Privacy Policy

Last Updated: June 8, 2026

1. About this Privacy Policy

This Privacy Policy explains how Solvira Technology Solutions Inc., a Delaware corporation, and its affiliates that make VendiSuite™, VendiCentral™ and VendiClient™ available (collectively, the “Company,” “we,” “us,” or “our”) collect, use, disclose, transfer, retain, and protect personal information in connection with our products and services.

For purposes of this Privacy Policy, “Services” means VendiSuite™, VendiCentral™, VendiClient™, our websites, web applications, cloud platform, portals, mobile applications, APIs, documentation, support services, and related features. The exact Services available to you may depend on your subscription, your organization, your distributor or delivery provider, and the modules enabled for your account.

This Privacy Policy applies to business customers, account administrators, authorized users, website visitors, mobile app users, distributors, manufacturers, suppliers, retailers, delivery providers, customers, end users, and other individuals whose personal information is processed through the Services.

This Privacy Policy does not replace any customer agreement, order form, data processing addendum, service-level agreement, or other contract that applies to the Services. If we process personal information on behalf of a business customer, that customer may be the primary organization responsible for the personal information, and its own privacy notices may also apply.

2. Who We Are

The Services may be provided by different legal entities within the Solvira group of companies, including Solvira Technology Solutions Inc., Solvira Information Technology Services Inc., Solvira Business Solutions, and their affiliates, as applicable (the “Group”).

The Group entity responsible for your personal information may depend on the product you use, the country where your account is registered, the entity named in your order form or subscription agreement, the app store listing, or other documentation provided to you. If no specific entity is identified, the responsible entity is Solvira Techology Solutions Inc. in the USA, Solvira Business Solutions in Canada, and Solvira Information Technology Services Inc. in other countries.

Where the context requires, references to “we,” “us,” and “our” include the Group entity that provides or operates the relevant Service and other Group entities that help host, secure, support, bill for, improve, or otherwise deliver the Services.

Privacy contact: privacy@solvira.com

Mailing address:

Solvira Technology Solutions Inc.

PO Box 298

Winter Park FL 32790-0298

United States

3. Our Role in Processing Personal Information

VendiSuite™, VendiCentral™ and VendiClient™ are primarily business-to-business tools. In many cases, we process personal information on behalf of a business customer, distributor, manufacturer, delivery provider, or other organization that decides how the Services are configured and how personal information is used within its account.

Processing contextTypical privacy role
Customer Data processed in a VendiSuite™ workspaceUsually the business customer is the controller/business, and we act as its processor/service provider, subject to the customer agreement and any data processing addendum.
VendiClient™ order, invoice, delivery, service request, or payment-related data linked to a delivery provider or distributorUsually the linked delivery provider, distributor, manufacturer, or other business customer determines the purposes of processing. We process the data to provide the app and related services.
Account registration, authentication, billing administration, support, security, website analytics, product analytics, and our own marketingWe may act as an independent controller/business for these purposes, unless a written agreement says otherwise.
Third-party integrations enabled by a customer or administratorThe customer decides whether to enable the integration. The third-party provider handles data under its own terms and privacy policy, unless otherwise agreed.

If you use the Services through an employer, distributor, delivery provider, manufacturer, customer account, or other organization, that organization may be able to access, export, restrict, or delete information associated with your use of the Services. Please contact that organization if you have questions about how it uses personal information in its account.

4. Personal Information We Collect

The personal information we collect depends on the Services you use, your role, the features enabled by your organization, the integrations configured by administrators, and the information you choose to provide. We do not intentionally collect every category listed below from every user.

