Legal

Privacy Policy

How NomNomVegan Oy collects, uses, stores, and protects your personal data — and your rights under GDPR.

Last updated: 17 June 2026  ·  Effective: 17 June 2026

Table of Contents

  1. Who We Are — Data Controller
  2. Personal Data We Collect
  3. Legal Basis for Processing
  4. How We Use Your Data
  5. Third-Party Services and Recipients
  6. International Data Transfers
  7. Data Retention
  8. Security Measures
  9. Your Rights Under GDPR
  10. Children's Privacy
  11. Cookies and Tracking
  12. Automated Decision-Making
  13. Changes to This Policy
  14. Contact Us

1. Who We Are — Data Controller

The data controller responsible for your personal data is:

NomNomVegan Oy
Business ID: [add your Y-tunnus here]
Registered address: Finland
Email: [email protected]
Website: nomnomvegan.com

NomNomVegan Oy operates the NomNomVegan mobile application and website (collectively, the "Service"). We are committed to protecting your privacy and handling your personal data transparently, lawfully, and in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR"), the Finnish Data Protection Act (1050/2018), and all other applicable data protection legislation.

If you have any questions, requests, or concerns about how we process your personal data, please contact us at the email address above. We aim to respond to all enquiries within 30 days.

2. Personal Data We Collect

We collect personal data that you provide directly to us, data generated through your use of the Service, and limited technical data collected automatically. We apply data minimisation and only collect what is necessary for the purposes described in this policy.

2.1 Account and Registration Data

2.2 Scan and Usage Data

2.3 Contribution and Feedback Data

2.4 Reputation and Contribution Statistics

2.5 Subscription and Payment Data

2.6 Shared Content

2.7 Technical and Log Data

We do not collect precise GPS location, contact lists, camera images outside of explicit product photo uploads, or any other sensitive categories of personal data under GDPR Article 9.

4. How We Use Your Data

We use your personal data strictly for the purposes for which it was collected. Specifically:

4.1 Providing and Improving the Service

4.2 Community Features

4.3 Safety, Security, and Legal Compliance

4.4 Subscription Management

4.5 What We Do Not Do

5. Third-Party Services and Recipients

We use a limited number of carefully selected third-party sub-processors to operate the Service. Each is bound by a data processing agreement or standard contractual clauses where applicable.

RecipientRoleData SharedLocation
Google LLC (Firebase)Authentication and identity managementEmail address, Firebase UIDUSA (SCCs)
Google LLC (Google Play)In-app purchase and subscription billingPurchase token, subscription product ID; billing handled directly by GoogleUSA (SCCs)
Cloudflare Inc.CDN, DDoS protection, DNSIP address, HTTP requests (in transit)USA/Global (SCCs)
Cloudflare R2Object storage for product and avatar photosUploaded image filesEU (Amsterdam)
Contabo GmbHVPS hosting (database, API server)All data stored on server; Contabo has no access to application-level dataGermany (EU)
Sentry (Functional Software, Inc.)Application error monitoringError stack traces, device OS version, app version; no personal data intentionally included in error eventsUSA (SCCs)
Open Food FactsOpen product database (read-only fallback)Barcode lookups only; no personal data transmittedFrance (EU)

We may disclose your personal data to competent authorities, courts, or law enforcement agencies if required by applicable law, court order, or governmental regulation, or if we reasonably believe disclosure is necessary to protect the rights, property, or safety of NomNomVegan Oy, our users, or the public.

In the event of a merger, acquisition, or sale of all or substantially all of our assets, personal data may be transferred as part of the transaction, subject to the same protections described in this policy.

6. International Data Transfers

Some of our sub-processors are located outside the European Economic Area (EEA), specifically in the United States. These transfers occur because Firebase Authentication and Google Play are operated by Google LLC (USA), and Sentry is operated by Functional Software, Inc. (USA).

Where personal data is transferred outside the EEA, we rely on the following safeguards to ensure an adequate level of protection:

Our primary data storage (PostgreSQL database, Cloudflare R2 photos) is hosted within the EEA (Germany and EU Amsterdam region respectively). We have deliberately chosen EU-hosted infrastructure for primary data storage to minimise the volume of cross-border transfers.

7. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. The following retention periods apply:

Data CategoryRetention PeriodBasis
Account data (email, alias, country, locale)Until account deletion request or 5 years of inactivityContract; legitimate interests (account recovery)
Scan history3 years from each scan date, or until account deletionContract; user feature
Product contributions (approved)Indefinitely as part of the community databaseLegitimate interests (community benefit); your alias remains associated with approved contributions
Product contributions (pending / rejected)2 years from submissionLegitimate interests (quality review)
Photos (product and avatar)Until deleted by user or account deletionContract
Feedback and votes3 yearsLegitimate interests (product trust calculation)
Reputation and statisticsUntil account deletionContract
Subscription records7 years from subscription end (Finnish accounting law)Legal obligation
Server and API access logs12 monthsLegitimate interests (security)
Admin audit logs3 yearsLegitimate interests (accountability)

When you delete your account through the app (Settings → Delete my data), we initiate erasure of your account data, scan history, and personal statistics within 30 days. Approved product contributions may be retained in anonymised or pseudonymised form as part of the community database, as they represent a collective resource. We will inform you of this when you submit a deletion request.

