FOODVERIX LEGAL
PRIVACY POLICY
FoodVerix
Effective date: to be inserted upon commercial launch
This Privacy Policy explains how RMP Services LLC, a Florida limited liability company, doing business as FoodVerix (“FoodVerix,” “we,” “us,” or “our”), collects, uses, and shares personal information, and the choices you have about that information. It applies to our website, our cloud-based food safety compliance documentation platform, and related communications (together, the “Services”).
Important: two different roles
FoodVerix is a business-to-business service used by food facilities. This policy covers personal information for which we decide the purposes and means, such as account, billing, website, and support data. When our business customers use the Services to store compliance records that may contain personal information about their own personnel, we act as a processor on that customer’s behalf, and that processing is governed by our Data Processing Agreement with the customer and by the customer’s own privacy policy, not by this policy. If you are an employee of one of our customers and have questions about records your employer stores in the Services, please contact your employer.
1. Information We Collect
We collect the following categories of personal information:
Account and profile information: name, business email address, role or title, and login identifiers when you register or are invited to an account.
Billing information: subscription plan, billing contact, and transaction records. Payment card details are collected and processed by our payment processor and are not stored by us.
Content you provide: information you enter into the Services, and support requests or other communications you send us.
Usage and device information: basic technical data such as IP address, browser type, and log information generated when you use the Services, used to operate, secure, and troubleshoot the Services.
Customers may record limited information reasonably necessary to investigate a food safety complaint or incident, but should not submit medical records, diagnoses, treatment information, insurance information, or other protected health information, and should minimize or de-identify personal information wherever reasonably possible.
2. How We Use Information
We use personal information to:
Provide, maintain, and improve the Services and your account.
Process subscriptions, billing, and payments.
Authenticate users and secure the Services, including preventing fraud and abuse.
Respond to your requests and provide customer support.
Send service-related communications, such as account, security, and transactional messages.
Comply with legal obligations and enforce our agreements.
We do not sell personal information, and we do not use it for cross-context behavioral advertising.
3. How We Share Information
We share personal information only as described below:
Service providers: vendors that perform services for us and process personal information on our behalf under contract. Our current service providers include Cloudflare (hosting, content delivery, and network security), Auth0 (authentication and login), Backblaze B2 (encrypted backup storage), and Google Workspace (business email and customer-support communications for info@, support@, and billing@foodverix.com). We update this list as our providers change.
Payment processor: Square processes payment card information through its own hosted checkout to handle subscription payments, under its own terms and privacy notice. We do not collect or store complete payment card numbers or card security codes, and we may receive limited transaction information from Square, such as payment status, amount, and transaction identifiers.
Legal and safety: when required by law, legal process, or to protect the rights, property, or safety of FoodVerix, our users, or others.
Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to this policy.
We do not share personal information with third parties for their own marketing purposes.
4. Data Retention
We retain personal information for as long as needed to provide the Services, maintain your account, comply with our legal obligations, resolve disputes, and enforce our agreements. Content that our customers store in the Services is retained and deleted as described in our agreements with those customers, including the Data Processing Agreement. When personal information is no longer needed, we delete or de-identify it using reasonable methods.
5. Data Security
We maintain reasonable technical and organizational measures designed to protect personal information, including encryption of data in transit and at rest, encryption of separately stored backups, multi-factor authentication, role-based access controls, regular backups, and confidentiality obligations for those with access. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential.
6. Your Privacy Rights
Depending on where you live and to the extent applicable U.S. state privacy laws apply to us, you may have some or all of the following rights regarding personal information we hold about you as a controller:
The right to access or obtain a copy of your personal information.
The right to correct inaccurate personal information.
The right to request deletion of your personal information.
The right to opt out of the sale of personal information or of targeted advertising. As noted above, we do not sell personal information or engage in cross-context behavioral advertising.
The right not to receive discriminatory treatment for exercising these rights.
To exercise a right, contact us using the details in Section 11. We will verify your request and respond as required by applicable law. If you are a resident whose data we process on behalf of a business customer, we will refer your request to that customer.
7. Cookies and Tracking
We use only cookies and similar technologies that are necessary to operate and secure the Services, such as keeping you logged in and protecting against abuse. These essential cookies include cookies set by our authentication and security providers, for example Auth0 to manage your login session and Cloudflare to help secure the Services and prevent fraud and automated abuse. We do not use third-party advertising or analytics cookies at this time.
8. Children’s Privacy
The Services are intended for businesses and their authorized personnel, and are not directed to children. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, please contact us and we will take appropriate steps to delete it.
9. Users Outside the United States
The Services are currently offered to customers in the United States, and personal information is processed primarily in the United States. Some infrastructure providers, such as our content delivery and network security provider, may route or process limited traffic through their global networks unless regional controls are configured. If we begin offering the Services to customers in the European Economic Area or the United Kingdom, we will update this policy to describe the legal bases for processing and the safeguards for international data transfers that those laws require.
10. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date above and, where appropriate, provide additional notice. Your continued use of the Services after an update means you accept the revised policy.
11. Contact Us
If you have questions about this Privacy Policy or our privacy practices, contact us at:
RMP Services LLC d/b/a FoodVerix
2310 SW 63rd Terrace, Miramar, FL 33023, United States
Privacy contact: support@foodverix.com