Privacy policy

Effective Date: 2017
Last Updated: 2025

1. Introduction

VegHeadsTO ("we," "us," or "our") is a holistic wellness company that merges ancient Ayurvedic wisdom with modern science. We offer personalized plant-based coaching, gut health programs, educational content, and nourishing plant-based food products. This Privacy Policy explains how we collect, use, disclose, and safeguard your information across all our services.

Our Services Include:

  • Online programs and health coaching

  • Plant-based food products (sauces, condiments, and future product lines)

  • Educational content, newsletters, and wellness resources

  • Online community platforms and consultation services

Contact Information:

  • Business Name: VegHeadsTO

  • Email: contact@vegheadsto

  • Website: vegheadsto.com

2. Information We Collect

Personal Information You Provide

Health and Wellness Services:

  • Assessment Participation: Name, email, responses to gut health and dosha questionnaires

  • Program Enrollment: Full name, email, phone number, health goals, dietary preferences

  • Coaching Sessions: Health history, symptoms, lifestyle factors, progress updates

  • Community Participation: Forum posts, group interactions, progress sharing

Product Purchases:

  • Order Information: Name, shipping address, billing address, phone number

  • Payment Details: Credit card information, billing preferences, purchase history

  • Dietary Restrictions: Allergies, preferences, special requirements for product recommendations

General Interactions:

  • Website Engagement: Account creation, newsletter subscriptions, content downloads

  • Communications: Email correspondence, support requests, feedback, testimonials

  • Event Participation: Workshop registrations, webinar attendance, consultation bookings

Automatically Collected Information

Website and Digital Analytics:

  • Technical Data: IP address, browser type, device information, operating system

  • Usage Patterns: Pages visited, time spent, click-through rates, download behavior

  • Cookies and Tracking: Login sessions, preferences, shopping cart contents

  • Email Engagement: Open rates, link clicks, unsubscribe patterns

Mobile App Data (if applicable):

  • Device Information: Mobile device ID, app version, push notification preferences

  • Usage Analytics: Feature usage, session duration, in-app behaviors

Health and Wellness Information

Program-Specific Data:

  • Assessment Results: Dosha type, digestive health status, wellness goals

  • Progress Tracking: Symptom improvements, habit tracking, goal achievements

  • Coaching Notes: Session summaries, recommendations, action plans (with consent)

  • Health Journals: Food diaries, symptom logs, wellness observations

Product-Related Health Data:

  • Allergy Information: Food sensitivities, ingredient restrictions

  • Dietary Preferences: Plant-based choices, nutritional requirements

  • Purchase Patterns: Product preferences, reorder frequency, taste preferences

3. How We Use Your Information

Primary Service Delivery

Health Coaching and Programs:

  • Providing personalized wellness consultations and program content

  • Customizing recommendations based on dosha type and health assessments

  • Tracking progress and adjusting program elements for optimal results

  • Facilitating community interactions and peer support

Product Services:

  • Processing and fulfilling food product orders

  • Recommending products based on dietary needs and preferences

  • Managing shipping, delivery, and customer service inquiries

  • Developing new products based on customer feedback and demand

Educational Content:

  • Delivering relevant health tips, recipes, and wellness information

  • Personalizing content recommendations based on interests and engagement

  • Providing access to exclusive materials and member-only resources

Communication and Marketing

Program Communications:

  • Sending course updates, coaching reminders, and educational materials

  • Providing technical support and answering program-related questions

  • Sharing community highlights and success stories (with permission)

Product Marketing:

  • Announcing new product launches and availability updates

  • Sending promotional offers, discounts, and seasonal recommendations

  • Sharing recipes, usage tips, and nutritional information

General Marketing:

  • Newsletter distribution with wellness tips and company updates

  • Social media engagement and community building

  • Event announcements and workshop invitations

Business Operations and Analytics

Service Improvement:

  • Analyzing program effectiveness and user engagement patterns

  • Gathering feedback to enhance product formulations and offerings

  • Understanding customer preferences to guide business decisions

Legal and Compliance:

