Privacy Policy
Last Updated: June 8, 2026
1. About this Privacy Policy
This Privacy Policy explains how Solvira Technology Solutions Inc., a Delaware corporation, and its affiliates that make VendiSuite™, VendiCentral™ and VendiClient™ available (collectively, the “Company,” “we,” “us,” or “our”) collect, use, disclose, transfer, retain, and protect personal information in connection with our products and services.
For purposes of this Privacy Policy, “Services” means VendiSuite™, VendiCentral™, VendiClient™, our websites, web applications, cloud platform, portals, mobile applications, APIs, documentation, support services, and related features. The exact Services available to you may depend on your subscription, your organization, your distributor or delivery provider, and the modules enabled for your account.
This Privacy Policy applies to business customers, account administrators, authorized users, website visitors, mobile app users, distributors, manufacturers, suppliers, retailers, delivery providers, customers, end users, and other individuals whose personal information is processed through the Services.
This Privacy Policy does not replace any customer agreement, order form, data processing addendum, service-level agreement, or other contract that applies to the Services. If we process personal information on behalf of a business customer, that customer may be the primary organization responsible for the personal information, and its own privacy notices may also apply.
2. Who We Are
The Services may be provided by different legal entities within the Solvira group of companies, including Solvira Technology Solutions Inc., Solvira Information Technology Services Inc., Solvira Business Solutions, and their affiliates, as applicable (the “Group”).
The Group entity responsible for your personal information may depend on the product you use, the country where your account is registered, the entity named in your order form or subscription agreement, the app store listing, or other documentation provided to you. If no specific entity is identified, the responsible entity is Solvira Techology Solutions Inc. in the USA, Solvira Business Solutions in Canada, and Solvira Information Technology Services Inc. in other countries.
Where the context requires, references to “we,” “us,” and “our” include the Group entity that provides or operates the relevant Service and other Group entities that help host, secure, support, bill for, improve, or otherwise deliver the Services.
Privacy contact: privacy@solvira.com
Mailing address:
Solvira Technology Solutions Inc.
PO Box 298
Winter Park FL 32790-0298
United States
3. Our Role in Processing Personal Information
VendiSuite™, VendiCentral™ and VendiClient™ are primarily business-to-business tools. In many cases, we process personal information on behalf of a business customer, distributor, manufacturer, delivery provider, or other organization that decides how the Services are configured and how personal information is used within its account.
| Processing context | Typical privacy role |
| Customer Data processed in a VendiSuite™ workspace | Usually the business customer is the controller/business, and we act as its processor/service provider, subject to the customer agreement and any data processing addendum. |
| VendiClient™ order, invoice, delivery, service request, or payment-related data linked to a delivery provider or distributor | Usually the linked delivery provider, distributor, manufacturer, or other business customer determines the purposes of processing. We process the data to provide the app and related services. |
| Account registration, authentication, billing administration, support, security, website analytics, product analytics, and our own marketing | We may act as an independent controller/business for these purposes, unless a written agreement says otherwise. |
| Third-party integrations enabled by a customer or administrator | The customer decides whether to enable the integration. The third-party provider handles data under its own terms and privacy policy, unless otherwise agreed. |
If you use the Services through an employer, distributor, delivery provider, manufacturer, customer account, or other organization, that organization may be able to access, export, restrict, or delete information associated with your use of the Services. Please contact that organization if you have questions about how it uses personal information in its account.
4. Personal Information We Collect
The personal information we collect depends on the Services you use, your role, the features enabled by your organization, the integrations configured by administrators, and the information you choose to provide. We do not intentionally collect every category listed below from every user.