CategoryExamplesCommon sources
Contact, account, and professional informationName, business email address, phone number, company, title, role, customer or account number, username, account ID, language, preferences, and administrator permissions.You, your organization, administrators, distributors, delivery providers, business partners, or account setup processes.
Authentication and security informationLogin credentials or credential hashes, multi-factor authentication settings, access tokens, session data, IP address, device/browser details, account activity, audit logs, and security events.You, your device/browser, our systems, identity providers, and security tools.
Customer Data and platform recordsDistributor, manufacturer, supplier, retailer, customer, product, price, inventory, order, invoice, route, merchandising, CRM, promotion, asset, RTI, analytics, territory, support, and related business records processed through the Services.Customers, administrators, authorized users, integrations, uploads, APIs, and connected systems.
VendiClient™ order, invoice, delivery, and service informationProducts ordered, quantities, pricing shown to you, order status, delivery status, invoices, bills, credits, service requests, messages, signatures, photos, notes, and related transaction records.You, delivery providers, distributors, manufacturers, VendiSuite™ systems, connected systems, and app activity.
Documents and filesDocuments attached to orders, invoices, assets, routes, customer records, service tickets, or other records; photos; proof-of-delivery materials; service request materials; and file metadata.Users who upload or link documents and files, delivery providers, distributors, and connected systems.
Payment, billing, and subscription informationBilling contacts, invoice details, subscription plan, payment status, transaction IDs, amount, currency, payment method metadata, and limited payment information. Full card details are generally handled by Stripe or another payment processor.You, your organization, delivery providers, payment processors, and our billing systems.
Mobile app, device, and permission dataDevice model, operating system, app version, device identifiers, crash logs, diagnostic data, push notification tokens, language settings, and permission status for app features.Your mobile device, operating system, app stores, analytics tools, and our app systems.
Location-related informationDelivery addresses, service locations, route-related information, approximate location from IP address, and, where enabled and permitted, precise device location for app functionality.You, your device, delivery providers, distributors, and connected systems.
Usage, log, and cookie dataIP address, browser type, operating system, device identifiers, pages or screens viewed, actions taken, API usage, feature usage, timestamps, referring URLs, diagnostics, errors, and performance data.Your browser/device, our systems, cookies, logs, analytics tools, and security tools.
Communications and support informationEmails, chat messages, support tickets, call notes, feedback, survey responses, attachments, service request communications, push notifications, SMS messages, and related correspondence.You, your organization, delivery providers, support providers, and communications systems.
Integration dataInformation received from or sent to ERP, CRM, accounting, logistics, payment, analytics, identity, and other third-party systems enabled by a customer or administrator.Third-party services and customer-configured integrations.

Please do not submit sensitive personal information, regulated health information, payment card numbers, government identification numbers, biometric data, children’s data, or other specially regulated information to the Services unless the relevant feature, customer agreement, and privacy documentation expressly permit it.

5. How We Use Personal Information

We use personal information for the purposes described below, depending on the Services, features, and account settings involved.

[1] Stripe is a trademark of Stripe, Inc.

6. Legal Bases for Processing in the EEA, UK, and Switzerland

Where European, UK, or Swiss data protection laws apply and we act as a controller, our legal bases may include the following. Where we act as a processor/service provider for a customer, the customer is responsible for identifying the relevant legal basis for its processing.

PurposeTypical legal basis
Provide the Services, administer accounts, authenticate users, process orders or service requests, provide support, and manage billingPerformance of a contract or steps taken before entering into a contract; legitimate interests in operating a B2B platform.
Security, fraud prevention, troubleshooting, auditing, and abuse preventionLegitimate interests in protecting the Services, users, customers, and our business; legal obligations where applicable.
Product analytics, diagnostics, research, and service improvementLegitimate interests in improving and securing business software; consent where required for certain cookies or mobile permissions.
Marketing communications and promotional messagesConsent where required; legitimate interests where permitted; compliance with opt-out and unsubscribe rules.
Payment facilitation, tax, accounting, compliance, and dispute handlingPerformance of a contract, legal obligations, and legitimate interests in managing transactions and legal rights.
International transfers and Group administrationPerformance of a contract, legitimate interests, and appropriate transfer mechanisms where required.

7. How We Disclose Personal Information

We disclose personal information only as needed for the purposes described in this Privacy Policy, as directed by customers or users, or as otherwise permitted or required by law. Depending on the circumstances, disclosures may include the following:

We may use and disclose aggregated, anonymized, or de-identified information for analytics, benchmarking, research, security, product improvement, and business purposes, provided the information does not identify an individual or reveal a customer’s confidential business information.

We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising as those terms are used in certain U.S. privacy laws unless we expressly disclose that practice and provide any required choices. If advertising cookies, pixels, or similar technologies are later added, this section and the cookie choices should be reviewed and updated before launch.

8. Cookies and Similar Technologies

We and our service providers may use cookies, local storage, pixels, SDKs, analytics tools, logs, and similar technologies to operate, secure, remember preferences for, analyze, and improve the Services. The technologies we use may vary between our websites, VendiSuite™, and VendiClient™.

Technology typePurpose
Strictly necessaryRequired for login, authentication, session management, security, load balancing, user preferences, and core functionality.
Analytics and performanceHelp us understand usage, diagnose errors, measure performance, and improve features.
Functional or preferenceRemember settings such as language, region, display preferences, and account choices.
Marketing or advertising, if usedSupport marketing measurement, campaign performance, and advertising preferences. Use of these tools may require consent or opt-out choices depending on your location.

