Privacy policy
Effective Date: 2017
Last Updated: 2025
1. Introduction
VegHeadsTO ("we," "us," or "our") is a holistic wellness company that merges ancient Ayurvedic wisdom with modern science. We offer personalized plant-based coaching, gut health programs, educational content, and nourishing plant-based food products. This Privacy Policy explains how we collect, use, disclose, and safeguard your information across all our services.
Our Services Include:
Online programs and health coaching
Plant-based food products (sauces, condiments, and future product lines)
Educational content, newsletters, and wellness resources
Online community platforms and consultation services
Contact Information:
Business Name: VegHeadsTO
Email: contact@vegheadsto
Website: vegheadsto.com
2. Information We Collect
Personal Information You Provide
Health and Wellness Services:
Assessment Participation: Name, email, responses to gut health and dosha questionnaires
Program Enrollment: Full name, email, phone number, health goals, dietary preferences
Coaching Sessions: Health history, symptoms, lifestyle factors, progress updates
Community Participation: Forum posts, group interactions, progress sharing
Product Purchases:
Order Information: Name, shipping address, billing address, phone number
Payment Details: Credit card information, billing preferences, purchase history
Dietary Restrictions: Allergies, preferences, special requirements for product recommendations
General Interactions:
Website Engagement: Account creation, newsletter subscriptions, content downloads
Communications: Email correspondence, support requests, feedback, testimonials
Event Participation: Workshop registrations, webinar attendance, consultation bookings
Automatically Collected Information
Website and Digital Analytics:
Technical Data: IP address, browser type, device information, operating system
Usage Patterns: Pages visited, time spent, click-through rates, download behavior
Cookies and Tracking: Login sessions, preferences, shopping cart contents
Email Engagement: Open rates, link clicks, unsubscribe patterns
Mobile App Data (if applicable):
Device Information: Mobile device ID, app version, push notification preferences
Usage Analytics: Feature usage, session duration, in-app behaviors
Health and Wellness Information
Program-Specific Data:
Assessment Results: Dosha type, digestive health status, wellness goals
Progress Tracking: Symptom improvements, habit tracking, goal achievements
Coaching Notes: Session summaries, recommendations, action plans (with consent)
Health Journals: Food diaries, symptom logs, wellness observations
Product-Related Health Data:
Allergy Information: Food sensitivities, ingredient restrictions
Dietary Preferences: Plant-based choices, nutritional requirements
Purchase Patterns: Product preferences, reorder frequency, taste preferences
3. How We Use Your Information
Primary Service Delivery
Health Coaching and Programs:
Providing personalized wellness consultations and program content
Customizing recommendations based on dosha type and health assessments
Tracking progress and adjusting program elements for optimal results
Facilitating community interactions and peer support
Product Services:
Processing and fulfilling food product orders
Recommending products based on dietary needs and preferences
Managing shipping, delivery, and customer service inquiries
Developing new products based on customer feedback and demand
Educational Content:
Delivering relevant health tips, recipes, and wellness information
Personalizing content recommendations based on interests and engagement
Providing access to exclusive materials and member-only resources
Communication and Marketing
Program Communications:
Sending course updates, coaching reminders, and educational materials
Providing technical support and answering program-related questions
Sharing community highlights and success stories (with permission)
Product Marketing:
Announcing new product launches and availability updates
Sending promotional offers, discounts, and seasonal recommendations
Sharing recipes, usage tips, and nutritional information
General Marketing:
Newsletter distribution with wellness tips and company updates
Social media engagement and community building
Event announcements and workshop invitations
Business Operations and Analytics
Service Improvement:
Analyzing program effectiveness and user engagement patterns
Gathering feedback to enhance product formulations and offerings
Understanding customer preferences to guide business decisions
Legal and Compliance:
Meeting regulatory requirements for food products and health services
Protecting intellectual property and business interests
Responding to legal requests and maintaining business records
4. Information Sharing and Disclosure
Third-Party Service Providers
We share information with trusted partners who help us operate our business:
Technology and Platform Providers:
Website Hosting: Squarespace (website functionality and hosting)
E-commerce: Shopify or similar platforms (online store operations)
Email Marketing: ConvertKit, Mailchimp (newsletters and automation)
Payment Processing: Stripe, PayPal (secure payment handling)
Analytics: Google Analytics, Facebook Pixel (performance tracking)
Fulfillment and Logistics:
