Privacy Policy
Last updated: September 6, 2026
Who we are
anVendor is operated by a sole trader established in Spain, who is the data controller for the information described in this policy. The full registration details — legal name, VAT number, and registered address — are below.
Available to signed-in users. anVendor is run by a sole trader, so these details are personal data and we keep them off the public page.
For anything to do with privacy, including any request under this policy, write to privacy@anvendor.com. For everything else, write to support@anvendor.com.
This policy is in three parts. Part A covers information about you — as a visitor to this site, or as someone with an anVendor account. Part B covers personal information that may appear inside the dataset anVendor searches, which is a separate question and the one most services in this market leave unanswered. It includes how to have such information corrected or removed, whether or not you are a customer. Part C applies to both.
Your use of anVendor is also governed by our Terms of Service and, for anything you pay for, our Refund Policy.
Part A
Information about you
This part covers information about you as a visitor to our website or as an account holder. For this information we are the data controller.
A1. Information you give us
- Account details — your email address and a password. Your password is never stored: we keep only an Argon2 hash of it, which cannot be reversed back into the password.
- Sign-in through Google or LinkedIn — if you choose this instead of a password, we receive your email address, your name as held by that provider, and the identifier that provider uses for you. We never receive your password for those accounts. We store the identifier so that we recognise you on your next sign-in.
- Correspondence — anything you send us by email, and our replies.
- Payment details are not in this list. You give those to Stripe, not to us. See A4.
A2. Information created when you use anVendor
- Your searches — the domain or service you searched for, when you searched, whether the answer came from our existing records or from a new lookup, and the result. This is your search history; you can read it, export it, and delete it from your account.
- Usage counters — the number of searches and lookups you have used in the current period, so that we can apply your plan's allowances.
- Sign-in records — for each session we record the IP address you signed in from, the approximate location derived from that address by our hosting provider (country and city only — we do not use GPS or any precise location), and your browser's user-agent string. This exists so that you and we can spot account access that does not look like you.
- Server and security logs — short-lived records of requests, including IP address, used to keep the service running, apply rate limits, and detect automated abuse.
A3. Cookies and analytics
anVendor sets two cookies. Both are strictly necessary — the service cannot work without them — and neither is used to track you.
- av_session — holds an opaque, randomly generated session identifier and nothing else. It is set only after you sign in, is marked httpOnly so that scripts cannot read it, and lasts at most 30 days.
- av_oauth_state — set only while a Google or LinkedIn sign-in is in progress, lasts a few minutes, and exists to protect that sign-in against cross-site request forgery.
For product analytics we use Vercel Web Analytics, which is cookieless: it sets no cookies, does not use device fingerprinting, and does not follow you across other websites. We also record which features are clicked, as counts rather than as a profile of you.
We do not use advertising cookies, retargeting pixels, session-replay tools, or third-party marketing trackers, and we do not embed any social media tracking. There is therefore no advertising consent for you to manage.
A4. Payments
Stripe is the merchant of record for every purchase on anVendor, through its Managed Payments service. That means Stripe, not us, is the seller for your transaction and is responsible for taking payment, issuing the invoice, and handling sales tax and VAT. Stripe handles these purchases under its Link brand, which is what you will see on your statement and on your receipts.
You enter your card or other payment details directly with Stripe. Those details never reach our servers and we never store them. What Stripe passes back to us is limited to: an identifier for you as a Stripe customer, the billing email address you used (which may differ from your anVendor account email), the status and current period of your subscription, and confirmation of any one-time purchase. Stripe's own privacy notice governs what Stripe does with your payment information.
A5. Why we use this information, and our legal basis
Where the UK GDPR or EU GDPR applies, we rely on the following legal bases.
- Running the service — accepting your searches, returning results, keeping your history, applying your plan's allowances. Basis: performance of our contract with you.
- Creating and securing your account, including verifying your email address, recovering your password, and managing your sessions. Basis: performance of our contract with you.
- Preventing fraud, abuse, credential stuffing, and automated extraction of the service; rate limiting; keeping sign-in records. Basis: our legitimate interests in keeping anVendor available, secure, and fairly metered.
- Taking payment and keeping accounting records. Basis: performance of our contract with you, and compliance with a legal obligation.
- Sending you service, security, and billing notices. These are not marketing and you cannot opt out of them while you hold an account. Basis: performance of our contract with you.
- Sending you product news and marketing email. Basis: your consent, which you can withdraw at any time using the unsubscribe link or by writing to us.
- Understanding which features are used, in aggregate. Basis: our legitimate interests in improving the service.