| Category | Examples | Common sources |
| Contact, account, and professional information | Name, business email address, phone number, company, title, role, customer or account number, username, account ID, language, preferences, and administrator permissions. | You, your organization, administrators, distributors, delivery providers, business partners, or account setup processes. |
| Authentication and security information | Login credentials or credential hashes, multi-factor authentication settings, access tokens, session data, IP address, device/browser details, account activity, audit logs, and security events. | You, your device/browser, our systems, identity providers, and security tools. |
| Customer Data and platform records | Distributor, manufacturer, supplier, retailer, customer, product, price, inventory, order, invoice, route, merchandising, CRM, promotion, asset, RTI, analytics, territory, support, and related business records processed through the Services. | Customers, administrators, authorized users, integrations, uploads, APIs, and connected systems. |
| VendiClient™ order, invoice, delivery, and service information | Products ordered, quantities, pricing shown to you, order status, delivery status, invoices, bills, credits, service requests, messages, signatures, photos, notes, and related transaction records. | You, delivery providers, distributors, manufacturers, VendiSuite™ systems, connected systems, and app activity. |
| Documents and files | Documents attached to orders, invoices, assets, routes, customer records, service tickets, or other records; photos; proof-of-delivery materials; service request materials; and file metadata. | Users who upload or link documents and files, delivery providers, distributors, and connected systems. |
| Payment, billing, and subscription information | Billing contacts, invoice details, subscription plan, payment status, transaction IDs, amount, currency, payment method metadata, and limited payment information. Full card details are generally handled by Stripe or another payment processor. | You, your organization, delivery providers, payment processors, and our billing systems. |
| Mobile app, device, and permission data | Device model, operating system, app version, device identifiers, crash logs, diagnostic data, push notification tokens, language settings, and permission status for app features. | Your mobile device, operating system, app stores, analytics tools, and our app systems. |
| Location-related information | Delivery addresses, service locations, route-related information, approximate location from IP address, and, where enabled and permitted, precise device location for app functionality. | You, your device, delivery providers, distributors, and connected systems. |
| Usage, log, and cookie data | IP address, browser type, operating system, device identifiers, pages or screens viewed, actions taken, API usage, feature usage, timestamps, referring URLs, diagnostics, errors, and performance data. | Your browser/device, our systems, cookies, logs, analytics tools, and security tools. |
| Communications and support information | Emails, chat messages, support tickets, call notes, feedback, survey responses, attachments, service request communications, push notifications, SMS messages, and related correspondence. | You, your organization, delivery providers, support providers, and communications systems. |
| Integration data | Information received from or sent to ERP, CRM, accounting, logistics, payment, analytics, identity, and other third-party systems enabled by a customer or administrator. | Third-party services and customer-configured integrations. |
Please do not submit sensitive personal information, regulated health information, payment card numbers, government identification numbers, biometric data, children’s data, or other specially regulated information to the Services unless the relevant feature, customer agreement, and privacy documentation expressly permit it.
5. How We Use Personal Information
We use personal information for the purposes described below, depending on the Services, features, and account settings involved.
- Provide, operate, maintain, host, authenticate, secure, troubleshoot, and support the Services.
- Create and administer accounts, organizations, roles, permissions, subscriptions, invoices, and customer relationships.
- Enable core product functionality, such as order management, inventory management, pricing, CRM, analytics, asset tracking and management, RTI tracking and management, promotions, route management, merchandising, document linking, reporting, and related current or future platform features.
- Process orders, invoices, delivery records, service requests, support requests, communications, and other transactions submitted through VendiClient™ or related customer-enabled workflows.
- Connect the Services with customer-enabled integrations, APIs, identity providers, payment processors, ERP systems, CRM systems, accounting systems, logistics providers, and other third-party services.
- Facilitate payments or payment status updates through Stripe [1] or another payment processor, where enabled.
- Send operational, transactional, administrative, security, billing, support, and service-related communications.
- Send marketing or promotional communications where permitted by law and your communication preferences.
- Analyze usage, improve performance, develop new features, measure adoption, conduct research, create aggregated or de-identified analytics, and improve the Services.
- Protect the Services, users, customers, and third parties against fraud, abuse, security incidents, misuse, unauthorized access, and unlawful activity.
- Comply with legal obligations, enforce agreements, resolve disputes, respond to lawful requests, and protect rights, property, and safety.
[1] Stripe is a trademark of Stripe, Inc.
6. Legal Bases for Processing in the EEA, UK, and Switzerland
Where European, UK, or Swiss data protection laws apply and we act as a controller, our legal bases may include the following. Where we act as a processor/service provider for a customer, the customer is responsible for identifying the relevant legal basis for its processing.
