Back to home

Privacy Policy

Effective date: 4 March 2026

1. Introduction

Ingredible (“we”, “us”, or “our”) operates the Ingredible platform, a SaaS tool that helps food manufacturers generate FSANZ-compliant food labels. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our website and services.

We are committed to protecting your privacy in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). By using Ingredible, you agree to the practices described in this policy.

2. Information We Collect

We collect the following categories of information:

  • Account information — your name, email address, company name, and company address when you register.
  • Product and formulation data — product names, ingredient lists, nutritional data, and label configuration you enter into the platform.
  • Usage data — pages visited, features used, and actions taken within the app, collected automatically to help us improve the service.
  • Authentication data — session tokens managed via secure cookies to keep you logged in.

We do not collect sensitive information such as government identifiers, health records, or payment card numbers. Payment processing (if applicable) is handled by a third-party processor and we do not store card details.

3. How We Use Your Information

We use your information to:

  • Create and manage your account and authenticate your identity.
  • Provide the Ingredible platform and generate FSANZ-compliant labels.
  • Send transactional emails (e.g. password resets, account notices).
  • Improve, debug, and develop new features for the platform.
  • Comply with our legal obligations.

We will not use your information for direct marketing without your explicit consent, and you may opt out at any time.

4. Data Storage & Security

Your data is stored on infrastructure provided by Supabase, hosted on Amazon Web Services (AWS) in the ap-southeast-2 (Sydney) region. All data is encrypted at rest and in transit using industry-standard TLS and AES-256 encryption.

Access to your data within the platform is governed by Row-Level Security (RLS) policies in our database, ensuring that each user can only access their own data. We apply the principle of least privilege to all internal systems.

While we take reasonable steps to protect your information, no internet transmission or electronic storage is 100% secure. We encourage you to use a strong, unique password for your account.

5. Data Sharing and Disclosure

We do not sell, rent, or trade your personal information to third parties. We may share your information only in the following limited circumstances:

  • Service providers — Supabase acts as our data processor under a data processing agreement. They process your data only on our instructions.
  • Legal requirements — if required by law, court order, or government authority.
  • Business transfers — in the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity, subject to the same privacy protections.

6. Data Retention

We retain your personal information for as long as your account is active or as needed to provide our services. If you close your account or request deletion, we will delete or anonymise your personal information within 30 days, except where we are required by law to retain certain records.

7. Your Privacy Rights

Under the Australian Privacy Principles, you have the right to:

  • Access — request a copy of the personal information we hold about you.
  • Correction — ask us to correct inaccurate or incomplete information.
  • Deletion — request that we delete your personal information (subject to legal retention obligations).
  • Portability — request your data in a structured, commonly used format.
  • Complaints — lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

To exercise any of these rights, contact us at the address below.

8. Cookies

Ingredible uses session cookies solely for authentication purposes — to keep you securely logged in between page visits. These are managed by Supabase SSR and are essential for the service to function.

We do not use advertising cookies, cross-site tracking cookies, or third-party analytics cookies. You can disable cookies in your browser settings, but doing so will prevent you from logging in.

9. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date at the top of this page and, where appropriate, notify you by email. Your continued use of the service after changes take effect constitutes your acceptance of the updated policy.

10. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of your personal information, please contact us at: privacy@ingredible.au