Last updated: September 7, 2026
1. Introduction
VendorVib ("we", "us", "our") is operated by TribeMingle. VendorVib is the AI operating system for vendors: two AI employees who remember your business, sell in your DMs and run your operations, while you stay in control. Remembering is the point, so this policy is mostly about what the team remembers, who else sees it, and how you stay the owner of it. This Privacy Policy explains what personal information we collect, how we use and share it, and the choices you have.
It covers vendorvib.com, every store we host (including a vendor's own custom domain), VendorVib on your phone once it is released, and the WhatsApp and social messaging services we run (together, the "Platform"). "Vendors" are the businesses that sell through VendorVib. "Buyers" are the people who buy from them or message them.
By using the Platform you agree to the practices described here. If you do not agree, please do not use the Platform.
2. Information We Collect
2.1 Vendor Account and Business Information
When you create and set up a Vendor account, we collect:
- Name, email address and password (stored only as a one-way hash)
- Business name, handle, country, category, logo, brand colour and social media links
- The WhatsApp number you link to talk to your Business Manager, and any PIN you set
- Team members' names and email addresses, and details of any extra brands you run
- Your storefront settings, shipping rules, policies and the knowledge you give your Sales Manager
2.2 Billing and Payout Information
- Paystack (Nigeria): bank name, account number and account holder name, shared with Paystack to create your payout subaccount and to bill your subscription in naira.
- Stripe (international): you are redirected to Stripe to verify your identity and add a bank account. Stripe holds that information under its own privacy policy. We store your Stripe account ID, connection status and display name.
- Flutterwave (some African markets): bank details shared with Flutterwave to create a payout subaccount.
- For subscriptions and add-ons we keep the provider's customer and payment references, the card brand and last four digits, and your invoices. Full card numbers never reach our servers.
2.3 Buyer Information
Buyers do not need an account. When you buy from a Vendor's storefront, pay a payment link or pay at a till, we collect:
- Name, phone number and email address
- Delivery address and any notes you add to the order
- Payment card and bank details, which are collected and processed only by Paystack, Stripe or Flutterwave and never stored by us
2.4 Orders and Transactions
For each order we record the products, amounts, currency and fees, the payment provider's references, the payment method type, the card brand and last four digits shown on receipts, delivery status and timestamps.
2.5 Products and Content
Vendors upload product photos, videos, descriptions, prices and collections, and may collect customer testimonials with the customer's consent. Media is stored on our database provider (Convex) and served through our content delivery network (Bunny).
2.6 Conversations With Your Business Manager
Everything you send your Business Manager on WhatsApp or on the web is kept as conversation history so it can remember context and act on your instructions. That includes text, voice notes, photos and documents. Everything it remembers, you can see, correct or delete: reset that history at any time and it starts fresh.
2.7 Buyer Conversations on Connected Channels
When a Vendor turns on the Sales Manager, messages between Buyers and the Vendor's connected WhatsApp, Instagram, Facebook or TikTok accounts pass through our systems so the Sales Manager can reply. We strip phone numbers, email addresses, card and account numbers from message bodies as we store them, and delete stored message bodies after 90 days. To serve a returning Buyer well, the Sales Manager keeps a short memory of preferences it has learned (for example a size or a product they asked about). Contact and payment details are never written into that memory. We also record when a Buyer opts out so they are not messaged again.
2.8 Connected Channel Data
To connect a channel we receive and store access tokens, the account, page or number identifiers, and the profile name from Meta or TikTok. We use them only to send and receive messages on your behalf and to publish content you approve.
2.9 Usage and Device Data
We collect standard technical data when you use the Platform: browser and device type, operating system, IP address and approximate location, the pages and screens you visit and the actions you take. We use PostHog for this product analytics. Vendors also see aggregate visit and sales statistics for their own storefront. VendorVib on your phone is in development. When it is released it will read your photo library only when you choose a photo to upload, and keep your sign-in in the phone's secure storage.
3. How We Use Your Information
We use the information we collect to:
- Run the Platform, including your storefront, checkout, orders and payouts
- Power your AI Business Manager and AI Sales Manager, so they know your catalogue, your customers and what you have asked them to do
- Send transactional messages: receipts, order and delivery updates, sale alerts, payout confirmations and account notices, by email and WhatsApp
- Send Vendors product updates, reports and tips, which you can turn off at any time
- Bill subscriptions and add-ons and process payouts through Paystack, Stripe or Flutterwave
- Prevent fraud, abuse and spam, and enforce our Terms of Service
- Meet legal obligations and the requirements of our payment and messaging providers
- Understand how the Platform is used so we can improve it
We do not sell your personal information. We do not use your data, or your customers' data, to train AI models. We do not send marketing emails to Buyers.
4. How Your AI Team Processes Your Data
To produce a reply or a piece of content, the team sends the relevant context (your message, recent conversation, the products and policies involved) to our AI providers, who return the result and do not keep it to train their models. We use Anthropic's Claude models for the team, Spitch to turn voice notes into text, and fal.ai to generate images. Only the data needed for that request is sent, and each provider processes it under its own privacy terms.
5. How We Share Your Information
We share personal information only in the following circumstances.