| Purpose | Typical legal basis |
| Provide the Services, administer accounts, authenticate users, process orders or service requests, provide support, and manage billing | Performance of a contract or steps taken before entering into a contract; legitimate interests in operating a B2B platform. |
| Security, fraud prevention, troubleshooting, auditing, and abuse prevention | Legitimate interests in protecting the Services, users, customers, and our business; legal obligations where applicable. |
| Product analytics, diagnostics, research, and service improvement | Legitimate interests in improving and securing business software; consent where required for certain cookies or mobile permissions. |
| Marketing communications and promotional messages | Consent where required; legitimate interests where permitted; compliance with opt-out and unsubscribe rules. |
| Payment facilitation, tax, accounting, compliance, and dispute handling | Performance of a contract, legal obligations, and legitimate interests in managing transactions and legal rights. |
| International transfers and Group administration | Performance of a contract, legitimate interests, and appropriate transfer mechanisms where required. |
7. How We Disclose Personal Information
We disclose personal information only as needed for the purposes described in this Privacy Policy, as directed by customers or users, or as otherwise permitted or required by law. Depending on the circumstances, disclosures may include the following:
- Within the Group: to affiliates and related entities that help provide, host, support, bill for, secure, analyze, improve, or administer the Services.
- To your organization and its administrators: if you use the Services through a customer account, administrators may access account information, activity, content, usage, orders, documents, and other data associated with that account.
- To distributors, manufacturers, delivery providers, suppliers, retailers, customers, or other business partners: when needed to provide the Services, complete an order, manage a route, support a promotion, handle an invoice or credit, process a service request, or otherwise support the business relationship configured in the Services.
- To service providers and subprocessors: such as cloud hosting providers, security providers, customer support tools, analytics providers, communications providers, payment processors, identity providers, development tools, and professional service providers.
- To payment processors: such as Stripe, where payments or payment-related features are enabled. Stripe and similar processors handle payment information under their own terms and privacy policies.
- To third-party integrations: when a customer, administrator, or authorized user enables or uses integrations with ERP, CRM, accounting, logistics, payment, analytics, identity, or other systems.
- For legal, compliance, safety, and enforcement purposes: to comply with law, respond to lawful requests, enforce agreements, prevent fraud or security incidents, and protect rights, property, and safety.
- In business transactions: in connection with a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar business transaction.
- With professional advisors: such as lawyers, auditors, insurers, accountants, consultants, and banks.
- With your consent or at your direction: where you authorize a disclosure or use a feature that involves sharing information.
We may use and disclose aggregated, anonymized, or de-identified information for analytics, benchmarking, research, security, product improvement, and business purposes, provided the information does not identify an individual or reveal a customer’s confidential business information.
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising as those terms are used in certain U.S. privacy laws unless we expressly disclose that practice and provide any required choices. If advertising cookies, pixels, or similar technologies are later added, this section and the cookie choices should be reviewed and updated before launch.
8. Cookies and Similar Technologies
We and our service providers may use cookies, local storage, pixels, SDKs, analytics tools, logs, and similar technologies to operate, secure, remember preferences for, analyze, and improve the Services. The technologies we use may vary between our websites, VendiSuite™, and VendiClient™.
| Technology type | Purpose |
| Strictly necessary | Required for login, authentication, session management, security, load balancing, user preferences, and core functionality. |
| Analytics and performance | Help us understand usage, diagnose errors, measure performance, and improve features. |
| Functional or preference | Remember settings such as language, region, display preferences, and account choices. |
| Marketing or advertising, if used | Support marketing measurement, campaign performance, and advertising preferences. Use of these tools may require consent or opt-out choices depending on your location. |
You can usually manage browser cookies through your browser settings. Where required, we will provide cookie banners, consent tools, or preference centers. Disabling cookies may affect the availability or functionality of some Services. Mobile devices may also provide settings for advertising identifiers, tracking permissions, notifications, location, camera, photos, and other app permissions.
9. Mobile App Permissions and Store Disclosures
VendiClient™ may request access to certain mobile device permissions only when relevant to enabled features. Not all versions, customers, or users will use every permission.
| Permission or data type | How it may be used |
| Camera, photos, and files | Used when you choose to upload or capture documents, photos, proof-of-delivery materials, service request attachments, invoice/order attachments, or similar files. |
| Location | Used where enabled for delivery, route, service-location, fraud prevention, security, or app functionality. You may be able to disable precise location in your device settings, but some features may not work properly. |
| Push notifications | Used for operational notices such as order, delivery, account, service request, security, or support updates, and for promotional messages where permitted. |
| Device identifiers and diagnostics | Used for authentication, app functionality, analytics, crash reporting, fraud prevention, security, and troubleshooting. |
App stores may require separate privacy labels or data-safety disclosures. Those disclosures should match the actual data collected by VendiClient™ and any third-party SDKs integrated into the app. If the app’s data practices change, the app store disclosures should be updated as well.
