verification, response, appeal, escalation, and recordkeeping workflow before publication.
Cross-references: Marketplace Customer Terms · Vendor Agreement · Fee and Payout Disclosure · Marketplace Booking Terms · README