- Responding to lawful requests from authorities, and establishing, exercising, or defending legal claims. Basis: compliance with a legal obligation, and our legitimate interests.
A6. Who we share it with
We use a small number of service providers to run anVendor. Each processes personal information only on our instructions, under a written contract. They are:
- Vercel — application hosting and cookieless web analytics. United States.
- Supabase — the managed PostgreSQL database that holds accounts, sessions, and search history. United States.
- Hetzner Online GmbH — servers that run our lookup infrastructure. Germany.
- Stripe — merchant of record: payment processing, invoicing, and tax. Ireland and the United States.
- Resend — delivery of transactional email such as address verification, password recovery, and security notices. United States.
- Google and LinkedIn — only if you choose to sign in with one of them, and only for that sign-in.
What we do not do
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We do not license, rent, or trade your account information or your search history. We do not use your searches to train machine-learning models for ourselves or for anyone else, and we do not make your search history available to other customers in any form, aggregated or otherwise.
Other disclosures
We will disclose information where we are legally required to, where it is necessary to establish or defend a legal claim, or where there is an urgent risk to someone's safety. We review any such request for validity before responding, and we will tell you about it unless we are prohibited from doing so. If anVendor is involved in a merger, acquisition, or sale of assets, information may transfer to the acquirer, who will remain bound by this policy or give you notice before changing it.
A7. How long we keep it
- Your account record — for as long as your account is open, and deleted within 30 days of you closing it, except for anything we must keep longer by law.
- Sign-in records (IP address, approximate location, user-agent) — only for the life of the session they belong to. They are deleted when you sign out or the session expires, which is at most 30 days.
- Your search history — for as long as your account is open. You can delete entries yourself, and export a copy first if you want to keep one.
- Email verification tokens — single-use, expiring after 24 hours. We store a SHA-256 hash of the token rather than the token itself.
- Password reset tokens — single-use, expiring after 60 minutes. We store a SHA-256 hash of the token rather than the token itself.
- Billing and tax records — held by Stripe as merchant of record for as long as their tax obligations require. We keep the subscription status record for as long as we need it for accounting and to resolve any dispute.
- Server and security logs — short-lived, and kept only as long as they are useful for the security purpose that created them.
- Records of administrative actions taken on accounts — kept as a security audit trail so that changes to accounts remain accountable.
A8. Your rights
If you are in the UK, EU, or EEA
You have the right to obtain a copy of the personal information we hold about you; to have inaccurate information corrected; to have information erased; to restrict how we process it; to receive it in a portable, machine-readable format; to object to processing we carry out on the basis of legitimate interests, including at any time and for any reason where the processing is for direct marketing; and to withdraw consent where we rely on it. Exercise any of these by writing to privacy@anvendor.com. We respond within one month. We do not charge for this, and we will not treat you any differently for asking. You also have the right to complain to your national data protection authority, though we would rather you gave us the chance to put things right first.
If you are in California
You have the right to know what personal information we collect, use, and disclose; to request deletion or correction; to opt out of the sale or sharing of personal information; to limit the use of sensitive personal information; and not to be discriminated against for exercising any of these. We have not sold or shared personal information in the preceding twelve months, and we do not collect sensitive personal information as that term is defined by California law, so there is nothing for you to opt out of or limit — but you can still make a request to know, delete, or correct at privacy@anvendor.com. You may use an authorised agent, and we will verify the request before acting on it.
Wherever you are
If your local law gives you rights that are not listed here, tell us and we will honour them. Write to privacy@anvendor.com.
Part B
Personal information in the anVendor dataset
This part is different. It is not about your account — it is about information that may relate to you, or to a business you run, appearing inside the records anVendor searches. Most services of this kind never explain this. We think you should be able to find out what is held, and have it corrected or removed, without holding an account with us.
B1. What the dataset is
anVendor is a subscription search service. It answers two questions: which companies hold a given subscription, and which services a company subscribes to. The dataset behind it is organised around companies and the internet domains they operate. It is a record of commercial relationships between businesses, not a record of people.
B2. Company subscription information
anVendor uses proprietary methods to determine company subscriptions. This policy explains how we handle personal information that may relate to a company record and the rights available to anyone concerned.
We process only information that we are lawfully entitled to use, for the purposes described in this policy.
B3. When personal information ends up in the dataset
The dataset is company-level by design, and in most records there is no personal information at all. It can nevertheless appear, usually for one of two reasons:
- The domain belongs to a sole trader, a freelancer, or a one-person company, so the business and the person are effectively the same and the company record is also information about an individual.
- Business identifying information attached to a company record may relate to a person, such as the name of someone representing that business.
