VERIFOODS PRIVACY & COOKIES POLICY
Effective Date: February 7, 2026
At VeriFoods Inc. ("VeriFoods," "we," "us," or "our"), we know privacy is important to you.
This Privacy & Cookies Policy ("Privacy Policy") applies to the personal information we collect, use, disclose, and otherwise handle when you use the VeriFoods website www.verifoods.com (the "Website") and the VeriFoods mobile application ("App"). The Website and the App (collectively, the "Services") are owned and operated by VeriFoods Inc., a company incorporated in the Province of British Columbia, Canada, which is the data controller in respect of your personal information. The contact information for our Privacy Officer can be found at the bottom of this policy.
The Services are intended for a mature audience and we encourage you to review the age rating standard applicable for your country of residence. If you are under 14 years of age, or otherwise have not reached the minimum age set out in standards applicable to your country of residence, you may not use the Services in any way.
VeriFoods does not knowingly or intentionally collect information from children under 14. If we learn that we have received information directly from a child who is under the age of 14, we will delete the information.
PERSONAL INFORMATION PROCESSING
We collect, use, and process your personal information in accordance with applicable laws: (i) to enable us to perform the contract entered into between you and us when you signed up to use the Services, (ii) for the purposes of our legitimate business interests, and/or (iii) where we have your consent to do so.
We collect, use, and process the following personal information through your use of: (1) the App, and (2) the Website, for the following purposes:
Device and Browsing Information
We collect technical information when you use the App or visit the Website. This includes:
- Device type, model, and manufacturer
- Operating system and version
- Unique device identifiers (Identifier for Vendors (IDFV) on iOS, Android ID on Android)
- IP address (used for approximate geolocation and security purposes)
- Browser type and version (web)
- Screen resolution and device capabilities
- Carrier provider
- Date and time of access to our servers
We use this information to improve the quality of our service, including for storing user preferences and determining appropriate settings for your device, and tracking user activity and trends in order to help us understand and improve the App and the Website. We also use cookies as described in further detail below, under "Cookies, Ads, and Additional Information About the Website and the App."
Account Registration and Authentication
You do not have to register or sign in to visit the Website or use basic App features. However, registering allows you to access additional features such as saving scan history, receiving product alerts, and personalized recommendations. When you register, we collect your email address and other information you provide to create and maintain your account.
We offer the following authentication methods, each of which collects specific information:
- Google Sign-In: email address, display name, and profile photo URL
- Apple Sign-In: email address (which may be an Apple relay address), and display name
- Email/Password (via Supabase Auth): email address, hashed password, authentication tokens, and session data
Barcode Scanning and Search History
When you scan barcodes or search for products using our App, we collect information about the products you scan or search for. This information helps us improve our product database, provide you with more relevant information, and enhance the overall user experience.
Search Query Data
We collect search queries you enter within the App when looking for products. This includes:
- Product search queries and search terms
- Interactions with search results (products viewed from search)
- Search timestamps
Search queries are stored in anonymized form for the purpose of improving search functionality, relevance, and our product database. No search data is shared with third parties.
Vote-to-Test Data
VeriFoods offers a feature allowing users to vote on which products should be sent for laboratory testing. When you participate, we collect:
- Products you have voted for testing
- Vote timestamps and frequency
- Vote weight calculations based on your subscription tier
This data is used to prioritize our lab testing pipeline and to provide you with updates on products you have voted for.
Article and Content Engagement Data
When you interact with articles and editorial content within the App, we collect:
- Articles viewed and view timestamps
- Reactions (such as likes) on articles
- Comments posted on articles
- Article sharing activity
- Estimated reading time and engagement duration
This data is used to personalize content recommendations, improve our editorial offerings, and understand which topics are most relevant to our users.
Streak and Gamification Data
The App includes engagement features such as streaks, experience points, and achievements. We collect:
- Daily login timestamps for streak tracking
- Experience points (XP) earned and your current level
- Badge and achievement unlock dates
- Engagement metrics including scans performed, votes cast, and article interactions
This data is used to power gamification features within the App and to encourage healthy engagement with food safety information.
