Privacy Policy
Last updated: April 28, 2026
The privacy of your data — and it is your data, not ours — is a big deal to us. In this policy, we lay out: what data we collect and why, how your data is handled, and your rights with respect to your data. We promise we never sell your data: never have, never will.
This policy applies to FSMA204Hub, a service operated by Darza Technologies LLC, a Wyoming limited liability company ("we," "us," or "Darza Technologies"). It covers our handling of information about site visitors, prospective customers, and customers and authorized users of FSMA204Hub. We refer collectively to these categories of individuals as "you" throughout this policy.
This policy does not cover lot-level traceability data, supplier records, or other operational records that you upload to FSMA204Hub in the course of running your business ("Customer Data"). We process Customer Data on your instructions as a service provider, and our obligations with respect to that data are governed by our Terms of Service.
If you are a California resident, additional disclosures required by California law are included in the "Your rights with respect to your information" section below.
What we collect and why
Our guiding principle is to collect only what we need.
Identity and access
When you sign up for FSMA204Hub, we ask for identifying information such as your name, email address, and your company name. That's so you can personalize your account, and we can send you product updates and other essential information. We may also send you optional surveys from time to time to help us understand how you use the product and to make improvements. With your consent, we will send you our newsletter and other updates.
We will never sell your personal information to third parties, and we won't use your name or company in marketing statements without your permission.
Billing information
If you sign up for a paid FSMA204Hub plan, you will be asked to provide your payment information and billing address. Credit card information is submitted directly to our payment processor and does not hit Darza Technologies' servers. We store a record of the payment transaction, including the last 4 digits of the credit card number, for purposes of account history, invoicing, and billing support. We store your billing address so we can charge you for service, calculate any sales tax due, send you invoices, and detect fraudulent transactions.
Product data
We store on our servers the operational records that you upload, link, or generate inside FSMA204Hub — for example, supplier lots, ingredient receipts, production batches, and traceability lot codes. This is so the product can do its job: linking ingredient lots to finished batches and producing a compliance score for FSMA 204 / retailer audits. We keep this content for as long as your account is active. If you cancel your account, we'll delete the content within 60 days. You can read more about this in the "What happens when you delete content" section below.
General geolocation data
We log the IP address used to sign up for an FSMA204Hub account and retain it for use in mitigating spammy signups. We also log account access by IP address for security and fraud prevention purposes, and we keep this login data for as long as your account is active.
Website interactions
We collect information about your browsing activity for analytics and statistical purposes such as conversion-rate testing and experimenting with new product designs. This includes, for example, your browser and operating system versions, your IP address, which web pages you visited and how long they took to load, and which website referred you to us.
We use Google Analytics 4 (measurement ID G-8V22MK3100) to collect aggregated, mostly anonymized analytics about visits to fsma204hub.com. Google Analytics sets first-party cookies on your device. You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on or by blocking cookies in your browser settings. We do not currently combine analytics data with the personal information you provide when signing up.
Cookies
A cookie is a piece of text stored by your browser. We use first-party cookies to keep you signed in, remember basic preferences, and support analytics as described above. Some of these cookies are set by our third-party providers (for example, Clerk for authentication and Google Analytics for measurement). You can adjust cookie retention settings and accept or block individual cookies in your browser settings, although the application will not work properly if you disable cookies entirely.
Voluntary correspondence
When you email us with a question or to ask for help, we keep that correspondence — including your email address — so that we have a history of past interactions to reference if you reach out again.
We also store information you may volunteer, for example, written responses to surveys. If you agree to a customer interview, we may ask for permission to record the conversation for future reference. We will only do so with your express consent.
When we access or disclose your information
To provide the product or services you've requested. We use a small number of third-party subprocessors to help run FSMA204Hub. As of the last-updated date above, these include:
- Clerk — authentication, user, and organization management
- Neon — managed PostgreSQL database hosting
- DigitalOcean — application hosting (App Platform)
- Cloudflare — DNS and email routing
- Google Analytics — website analytics
- Resend — transactional email delivery (when added)
- Paddle — payment processing and merchant of record (when added)
We may update this list as we add or change service providers. Each of these subprocessors has its own privacy policy and processes data on our instructions.
To investigate or take action regarding abuse. Accessing a customer's account when investigating potential abuse is a measure of last resort. We aim to balance the privacy and safety of our customers against the need to respond to issues. If we discover you are using FSMA204Hub for a restricted purpose (for example, attempting to falsify regulatory records), we will take action as necessary, including notifying appropriate authorities where warranted.
To help you troubleshoot a problem, with your permission. If we need to access your content to help you with a support case, we will ask for your consent before proceeding.
Aggregated and de-identified data. We may aggregate and/or de-identify information collected through the service. We may use de-identified or aggregated data for any purpose, including product improvement and analytics.
When required under applicable law. Darza Technologies is a U.S. company and our data infrastructure is located in the United States.
- Requests for user data. Our policy is to not respond to government requests for user data unless we are compelled by legal process or in limited circumstances in the event of an emergency request. If U.S. law-enforcement authorities have the necessary warrant, criminal subpoena, or court order requiring us to disclose data, we must comply. We will only respond to requests from government authorities outside the U.S. if compelled by the U.S. government through procedures outlined in a mutual legal-assistance treaty or agreement. It is our policy to notify affected users before we disclose data unless we are legally prohibited from doing so, and except in some emergency cases.
