Privacy Policy
Last updated: 27 July 2026
VerdLynx (“the Service”) is operated by Pineapple Labs LLC (“we”, “us”). This policy describes what personal data we process when you use www.verdlynx.com, why, and the rights you have over it. We act as the data controller for account data, and as a processor for the product and compliance data your organisation uploads.
What we collect
- Account data — your name, work email address, password (stored as a salted hash, never in plain text) and company name, provided at sign-up.
- Workspace content — the SKUs, packaging specifications, artwork files, laboratory certificates, declarations and scan events your organisation creates in the Service. This data belongs to your organisation; we process it only to provide the Service.
- Billing data — subscription status and plan. Card details are collected and stored by Stripe, our payment processor; they never touch our servers.
- Checklist & reminder sign-ups — if you request our PPWR readiness checklist on the public site, we store the email address you give us to send the checklist link and a small number of deadline-reminder emails. Those emails are delivered on our behalf by Resend (see Sub-processors below). Every such email contains a one-click unsubscribe link, and unsubscribing stops them immediately.
- Usage records — timestamps and counters for AI-assisted actions (used for plan quotas) and authentication events. On our public marketing pages we use Google’s advertising measurement to see which ads lead to a sign-up, and only after you consent (see Cookies below). We run no trackers inside the signed-in product, and never use your uploaded content for advertising.
Why we may process it (legal bases)
- Performing our contract with you (GDPR Art. 6(1)(b)) — account data, workspace content and billing status, processed to provide the Service you signed up for.
- Legitimate interests (Art. 6(1)(f)) — usage counters for plan quotas, authentication and security logs, and protecting the Service against abuse.
- Legal obligations (Art. 6(1)(c)) — tax and accounting records connected to billing.
- Consent (Art. 6(1)(a)) — the optional checklist/deadline-reminder emails you can request on our public pages (withdraw via the unsubscribe link in any of those emails), and the optional ad-measurement cookies on our marketing pages (withdraw any time via “Cookie settings” in the page footer). Withdrawing is as easy as consenting was.
Where it lives
Application data is stored with Supabase in the European Union. The web application is served by Vercel. Payments are handled by Stripe. When you use an AI-assisted feature (artwork verification, recyclability scoring, certificate extraction, document drafting), the content you submit for that feature is processed by Anthropic’s Claude API to produce the result; we do not permit our AI providers to train models on your data. Email is delivered through Resend — both transactional messages (sign-in, password reset, invitations) and the checklist and deadline-reminder emails you can request on our public pages.
Sub-processors
We rely on a small set of vetted providers to run the Service, each under a data-processing agreement:
- Supabase — application database and file storage (European Union, Paris).
- Vercel — web application hosting (EU region).
- Anthropic — AI processing for AI-assisted features (United States; no model training on your data).
- Stripe — payment processing.
- Resend — email delivery, both transactional and the checklist and deadline-reminder emails you can request on our public pages (United States; Standard Contractual Clauses in place).
We keep this list current and note material changes here.
How we protect it
We host application data in the European Union, encrypt it in transit and at rest, store passwords only as salted hashes, isolate each workspace’s data by tenant (database row-level security), and limit access to the people who need it. No system is perfectly secure, but we apply reasonable technical and organisational measures appropriate to the data we handle.
International transfers
Some of our providers process data in the United States (for example, AI processing by Anthropic, and email delivery by Resend). Where personal data leaves the European Economic Area, we rely on Standard Contractual Clauses in our agreements with those providers and, where available, their certification under the EU–US Data Privacy Framework.
Cookies
Inside the product we set only the cookies required to keep you signed in (authentication session cookies). On our public marketing pages we also use Google Ads conversion-measurement cookies to see which ads lead to a sign-up — these are optional, set only if you choose “Accept” on the cookie banner, and default to off until you do (Google Consent Mode). If you accept, Google receives technical signals such as your IP address and device information as part of that measurement. You can decline with no loss of functionality, and change or withdraw your choice at any time via “Cookie settings” in the page footer. We set no cross-site tracking cookies inside the signed-in product.
Retention
Workspace content is retained while your account is active, subject to any retention window of your plan. You can delete your account at any time from workspace settings, or by emailing us at the address below; we delete your workspace and its content — including signed declarations of conformity — from production systems within 30 days, with residual copies in encrypted backups expiring on their normal cycle. Regulatory retention duties (for example the PPWR’s 5–10 year duty to keep declarations of conformity) rest with your organisation, so export or print any records you must keep before deleting — the product reminds you of this at the point of deletion.
Account data and the authentication and usage logs tied to your workspace exist for the life of your account and are removed when it is deleted. Invoices and payment records are retained by Stripe and, where the law requires it, by us for as long as tax and accounting rules oblige — typically up to seven years — even after account deletion.
If you only asked for the checklist or deadline reminders, we keep your email address until you unsubscribe, after which we retain a minimal record of the opt-out so we don’t email you again.
Data breaches
If a personal-data breach affecting you occurs, we will notify you and, where required, the relevant supervisory authority without undue delay, as the GDPR requires.
Your rights
Under the GDPR you can request access to, correction of, export of, or deletion of your personal data, and you can object to or restrict certain processing. Where processing rests on consent (the optional ad-measurement cookies), you can withdraw it at any time via “Cookie settings” in the page footer. Write to us at the address below and we’ll respond within 30 days. You also have the right to lodge a complaint with your supervisory authority. If your organisation needs a Data Processing Agreement (GDPR Article 28), we make one available on request.
Contact
Pineapple Labs LLC, 145 Tremont Street, Suite 201-1605, Boston, MA 02111, USA — email contact@verdlynx.com. We’ll update this policy as the Service evolves and note the date of the latest revision at the top of this page.