Marketing and Push Notifications
You can sign up on the Website to receive our newsletter and other emails about promotions and information about VeriFoods products and services. If you sign up for our newsletter or other promotional emails, you can opt out of receiving these emails from VeriFoods at any time by following the unsubscribe instructions included in our emails, or by contacting us at the contact information set out below. Please note that you may continue to receive certain transactional and account-related emails from us.
If you access the App, we may also send push notifications to your mobile device to provide you with product alerts, test result updates, and other app-related information, with your consent. You can manage these notifications in the "Settings" of your mobile device. You can unsubscribe from push notifications at any time by changing the settings on your mobile device.
We use Firebase Cloud Messaging (FCM) to deliver push notifications. FCM collects and stores device tokens necessary for push notification delivery. These tokens are associated with your device and are used solely for the purpose of sending you notifications.
Surveys
From time to time, we may also offer users of the App the opportunity to participate in a survey or ask you for your feedback. The information obtained through our surveys and user feedback is used in an aggregated, non-personally identifiable form. We use this information to help us understand our users, and to enhance VeriFoods, including to assist us in creating new features or functionalities.
Careers
To apply for work opportunities, you may choose to provide us with personal information by answering a questionnaire relating to the job application you selected, and providing us with related job history and personal information. We use this information to assess your qualifications for relevant work opportunities.
Contact Us
When you contact us with a comment, question, or complaint, you may provide us with personal information to help us promptly answer your question or to respond to your request, comment, or complaint. We retain this information to assist you in the future and to improve our customer service. We also use personal information to establish and manage our relationship with you and to provide quality service.
AFFILIATE AND PARTNER DATA COLLECTION
If you apply for or participate in the VeriFoods Affiliate or Partner Program, we collect additional information including:
- Partner application data: your name, email address, social media profiles, and website URL
- Click tracking on partner referral links to measure the effectiveness of your referrals
- Conversion tracking, including referred user sign-ups and subscription activations
- Commission calculations and payment-related data necessary to compensate you
- Partner performance metrics and analytics
This data is used to administer the affiliate and partner program, calculate and process commissions, and provide you with performance reporting. Payment data is processed through our payment service providers in accordance with their respective privacy policies.
REFERRAL DATA
VeriFoods offers a referral program that allows users to invite others to use the Services. When you participate in the referral program, we collect:
- Referral codes generated by you and used by referred users
- Attribution data linking the referrer to the referred user for the purpose of reward fulfillment
- Referral reward tracking data
- Branch.io deep link data used for referral attribution (see Third-Party Services below)
This data is used to administer the referral program, attribute referrals correctly, and distribute referral rewards.
THIRD-PARTY SERVICES AND DATA COLLECTION
We use a number of third-party services to operate, improve, and secure the Services. Below is a description of each category of third-party service and the data they collect or process on our behalf.
Analytics
- Firebase Analytics (Google): Collects app usage events, screen views, user engagement metrics, and crash reports. This data helps us understand how users interact with the App and identify areas for improvement. For more information, see Google's privacy policy at https://policies.google.com/privacy.
- Gleap: Collects bug reports, user feedback, session recordings (anonymized), and device information. This data is used to identify and resolve technical issues and to improve the user experience.
- Branch.io: Collects deep link attribution data, install and referral tracking information, and device fingerprinting data for the purpose of attribution. This data helps us understand how users discover and install the App. For more information, see Branch's privacy policy at https://branch.io/policies/privacy-policy/.
Payments
- RevenueCat: Processes and stores subscription status, purchase history, transaction IDs, and subscription tier information. RevenueCat acts as a service provider to manage in-app subscriptions. For more information, see RevenueCat's privacy policy at https://www.revenuecat.com/privacy.
- Stripe: Processes payment card details (tokenized; card details are not stored by VeriFoods), billing address, and transaction history. Stripe acts as our payment processor for certain transactions. For more information, see Stripe's privacy policy at https://stripe.com/privacy.