We do not deliberately construct profiles of individuals. We do not collect special category data — information revealing health, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, sex life or sexual orientation, or genetic or biometric data — and we do not collect criminal offence data. We do not collect information about children.
B4. Our legal basis, and how we weighed it
Where dataset information is personal information, we rely on our legitimate interests under Article 6(1)(f) of the GDPR. The interest is providing business-to-business market and technology intelligence to our customers, which is a recognised and lawful commercial purpose.
We have weighed that interest against your interests and rights, and recorded the result. The factors that matter: the information concerns a business context rather than private life; it is limited to what is needed to identify a company and its service usage, and does not extend to personal characteristics; it is not combined with data about your private behaviour; it is not used to make any automated decision that produces a legal or similarly significant effect about you; it is disclosed to business customers under contractual restrictions, not published openly; and you can object at any time under B6, at which point we stop unless we can show compelling grounds that override your rights. We will provide the balancing assessment on request.
B5. Telling you the dataset exists
Because we did not collect this information from you directly, Article 14 of the GDPR requires us to make this notice available to you rather than contact each person individually — contacting everyone would be impossible at this scale and would itself require us to gather far more personal information than we hold. Part B is that notice.
If you ask, we will tell you what the dataset holds in relation to you and the general categories of source, to the extent that answering does not oblige us to disclose our method — which is a trade secret and is protected from disclosure for that reason — or reveal information about another person. Write to privacy@anvendor.com.
B6. Objection, correction, and removal
Write to privacy@anvendor.com. Tell us the domain or company name concerned and enough detail for us to find the record, and say which of the following you want:
- Correction — the record says something inaccurate and you want it fixed.
- Suppression — you want the record withheld from search results.
- Removal — you want personal information taken out of the record, or the record deleted.
- Objection — you object to us processing the information at all.
You do not need an anVendor account to make any of these requests, and we do not charge for them. We acknowledge receipt promptly and act within one month, extending only where a request is genuinely complex, in which case we will tell you why. We may ask for enough information to satisfy ourselves that the request is genuine and that you are entitled to make it — we will not ask for more than that.
Where we act on a suppression or removal request, we also record it so that the record is not simply re-created the next time our processing runs. A removal that quietly undoes itself is not a removal.
B7. Accuracy of the dataset
Dataset records are derived, not declared. A record may be incomplete, out of date, inferred, or wrong, and the absence of a record is not evidence that a company does not hold a subscription. We do not warrant the accuracy or completeness of any record, and neither we nor our customers should treat one as a statement of fact about a company. If you tell us a record is wrong, we will correct it under B6 — but the right place to resolve a commercial question is with the company concerned, not with us.
Part C
Provisions that apply to both
C1. Security
- All traffic to and from anVendor is encrypted in transit with TLS, and connections to our database are encrypted and certificate-verified.
- Passwords are stored as Argon2 hashes, never in a form that can be turned back into the password.
- Session tokens are opaque random values held in an httpOnly cookie, so they are not readable by scripts in your browser.
- Database access is least-privilege: the application's database role can read and write data but cannot alter the schema.
- Payment card data never enters our systems at all, because Stripe handles it.
- Administrative actions on accounts are written to an audit trail.
No system is perfectly secure and we will not claim otherwise. If we become aware of a breach affecting your personal information, we will notify the relevant supervisory authority and, where the law requires it, you.
C2. International transfers
anVendor is operated from a small number of locations and several of our providers are in the United States, as listed in A6. Where personal information leaves the UK or the EEA, we rely on the UK and EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, and on the EU–US and UK–US Data Privacy Framework where the provider concerned is certified under it. You can ask us for details of the safeguards that apply to a particular transfer.
C3. Automated decision-making
We do not make decisions about you by automated means alone that produce legal effects or similarly significantly affect you. The only automated logic that affects your access to anVendor is plan metering and our automated abuse controls, and if either produces a result you think is wrong you can have it reviewed by a person by writing to support@anvendor.com.
C4. Children
anVendor is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, tell us and we will delete it.
C5. Changes to this policy
We may update this policy. When we do, we revise the date at the top of the page. Where a change is material — a new purpose, a new category of recipient, or a change to your rights — we will tell you by email or in the product before it takes effect, and we will not apply it retroactively to information already collected under the previous version.
C6. How to contact us
- Privacy matters, and every request made under this policy — including Part B corrections, suppressions, removals, and objections: privacy@anvendor.com
- Everything else: support@anvendor.com
Our registration details are at the top of this page. We have not appointed a data protection officer, because the scale and nature of our processing does not require one under Article 37 of the GDPR; requests sent to privacy@anvendor.com reach the people who can act on them.