You can usually manage browser cookies through your browser settings. Where required, we will provide cookie banners, consent tools, or preference centers. Disabling cookies may affect the availability or functionality of some Services. Mobile devices may also provide settings for advertising identifiers, tracking permissions, notifications, location, camera, photos, and other app permissions.

9. Mobile App Permissions and Store Disclosures

VendiClient™ may request access to certain mobile device permissions only when relevant to enabled features. Not all versions, customers, or users will use every permission.

Permission or data typeHow it may be used
Camera, photos, and filesUsed when you choose to upload or capture documents, photos, proof-of-delivery materials, service request attachments, invoice/order attachments, or similar files.
LocationUsed where enabled for delivery, route, service-location, fraud prevention, security, or app functionality. You may be able to disable precise location in your device settings, but some features may not work properly.
Push notificationsUsed for operational notices such as order, delivery, account, service request, security, or support updates, and for promotional messages where permitted.
Device identifiers and diagnosticsUsed for authentication, app functionality, analytics, crash reporting, fraud prevention, security, and troubleshooting.

App stores may require separate privacy labels or data-safety disclosures. Those disclosures should match the actual data collected by VendiClient™ and any third-party SDKs integrated into the app. If the app’s data practices change, the app store disclosures should be updated as well.

10. Payments

We do not generally collect or store full payment card numbers through the Services. Where payment features are enabled, payments may be processed by Stripe or another third-party payment processor. The payment processor may collect payment card details, bank account information, billing information, authentication information, transaction information, fraud-prevention data, and other information needed to process the payment.

We may receive limited payment-related information, such as payment status, transaction ID, amount, currency, invoice number, billing contact, payment method type, last four digits, expiration month/year, and fraud or risk signals, as necessary to provide the Services, reconcile invoices, support users, prevent fraud, and comply with legal obligations.

Payment processors handle personal information under their own terms and privacy policies. Please review the applicable payment processor’s terms and privacy policy before submitting payment information.

11. Data Retention

We retain personal information for as long as reasonably necessary to provide the Services, maintain accounts, comply with legal obligations, resolve disputes, enforce agreements, prevent fraud or abuse, maintain security, complete transactions, and support legitimate business purposes.

Customer Data is generally retained according to the applicable customer agreement, account settings, data processing addendum, and deletion or export processes. After an account ends, data may remain in backups, archives, logs, or legal records for a limited period before deletion or de-identification according to our retention practices, unless a longer retention period is required or permitted by law.

We may retain certain records longer where necessary for tax, accounting, audit, compliance, fraud prevention, security, dispute resolution, or legal purposes. We may also retain aggregated, anonymized, or de-identified information that no longer identifies an individual.

12. International Transfers

The Services may be provided from, and personal information may be processed in, the United States, Canada, the European Economic Area, the United Kingdom, and other countries where we, our affiliates, customers, service providers, or subprocessors operate. These countries may have data protection laws that differ from those in your country.

Where required, we use appropriate safeguards for international transfers, which may include data processing agreements, standard contractual clauses, adequacy decisions, participation in recognized transfer frameworks, technical and organizational safeguards, and other lawful transfer mechanisms.

13. Security

We use administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, and disclosure. These safeguards may include access controls, authentication, logging, monitoring, encryption, secure development practices, vendor management, backups, and incident response procedures, depending on the Services and data involved.

No method of transmission, storage, hosting, or processing is completely secure. You are responsible for maintaining the confidentiality of your credentials, using available security features, configuring user permissions appropriately, and promptly notifying us of suspected unauthorized access or misuse.

14. Your Choices and Privacy Rights

Depending on your location and relationship with us, you may have rights to access, correct, update, delete, restrict, object to, or receive a copy of personal information about you. You may also have the right to withdraw consent, opt out of certain processing, appeal a decision, limit use of sensitive personal information, or lodge a complaint with a data protection authority.

To submit a privacy request, contact us at privacy@solvira.com . Please include sufficient information for us to verify and process your request. If your information is controlled by a business customer, distributor, delivery provider, manufacturer, employer, or other organization, we may refer your request to that organization or process it according to that organization’s instructions.

We will not discriminate against you for exercising privacy rights that apply to you. We may deny or limit a request where permitted by law, such as when we cannot verify your identity, the request conflicts with legal obligations, the information is controlled by a customer, or an exception applies.

15. Children’s Privacy

The Services are business-focused and are not directed to children. We do not knowingly collect personal information from children under the age required by applicable law. If you believe a child has provided personal information to us through the Services, please contact us so we can take appropriate steps.

