Privacy Policy
Troha · troha-app.com
Verdelab EOOD, Bulgaria · Version 1.0 · Last updated: July 2026
This document contains two Privacy Policies: Part A covers the Troha Website (verdelabapp.com) and applies to visitors who sign up for early access or apply as ambassadors. Part B covers the Troha App and applies to registered App users. Please read the section that applies to you.
These policies are intended to explain how we collect personal data, depending on your relationship with us. The Privacy Policies should be interpreted alongside any other relevant policies, terms and conditions currently in effect.
Part A — Website Privacy Policy · verdelabapp.com
A1. Who We Are
Troha is a meal planning and budget tracking web application designed for university students (“Website”). The data controller operating the Website is Verde Lab Ltd., registered in Bulgaria as an EOOD (private limited company), registration number 208741188, registered address at Sv. Patriarh Evtimii 102, Burgas 8000, Bulgaria (“We”, “us”, etc.).
A2. What We Collect and Why
We collect personal data through two forms on the Website:
Early access sign-up
We collect your email address only. We use it to send you a single email when the Troha application launches its first official version on the Google Play Store and Apple App Store—containing your free one-month Pro access code and early access information as promised.
- Legal basis: Article 6(1)(a) GDPR — your consent.
- Retention: until you unsubscribe, withdraw your consent, or 12 months after launch, whichever comes first.
Ambassador application
We collect your name, university affiliation and email address. We use these personal data to review your application, contact you about ambassador terms and coordinate university introduction week visits.
- Legal basis: Article 6(1)(a) GDPR — your consent.
- Retention: 60 days if not selected; duration of programme plus 12 months if active.
A3. What We Will Never Do
- Sell your personal data or share it with advertisers.
- Send you spam or unrelated emails.
- Transfer your personal data outside the European Union (“EU”) or the European Economic Area (“EEA”) without appropriate safeguards.
- Use your personal data for automated decision-making or profiling.
A4. Unsubscribe and Data Deletion
You can withdraw consent at any time. Click unsubscribe in any email we send you or email support@verdelabapp.com. We will delete your personal data within 5 business days and confirm by email.
A5. Cookies and Other Trackers on the Website
The Website uses only strictly necessary technical cookies. We do not use analytics cookies, advertising cookies or any non-essential tracking technologies.
| Storage Item | Purpose | Lifespan |
|---|---|---|
| sidebar_state (Cookie) | Remembers whether the sidebar UI is expanded or collapsed. | 7 days (set only when sidebar component is rendered) |
| Waitlist & Ambassador sign-up data (localStorage) | Temporarily stores waitlist and ambassador sign-ups locally in browser before submission. | Until form submission or browser cache is cleared |
A6. Your Rights
Based on the GDPR, data subjects have the following rights which you can exercise:
- Right of access — request a copy of all your personal data.
- Right to rectification — correct inaccurate or incomplete personal data.
- Right to erasure — delete all your personal data, under certain circumstances.
- Right to restriction — limit how we use your personal data.
- Right to withdraw consent — at any time for consent-based processing.
- Right to data portability — receive your personal data in a machine-readable format.
To exercise any of these rights: email support@verdelabapp.com. We will respond within 30 days. In addition, you have the right to lodge a complaint with your national data protection authority.
A7. Users Under 16
The Website is intended for users aged 16 and over. In the Netherlands, the age of digital consent is 16. Users confirm their age at registration. If we discover a user under 16 has created an account without parental consent, we will delete the account and all related personal data immediately.
A8. Data Security
- All data transmitted is encrypted using HTTPS/TLS.
- Database access is restricted to authorised personnel only.
- Regular security practice reviews are conducted.
In the event of a personal data breach, we will notify the relevant data protection authority within 72 hours as required by Article 33 GDPR.
A9. Changes to This Policy
We may update this policy from time to time. When we make significant changes we will notify you by email and display a notice on the Website.
A10. Contact and Complaints
- Email: support@verdelabapp.com
- Verdelab EOOD, Bulgaria
- Bulgarian CPDP: www.cpdp.bg — 2 Prof. Tsvetan Lazarov Blvd, Sofia 1592
- Netherlands: www.autoriteitpersoonsgegevens.nl
- Or your national data protection authority.
Part B — App Privacy Policy · Troha App
B1. Who We Are
Troha is a meal planning and budget tracking application designed for university students (“App”). The data controller operating the App is Verde Lab Ltd., registered in Bulgaria as an EOOD (private limited company), registration number 208741188, registered address at Sv. Patriarh Evtimii 102, Burgas 8000, Bulgaria (“We”, “us”, etc.).
