Privacy Policy
What Unvendored collects, why it collects it, and who processes it.
Last updated: September 11, 2026
What we collect
You can browse the entire directory without an account and without giving us anything. We only hold personal data in four cases.
An account. If you sign in, we store your email address, and the display name and avatar your provider gives us. Signing in with Google or GitHub tells us your email, name and public avatar, and nothing else. Signing in with a login link tells us only your email address.
The newsletter. Subscribing stores your email address so we can send the weekly issue. Every issue carries an unsubscribe link.
Usage analytics. We record which pages are visited and which links are clicked, to see what people look for. Analytics requests go through our own domain rather than to a third-party host directly, and a visitor is profiled only once signed in.
Your IP address, briefly. Submitting a tool, subscribing or claiming a listing is rate limited by IP so the forms cannot be flooded. The address is held only for the length of the limit window and then expires.
What we do not do
We do not sell personal data, we do not share it for advertising, and we do not track you across other sites. We do not ask for payment details; if paid listings are introduced, the payment processor handles them and we never see the card.
Who processes it
The site runs on Vercel and stores its data in a Neon Postgres database. Images are served from Cloudflare R2. The newsletter runs on Beehiiv, login emails are sent through Resend, analytics run on PostHog, and rate limit counters live in Upstash Redis. Each receives only the data its job needs.
Your choices
You can unsubscribe from the newsletter at any time from the link in any issue. You can ask us to delete your account and the data attached to it by writing to hola@unvendored.com, and we will action it rather than ask you why.
Changes
If this policy changes in a way that affects what we collect, the date at the top changes with it.