Push Notifications
- Firebase Cloud Messaging (FCM): Collects and stores device tokens necessary for push notification delivery. These tokens are used solely for the purpose of delivering push notifications to your device.
A/B Testing and Feature Management
We conduct A/B testing to improve the Services. When you use the App, we may collect:
- A/B test variant assignments (which version of a feature you are shown)
- Feature flag states (which features are enabled for your account)
- Interaction metrics related to tested features
This data is used to evaluate the effectiveness of new features and improvements. A/B test participation does not affect your access to core App functionality.
SHARING OF PERSONAL INFORMATION
We do not sell or disclose your personal information to third parties without your consent, except as set forth below or as required or permitted by law.
Service Providers
Your personal information may be transferred (or otherwise made available) to third parties that provide services on our behalf. For example, we may use service providers for certain functions such as hosting of the Website and the App, processing payments, delivering push notifications, providing analytics, and managing customer support. Our service providers are given the information they need to perform their designated functions, and are not authorized to use or disclose personal information for their own marketing or other purposes. We also use third-party service providers to collect certain analytical information, such as the App features used and time spent on the App, to help us improve the quality of our Services and manage and analyze data about our users. These data are collected by our third-party service providers in an aggregate form that does not personally identify any individual App user.
Legal and Compliance
We and our service providers may provide your personal information in response to a search warrant or other legally valid inquiry or order, or to another organization for the purposes of investigating a breach of an agreement or contravention of law or detecting, suppressing, or preventing fraud, or as otherwise may be required or permitted by applicable Canadian, U.S., or other law or legal process. Your personal information may also be disclosed where necessary for the establishment, exercise, or defence of legal claims and to investigate or prevent actual or suspected loss or harm to persons or property.
Sale of Business
Personal information may be provided to third parties in connection with a business transaction, including a merger or sale (including transfers made as part of insolvency or bankruptcy proceedings) involving all or part of VeriFoods or as part of a corporate reorganization, stock or asset sale, or other change in corporate control, including for the purpose of determining whether to proceed or continue with such transaction or business relationship.
AUTOMATED DECISION-MAKING AND AI DISCLOSURE
VeriFoods uses AI-powered algorithms and automated processes to generate product safety scores and risk assessments displayed within the App. We believe it is important for you to understand how these systems work:
- Product Scoring: Our scoring system considers laboratory test results, ingredient analysis, regulatory data, and third-party databases to assign safety and risk scores to food products.
- AI-Powered Analysis: We use AI language models (including OpenAI GPT-4 and successor models) to process product data, extract ingredient information, and generate analytical summaries. Product data -- not your personal information -- is sent to these AI services for analysis.
- Impact on You: These automated decisions affect the product information, scores, and risk assessments displayed to you within the App.
- Informational Only: Automated scoring does not make health decisions for you. It provides informational assessments only and is not intended as medical, dietary, or health advice.
- Your Rights: You may request information about the logic involved in our automated decision-making processes by contacting us at support@verifoods.com.
INTERNATIONAL DATA TRANSFER
Your personal information may be maintained and processed by us, our affiliates, and other third-party service providers in Canada, the United States, or other jurisdictions. Specifically:
- Our primary infrastructure is hosted by Supabase, with data processing occurring in applicable cloud regions.
- Firebase and Google services may process data globally in accordance with Google's data processing terms.
- Branch.io processes attribution data in the United States.
- Stripe processes payment data in the jurisdictions where it operates.
Such jurisdictions may not have the same data protection laws as the jurisdiction in which you provided the information. When we transfer your information to other jurisdictions, including to jurisdictions outside of the province in which you reside (which may include transfer outside of Quebec for Quebec residents), Canada, or the European Economic Area, it will be subject to the laws of that jurisdiction and may be disclosed to or accessed by the courts, law enforcement, and governmental authorities in accordance with those laws.
By using the Services, you consent to the transfer, storage, and processing of your personal information in jurisdictions outside of your country of residence, including Canada and the United States. Data transfers are conducted in compliance with applicable privacy frameworks and data protection laws.