B2. What Personal Data We Collect and on What Legal Basis
Account Data
| Data Element | Purpose | Legal Basis | Retention |
|---|---|---|---|
| Email address | Account creation and login | Art. 6(1)(b) — Contract | Until account deletion |
| Display name | User profile personalisation | Art. 6(1)(b) — Contract | Until account deletion |
| Password (hashed) | Authentication | Art. 6(1)(b) — Contract | Until account deletion |
| Google account ID | Google OAuth login | Art. 6(1)(b) — Contract | Until account deletion |
| Apple account ID | Apple login | Art. 6(1)(b) — Contract | Until account deletion |
| Age confirmation | Minimum age verification (16+) | Art. 6(1)(b) — Contract | Until account deletion |
User-Generated Content
| Data Element | Purpose | Legal Basis | Retention |
|---|---|---|---|
| Recipe ratings | Rating system | Art. 6(1)(b) — Contract | Until account deletion |
| Written recipe reviews | Review system | Art. 6(1)(b) — Contract | Until account deletion |
| Shopping list items | Shopping list functionality | Art. 6(1)(b) — Contract | Until item or account deletion |
Technical and Session Data
We collect anonymous aggregated statistics about how the App is used. This data cannot be linked to any individual user. The following technical data is collected automatically to ensure the App functions correctly:
| Data Element | Purpose | Legal Basis | Retention |
|---|---|---|---|
| Supabase auth token | Session management | Art. 6(1)(a) — Consent | Deleted on logout |
| PWA install visit count | App install prompt timing | Art. 6(1)(a) — Consent | Persistent in localStorage |
| Sidebar state preference | UI preference | Art. 6(1)(a) — Consent | 7 days |
| IP address | Infrastructure security (Lovable Cloud) | Art. 6(1)(a) — Consent | Up to 90 days (Lovable Cloud policy) |
Dietary Filters (Special Category Personal Data)
Dietary preference filters (i.e., Gluten-Free, Dairy-Free, Egg-Free, Vegetarian, Period Support, Gym Mode) operate as session-only selections. No health or dietary data is stored in our database, in local storage or on your device at any time.
Legal basis: Article 6(1)(a) and 9(2)(a) GDPR — explicit consent.
B3. Cookies and Local Storage
We use only strictly necessary cookies (essential for the operation of our App) and local storage items. As those are strictly necessary, these cookies do not require your consent. We do not use analytics cookies, advertising cookies or any non-essential tracking technologies.
Google OAuth and Sign in with Apple set cookies and process authentication only on their respective domains (accounts.google.com and appleid.apple.com) during login — never on our domain. RevenueCat manages subscription and payment data as a third-party processor.
| Storage Item | Purpose | Lifespan |
|---|---|---|
| cookie-consent | Stores user cookie consent choice | Persistent |
| pwa-install-visits | Counts visits for PWA install prompt | Persistent |
| pwa-install-dismissed | Tracks PWA prompt dismissal | Persistent |
| sb-[id]-auth-token | Supabase authentication session token | Persistent (auto-refreshed) |
| Google OAuth (Google domain only) | Login authentication — never on our domain | Session/persistent on Google domain |
| RevenueCat | Subscription and payment management | Until subscription expires or account deleted |
B4. How We Use Your Personal Data
- To provide and manage your App account and all core App functionality.
- To process subscription payments securely through RevenueCat.
- To collect anonymous aggregated usage statistics that cannot be linked to any individual.
- We never use your personal data for advertising, profiling or automated decision-making.
B5. Who We Share Your Data With
- Supabase — database and authentication, hosted in the EU (Frankfurt, Germany).
- Google — if you use Google login, possibly hosted in the US under EU-US Data Privacy Framework.
- Apple — if you use Apple login, Apple Inc. is certified under the EU-U.S. Data Privacy Framework (DPF) and also utilizes Standard Contractual Clauses (SCCs) as a secondary safeguard.
- Lovable Cloud — Lovable hosts infrastructure primarily within the EU (Frankfurt, Germany) and uses Standard Contractual Clauses (SCCs) for any processing involving US services/data transfers.
- RevenueCat — subscription and payment management, hosted in the US under Standard Contractual Clauses.
We do not sell your data to any third party.
B6. Your Rights Under the GDPR
As a user in the EU/EEA you have the following rights:
- Right of access — request a copy of all your personal data.
- Right to rectification — correct inaccurate or incomplete personal data.
- Right to erasure — delete your account and all data within 30 days (via Account Settings → Delete Account).
- Right to restriction — limit how we use your personal data.
- Right to withdraw consent — at any time for consent-based processing.
- Right to data portability — receive your personal data in a machine-readable format (via Account Settings → Download My Data).
To exercise any of these rights: email support@verdelabapp.com. We will respond within 30 days. In addition, you have the right to lodge a complaint with your national data protection authority.
Data in scope for portability requests:
- Account profile: email address, display name, account creation date.
- Recipe ratings and reviews.
- Shopping list items.
B7. Users Under 16
The App is intended for users aged 16 and over. In the Netherlands, the age of digital consent is 16. Users confirm their age at registration. If we discover a user under 16 has created an account without parental consent, we will delete the account and all related personal data immediately.
B8. Data Security
- All data transmitted is encrypted using HTTPS/TLS.
- Passwords are hashed and never stored in readable form.
- Database access is restricted to authorised personnel only.
- Regular security practice reviews are conducted.
In the event of a personal data breach, we will notify the relevant data protection authority within 72 hours as required by Article 33 GDPR.
B9. Changes to This Policy
We may update this policy from time to time. When we make significant changes we will notify you by email and display a notice in the App.
B10. Contact and Complaints
- Email: support@verdelabapp.com
- Verdelab EOOD, Bulgaria
- Bulgarian CPDP: www.cpdp.bg — 2 Prof. Tsvetan Lazarov Blvd, Sofia 1592
- Netherlands: www.autoriteitpersoonsgegevens.nl
- Or your national data protection authority.
Troha — Eat smart, spend less.
verdelabapp.com · support@verdelabapp.com