Shipping Partners: Canada Post, UPS, FedEx (product delivery)
Warehouse Services: Third-party fulfillment centers (inventory management)
Manufacturing Partners: Co-packers and production facilities (product creation)
Customer Support and Communication:
Help Desk Platforms: Customer service management systems
Video Conferencing: Zoom, Google Meet (coaching sessions)
Community Platforms: Facebook Groups, Discord (member interactions)
Business Services:
Accounting Software: QuickBooks (financial management)
CRM Systems: Customer relationship management platforms
Legal Services: Law firms for compliance and business matters
Product-Specific Sharing
Food Product Compliance:
Regulatory Authorities: Health Canada, FDA (as required for food safety)
Certification Bodies: Organic certifiers, allergen testing labs
Supply Chain Partners: Ingredient suppliers, quality assurance providers
Health Coaching Compliance:
Professional Organizations: Relevant coaching and wellness associations
Insurance Providers: Professional liability insurance companies
Continuing Education: Training organizations and certification bodies
Legal and Emergency Disclosures
We may share information when legally required or to protect our business:
Legal Compliance: Court orders, government investigations, regulatory requests
Safety Protection: Preventing fraud, protecting rights and property
Business Transfers: Mergers, acquisitions, or asset sales
Emergency Situations: Immediate health or safety concerns
5. Data Security and Protection
Technical Safeguards
Data Transmission:
SSL/TLS Encryption: All data transmitted securely between devices and servers
Secure Payment Processing: PCI DSS compliant payment handling
API Security: Encrypted connections for all third-party integrations
Data Storage:
Access Controls: Role-based access with minimum necessary permissions
Regular Backups: Automated, encrypted backup systems
Server Security: Firewall protection, intrusion detection, regular updates
Application Security:
Authentication: Strong password requirements, optional two-factor authentication
Session Management: Automatic logout, secure session handling
Regular Audits: Security assessments and vulnerability testing
Physical and Administrative Safeguards
Physical Security:
Secure Facilities: Restricted access to offices and storage areas
Device Management: Encrypted laptops, secure mobile device policies
Disposal Procedures: Secure destruction of physical documents and devices
Administrative Controls:
Staff Training: Regular privacy and security education for all team members
Incident Response: Documented procedures for data breach response
Vendor Management: Security requirements for all third-party service providers
6. International Data Transfers and Compliance
Cross-Border Data Handling
For Canadian Residents (PIPEDA Compliance):
We comply with the Personal Information Protection and Electronic Documents Act
Cross-border transfers maintain appropriate safeguards through contractual protections
You have rights to access, correct, and withdraw consent for your personal information
For US Residents:
State-Specific Rights: Compliance with California CCPA, Virginia CDPA, and other applicable state laws
Data Minimization: Collection limited to information necessary for stated purposes
Opt-Out Rights: Options to limit sale or sharing of personal information
For EU Residents (GDPR Compliance):
Legal Basis: Processing based on consent, legitimate interests, or contractual necessity
Data Subject Rights: Access, rectification, erasure, portability, and objection rights
International Transfers: Standard Contractual Clauses and adequacy decisions ensure protection
Product-Specific International Considerations
Food Product Exports:
Customs Documentation: Ingredient lists, nutritional information, safety certificates
Regulatory Compliance: Meeting import requirements for destination countries
Shipping Restrictions: Temperature control, expiration date management
Digital Service Access:
Geographic Restrictions: Some services may be limited based on local regulations
Currency and Pricing: Localized pricing and payment methods where possible
Language Accessibility: Content translation for international markets
7. Your Rights and Choices
Data Access and Control
Information Rights:
Access: Request copies of all personal information we hold about you
Correction: Update or correct inaccurate or incomplete information
Deletion: Request removal of your personal information (subject to legal requirements)
Portability: Receive your data in a machine-readable format for transfer
Communication Preferences:
Email Management: Unsubscribe from marketing emails while maintaining service communications
Notification Settings: Choose which types of updates and alerts you receive
Frequency Controls: Select how often you hear from us
Product and Service Controls:
Account Deletion: Complete removal of your account and associated data
Service Limitation: Restrict certain uses of your information
Consent Withdrawal: Revoke previously given consent for data processing
How to Exercise Your Rights
Contact Methods:
Email: contact@vegheadsto] with subject line "Privacy Rights Request"
Required Information:
Full name and email address associated with your account
Specific request (access, correction, deletion, etc.)