- Preservation requests. We comply with requests to preserve data only if compelled by the U.S. Federal Stored Communications Act, 18 U.S.C. § 2703(f), or by a properly served U.S. subpoena. We do not disclose preserved data unless required by law or compelled by a court order that we choose not to appeal.
- Tax authorities. If we are audited by a tax authority, we may be required to disclose billing-related information. If that happens, we will disclose only the minimum needed, such as billing addresses and tax-exemption information.
If Darza Technologies is acquired by or merges with another company — we don't plan on that, but if it happens — we'll notify you well before any of your personal information is transferred or becomes subject to a different privacy policy.
Your rights with respect to your information
We strive to apply the same data rights to all customers, regardless of their location. Some of these rights include:
- Right to Know. You have the right to know what personal information is collected, used, shared or sold. We outline both the categories and specific bits of data we collect, as well as how they are used, in this privacy policy.
- Right of Access. You have the right to access the personal information we hold about you, and to obtain information about the sharing, storage, security, and processing of that information.
- Right to Correction. You have the right to request correction of your personal information.
- Right to Erasure / "To Be Forgotten". Subject to certain limitations under applicable law, you may request that your personal information be erased from our possession and from our service providers. Fulfillment of some data-deletion requests may prevent you from using FSMA204Hub. In such cases, a deletion request may result in closing your account.
- Right to Complain. You have the right to make a complaint with the appropriate supervisory authority regarding our handling of your personal information.
- Right to Restrict Processing. You may request restriction of how and why your personal information is used or processed, including opting out of the sale of your personal information. (We never have and never will sell your personal data.)
- Right to Object. You may, in certain situations, object to how or why your personal information is processed.
- Right to Portability. You have the right to receive the personal information we have about you and to transmit it to another party. FSMA204Hub provides export tools for the operational data you upload to your account; for personal information beyond that, contact us using the email below.
- Right to not Be Subject to Automated Decision-Making. You have the right to object to and prevent any decision that could have a legal or similarly significant effect on you from being made solely based on automated processes, except where the decision is necessary for the performance of a contract between you and us, is allowed by applicable law, or is based on your explicit consent.
- Right to Non-Discrimination. We do not and will not charge you a different amount, offer different discounts, or provide a lower level of customer service because you have exercised your data privacy rights. However, the exercise of certain rights may, by virtue of your exercising those rights, prevent you from using the service.
Many of these rights can be exercised by signing in and updating your account information. Some information may be exempt from such requests under applicable law (for example, we need to retain certain billing records to comply with tax law).
In some cases we also need to take reasonable steps to verify your identity before responding to a request. If we are unable to verify you, we may be unable to respond. To exercise these rights or ask questions, please contact us at [email protected]. If an authorized agent corresponds on your behalf, we will need written consent with a signature from the account holder before proceeding.
Depending on applicable law, you may have the right to appeal our decision to deny a request. We will provide information about how to appeal in any response that denies a request. You also have the right to lodge a complaint with a supervisory authority. If you are in the EU or UK, you can contact your local data-protection authority to file a complaint or learn more about local privacy laws.
How we secure your data
All data is encrypted in transit using TLS when transmitted between our servers and your browser. Database backups are also encrypted in transit and at rest by our database provider. We restrict access to production data to a small number of authorized personnel and require strong authentication for all administrative access.
No system is perfectly secure. We will continue to invest in security as the product and customer base grow.
What happens when you delete content in your account
If you choose to cancel your FSMA204Hub account, your content will become inaccessible immediately and should be purged from our active systems within 60 days. Backups of our application database may retain a copy for up to 30 days after that. Altogether, content from a canceled account should be purged from all of our systems within approximately 90 days.
If you delete individual records (lots, batches, suppliers) inside an active account, those records may remain in soft-deleted form for a short period to allow recovery, after which they are purged as part of routine database maintenance.
Data retention
We keep your information for the time necessary for the purposes for which it is processed. The length of time we retain information depends on the purposes for which we collected and use it and your choices, after which we may delete and/or aggregate it. We may also retain and use information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements. Specific retention periods for certain types of information are described above.
Location of site and data
FSMA204Hub is operated in the United States. If you are located in the European Union, the United Kingdom, or elsewhere outside of the United States, please be aware that any information you provide to us will be transferred to and stored in the United States. By using the service or providing us with your personal information, you consent to this transfer.
When transferring personal data from the EU
The European Data Protection Board has issued guidance that personal data transferred out of the EU must be treated with the same level of protection that is granted under EU privacy law. UK law provides similar safeguards. We will adopt a data-processing addendum with Standard Contractual Clauses for customers who require one. If you require a DPA, please contact us at [email protected].
Changes and questions
We may update this policy as needed to comply with relevant regulations and reflect any new practices. Whenever we make a significant change, we will refresh the "Last updated" date at the top of this page and take any other appropriate steps to notify users.
Have any questions, comments, or concerns about this privacy policy, your data, or your rights with respect to your information? Email us at [email protected] and we'll be happy to help.
This policy is adapted from Basecamp's open-source policies, used under a Creative Commons Attribution 4.0 International license. The original text has been substantially modified to reflect Darza Technologies' practices and the FSMA204Hub product.