Batch'd

Privacy Policy

Effective 6 August 2026

This policy explains what personal data the Batch'd platform processes, why, and what rights you have. It applies to the scanning app, the retailer dashboard, signup, and related pages.

1. Who is responsible

For data your organisation's staff enter while using the service (scan records, photos, recall responses, complaint records), your organisation is the data controller and Batch'd processes that data on its behalf to provide the service. For account signup data and platform operations, Batch'd (operated from Norway; contact below) acts as controller.

2. Data processed

Photos are of products and packaging; don't photograph people when capturing lot codes.

3. Purposes and legal bases

4. Service providers (subprocessors)

ProviderPurpose
SupabaseDatabase, authentication, file storage
NetlifyHosting and serverless functions
ResendOperational email delivery
AnthropicAI product identification — a photo taken in the scanner's product step is processed to identify the product; it is not used by the provider to train models
Sentry (EU-hosted)Error monitoring — when the app encounters a technical error, a report including browser details and the error context is sent to Sentry's EU data centre
Google Fonts / jsDelivrContent delivery for fonts and libraries (your IP address is disclosed to the CDN when pages load)

5. International transfers

Some providers process data in the United States. Where data of EU/EEA users is transferred, it is done under the providers' standard contractual clauses or an equivalent recognised mechanism.

6. Retention

7. Your rights

Under the GDPR (and similar laws), you can request access to, correction of, or deletion of your personal data, restriction of or objection to processing, and portability. For operational data, requests are handled together with your organisation, which controls those records. You can also complain to a supervisory authority — in Norway, Datatilsynet.

8. Security

Data is encrypted in transit, access is segregated per organisation with row-level security, and role-based permissions limit what each account can see and do. No system is perfectly secure; report suspected vulnerabilities to the contact below.

9. Changes

Updates to this policy will be posted here with a new effective date; material changes will be announced to organisation administrators.

10. Contact

Privacy questions and requests: ian.w.race@gmail.com.