Privacy Policy

Last updated: April 28, 2026

The privacy of your data — and it is your data, not ours — is a big deal to us. In this policy, we lay out: what data we collect and why, how your data is handled, and your rights with respect to your data. We promise we never sell your data: never have, never will.

This policy applies to FSMA204Hub, a service operated by Darza Technologies LLC, a Wyoming limited liability company ("we," "us," or "Darza Technologies"). It covers our handling of information about site visitors, prospective customers, and customers and authorized users of FSMA204Hub. We refer collectively to these categories of individuals as "you" throughout this policy.

This policy does not cover lot-level traceability data, supplier records, or other operational records that you upload to FSMA204Hub in the course of running your business ("Customer Data"). We process Customer Data on your instructions as a service provider, and our obligations with respect to that data are governed by our Terms of Service.

If you are a California resident, additional disclosures required by California law are included in the "Your rights with respect to your information" section below.

What we collect and why

Our guiding principle is to collect only what we need.

Identity and access

When you sign up for FSMA204Hub, we ask for identifying information such as your name, email address, and your company name. That's so you can personalize your account, and we can send you product updates and other essential information. We may also send you optional surveys from time to time to help us understand how you use the product and to make improvements. With your consent, we will send you our newsletter and other updates.

We will never sell your personal information to third parties, and we won't use your name or company in marketing statements without your permission.

Billing information

If you sign up for a paid FSMA204Hub plan, you will be asked to provide your payment information and billing address. Credit card information is submitted directly to our payment processor and does not hit Darza Technologies' servers. We store a record of the payment transaction, including the last 4 digits of the credit card number, for purposes of account history, invoicing, and billing support. We store your billing address so we can charge you for service, calculate any sales tax due, send you invoices, and detect fraudulent transactions.

Product data

We store on our servers the operational records that you upload, link, or generate inside FSMA204Hub — for example, supplier lots, ingredient receipts, production batches, and traceability lot codes. This is so the product can do its job: linking ingredient lots to finished batches and producing a compliance score for FSMA 204 / retailer audits. We keep this content for as long as your account is active. If you cancel your account, we'll delete the content within 60 days. You can read more about this in the "What happens when you delete content" section below.

General geolocation data

We log the IP address used to sign up for an FSMA204Hub account and retain it for use in mitigating spammy signups. We also log account access by IP address for security and fraud prevention purposes, and we keep this login data for as long as your account is active.

Website interactions

We collect information about your browsing activity for analytics and statistical purposes such as conversion-rate testing and experimenting with new product designs. This includes, for example, your browser and operating system versions, your IP address, which web pages you visited and how long they took to load, and which website referred you to us.

We use Google Analytics 4 (measurement ID G-8V22MK3100) to collect aggregated, mostly anonymized analytics about visits to fsma204hub.com. Google Analytics sets first-party cookies on your device. You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on or by blocking cookies in your browser settings. We do not currently combine analytics data with the personal information you provide when signing up.

Cookies

A cookie is a piece of text stored by your browser. We use first-party cookies to keep you signed in, remember basic preferences, and support analytics as described above. Some of these cookies are set by our third-party providers (for example, Clerk for authentication and Google Analytics for measurement). You can adjust cookie retention settings and accept or block individual cookies in your browser settings, although the application will not work properly if you disable cookies entirely.

Voluntary correspondence

When you email us with a question or to ask for help, we keep that correspondence — including your email address — so that we have a history of past interactions to reference if you reach out again.

We also store information you may volunteer, for example, written responses to surveys. If you agree to a customer interview, we may ask for permission to record the conversation for future reference. We will only do so with your express consent.

When we access or disclose your information

To provide the product or services you've requested. We use a small number of third-party subprocessors to help run FSMA204Hub. As of the last-updated date above, these include:

We may update this list as we add or change service providers. Each of these subprocessors has its own privacy policy and processes data on our instructions.

To investigate or take action regarding abuse. Accessing a customer's account when investigating potential abuse is a measure of last resort. We aim to balance the privacy and safety of our customers against the need to respond to issues. If we discover you are using FSMA204Hub for a restricted purpose (for example, attempting to falsify regulatory records), we will take action as necessary, including notifying appropriate authorities where warranted.

To help you troubleshoot a problem, with your permission. If we need to access your content to help you with a support case, we will ask for your consent before proceeding.

Aggregated and de-identified data. We may aggregate and/or de-identify information collected through the service. We may use de-identified or aggregated data for any purpose, including product improvement and analytics.

When required under applicable law. Darza Technologies is a U.S. company and our data infrastructure is located in the United States.

If Darza Technologies is acquired by or merges with another company — we don't plan on that, but if it happens — we'll notify you well before any of your personal information is transferred or becomes subject to a different privacy policy.

Your rights with respect to your information

We strive to apply the same data rights to all customers, regardless of their location. Some of these rights include:

Many of these rights can be exercised by signing in and updating your account information. Some information may be exempt from such requests under applicable law (for example, we need to retain certain billing records to comply with tax law).

In some cases we also need to take reasonable steps to verify your identity before responding to a request. If we are unable to verify you, we may be unable to respond. To exercise these rights or ask questions, please contact us at [email protected]. If an authorized agent corresponds on your behalf, we will need written consent with a signature from the account holder before proceeding.

Depending on applicable law, you may have the right to appeal our decision to deny a request. We will provide information about how to appeal in any response that denies a request. You also have the right to lodge a complaint with a supervisory authority. If you are in the EU or UK, you can contact your local data-protection authority to file a complaint or learn more about local privacy laws.

How we secure your data

All data is encrypted in transit using TLS when transmitted between our servers and your browser. Database backups are also encrypted in transit and at rest by our database provider. We restrict access to production data to a small number of authorized personnel and require strong authentication for all administrative access.

No system is perfectly secure. We will continue to invest in security as the product and customer base grow.

What happens when you delete content in your account

If you choose to cancel your FSMA204Hub account, your content will become inaccessible immediately and should be purged from our active systems within 60 days. Backups of our application database may retain a copy for up to 30 days after that. Altogether, content from a canceled account should be purged from all of our systems within approximately 90 days.

If you delete individual records (lots, batches, suppliers) inside an active account, those records may remain in soft-deleted form for a short period to allow recovery, after which they are purged as part of routine database maintenance.

Data retention

We keep your information for the time necessary for the purposes for which it is processed. The length of time we retain information depends on the purposes for which we collected and use it and your choices, after which we may delete and/or aggregate it. We may also retain and use information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements. Specific retention periods for certain types of information are described above.

Location of site and data

FSMA204Hub is operated in the United States. If you are located in the European Union, the United Kingdom, or elsewhere outside of the United States, please be aware that any information you provide to us will be transferred to and stored in the United States. By using the service or providing us with your personal information, you consent to this transfer.

When transferring personal data from the EU

The European Data Protection Board has issued guidance that personal data transferred out of the EU must be treated with the same level of protection that is granted under EU privacy law. UK law provides similar safeguards. We will adopt a data-processing addendum with Standard Contractual Clauses for customers who require one. If you require a DPA, please contact us at [email protected].

Changes and questions

We may update this policy as needed to comply with relevant regulations and reflect any new practices. Whenever we make a significant change, we will refresh the "Last updated" date at the top of this page and take any other appropriate steps to notify users.

Have any questions, comments, or concerns about this privacy policy, your data, or your rights with respect to your information? Email us at [email protected] and we'll be happy to help.


This policy is adapted from Basecamp's open-source policies, used under a Creative Commons Attribution 4.0 International license. The original text has been substantially modified to reflect Darza Technologies' practices and the FSMA204Hub product.