5.1 Service Providers
These companies process data on our behalf, each under its own privacy policy and only for the purpose listed:
- Paystack, Stripe and Flutterwave: payments, subscriptions and payouts
- Zernio: connecting your WhatsApp, Instagram, Facebook and TikTok accounts and carrying messages to and from them
- Meta (WhatsApp, Instagram, Facebook) and TikTok: the platforms your channels live on, which see the messages sent through them
- Anthropic, Spitch and fal.ai: AI text, speech-to-text and image generation, as described in section 4
- Convex (database and file storage), Bunny (media delivery) and Cloudflare (hosting): running and serving the Platform
- Resend: sending our emails
- PostHog: product analytics
- Shipbubble: booking couriers and printing labels, when a Vendor chooses to ship an order that way, which requires sharing the Buyer's name, phone number and address with the courier
- Google: listing a Vendor's products in Google Shopping, only when the Vendor connects it
5.2 Between Vendors and Buyers
When a Buyer places an order or messages a Vendor, the Vendor receives the Buyer's name, phone number, email address, delivery address and the conversation, so they can fulfil the order and reply. Vendors are responsible for how they use that information.
5.3 Vendor Tracking Pixels
A Vendor may add their own Meta or TikTok tracking pixel to their storefront to measure their advertising. Data those pixels collect goes to the ad platform under the Vendor's account and the platform's privacy policy, not to us.
5.4 Legal and Business Reasons
We may disclose information when required by law, regulation, legal process or a government request, to protect the rights, property or safety of VendorVib, our users or the public, or as part of a merger, acquisition or sale of assets, in which case this policy continues to apply.
6. Data Retention
- Account, business and catalogue data: for as long as your account is active
- Orders and transaction records: typically 7 years, for accounting and legal compliance
- Business Manager conversation history: until you reset it or close your account
- Buyer message bodies on connected channels: 90 days; opt-out records for as long as needed to honour them
- Channel access tokens: until you disconnect the channel or close your account
When you close your account we delete your personal information, except what we must keep by law.
7. Data Security
We use reasonable technical and organisational measures to protect your data, including:
- Passwords are hashed and never stored in plain text
- All data in transit is encrypted with HTTPS/TLS
- Card details are handled only by PCI-compliant payment providers and never touch our servers
- Sensitive actions in the Business Manager can be protected by a PIN you set
- Access to production systems is restricted to authorised staff
No method of transmission over the internet is completely secure. We work to protect your data but cannot guarantee absolute security.
8. Cookies, Local Storage and Analytics
VendorVib uses cookies and browser storage for:
- Authentication sessions, so you stay signed in
- Preferences and drafts saved in your browser so you can pick up where you left off
- Product analytics through PostHog, which sets a first-party identifier so we can see how the Platform is used, and which gives Vendors the traffic figures for their storefront
We do not run advertising cookies of our own. A Vendor's storefront may carry that Vendor's own tracking pixel, as described in section 5.3.
8.1 Your cookie choice
The landing page and every storefront show a cookie banner with two choices: Accept, or Decline. Declining keeps the essentials working, which means signing in, your cart and your saved preferences, and stops analytics and any Vendor pixel. In the European Economic Area, the United Kingdom and Switzerland, nothing beyond the essentials runs until you accept. Everywhere else it runs from the start and stops the moment you decline.
If your browser sends the Global Privacy Control signal, we treat that as a No before the page loads. Analytics and any Vendor pixel stay off, and you are not asked, because you have already answered. Turning the signal off, or making a choice yourself, overrides it.
Your choice is kept in your browser for up to twelve months. It is kept per site, so a choice on vendorvib.com does not carry to a Vendor's own domain. You can change it whenever you want:
9. Your Choices
- Buyers: reply STOP to any Vendor conversation to stop automated replies and updates from that business on that channel.
- Emails: every non-transactional email has an unsubscribe link. Receipts and order updates are sent regardless, because they are part of your purchase.
- Vendors: disconnect a channel, reset your Business Manager's history, correct what the team remembers or remove a tracking pixel at any time from your settings. Leave whenever you want, and take everything with you.
- Analytics: use the cookie banner, or the button in section 8.1, to accept or decline analytics and Vendor pixels. The Platform works either way.
10. Your Rights
Depending on where you live, including under the Nigeria Data Protection Act 2023 and the GDPR, you may have the right to:
- Access: request a copy of the personal data we hold about you.
- Correction: request correction of inaccurate or incomplete data.
- Deletion: request deletion of your personal data, subject to legal retention requirements.
- Portability: request a machine-readable copy of your data.
- Objection: object to certain processing, including automated messaging.
To exercise any of these rights, contact us at support@vendorvib.com. We will respond within 30 days. Buyers may also ask the Vendor they dealt with, who holds their own copy of the order and conversation.
11. Children's Privacy
The Platform is not intended for children under 16. We do not knowingly collect personal information from children. If you believe a child has given us personal data, contact us and we will delete it promptly.
12. International Data Transfers
Your data may be processed and stored outside your own country, including in the United States, where our database provider Convex and several of our other providers operate, and wherever our content delivery network serves files from. We put appropriate safeguards in place for those transfers.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered Vendors of material changes by email or WhatsApp. The "Last updated" date at the top of this page shows the most recent revision.
14. Contact
For questions about this Privacy Policy or to exercise your data rights, contact us at:
Email: support@vendorvib.com
Operated by: TribeMingle
www.tribemingle.com