Privacy Policy

Last updated August 2026

What we collect

Account information: your name, work email, organization name, and a salted hash of your password. We never store your password itself.

Content you enter: vendor records, contact names and email addresses, assessment questionnaires and responses, notes, and scores. Much of this is information about your vendors and their staff rather than about you.

Operational records: a log of emails the service queued or sent on your behalf, including delivery status, so failures are visible rather than silent.

Cookies and measurement

A session cookie keeps you signed in and protects forms against forgery. The same cookie remembers, for the first page of a visit, which link or search brought you here (the campaign tag in the link, or the site you came from), so that if you sign up we can tell which of our content is working. It is first-party, expires when the session does, and is not shared with anyone.

Visit counting. We count how many visits each public page receives and where they came from, per day, as a single number. No IP address, device detail or identifier of any kind is stored with that count, and it sets no cookie of its own.

LinkedIn Insight Tag - only if you accept. On our public marketing pages we ask whether we may load LinkedIn's Insight Tag. If you accept, LinkedIn sets its own cookies and learns that you visited, which lets us see which LinkedIn posts bring people here and show our posts to people who have visited. LinkedIn processes that under its own privacy policy. If you decline, or ignore the question, it never loads. It never runs on sign-in, password-reset or assessment pages, or anywhere inside the product. Your choice is kept for six months in a small cookie (vt_consent) that holds only the word "granted" or "denied".

You can change your mind from Cookie settings at the foot of any marketing page. Withdrawing stops the tag loading from then on; cookies LinkedIn has already set are LinkedIn's and are removed through your browser or your LinkedIn settings.

If you ask for the maturity guide

We keep your email address, which page or campaign brought you to us, and a link unique to you so the guide can be sent. We send one email containing that link. If you also ticked the box asking for occasional emails, we keep the exact wording you agreed to and when, and we may email you about vendor and operational risk; every such email has an unsubscribe link, and unsubscribing takes effect immediately. If you did not tick it, we do not contact you again. We record when the link is first opened, which email security systems sometimes do before a person has. None of this is shared with anyone, and it is kept apart from customer accounts. Ask us to delete it at privacy@vetrail.io.

Calendar connections

If you publish your action items to a calendar - by subscribing to a feed, or by connecting a Google or Microsoft account - the calendar receives each item's title, due date, status, owner name and a link back to Vetrail, and nothing else: no assessment answers, evidence or vendor contacts. A connected account's access token is stored encrypted and used only to write to the one calendar Vetrail creates in it. For Microsoft we also read your mailbox time zone, so that a deadline appears on the right day. Disconnecting deletes that calendar and the stored token. Google and Microsoft process what they receive under their own privacy policies.

How we use it

To operate the service: storing your register, delivering questionnaires to the vendor contacts you specify, scoring responses, generating your exports, and sending you account email such as password resets. We do not sell personal information, and we do not use your content to train AI models.

Vendor contacts

When you send an assessment, we email the vendor contact you entered and host the questionnaire they complete. You are responsible for having a proper basis to share that contact's details with us. We use those details only to deliver and process the assessment you requested.

AI features

Assessment scoring is entirely deterministic and computed locally: no third-party AI service is involved in producing a vendor's score or rating. If an administrator configures the relevant API key, a language model may be used for three opt-in features, each disabled unless deliberately enabled: writing a narrative summary of an already-computed assessment result (Anthropic), drafting a starting point for a new risk-register entry from a short description you type (Anthropic), and the same drafting from a short spoken description instead (Google's Gemini API) - for that one, a recording of your voice for the turn you're speaking is sent to Google, and nothing else about your account goes with it. In every case the model's output is a suggestion only - nothing it writes is saved until you review it and submit the form yourself.

Service providers

We use a small number of infrastructure providers to run Vetrail, including a cloud hosting provider, a DNS and network provider, and an email delivery provider. They process data only to provide those services to us. The full list, with what each one does, is on our Trust page.

Where data is held

The application and its database run on cloud infrastructure located in the United States.

Retention and deletion

We keep your data for as long as your account is active. You can export a complete copy at any time from the Team page. Ask us to delete your organization and we will remove it.

Security

Passwords are stored as salted hashes. Traffic is encrypted in transit. Data is scoped to your organization, and public endpoints are rate limited. Backups of the underlying storage are taken daily. No system is perfectly secure, and we will not pretend otherwise.

Your rights

Depending on where you live, you may have rights to access, correct, delete, or port your personal information, and to complain to a regulator. Contact us to exercise them. In Canada you may also contact the Office of the Privacy Commissioner.

Contact

Privacy questions: privacy@vetrail.io