Privacy notice
This site sets no cookies, runs no analytics and loads nothing from anyone else’s servers. The only personal data involved is what a purchase or an email to support necessarily produces. This page says exactly what that is.
Version of 3 August 2026.
The short version
No cookies. No analytics, tag managers or tracking pixels. No advertising, no profiling, no data sold or shared with anyone who is not needed to complete your order. The calculators do their sums in your browser and send nothing anywhere. If you buy something, the checkout runs on Payhip and the card payment on Stripe, so your order data goes to them and your card details go only to Stripe. If you email support, one person reads it.
1. Who is responsible
The controller for the personal data described here is:
Vendwright
Vrijewade 40-129, 3439 PB Nieuwegein, Netherlands
Chamber of Commerce (KvK) number:
70123101
VAT identification number:
NL002309273B30
Email: support@vendwright.com
Controller is the GDPR’s word for whoever decides what happens to your data and answers for it. That is us: the sale is ours, so the decisions are ours. The companies in section 5 handle parts of it for us, or — where that section says so — for their own separate purposes.
There is no data protection officer. One is not required for an operation this small, and we are not going to appoint an imaginary one.
2. What the website itself collects
Nothing, as far as the pages are concerned. Every page here is a static file. To be specific about what is not present:
- no cookies of any kind, which is why there is no cookie banner — there is nothing to consent to;
- no analytics, no tag manager, no heatmaps, no session recording;
- no advertising or remarketing pixels, no social share widgets, no embedded video;
- no web fonts and no CDN. The type is whatever your device already has, and every stylesheet, script and image is served from this domain.
You can verify all of that: open your browser’s network and storage panels on any page of this site and see what is requested and what is stored.
Server logs
The files have to be served by a web server, and web servers keep access logs as a matter of course — typically your IP address, the time, the page requested, and the browser string your device sends. Those logs exist for security and for fixing faults. They are not used for analytics, they are not combined with anything else, and no attempt is made to identify anyone from them. The lawful basis is our legitimate interest in keeping the site working and secure (Article 6(1)(f) GDPR).
The calculators
Every calculation on the free tools happens in your browser, in JavaScript, on your own device. The numbers you type are never transmitted to us or to anyone else — there is no server to receive them.
Two of the calculators — the renovation contingency calculator and the Airbnb break-even occupancy calculator — save what you typed into your own browser’s local storage, so the form is still filled in when you come back to the page. That data stays on your device, is readable only by you, and is not personal data in anyone else’s hands because it never leaves the machine. Clearing site data for this domain removes it. Nothing else on the site writes to storage.
3. When you buy something
Payments are not processed on this site. Clicking a buy button takes you to payhip.com, which is somebody else’s website with its own cookies and its own privacy policy, and the card payment there is taken by Stripe. Section 5 says who those two are and section 6 covers the transfer to the UK that the first of them involves.
A purchase produces this much personal data, and no more:
- Your email address. Required — it is where the download link and the receipt go.
- Your name, if the checkout asks you for it or you type it in.
- The order record: which product, the amount, the currency, the date, your billing country and the order reference.
- Your answer to the withdrawal-consent question that the checkout requires before payment (section 5 of the terms explains what it is for). What is stored is that you were asked and what you answered.
- Technical data at checkout: your IP address and browser details. The platform uses them to work out which country’s VAT applies, and Stripe uses them to screen the payment for fraud.
- Card details go to Stripe and nowhere else. They do not pass through this site and we never see them, store them or receive them.
We hold the order record, minus the card data, and we use it for three things: delivering the file and answering questions about the order (Article 6(1)(b) GDPR — performance of your contract); keeping the sales and VAT records the law obliges us to keep (Article 6(1)(c) — legal obligation); and keeping the consent answer, which is our evidence that the withdrawal question was properly asked if that is ever disputed (Article 6(1)(f) — legitimate interest). Stripe screens payments for fraud on its own account as well as ours.
How long. Dutch tax law requires the records behind a return to be kept for seven years, so the order record is kept for that long and then deleted. The consent answer is part of that record and shares its life. Nothing is kept longer merely because it might one day be handy.
We do not run a marketing list. Buying something does not sign you up to anything, because there is nothing to be signed up to.
4. When you email support
If you write to support@vendwright.com, your email address, your message and anything you attach sit in the operator’s mailbox. The mailbox is hosted by an email provider, which processes the message in order to deliver and store it, as every email provider must.
