GDPR-ready

Privacy Policy

Troha · troha-app.com

Verdelab EOOD, Bulgaria · Version 1.0 · Last updated: July 2026

This document contains two Privacy Policies: Part A covers the Troha Website (verdelabapp.com) and applies to visitors who sign up for early access or apply as ambassadors. Part B covers the Troha App and applies to registered App users. Please read the section that applies to you.

These policies are intended to explain how we collect personal data, depending on your relationship with us. The Privacy Policies should be interpreted alongside any other relevant policies, terms and conditions currently in effect.

Part A — Website Privacy Policy · verdelabapp.com

A1. Who We Are

Troha is a meal planning and budget tracking web application designed for university students (“Website”). The data controller operating the Website is Verde Lab Ltd., registered in Bulgaria as an EOOD (private limited company), registration number 208741188, registered address at Sv. Patriarh Evtimii 102, Burgas 8000, Bulgaria (“We”, “us”, etc.).

A2. What We Collect and Why

We collect personal data through two forms on the Website:

Early access sign-up

We collect your email address only. We use it to send you a single email when the Troha application launches its first official version on the Google Play Store and Apple App Store—containing your free one-month Pro access code and early access information as promised.

  • Legal basis: Article 6(1)(a) GDPR — your consent.
  • Retention: until you unsubscribe, withdraw your consent, or 12 months after launch, whichever comes first.

Ambassador application

We collect your name, university affiliation and email address. We use these personal data to review your application, contact you about ambassador terms and coordinate university introduction week visits.

  • Legal basis: Article 6(1)(a) GDPR — your consent.
  • Retention: 60 days if not selected; duration of programme plus 12 months if active.

A3. What We Will Never Do

  • Sell your personal data or share it with advertisers.
  • Send you spam or unrelated emails.
  • Transfer your personal data outside the European Union (“EU”) or the European Economic Area (“EEA”) without appropriate safeguards.
  • Use your personal data for automated decision-making or profiling.

A4. Unsubscribe and Data Deletion

You can withdraw consent at any time. Click unsubscribe in any email we send you or email support@verdelabapp.com. We will delete your personal data within 5 business days and confirm by email.

A5. Cookies and Other Trackers on the Website

The Website uses only strictly necessary technical cookies. We do not use analytics cookies, advertising cookies or any non-essential tracking technologies.

Storage ItemPurposeLifespan
sidebar_state (Cookie)Remembers whether the sidebar UI is expanded or collapsed.7 days (set only when sidebar component is rendered)
Waitlist & Ambassador sign-up data (localStorage)Temporarily stores waitlist and ambassador sign-ups locally in browser before submission.Until form submission or browser cache is cleared

A6. Your Rights

Based on the GDPR, data subjects have the following rights which you can exercise:

  • Right of access — request a copy of all your personal data.
  • Right to rectification — correct inaccurate or incomplete personal data.
  • Right to erasure — delete all your personal data, under certain circumstances.
  • Right to restriction — limit how we use your personal data.
  • Right to withdraw consent — at any time for consent-based processing.
  • Right to data portability — receive your personal data in a machine-readable format.

To exercise any of these rights: email support@verdelabapp.com. We will respond within 30 days. In addition, you have the right to lodge a complaint with your national data protection authority.

A7. Users Under 16

The Website is intended for users aged 16 and over. In the Netherlands, the age of digital consent is 16. Users confirm their age at registration. If we discover a user under 16 has created an account without parental consent, we will delete the account and all related personal data immediately.

A8. Data Security

  • All data transmitted is encrypted using HTTPS/TLS.
  • Database access is restricted to authorised personnel only.
  • Regular security practice reviews are conducted.

In the event of a personal data breach, we will notify the relevant data protection authority within 72 hours as required by Article 33 GDPR.

A9. Changes to This Policy

We may update this policy from time to time. When we make significant changes we will notify you by email and display a notice on the Website.

A10. Contact and Complaints

Part B — App Privacy Policy · Troha App

B1. Who We Are

Troha is a meal planning and budget tracking application designed for university students (“App”). The data controller operating the App is Verde Lab Ltd., registered in Bulgaria as an EOOD (private limited company), registration number 208741188, registered address at Sv. Patriarh Evtimii 102, Burgas 8000, Bulgaria (“We”, “us”, etc.).