16. Third-Party Services and Links

The Services may link to or integrate with third-party websites, applications, services, SDKs, payment processors, app stores, identity providers, analytics tools, ERP systems, CRM systems, accounting systems, logistics providers, and other third-party platforms. We are not responsible for the privacy practices of third parties. Their own terms and privacy policies apply to their processing of personal information.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our Services, legal requirements, data practices, or business operations. The updated version will be indicated by an updated “Last Updated” date. If required by law or if changes are material, we will provide additional notice, such as through the Services, email, in-app notification, or other reasonable means.

18. Contact

If you have questions, requests, complaints, or concerns about this Privacy Policy or our privacy practices, please contact us at:

Solvira Technology Solutions Inc.
Privacy and Data Protection Inquiries
PO Box 298
Winter Park FL 32790-0298
United States

privacy@solvira.com

Appendix A: Regional Privacy Notices

This appendix provides additional information for individuals in certain jurisdictions. It should be reviewed and localized before publication in any specific market.

A. EEA, United Kingdom, and Switzerland

If you are located in the European Economic Area, the United Kingdom, or Switzerland, you may have rights to access, rectify, erase, restrict, object to, or port personal data, and to withdraw consent where processing is based on consent. You may also have the right to lodge a complaint with your local supervisory authority.

Where we act as a controller, the controller is the Group entity identified in Section 2 or in the applicable agreement, app listing, or other notice. Where we act as a processor for a customer, the customer is the controller and we process personal data according to the customer agreement and any data processing addendum.

Where personal data is transferred internationally, we will use appropriate safeguards where required, such as standard contractual clauses, recognized adequacy mechanisms, transfer frameworks, and supplementary technical and organizational measures.

B. Canada

For individuals in Canada, we handle personal information in accordance with applicable Canadian privacy laws, which may include PIPEDA and substantially similar provincial privacy laws where applicable. We identify purposes for collection, use, and disclosure, limit collection to what is reasonably necessary, use appropriate safeguards, and provide access and correction rights subject to legal exceptions.

If a Canadian commercial electronic message is sent, we will provide required sender identification and unsubscribe mechanisms and will rely on consent or another permitted basis where required.

C. United States, including California

Certain U.S. state privacy laws may give residents rights to know/access, delete, correct, receive a portable copy, opt out of certain processing, limit use of sensitive personal information, and appeal privacy decisions. The rights available to you depend on your state and our role in processing the information.

Personal information categoryBusiness or commercial purposesCategories of recipients
Identifiers and contact informationAccount setup, authentication, billing, support, communications, security, customer administration, and service delivery.Group entities, business customers, administrators, delivery providers/distributors, service providers, integrations, and legal recipients.
Commercial, order, invoice, subscription, and transaction informationOrder processing, invoice management, payment facilitation, customer support, reporting, analytics, accounting, and compliance.Business customers, delivery providers/distributors, payment processors, service providers, integrations, and legal recipients.
Internet, network, device, app, and usage informationAuthentication, security, fraud prevention, troubleshooting, analytics, service improvement, and support.Group entities, security providers, analytics providers, hosting providers, support providers, and integrations.
Geolocation informationDelivery address, service location, route management, app functionality, fraud prevention, and security where enabled.Delivery providers/distributors, business customers, hosting providers, app service providers, and support providers.
Professional or employment-related informationB2B account administration, user roles, permissions, support, sales, and customer relationship management.Business customers, administrators, Group entities, service providers, and integrations.
User-generated content, documents, photos, messages, and support materialsProvide enabled features, attach files to orders/invoices/service requests, support users, maintain records, and resolve disputes.Business customers, delivery providers/distributors, service providers, integrations, and legal recipients.
Sensitive personal information, if intentionally provided or required for limited featuresWe do not seek sensitive personal information unless expressly enabled or required. If processed, it is used only for permitted purposes such as security, account access, compliance, or feature delivery.Only as necessary for the relevant feature, customer instruction, service provider support, or legal compliance.

We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising unless we expressly state otherwise and provide any required opt-out mechanism. We do not knowingly sell or share the personal information of individuals under 16.

D. Singapore, Malaysia, Pakistan, and Other Jurisdictions

The Services may be used in additional countries. Local privacy, data protection, marketing, telecommunications, consumer, employment, sector-specific, or data localization laws may apply depending on the country, product, customer, data subjects, and data flows involved. Before launching or materially expanding the Services in a new jurisdiction, the Company should confirm whether local notices, consents, contracts, registrations, representatives, breach notices, transfer mechanisms, or regulator filings are required.