  • Meeting regulatory requirements for food products and health services

  • Protecting intellectual property and business interests

  • Responding to legal requests and maintaining business records

4. Information Sharing and Disclosure

Third-Party Service Providers

We share information with trusted partners who help us operate our business:

Technology and Platform Providers:

  • Website Hosting: Squarespace (website functionality and hosting)

  • E-commerce: Shopify or similar platforms (online store operations)

  • Email Marketing: ConvertKit, Mailchimp (newsletters and automation)

  • Payment Processing: Stripe, PayPal (secure payment handling)

  • Analytics: Google Analytics, Facebook Pixel (performance tracking)

Fulfillment and Logistics:

  • Shipping Partners: Canada Post, UPS, FedEx (product delivery)

  • Warehouse Services: Third-party fulfillment centers (inventory management)

  • Manufacturing Partners: Co-packers and production facilities (product creation)

Customer Support and Communication:

  • Help Desk Platforms: Customer service management systems

  • Video Conferencing: Zoom, Google Meet (coaching sessions)

  • Community Platforms: Facebook Groups, Discord (member interactions)

Business Services:

  • Accounting Software: QuickBooks (financial management)

  • CRM Systems: Customer relationship management platforms

  • Legal Services: Law firms for compliance and business matters

Product-Specific Sharing

Food Product Compliance:

  • Regulatory Authorities: Health Canada, FDA (as required for food safety)

  • Certification Bodies: Organic certifiers, allergen testing labs

  • Supply Chain Partners: Ingredient suppliers, quality assurance providers

Health Coaching Compliance:

  • Professional Organizations: Relevant coaching and wellness associations

  • Insurance Providers: Professional liability insurance companies

  • Continuing Education: Training organizations and certification bodies

Legal and Emergency Disclosures

We may share information when legally required or to protect our business:

  • Legal Compliance: Court orders, government investigations, regulatory requests

  • Safety Protection: Preventing fraud, protecting rights and property

  • Business Transfers: Mergers, acquisitions, or asset sales

  • Emergency Situations: Immediate health or safety concerns

5. Data Security and Protection

Technical Safeguards

Data Transmission:

  • SSL/TLS Encryption: All data transmitted securely between devices and servers

  • Secure Payment Processing: PCI DSS compliant payment handling

  • API Security: Encrypted connections for all third-party integrations

Data Storage:

  • Access Controls: Role-based access with minimum necessary permissions

  • Regular Backups: Automated, encrypted backup systems

  • Server Security: Firewall protection, intrusion detection, regular updates

Application Security:

  • Authentication: Strong password requirements, optional two-factor authentication

  • Session Management: Automatic logout, secure session handling

  • Regular Audits: Security assessments and vulnerability testing

Physical and Administrative Safeguards

Physical Security:

  • Secure Facilities: Restricted access to offices and storage areas

  • Device Management: Encrypted laptops, secure mobile device policies

  • Disposal Procedures: Secure destruction of physical documents and devices

Administrative Controls:

  • Staff Training: Regular privacy and security education for all team members

  • Incident Response: Documented procedures for data breach response

  • Vendor Management: Security requirements for all third-party service providers

6. International Data Transfers and Compliance

Cross-Border Data Handling

For Canadian Residents (PIPEDA Compliance):

  • We comply with the Personal Information Protection and Electronic Documents Act

  • Cross-border transfers maintain appropriate safeguards through contractual protections

  • You have rights to access, correct, and withdraw consent for your personal information

For US Residents:

  • State-Specific Rights: Compliance with California CCPA, Virginia CDPA, and other applicable state laws

  • Data Minimization: Collection limited to information necessary for stated purposes

  • Opt-Out Rights: Options to limit sale or sharing of personal information

For EU Residents (GDPR Compliance):

  • Legal Basis: Processing based on consent, legitimate interests, or contractual necessity

  • Data Subject Rights: Access, rectification, erasure, portability, and objection rights

  • International Transfers: Standard Contractual Clauses and adequacy decisions ensure protection