SAFEGUARDING AND RETENTION OF PERSONAL INFORMATION
We have implemented administrative, technical, and physical measures designed to safeguard personal information in our custody and control against theft, loss, and unauthorized access, use, modification, and disclosure. We restrict access to information on a need-to-know basis to employees and authorized service providers who require access to fulfill their job requirements.
We have information retention processes designed to retain information for no longer than necessary for the purposes stated above or to otherwise meet legal requirements. To determine the appropriate retention period for personal information, we consider the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure of your personal information, the purposes for which we process your personal information and whether we can achieve those purposes through other means, and the applicable legal requirements.
The following retention periods apply to specific categories of personal information:
- Account data: Retained while your account is active, plus 30 days following a deletion request to allow for processing and confirmation.
- Scan history: Retained while your account is active and deleted upon account deletion.
- Payment and transaction records: Retained for 7 years after the transaction date, as required for legal and tax compliance purposes.
- Analytics data: Aggregated analytics data is retained indefinitely. Individual session-level analytics data is retained for 26 months.
- Support communications: Retained for 3 years from the date of the communication.
- Affiliate and partner data: Retained for the duration of the partnership, plus 2 years following termination of the partnership for audit, legal, and tax purposes.
- Referral data: Retained while the referral program is active and your account is open, and deleted upon account deletion.
- Streak and gamification data: Retained while your account is active and deleted upon account deletion.
For additional details regarding retention periods for specific categories of your personal information, you may contact us using the details provided at the end of this Privacy Policy.
COOKIES, ADS, AND ADDITIONAL INFORMATION ABOUT THE WEBSITE AND THE APP
Using the App and Visiting the Website
In general, you can visit our Website and use the App without telling us who you are or submitting any personal information. However, when you use the App, we collect information regarding your device type, operating system and version, carrier provider, unique device identifier, and the date and time that the App accesses our servers. We also collect information about the barcodes you scan and products you view. When you visit our Website, we collect your IP (Internet protocol) addresses, internet service provider, and other related information such as page requests, browser type, operating system, and average time spent on our Website. We also collect the website or advertisement that was linked to or from the Website or the App when you accessed our Services.
We use this information to help us understand the activity on our Services, to monitor and improve our Services, and to tailor your in-app experience.
Cookies, Tracer Tags, and Beacons
We and our third-party providers, including Google Analytics, collect, process, store, and analyze information obtained from your browser or mobile device through the use of "cookies" or other tools such as "tracer tags" and "web beacons."
A cookie is a tiny element of data that the Website or App can send to your browser, which may then be stored on your computer or mobile device so that we can recognize you when you return. "Tracer tags" and "web beacons" allow us to understand your activity when you visit the Website or use the App.
For more information on cookies and how they can be managed and deleted, please visit https://www.allaboutcookies.org/ or https://www.networkadvertising.org/choices/. We use the following cookies and other tools on the Website or the App, as applicable:
Strictly necessary cookies:
These are essential in order to enable you to use the Website and its features as well as maintaining site security. Without these cookies, you would not be able to access the Services securely or at all.
Functionality cookies:
These cookies are necessary for the Website to operate and allow us to remember what choices you make and provide enhanced, more personal features. The information these cookies collect does not track your browsing activity on other websites.
Analytical cookies:
These cookies allow us to recognize and count the number of visitors and to see how visitors move around the Website. For example, they allow us to understand which pages are visited most often, and if they get error messages from web pages. All information collected by these cookies is aggregated. These tools help us track, measure, and analyze the behaviours and usage patterns of visitors to the Website and users of the App. We use this information to help us understand how visitors engage with the Website and the App, and to improve and tailor our visitors' and users' experience.
If you have connected a Sign-in Partner account to the Website and/or App, cookies may let us know who you are and provide us and our service providers with information that we will use to personalize your experience.
You may set your web browser to notify you when you receive a cookie or not to accept certain cookies. However, if you decide not to accept cookies from the Website or App, you may not be able to take advantage of all of the features of our Services.