Support mail is used to answer you and nothing else: no list, no profiling, no forwarding to third parties. The lawful basis is performance of the contract where it concerns an order, and otherwise our legitimate interest in replying to people who write to us. Threads are kept while they are useful for support and warranty history, and are deleted when they are not.
Please do not send us sensitive documents. Nothing in our products or support needs your bank statements, your probate paperwork or your customers’ details, and we would rather not hold them.
5. Who else sees any of this
Only the parties that are structurally necessary. Named, because you are entitled to know who they are:
- Payhip Limited — registered in England and Wales, company number 08386910, 167–169 Great Portland Street, 5th Floor, London W1W 5PF, United Kingdom. Runs the checkout, hosts the file, serves the download link and sends the receipt. It processes the order data for us, on our instructions, which makes it our processor and us the controller. One thing to be straight about: Payhip publishes no data processing agreement, and its own privacy policy is old enough to still cite the UK Data Protection Act 1998. We cannot point you at a contract that does not exist. What we can do is tell you exactly what it holds, which is the list in section 3, and answer for it ourselves rather than send you away.
- Stripe — takes the card payment at that checkout and settles it into our account. Card data is handled on Stripe’s systems under Stripe’s own privacy policy. For processing the payment Stripe acts for us; for fraud prevention, anti-money-laundering and its own regulatory duties it acts on its own account, as a controller, and not on our instructions.
- The email provider hosting the support mailbox — to carry and store messages.
- The hosting provider serving these files — which sees the server logs described above.
Nobody else. No advertising networks, no data brokers, no analytics companies, no AI training pipelines. Personal data is not sold, rented or bartered. We would disclose data if a court or a competent authority lawfully required it, and only then.
6. Data leaving the EU
Payhip Limited is a UK company, so buying through its checkout means your order data goes from the Netherlands to the United Kingdom — a transfer to a country outside the EU. The GDPR says you must be told that, and told what makes it lawful.
What makes it lawful is an adequacy decision. The European Commission has found that the United Kingdom protects personal data to a standard essentially equivalent to the EU’s, most recently in Commission Implementing Decision (EU) 2025/2574 of 19 December 2025, which runs until 27 December 2031. While that decision stands, the transfer needs no extra contract, no standard contractual clauses and no separate safeguard, and your rights under this notice travel with the data.
Stripe moves payment data across its own international infrastructure; where that leaves the EEA it happens under the safeguards set out in Stripe’s own privacy policy and payment terms, which are Stripe’s to give and not ours. The same goes for the hosting and email providers in section 5, each under its own published terms.
7. Your rights
Under the GDPR you can ask us to give you a copy of the personal data we hold about you, to correct it, to erase it, to restrict or object to how we use it, or to hand it over in a portable format. Ask by email; we will answer within one month, and we will not charge you for it.
Two honest caveats. First, we may need to keep records that tax law obliges us to retain, even if you ask for erasure — the seven years in section 3. Second, the split in section 5 decides who you ask: for the order data, ask us, because Payhip holds it for us and we will deal with it rather than pass you along; for what Stripe holds for its own fraud and regulatory purposes, the request has to go to Stripe, and we will point you at the right form.
If you think we have handled your data badly, tell us first and we will try to put it right. You are also entitled to complain to a supervisory authority. Because the trader is established in the Netherlands, the competent authority is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), and you may equally complain to the authority in the EU country where you live or work. Payhip’s own privacy policy sends people to the UK Information Commissioner’s Office; that is the right address for a complaint about Payhip’s own business, but not for this sale. For anything on this page, the Autoriteit Persoonsgegevens is the one to go to.
8. Children
These are bookkeeping and pricing tools for adults. The site is not directed at children and we do not knowingly collect data about them.
9. What we do and do not claim about security
The honest position: this is a small operation, and most of the security here is structural rather than something we built. The site is a set of static files served over HTTPS, so there is no customer database on it to breach and no login to compromise. Payment data never touches our systems at all. What is left is the support mailbox and our own Payhip and Stripe accounts, which rely on the account security those providers offer and on us using it properly.
We are not going to list certifications we do not hold, encryption we do not perform or audits that have not happened. If that changes, this page changes with it.
10. Changes to this notice
If what we do changes — if analytics are ever added, for instance — this page is updated before that happens, and the date at the top tells you when it last changed. Questions: support@vendwright.com.