Product-Specific International Considerations

Food Product Exports:

  • Customs Documentation: Ingredient lists, nutritional information, safety certificates

  • Regulatory Compliance: Meeting import requirements for destination countries

  • Shipping Restrictions: Temperature control, expiration date management

Digital Service Access:

  • Geographic Restrictions: Some services may be limited based on local regulations

  • Currency and Pricing: Localized pricing and payment methods where possible

  • Language Accessibility: Content translation for international markets

7. Your Rights and Choices

Data Access and Control

Information Rights:

  • Access: Request copies of all personal information we hold about you

  • Correction: Update or correct inaccurate or incomplete information

  • Deletion: Request removal of your personal information (subject to legal requirements)

  • Portability: Receive your data in a machine-readable format for transfer

Communication Preferences:

  • Email Management: Unsubscribe from marketing emails while maintaining service communications

  • Notification Settings: Choose which types of updates and alerts you receive

  • Frequency Controls: Select how often you hear from us

Product and Service Controls:

  • Account Deletion: Complete removal of your account and associated data

  • Service Limitation: Restrict certain uses of your information

  • Consent Withdrawal: Revoke previously given consent for data processing

How to Exercise Your Rights

Contact Methods:

  • Email: contact@vegheadsto] with subject line "Privacy Rights Request"

Required Information:

  • Full name and email address associated with your account

  • Specific request (access, correction, deletion, etc.)

  • Verification information to confirm your identity

  • Preferred response method and timeline

Response Timeline:

  • Initial Response: Acknowledgment within 48 hours

  • Complete Response: Fulfillment within 30 days (may extend to 60 days for complex requests)

  • Appeal Process: Right to escalate denied requests to supervisory authorities

8. Special Considerations for Health Information

Health Information Protection

Educational vs. Medical Information:

  • Our programs provide educational information about wellness and nutrition

  • Information shared is not intended as medical advice or treatment

  • We encourage consultation with healthcare providers for medical concerns

Health Data Sensitivity:

  • Extra Security: Health-related information receives additional protection measures

  • Limited Access: Only authorized personnel with legitimate need can access health data

  • Consent Requirements: Explicit consent required for sharing health information

HIPAA Considerations:

  • Not Covered Entity: VegHeadsTO is not subject to HIPAA as we're not a healthcare provider

  • Privacy Standards: We voluntarily apply HIPAA-level protections to health information

  • Medical Referrals: Clear guidelines for when to recommend professional medical care

Product Safety and Allergies

Allergen Information Management:

  • Accurate Labeling: Clear ingredient lists and allergen warnings on all products

  • Cross-Contamination: Facility information and manufacturing process transparency

  • Emergency Procedures: Clear protocols for allergy-related incidents

Health Claims and Disclaimers:

  • Educational Purpose: All health information is for educational purposes only

  • No Medical Claims: Products are not intended to diagnose, treat, cure, or prevent disease

  • Individual Results: Acknowledgment that results may vary between individuals

9. Data Retention Policies

Service-Specific Retention Periods

Health Coaching and Programs:

  • Active Participation: Data retained during program enrollment plus 2 years

  • Health Assessments: Results maintained for 3 years for progress tracking

  • Coaching Notes: Session records kept for 2 years after program completion

Product Purchases:

  • Order History: Purchase records retained for 7 years for tax and warranty purposes

  • Customer Service: Support interactions kept for 3 years

  • Product Development: Anonymized feedback used indefinitely for product improvement

Marketing and Communications:

  • Email Lists: Maintained until unsubscribe or 3 years of inactivity

  • Website Analytics: Aggregate data retained for 26 months (Google Analytics standard)

  • Social Media Interactions: Public interactions retained indefinitely

Deletion Procedures

Automatic Deletion:

  • Expired Sessions: Temporary data cleared automatically

  • Inactive Accounts: Accounts dormant for 3+ years subject to deletion with notice

  • Temporary Files: Processing data removed after transaction completion

Manual Deletion Requests:

