Your dashboard

VendorButton Advantage · FiveToClose

Privacy Policy

Effective September 11, 2026 · Updated September 13, 2026

The recommendation widget uses site and offer context. It does not use third-party advertising cookies, build cross-site visitor profiles, or read shopping-cart or payment-card details to choose an offer.

1. Who processes information

FiveToClose operates VendorButton. This policy covers the VendorButton website, dashboard, and scripts. Destination vendors have their own privacy practices. A merchant installing our script remains responsible for its own website notices and any customer information it collects independently.

2. Account and payment information

Google sign-in provides your verified email address, Google account identifier, and name. We use these to authenticate your account, keep your dashboard separate, and administer membership. Stripe processes checkout; we retain references to payments, the account email, amount, and payment or refund status. We do not receive or store full card numbers or card security codes.

We store the sites, domain-verification records, offer text, URLs, tags, priorities, and settings you submit. Offer information intended for display is public when served on participating sites. Your account email and dashboard settings are not part of the public recommendation response.

3. Visitor requests and measurement

Loading a script or recommendation makes a network request to VendorButton. Our server necessarily receives technical connection data, including an IP address and browser request headers. We use short-lived request counters to prevent abuse. Standard infrastructure logs may record technical access information. The widget sends its registered site identifier; recommendation matching uses the site’s configured tags, not a profile of the visitor.

We record random impression identifiers, the source site, recommended offer, time, and whether that recommendation was observed or clicked. These identifiers relate to a recommendation event rather than a persistent cross-site visitor identity. We do not call them unique-person counts. We retain these event records for up to 90 days; dashboard statistics normally cover 30 days. Requests may be limited to protect availability.

For specifically configured purchase-success integrations on the operator’s sites, a checkout-session reference may be used to verify that payment completed, or the local application’s payment-confirmation response may trigger the widget. Payment verification is separate from recommendation selection. Customer email, purchased item details, and card information are not used to target recommendations or sent to other vendors by the widget.

4. Cookies and browser storage

VendorButton uses a first-party session cookie for member sign-in and a short-lived cookie to secure the Google sign-in flow. These are authentication and security functions. The embedded recommendation widget does not set a persistent visitor cookie, use browser storage for cross-site tracking, or send a member session cookie with its recommendation requests. Google, Stripe, destination vendors, or your own installed tools may use cookies under their own policies. If your installation adds nonessential tracking, you must provide any required consent controls; a privacy link alone is not consent.

5. Purposes and legal bases

We use account and order information to deliver and administer the purchased service, including verification and refunds. We use operational data to keep the service secure, prevent misuse, diagnose failures, and measure recommendation events. Where relevant data-protection law requires a basis, these purposes rely on performance of a contract, legitimate interests in a secure and functioning service, or legal obligations. Where a separate activity requires consent, we must obtain it before that activity. We do not sell account contact lists or use network membership to enroll you in unrelated marketing.

6. Service providers and disclosures

Google provides authentication, Stripe handles payment processing, and our hosting and infrastructure providers operate the service. We disclose information as necessary for those functions, lawful requests, fraud prevention, or a properly protected business transfer. We do not share customer payment records with other network vendors. Providers may process data in countries other than yours; applicable transfer protections are required where law mandates them.

Sandboxed installation and migration

The recommended installation is now a cross-origin sandboxed iframe, without allow-same-origin, form submission, or top-navigation permission. Its browser security boundary prevents it from reading the parent page’s DOM, email fields, cookies, and storage. The iframe URL contains a public site identifier, not buyer details. Keep the supplied sandbox and no-referrer attributes intact. A destination opened by a visitor has its own privacy practices.

Older external script installations have page-level JavaScript access by design. Replace them with the iframe and remove old VendorButton script tags; updating dashboard settings alone does not remove that access. The operator’s own sites use locally served, fixed purchase-confirmation adapters to insert the iframe. Those first-party adapters remain part of the merchant’s trusted code. These protections do not secure unrelated scripts, a compromised merchant site, or information a visitor voluntarily supplies to another destination.

Buyer and offer controls

New sites start with network fallback disabled and site offers marked private. Existing sites retain their settings. In Settings & installation, private mode disables other vendors’ recommendations and keeps that site’s offers within your account. Private offer settings also cover affiliate links. Receiving network offers and sharing your offers are separate controls.

Recommendation requests and outbound widget links suppress the page referrer. The iframe installation includes a no-referrer attribute; replace older script snippets to receive the browser isolation protection. We do not pass buyer contact lists to destination vendors. Clicking an offer still visits its destination, which receives the visitor’s connection and any information the visitor supplies. Affiliate URLs may contain the affiliate provider’s tracking parameters. Do not enter buyer personal information in offer URLs. These controls do not guarantee customer exclusivity.

7. Retention and your choices

Site and offer records remain while needed to operate your account unless you remove them or request account deletion. We retain purchase and refund records as needed for accounting, fraud prevention, disputes, and legal requirements. Security logs and backups may persist for a limited operational period; deleting an active record may not immediately remove it from a backup. Backups are not used as a separate marketing database.

You may edit your site information and pause or delete offers in the dashboard. Contact us to request account deletion, access, correction, a copy of your records, restriction, or an objection to processing where applicable. We may verify your identity and retain records we are legally required to keep. Closing your account may end access without automatically creating a refund outside the Refund Policy. You may also complain to your relevant data-protection authority.

8. Security, children, and updates

We use access controls, HTTPS, payment-signature verification, and other reasonable safeguards. No system is guaranteed secure. The service is for adults and is not directed to children. Do not submit children’s information or sensitive personal data. We will update this policy when our practices change and provide additional notice where required.

Contact

Contact FiveToClose about VendorButton at support@fivetoclose.cloud. Include your account email and a relevant site or payment reference, but never your password or full card details.