What Venduex stores, why, and who else touches it. Last updated 25 July 2026.
Used to sign you in and to send account email. If you sign in with Google we receive your email address and basic profile (name and picture) from Google — nothing else, and we never gain access to your Google account itself.
The read-only keys you choose to connect. They are encrypted with AES-256-GCM before being stored, are never sent to a browser, and are never written to logs. They are decrypted only by our sync worker, only to read your bid data from the auction site. You can delete them at any time by disconnecting a site, and you can revoke them independently on the auction site itself.
The bids, results and prices we read from the sites you connect, plus anything you enter yourself such as budget caps. This is the product — it's what your desk displays.
Page views and referrers via Vercel Web Analytics, which is cookie-free and does not build a profile of you across sites. Server logs record request metadata for a short period for security and debugging.
Venduex calls read endpoints only. There is no code path that can place, raise, or cancel a bid on your behalf.
Your bids, credentials and history are not sold, rented, shared with other users, or used for advertising. Aggregate public auction data shown on the market board comes from the auction sites, not from users.
Each processes data solely to run Venduex. The auction sites you connect receive API requests from us on your behalf, under their own terms.
Disconnecting a site deletes its encrypted credential immediately. Ask us to delete your account and we remove your account, credentials, positions and history. You can export your own data at any time through the read-only API in Settings.
We keep your auction history for as long as your account exists, because its value is that it accumulates. Deleted credentials are gone at once, not archived.
Questions, deletion requests, or anything else: email hello@venduex.com.