Procurement VMS, Inc. is committed to protecting the privacy and security of the personal and business information entrusted to us. This Privacy Policy explains how we collect, use, share, and protect information when you use ProcurementVMS.com and the Procurement VMS platform (collectively, the "Services").
We collect the following categories of information:
A. Account and Registration Data: Name, business email, company name, job title, and password credentials collected when you create an account.
B. Customer Data: All information you input into or generate within the Procurement VMS platform — including vendor records, contract documents, sourcing event data, spend records, risk assessment data, and related business information. Customer Data belongs to you. We process it only to deliver and improve the Services.
C. Usage and Technical Data: Log files, IP addresses, browser type and version, device identifiers, features accessed, session duration, and interaction patterns. Collected automatically to operate and improve the platform.
D. Communications Data: Records of your communications with our team, including support inquiries, sales correspondence, and chat interactions.
E. Payment Information: Billing contact details and payment method information. Full payment card data is processed by our PCI-DSS compliant payment processor and is not stored on our systems.
F. Cookies and Tracking Data: Described in detail in Section 5 below.
Service Delivery: To operate, maintain, secure, and improve the Procurement VMS platform and Services.
Account Management: To create and manage accounts, verify identity, and provide customer support.
Service Communications: To send account-related notifications, product updates, security alerts, and support responses. We do not send marketing communications without explicit consent.
Security and Fraud Prevention: To detect, investigate, and prevent unauthorized access, fraud, and security incidents.
Analytics and Platform Improvement: To understand usage patterns and identify improvement opportunities. We use aggregated and anonymized data for this purpose wherever practicable.
Legal Compliance: To comply with applicable US federal and state law and respond to lawful government requests.
We do not sell personal data. We do not use Customer Data for advertising purposes.
Our processing of personal data is based on: (a) contract performance — processing necessary to deliver the Services under your subscription agreement; (b) legitimate interests — security monitoring, fraud prevention, and platform improvement, balanced against your privacy rights; (c) legal obligation — processing required by applicable US federal or state law; (d) consent — for specific processing activities where you have provided explicit consent.
We do not sell personal data or Customer Data. We share information only in the following circumstances:
Service Providers: Selected third-party vendors providing infrastructure, security, analytics, payment processing, and customer support under contractual obligations to protect your data.
Business Transfers: In connection with a merger, acquisition, or asset sale, with prior notice to affected users.
Legal Requirements: When required by law, court order, or governmental authority, or to protect the rights, property, or safety of Procurement VMS, our customers, or the public.
With Your Consent: For any other purpose with your explicit prior consent.
Essential Cookies: Required for core website and platform functionality. Cannot be disabled without affecting service operation.
Analytics Cookies: Used to collect aggregated data about website usage patterns — traffic sources, page performance, session behavior. Data is aggregated and does not identify individual users.
Functional Cookies: Used to remember preferences, settings, and session state across visits.
Marketing Measurement Cookies: Limited use to measure the effectiveness of our own advertising. We do not share behavioral data with third-party advertising networks.
You may manage cookie preferences through your browser settings or our cookie consent management tool. Disabling essential cookies may affect platform functionality.
We maintain a comprehensive information security program that includes technical, administrative, and physical safeguards against unauthorized access, disclosure, alteration, and destruction of personal and customer data.
Our security practices include: end-to-end encryption of data in transit (TLS 1.2+) and at rest (AES-256); role-based access controls; multi-factor authentication requirements; SOC 2 Type II aligned security controls; regular independent penetration testing and vulnerability assessments; and mandatory security training for all personnel with data access.
In the event of a data breach affecting your personal information, we will notify you in accordance with applicable US state breach notification laws.
We retain personal data and Customer Data for as long as necessary to provide the Services and fulfill the purposes outlined in this Policy, unless a longer retention period is required by law. Account data is retained for the subscription duration and up to three (3) years post-termination for legal and legitimate business purposes.
Customer Data is available for export for thirty (30) days following account termination, after which it is deleted from active systems within ninety (90) days, subject to legal retention requirements. Usage and technical data may be retained in anonymized, aggregated form for longer periods for analytics purposes.
We honor the following privacy rights for all US-based users:
California Residents (CCPA/CPRA): You have additional rights under the California Consumer Privacy Act and the California Privacy Rights Act, including the right to know, opt out of the sale or sharing of personal information (we do not sell or share personal information), correct inaccurate personal information, and limit the use of sensitive personal information. Submit requests to: ccpa@procurementvms.com
Virginia Residents (VCDPA): You have rights under the Virginia Consumer Data Protection Act, including access, correction, deletion, portability, and the right to opt out of targeted advertising and profiling.
Colorado Residents (CPA): You have rights under the Colorado Privacy Act, including access, correction, deletion, portability, and opt-out rights.
To exercise any privacy right, contact: privacy@procurementvms.com. We will respond within forty-five (45) calendar days of receiving a verifiable request.
The Procurement VMS platform is a business application designed for adult professionals. We do not knowingly collect personal data from individuals under 18 years of age. If we become aware of such collection, we will delete the data promptly.
Our platform may link to third-party websites or integrate with third-party services (such as ERP systems, AP automation platforms, or identity providers). We are not responsible for the privacy practices of third parties. We encourage you to review third-party privacy policies before sharing data with those services. When you connect third-party integrations to Procurement VMS, data shared between systems is governed by your agreements with those third parties and the data processing scope required to deliver the integration functionality.
Procurement VMS is a US-based platform. All Customer Data is processed and stored within the United States. If you access our Services from outside the United States, your data will be transferred to and processed in the United States. By using the Services from outside the US, you acknowledge this transfer.
We may update this Privacy Policy to reflect changes in our data practices, technology, or applicable law. We will provide at least thirty (30) days' advance notice of material changes via email or platform notification. Continued use of the Services following the effective date of any update constitutes acceptance of the revised Policy.
Privacy Officer, Procurement VMS, Inc.
General Privacy Inquiries: privacy@procurementvms.com
California CCPA/CPRA Requests: ccpa@procurementvms.com
Data Security Concerns: security@procurementvms.com
We are committed to responding to all privacy inquiries promptly, professionally, and with full transparency about our data practices.