You can opt out from being tracked by Google Analytics in the future by visiting: https://tools.google.com/dlpage/gaoptout. For more information about Google Analytics, see www.google.com/policies/privacy/partners/.
We do not use cookies in our App. However, we use other tracking tools to collect and process details of your user activity within the App in order to send you push notifications, offers, and other service-related information.
We may also use services provided by third-party platforms (such as social media sites) to serve tailored ads about our products and services on such platforms to you or others. We may provide a hashed version of your email address, device ID, or other information to the platform provider for such purposes.
To opt out of the use of your information for this type of advertising, contact us using the details below or adjust your advertising settings on such third-party platforms.
Third-Party Links and Content
The App and Website may contain or incorporate services and content from third parties and may contain links to other third-party websites and apps that are not owned or controlled by us, including social media websites or apps, or online shopping websites. Except as provided in this policy, we will not provide any of your personal information to these third parties without your consent. We provide third-party content, services, and links to third-party websites and apps as a convenience to the user. This content, and these services and links, are not intended as an endorsement of or referral to the third-party content, services, or linked websites and apps. The incorporated content or services, or linked websites and apps, have separate and independent privacy statements, notices, and terms of use, which we recommend you read carefully. We have no control over, do not review, and are not responsible for the privacy policies of or content displayed on such other websites and apps, or in connection with such content or services. When you use a third-party service or click on such a link, you will leave our service and go to another site. During this process, another entity may collect personal information from you.
YOUR RIGHTS
Subject to applicable law, you may have certain rights with respect to our processing of your personal information. You may have the right to request access to the information we hold about you, obtain confirmation as to whether or not information concerning you exists, be informed of the content and source of such information, and check its accuracy.
If you change your mind and no longer wish to receive marketing emails from us, or if you wish to stop seeing tailored ads and other electronic messages on social media, you can request that we cease sending such emails or serving such ads.
You may exercise your rights or the choices described above by contacting us at the contact information set out below, or by clicking the unsubscribe link displayed in any of our marketing emails. We may request certain personal information for the purposes of verifying the identity of the individual seeking access to their personal information records.
If you wish to stop receiving push notifications from us to your mobile device, you can turn off push notifications for the App in the settings of your mobile device.
DATA DELETION AND OTHER RIGHTS
You have the right to correct, update, delete, block, cancel, or object to the use of your personal information held by us, and the right to withdraw your consent to our processing or sharing of your personal information, subject to applicable laws. If you wish to exercise any of these rights, please contact our Privacy Officer using the contact details provided at the end of this Privacy Policy. We will respond to all requests within a reasonable timeframe.
To request deletion of your account, please contact us at support@verifoods.com.
We may ask you for additional information to confirm your identity and for security purposes before disclosing information requested to you.
Should you have cause to complain about how we handle your personal information, please contact us in the first instance. We will do our best to resolve your concern.
Requests to delete accounts are final and permanent. All personal data will be removed from our servers within 30 days of the confirmed deletion request. Some data which forms content you have contributed to (such as comments on articles) may remain but with all personally identifiable information removed.
YOUR CALIFORNIA PRIVACY RIGHTS (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 ("CCPA"), provides you with specific rights regarding your personal information. This section describes the categories of personal information we collect, your rights under the CCPA, and how to exercise those rights.
Categories of Personal Information Collected
We have collected the following categories of personal information from consumers within the last twelve (12) months:
| Category | Examples | Collected |
|---|---|---|
| A. Identifiers | Name, email address, unique device identifiers (IDFV, Android ID), IP address, account name | Yes |
| B. Personal information categories listed in Cal. Civ. Code 1798.80(e) | Name, email address | Yes |
| C. Protected classification characteristics | None | No |
| D. Commercial information | Purchase and subscription history, transaction records, subscription tier | Yes |
| E. Biometric information | None | No |
| F. Internet or other similar network activity | Browsing history within the App, search history, interaction with the App and Website, products scanned, articles viewed | Yes |
| G. Geolocation data | Approximate location derived from IP address | Yes |
| H. Sensory data | None | No |
| I. Professional or employment-related information | Job application data (if applicable) | Yes (if applied) |
| J. Non-public education information | None | No |
| K. Inferences drawn from other personal information | Product preferences, usage patterns, engagement tendencies | Yes |
Your Rights Under the CCPA
As a California resident, you have the following rights:
Right to Know: You have the right to request that we disclose to you the categories of personal information we have collected about you, the categories of sources from which the personal information was collected, the business or commercial purpose for collecting the personal information, the categories of third parties with whom we share personal information, and the specific pieces of personal information we have collected about you.