10. Payments
We do not generally collect or store full payment card numbers through the Services. Where payment features are enabled, payments may be processed by Stripe or another third-party payment processor. The payment processor may collect payment card details, bank account information, billing information, authentication information, transaction information, fraud-prevention data, and other information needed to process the payment.
We may receive limited payment-related information, such as payment status, transaction ID, amount, currency, invoice number, billing contact, payment method type, last four digits, expiration month/year, and fraud or risk signals, as necessary to provide the Services, reconcile invoices, support users, prevent fraud, and comply with legal obligations.
Payment processors handle personal information under their own terms and privacy policies. Please review the applicable payment processor’s terms and privacy policy before submitting payment information.
11. Data Retention
We retain personal information for as long as reasonably necessary to provide the Services, maintain accounts, comply with legal obligations, resolve disputes, enforce agreements, prevent fraud or abuse, maintain security, complete transactions, and support legitimate business purposes.
Customer Data is generally retained according to the applicable customer agreement, account settings, data processing addendum, and deletion or export processes. After an account ends, data may remain in backups, archives, logs, or legal records for a limited period before deletion or de-identification according to our retention practices, unless a longer retention period is required or permitted by law.
We may retain certain records longer where necessary for tax, accounting, audit, compliance, fraud prevention, security, dispute resolution, or legal purposes. We may also retain aggregated, anonymized, or de-identified information that no longer identifies an individual.
12. International Transfers
The Services may be provided from, and personal information may be processed in, the United States, Canada, the European Economic Area, the United Kingdom, and other countries where we, our affiliates, customers, service providers, or subprocessors operate. These countries may have data protection laws that differ from those in your country.
Where required, we use appropriate safeguards for international transfers, which may include data processing agreements, standard contractual clauses, adequacy decisions, participation in recognized transfer frameworks, technical and organizational safeguards, and other lawful transfer mechanisms.
13. Security
We use administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, and disclosure. These safeguards may include access controls, authentication, logging, monitoring, encryption, secure development practices, vendor management, backups, and incident response procedures, depending on the Services and data involved.
No method of transmission, storage, hosting, or processing is completely secure. You are responsible for maintaining the confidentiality of your credentials, using available security features, configuring user permissions appropriately, and promptly notifying us of suspected unauthorized access or misuse.
14. Your Choices and Privacy Rights
Depending on your location and relationship with us, you may have rights to access, correct, update, delete, restrict, object to, or receive a copy of personal information about you. You may also have the right to withdraw consent, opt out of certain processing, appeal a decision, limit use of sensitive personal information, or lodge a complaint with a data protection authority.
- Account information: You may be able to access or update certain profile information through your account settings.
- Marketing: You may opt out of promotional emails using the unsubscribe link in the message or by contacting us. You may still receive transactional, security, billing, service, or administrative messages.
- SMS and electronic messages: Where required, we will send commercial electronic messages only with appropriate consent or another lawful basis and will provide required identification and unsubscribe mechanisms.
- Push notifications: You can usually manage push notifications through your device settings or app settings.
- Cookies: You can manage many cookies through your browser settings and any cookie preference tool we may provide.
- Mobile permissions: You can usually manage camera, photo, file, location, and notification permissions through your device settings.
To submit a privacy request, contact us at privacy@solvira.com . Please include sufficient information for us to verify and process your request. If your information is controlled by a business customer, distributor, delivery provider, manufacturer, employer, or other organization, we may refer your request to that organization or process it according to that organization’s instructions.
We will not discriminate against you for exercising privacy rights that apply to you. We may deny or limit a request where permitted by law, such as when we cannot verify your identity, the request conflicts with legal obligations, the information is controlled by a customer, or an exception applies.
15. Children’s Privacy
The Services are business-focused and are not directed to children. We do not knowingly collect personal information from children under the age required by applicable law. If you believe a child has provided personal information to us through the Services, please contact us so we can take appropriate steps.