8. Security Measures

We take the security of your personal data seriously and have implemented a range of technical and organisational measures consistent with the nature of the data and the risks involved:

8.1 Technical Measures

8.2 Organisational Measures

8.3 Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Finnish Data Protection Ombudsman (Tietosuojavaltuutettu) within 72 hours of becoming aware of the breach, as required by GDPR Article 33. If the breach is likely to result in a high risk to your rights, we will also notify you without undue delay, as required by GDPR Article 34.

9. Your Rights Under GDPR

As a data subject under the GDPR, you have the following rights. We will respond to all requests within one month. For complex or numerous requests, we may extend this to three months with notice to you.

9.1 Right of Access (Article 15)

You have the right to obtain confirmation of whether we process your personal data, and if so, to receive a copy of that data along with information about how it is processed. You can request a data export directly from the app (Settings → Request my data).

9.2 Right to Rectification (Article 16)

You have the right to have inaccurate personal data corrected without undue delay. You can update your alias, country, and locale directly from the app settings. For other corrections, contact us at [email protected].

9.3 Right to Erasure — "Right to Be Forgotten" (Article 17)

You have the right to request erasure of your personal data where one of the conditions in Article 17 applies (e.g. data no longer necessary for the purpose collected, withdrawal of consent, or objection to processing with no overriding legitimate grounds). You can submit a deletion request from the app (Settings → Delete my data). Note the retention exceptions described in Section 7.

9.4 Right to Restriction of Processing (Article 18)

You have the right to request that we restrict the processing of your data in certain circumstances, such as while we verify the accuracy of data you have contested, or while we assess an objection you have raised.

9.5 Right to Data Portability (Article 20)

Where processing is based on your consent or on a contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format (JSON), and to transmit it to another controller. Use the in-app data export feature or contact us.

9.6 Right to Object (Article 21)

You have the right to object to processing of your personal data based on our legitimate interests (Article 6(1)(f)). We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, or if the processing is necessary for the establishment, exercise, or defence of legal claims. To object, contact us at [email protected].

9.7 Right Not to Be Subject to Solely Automated Decision-Making (Article 22)

We do not make decisions with significant legal or similarly significant effects based solely on automated processing, without human involvement. See Section 12 for more detail.

9.8 Right to Withdraw Consent

Where we rely on your consent for processing, you have the right to withdraw it at any time without affecting the lawfulness of processing before withdrawal. As described in Section 3, we rely primarily on contract and legitimate interests as our legal basis, not consent.

9.9 Right to Lodge a Complaint

If you believe we are processing your personal data unlawfully, you have the right to lodge a complaint with the Finnish Data Protection Ombudsman (Tietosuojavaltuutettu):

Office of the Data Protection Ombudsman
PO Box 800, FI-00531 Helsinki, Finland
tietosuoja.fi
[email protected]

We kindly ask that you contact us first, as we would like the opportunity to address your concern before you escalate to a supervisory authority.

To exercise any of the rights above, contact us at [email protected] or use the in-app request features in Settings. We do not charge for requests and will not discriminate against you for exercising your rights.

10. Children's Privacy

The Service is not directed to children under the age of 13. We do not knowingly collect personal data from children under 13. Users in the European Union and European Economic Area should be at least 16 years of age, or have verified parental or guardian consent, to use the Service, in accordance with GDPR Article 8.

If you are a parent or guardian and believe that your child has provided us with personal data without your consent, please contact us at [email protected] and we will take steps to delete such data promptly.

11. Cookies and Tracking

The NomNomVegan Android app does not use browser cookies, as it is a native mobile application. The app uses:

The NomNomVegan website (nomnomvegan.com) does not use analytics cookies, advertising cookies, or tracking pixels. We make a single API request to our own server to load community statistics. Google Fonts is loaded from Google's CDN, which may result in Google receiving your IP address as part of the font file request.

Our admin panel uses an HTTP-only, Secure, SameSite=Lax session cookie for authenticated admin sessions only. This cookie is not set for regular users.

12. Automated Decision-Making and Profiling

We use limited automated processing to operate the Service:

None of these automated processes constitute solely automated decision-making that produces legal effects or similarly significant effects on you within the meaning of GDPR Article 22. If you believe an automated decision has affected you unfairly, contact us and we will review it manually.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. When we make material changes, we will:

We encourage you to review this page periodically. Your continued use of the Service after the effective date of changes constitutes acceptance of the updated policy, to the extent permitted by applicable law.

14. Contact Us

If you have any questions, requests, or complaints about this Privacy Policy or the way we process your personal data, please contact us:

NomNomVegan Oy — Data Protection Contact
Email: [email protected]
Website: nomnomvegan.com

We aim to acknowledge all enquiries within 5 business days and provide a substantive response within 30 days. For complex matters, we will inform you if we need up to three months to respond.

You may also use the in-app features under Settings → Privacy & Data to submit GDPR data access and deletion requests directly.