  • Complete Removal: All data deleted within 30 days of verified request

  • Legal Exceptions: Some data may be retained for legal compliance or dispute resolution

  • Anonymization: Data may be anonymized rather than deleted for research purposes

10. Cookies and Tracking Technologies

Cookie Types and Purposes

Essential Cookies:

  • Site Function: Enable basic website operation and security

  • Account Management: Maintain login sessions and preferences

  • Shopping Cart: Remember items and checkout progress

Performance Cookies:

  • Analytics: Understand how visitors use our website

  • Error Tracking: Identify and resolve technical issues

  • Load Testing: Optimize site performance and speed

Marketing Cookies:

  • Personalization: Customize content and product recommendations

  • Advertising: Track effectiveness of marketing campaigns

  • Social Media: Enable social sharing and integration features

Cookie Management

User Controls:

  • Browser Settings: Disable or limit cookies through browser preferences

  • Consent Management: Granular consent options for different cookie types

  • Opt-Out Tools: Industry standard opt-out mechanisms for advertising cookies

Third-Party Cookies:

  • Google Analytics: Website performance and user behavior analysis

  • Facebook Pixel: Social media marketing and audience building

  • Payment Processors: Fraud prevention and transaction security

11. Children's Privacy

Age Restrictions

Minimum Age Requirements:

  • General Services: Must be 18+ to create accounts or make purchases

  • Parental Consent: Users 13-17 require parental consent and supervision

  • Health Information: No collection of health data from minors without guardian consent

Protection Measures:

  • Age Verification: Processes to confirm user age during registration

  • Parental Controls: Options for parents to manage minor's information

  • Educational Content: Age-appropriate wellness information for families

Compliance Standards:

  • COPPA: Full compliance with Children's Online Privacy Protection Act

  • Provincial Laws: Adherence to Canadian provincial age-of-consent requirements

  • International Standards: Meeting global standards for child privacy protection

12. Changes to This Privacy Policy

Update Procedures

Notification Methods:

  • Email Notice: Direct communication to all registered users

  • Website Banner: Prominent notice on main pages for 30 days

  • Social Media: Announcements on official VegHeadsTO channels

Effective Date Management:

  • Advance Notice: Minimum 30 days notice before changes take effect

  • Grandfathering: Existing users may be subject to previous policy terms

  • Consent Requirements: Material changes may require explicit user consent

Version Control:

  • Document History: Previous versions archived and available upon request

  • Change Summaries: Clear explanation of modifications in each update

  • Legal Review: All changes reviewed by qualified legal counsel

13. Contact Information and Support

Privacy-Related Inquiries

General Privacy Questions:

  • Email: contact@vegheadsto.com

  • Subject Line: "Privacy Policy Inquiry"

  • Response Time: 24-48 hours during business days

Data Rights Requests:

  • Email: contact@vegheadsto

  • Subject Line: "Data Rights Request - [Specific Request Type]"

  • Required Information: Account details and specific request description

Privacy Complaints:

  • Internal Process: Direct resolution through customer service

  • External Escalation: Information about supervisory authority contacts

  • Response Timeline: Acknowledgment within 2 business days

Regulatory Authority Contacts

Canada - Office of the Privacy Commissioner:

  • Website: priv.gc.ca

  • Phone: 1-800-282-1376

European Union - Data Protection Authorities:

  • Find your local DPA at: edpb.europa.eu

United States - Federal Trade Commission:

  • Website: consumer.ftc.gov

  • Phone: 1-877-FTC-HELP

Acknowledgment: By using VegHeadsTO services, purchasing our products, or participating in our programs, you acknowledge that you have read, understood, and agree to this Privacy Policy. Your continued use of our services after any modifications constitutes acceptance of the updated policy.

Last Updated: 2025
Version: 1.0

This Privacy Policy is designed to comply with GDPR (EU), PIPEDA (Canada), CCPA (California), and other applicable privacy laws. It covers all VegHeadsTO services including health coaching, food products, and digital platforms. For specific legal advice, consult with a qualified attorney.