Legal

Privacy Policy

Last updated: April 30, 2026

1. Introduction

Chowmark ("we," "us," or "our") is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use Chowmark.com (the "Service"). This policy complies with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).

2. Information We Collect

Information You Provide

  • Account information: name, email address, password (stored as a hashed value — we never store your plaintext password)
  • Product submissions: product name, brand, barcode, category, notes, and optional photos you submit through the Service
  • Communications: messages you send to us via email or contact forms

Information Collected Automatically

  • Usage data: pages visited, search queries, barcode scans, product views, and affiliate link clicks
  • Device and browser information: IP address, browser type, operating system, and approximate geographic location (country/region level)
  • Session data: session identifiers stored in cookies to maintain your login state

Information from Third Parties

  • If you sign in via Manus OAuth, we receive your name and email from the OAuth provider
  • Analytics data from PostHog (self-hosted analytics, no third-party data sharing)

3. How We Use Your Information

  • To provide and improve the Service, including personalized recall alerts and pantry watch lists
  • To send recall alert emails when products you are watching are recalled
  • To respond to your inquiries and support requests
  • To analyze usage patterns and improve our scoring methodology
  • To detect and prevent fraud, abuse, and security incidents
  • To comply with legal obligations

4. Affiliate Tracking

When you click affiliate links on Chowmark, our affiliate partners (including Amazon, Chewy, and others via Skimlinks) may place cookies on your device to track purchases and calculate commissions. This tracking is performed by our affiliate partners under their own privacy policies. We do not receive your personal purchase data from these partners — only aggregate commission information.

5. Information Sharing

We do not sell your personal information. We may share your information with:

  • Service providers: Resend (transactional email), PostHog (analytics), Manus (hosting and authentication) — each bound by data processing agreements
  • Legal requirements: When required by law, court order, or government authority
  • Business transfers: In connection with a merger, acquisition, or sale of assets, with notice provided to affected users

6. Cookies

We use cookies to maintain your session, remember your locale preference, and analyze usage patterns. For a full description of the cookies we use, see our Cookie Policy. You can manage cookie preferences through our cookie consent banner or your browser settings.

7. Data Retention

We retain your account information for as long as your account is active or as needed to provide the Service. Usage and analytics data is retained for up to 24 months. Product submission data is retained indefinitely as part of our product database. You may request deletion of your personal data at any time (see Section 9).

8. Data Security

We implement industry-standard security measures including HTTPS encryption, hashed password storage, and access controls. However, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security of your information.

9. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal information:

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request correction of inaccurate personal information
  • Deletion: Request deletion of your personal information
  • Portability: Request your data in a machine-readable format (GDPR/EEA users)
  • Opt-out of marketing: Unsubscribe from marketing emails at any time via the unsubscribe link in any email
  • Do Not Sell: We do not sell personal information (CCPA)

To exercise these rights, email [email protected] with the subject line "Data Request" or "Data Deletion Request." We will respond within 30 days.

10. Children's Privacy

The Service is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, contact us at privacy@chowmark.com and we will delete it promptly.

11. International Transfers

Chowmark operates primarily in Canada and the United States. If you access the Service from outside these regions, your information may be transferred to and processed in Canada or the United States. By using the Service, you consent to this transfer.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes by email or by posting a notice on the Service. Your continued use of the Service after any changes constitutes your acceptance of the updated policy.

13. Contact

For privacy-related inquiries, contact our Privacy Officer at [email protected].