16. Third-Party Services and Links
The Services may link to or integrate with third-party websites, applications, services, SDKs, payment processors, app stores, identity providers, analytics tools, ERP systems, CRM systems, accounting systems, logistics providers, and other third-party platforms. We are not responsible for the privacy practices of third parties. Their own terms and privacy policies apply to their processing of personal information.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our Services, legal requirements, data practices, or business operations. The updated version will be indicated by an updated “Last Updated” date. If required by law or if changes are material, we will provide additional notice, such as through the Services, email, in-app notification, or other reasonable means.
18. Contact
If you have questions, requests, complaints, or concerns about this Privacy Policy or our privacy practices, please contact us at:
Solvira Technology Solutions Inc.
Privacy and Data Protection Inquiries
PO Box 298
Winter Park FL 32790-0298
United States
privacy@solvira.com
Appendix A: Regional Privacy Notices
This appendix provides additional information for individuals in certain jurisdictions. It should be reviewed and localized before publication in any specific market.
A. EEA, United Kingdom, and Switzerland
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you may have rights to access, rectify, erase, restrict, object to, or port personal data, and to withdraw consent where processing is based on consent. You may also have the right to lodge a complaint with your local supervisory authority.
Where we act as a controller, the controller is the Group entity identified in Section 2 or in the applicable agreement, app listing, or other notice. Where we act as a processor for a customer, the customer is the controller and we process personal data according to the customer agreement and any data processing addendum.
Where personal data is transferred internationally, we will use appropriate safeguards where required, such as standard contractual clauses, recognized adequacy mechanisms, transfer frameworks, and supplementary technical and organizational measures.
B. Canada
For individuals in Canada, we handle personal information in accordance with applicable Canadian privacy laws, which may include PIPEDA and substantially similar provincial privacy laws where applicable. We identify purposes for collection, use, and disclosure, limit collection to what is reasonably necessary, use appropriate safeguards, and provide access and correction rights subject to legal exceptions.
If a Canadian commercial electronic message is sent, we will provide required sender identification and unsubscribe mechanisms and will rely on consent or another permitted basis where required.
C. United States, including California
Certain U.S. state privacy laws may give residents rights to know/access, delete, correct, receive a portable copy, opt out of certain processing, limit use of sensitive personal information, and appeal privacy decisions. The rights available to you depend on your state and our role in processing the information.
| Personal information category | Business or commercial purposes | Categories of recipients |
| Identifiers and contact information | Account setup, authentication, billing, support, communications, security, customer administration, and service delivery. | Group entities, business customers, administrators, delivery providers/distributors, service providers, integrations, and legal recipients. |
| Commercial, order, invoice, subscription, and transaction information | Order processing, invoice management, payment facilitation, customer support, reporting, analytics, accounting, and compliance. | Business customers, delivery providers/distributors, payment processors, service providers, integrations, and legal recipients. |
| Internet, network, device, app, and usage information | Authentication, security, fraud prevention, troubleshooting, analytics, service improvement, and support. | Group entities, security providers, analytics providers, hosting providers, support providers, and integrations. |
| Geolocation information | Delivery address, service location, route management, app functionality, fraud prevention, and security where enabled. | Delivery providers/distributors, business customers, hosting providers, app service providers, and support providers. |
| Professional or employment-related information | B2B account administration, user roles, permissions, support, sales, and customer relationship management. | Business customers, administrators, Group entities, service providers, and integrations. |
| User-generated content, documents, photos, messages, and support materials | Provide enabled features, attach files to orders/invoices/service requests, support users, maintain records, and resolve disputes. | Business customers, delivery providers/distributors, service providers, integrations, and legal recipients. |
| Sensitive personal information, if intentionally provided or required for limited features | We do not seek sensitive personal information unless expressly enabled or required. If processed, it is used only for permitted purposes such as security, account access, compliance, or feature delivery. | Only as necessary for the relevant feature, customer instruction, service provider support, or legal compliance. |
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising unless we expressly state otherwise and provide any required opt-out mechanism. We do not knowingly sell or share the personal information of individuals under 16.
D. Singapore, Malaysia, Pakistan, and Other Jurisdictions
The Services may be used in additional countries. Local privacy, data protection, marketing, telecommunications, consumer, employment, sector-specific, or data localization laws may apply depending on the country, product, customer, data subjects, and data flows involved. Before launching or materially expanding the Services in a new jurisdiction, the Company should confirm whether local notices, consents, contracts, registrations, representatives, breach notices, transfer mechanisms, or regulator filings are required.