Verification information to confirm your identity
Preferred response method and timeline
Response Timeline:
Initial Response: Acknowledgment within 48 hours
Complete Response: Fulfillment within 30 days (may extend to 60 days for complex requests)
Appeal Process: Right to escalate denied requests to supervisory authorities
8. Special Considerations for Health Information
Health Information Protection
Educational vs. Medical Information:
Our programs provide educational information about wellness and nutrition
Information shared is not intended as medical advice or treatment
We encourage consultation with healthcare providers for medical concerns
Health Data Sensitivity:
Extra Security: Health-related information receives additional protection measures
Limited Access: Only authorized personnel with legitimate need can access health data
Consent Requirements: Explicit consent required for sharing health information
HIPAA Considerations:
Not Covered Entity: VegHeadsTO is not subject to HIPAA as we're not a healthcare provider
Privacy Standards: We voluntarily apply HIPAA-level protections to health information
Medical Referrals: Clear guidelines for when to recommend professional medical care
Product Safety and Allergies
Allergen Information Management:
Accurate Labeling: Clear ingredient lists and allergen warnings on all products
Cross-Contamination: Facility information and manufacturing process transparency
Emergency Procedures: Clear protocols for allergy-related incidents
Health Claims and Disclaimers:
Educational Purpose: All health information is for educational purposes only
No Medical Claims: Products are not intended to diagnose, treat, cure, or prevent disease
Individual Results: Acknowledgment that results may vary between individuals
9. Data Retention Policies
Service-Specific Retention Periods
Health Coaching and Programs:
Active Participation: Data retained during program enrollment plus 2 years
Health Assessments: Results maintained for 3 years for progress tracking
Coaching Notes: Session records kept for 2 years after program completion
Product Purchases:
Order History: Purchase records retained for 7 years for tax and warranty purposes
Customer Service: Support interactions kept for 3 years
Product Development: Anonymized feedback used indefinitely for product improvement
Marketing and Communications:
Email Lists: Maintained until unsubscribe or 3 years of inactivity
Website Analytics: Aggregate data retained for 26 months (Google Analytics standard)
Social Media Interactions: Public interactions retained indefinitely
Deletion Procedures
Automatic Deletion:
Expired Sessions: Temporary data cleared automatically
Inactive Accounts: Accounts dormant for 3+ years subject to deletion with notice
Temporary Files: Processing data removed after transaction completion
Manual Deletion Requests:
Complete Removal: All data deleted within 30 days of verified request
Legal Exceptions: Some data may be retained for legal compliance or dispute resolution
Anonymization: Data may be anonymized rather than deleted for research purposes
10. Cookies and Tracking Technologies
Cookie Types and Purposes
Essential Cookies:
Site Function: Enable basic website operation and security
Account Management: Maintain login sessions and preferences
Shopping Cart: Remember items and checkout progress
Performance Cookies:
Analytics: Understand how visitors use our website
Error Tracking: Identify and resolve technical issues
Load Testing: Optimize site performance and speed
Marketing Cookies:
Personalization: Customize content and product recommendations
Advertising: Track effectiveness of marketing campaigns
Social Media: Enable social sharing and integration features
Cookie Management
User Controls:
Browser Settings: Disable or limit cookies through browser preferences
Consent Management: Granular consent options for different cookie types
Opt-Out Tools: Industry standard opt-out mechanisms for advertising cookies
Third-Party Cookies:
Google Analytics: Website performance and user behavior analysis
Facebook Pixel: Social media marketing and audience building
Payment Processors: Fraud prevention and transaction security
11. Children's Privacy
Age Restrictions
Minimum Age Requirements:
General Services: Must be 18+ to create accounts or make purchases
Parental Consent: Users 13-17 require parental consent and supervision
Health Information: No collection of health data from minors without guardian consent
Protection Measures:
Age Verification: Processes to confirm user age during registration
Parental Controls: Options for parents to manage minor's information
Educational Content: Age-appropriate wellness information for families
Compliance Standards:
COPPA: Full compliance with Children's Online Privacy Protection Act
Provincial Laws: Adherence to Canadian provincial age-of-consent requirements
International Standards: Meeting global standards for child privacy protection
12. Changes to This Privacy Policy
Update Procedures
Notification Methods:
Email Notice: Direct communication to all registered users
Website Banner: Prominent notice on main pages for 30 days
Social Media: Announcements on official VegHeadsTO channels
Effective Date Management:
Advance Notice: Minimum 30 days notice before changes take effect
Grandfathering: Existing users may be subject to previous policy terms
Consent Requirements: Material changes may require explicit user consent
Version Control:
Document History: Previous versions archived and available upon request
Change Summaries: Clear explanation of modifications in each update
Legal Review: All changes reviewed by qualified legal counsel
13. Contact Information and Support
Privacy-Related Inquiries
General Privacy Questions:
Email: contact@vegheadsto.com
Subject Line: "Privacy Policy Inquiry"
Response Time: 24-48 hours during business days
Data Rights Requests:
Email: contact@vegheadsto
Subject Line: "Data Rights Request - [Specific Request Type]"
Required Information: Account details and specific request description
Privacy Complaints:
Internal Process: Direct resolution through customer service
External Escalation: Information about supervisory authority contacts
Response Timeline: Acknowledgment within 2 business days
Regulatory Authority Contacts
Canada - Office of the Privacy Commissioner:
Website: priv.gc.ca
Phone: 1-800-282-1376
European Union - Data Protection Authorities:
Find your local DPA at: edpb.europa.eu
United States - Federal Trade Commission:
Website: consumer.ftc.gov
Phone: 1-877-FTC-HELP
Acknowledgment: By using VegHeadsTO services, purchasing our products, or participating in our programs, you acknowledge that you have read, understood, and agree to this Privacy Policy. Your continued use of our services after any modifications constitutes acceptance of the updated policy.
Last Updated: 2025
Version: 1.0
This Privacy Policy is designed to comply with GDPR (EU), PIPEDA (Canada), CCPA (California), and other applicable privacy laws. It covers all VegHeadsTO services including health coaching, food products, and digital platforms. For specific legal advice, consult with a qualified attorney.