Right to Delete: You have the right to request that we delete any personal information about you that we have collected from you, subject to certain exceptions provided by law (such as where the information is necessary to complete a transaction, detect security incidents, comply with legal obligations, or for certain other purposes permitted by law).
Right to Correct: You have the right to request that we correct inaccurate personal information that we maintain about you.
Right to Opt-Out of Sale or Sharing: VeriFoods does not sell your personal information. We do not sell, rent, or trade your personal information to third parties for monetary or other valuable consideration. We do not share your personal information for cross-context behavioral advertising purposes.
Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights. We will not deny you goods or services, charge you different prices or rates, provide you a different level or quality of goods or services, or suggest that you may receive a different price or rate or different level or quality of goods or services as a result of exercising your CCPA rights.
Right to Limit Use and Disclosure of Sensitive Personal Information: We do not use or disclose sensitive personal information for purposes beyond those permitted under the CCPA.
"Do Not Sell or Share My Personal Information"
VeriFoods does not sell or share your personal information for cross-context behavioral advertising. Because we do not engage in such practices, there is no need for you to submit an opt-out request. However, if you have questions or concerns about our data practices, you may contact us at any time using the information provided below.
How to Submit CCPA Requests
To exercise any of the rights described above, you may submit a verifiable consumer request to us by:
- Email: support@verifoods.com
We will respond to verifiable consumer requests within forty-five (45) days of receipt. If we require more time (up to an additional 45 days), we will inform you of the reason and the extension period in writing.
To verify your identity when you submit a request, we may ask you to provide information that matches information we have on file about you. We will only use personal information provided in a verifiable consumer request to verify the requestor's identity or authority to make the request.
Authorized Agents
You may designate an authorized agent to submit a request on your behalf. To do so, you must provide the authorized agent with written permission to act on your behalf, and we may require you to verify your own identity directly with us and confirm that you provided the authorized agent permission to submit the request.
UPDATES TO THE PRIVACY POLICY
We may update this Privacy Policy periodically to reflect changes to our privacy and data practices. We encourage you to periodically review this policy. We will indicate at the top of this Privacy Policy when it was most recently updated.
INFORMATION ABOUT OUR PRIVACY GOVERNANCE POLICIES AND PRACTICES
- We are committed to protecting personal information and have implemented a comprehensive set of policies and practices that govern our treatment of personal information. These policies and procedures include, among other things, the following:
- We have implemented policies and procedures to protect personal information in our custody and control from unauthorized access, use, or disclosure.
- We have implemented processes to respond to data subject requests and complaints in a timely and effective manner.
- As set out above, we have implemented a framework for the retention and destruction of personal information to ensure compliance with legal obligations, and to securely destroy personal information once no longer required.
- We have designated a Privacy Officer who is responsible for overseeing our compliance with privacy legislation.
- We have implemented a privacy framework that defines the roles and responsibilities for our employees with respect to the treatment of personal information.
- We provide our employees with regular privacy training and awareness.
CONTACT US
Please contact us if:
- you have any questions or comments about this Privacy Policy;
- you wish to update information we have about you or your preferences;
- you would like to exercise your rights of access, rectification, blocking, or deletion, or to object to the processing of your information;
- you wish to submit a CCPA request or exercise any of your California privacy rights;
- you are a parent or guardian and wish to review information collected from your child or have that information deleted.
Privacy Officer
VeriFoods Inc.
Province of British Columbia, Canada
Email: support@verifoods.com