B2. What Personal Data We Collect and on What Legal Basis

Account Data

Data ElementPurposeLegal BasisRetention
Email addressAccount creation and loginArt. 6(1)(b) — ContractUntil account deletion
Display nameUser profile personalisationArt. 6(1)(b) — ContractUntil account deletion
Password (hashed)AuthenticationArt. 6(1)(b) — ContractUntil account deletion
Google account IDGoogle OAuth loginArt. 6(1)(b) — ContractUntil account deletion
Apple account IDApple loginArt. 6(1)(b) — ContractUntil account deletion
Age confirmationMinimum age verification (16+)Art. 6(1)(b) — ContractUntil account deletion

User-Generated Content

Data ElementPurposeLegal BasisRetention
Recipe ratingsRating systemArt. 6(1)(b) — ContractUntil account deletion
Written recipe reviewsReview systemArt. 6(1)(b) — ContractUntil account deletion
Shopping list itemsShopping list functionalityArt. 6(1)(b) — ContractUntil item or account deletion

Technical and Session Data

We collect anonymous aggregated statistics about how the App is used. This data cannot be linked to any individual user. The following technical data is collected automatically to ensure the App functions correctly:

Data ElementPurposeLegal BasisRetention
Supabase auth tokenSession managementArt. 6(1)(a) — ConsentDeleted on logout
PWA install visit countApp install prompt timingArt. 6(1)(a) — ConsentPersistent in localStorage
Sidebar state preferenceUI preferenceArt. 6(1)(a) — Consent7 days
IP addressInfrastructure security (Lovable Cloud)Art. 6(1)(a) — ConsentUp to 90 days (Lovable Cloud policy)

Dietary Filters (Special Category Personal Data)

Dietary preference filters (i.e., Gluten-Free, Dairy-Free, Egg-Free, Vegetarian, Period Support, Gym Mode) operate as session-only selections. No health or dietary data is stored in our database, in local storage or on your device at any time.

Legal basis: Article 6(1)(a) and 9(2)(a) GDPR — explicit consent.

B3. Cookies and Local Storage

We use only strictly necessary cookies (essential for the operation of our App) and local storage items. As those are strictly necessary, these cookies do not require your consent. We do not use analytics cookies, advertising cookies or any non-essential tracking technologies.

Google OAuth and Sign in with Apple set cookies and process authentication only on their respective domains (accounts.google.com and appleid.apple.com) during login — never on our domain. RevenueCat manages subscription and payment data as a third-party processor.

Storage ItemPurposeLifespan
cookie-consentStores user cookie consent choicePersistent
pwa-install-visitsCounts visits for PWA install promptPersistent
pwa-install-dismissedTracks PWA prompt dismissalPersistent
sb-[id]-auth-tokenSupabase authentication session tokenPersistent (auto-refreshed)
Google OAuth (Google domain only)Login authentication — never on our domainSession/persistent on Google domain
RevenueCatSubscription and payment managementUntil subscription expires or account deleted

B4. How We Use Your Personal Data

  • To provide and manage your App account and all core App functionality.
  • To process subscription payments securely through RevenueCat.
  • To collect anonymous aggregated usage statistics that cannot be linked to any individual.
  • We never use your personal data for advertising, profiling or automated decision-making.

B5. Who We Share Your Data With

  • Supabase — database and authentication, hosted in the EU (Frankfurt, Germany).
  • Google — if you use Google login, possibly hosted in the US under EU-US Data Privacy Framework.
  • Apple — if you use Apple login, Apple Inc. is certified under the EU-U.S. Data Privacy Framework (DPF) and also utilizes Standard Contractual Clauses (SCCs) as a secondary safeguard.
  • Lovable Cloud — Lovable hosts infrastructure primarily within the EU (Frankfurt, Germany) and uses Standard Contractual Clauses (SCCs) for any processing involving US services/data transfers.
  • RevenueCat — subscription and payment management, hosted in the US under Standard Contractual Clauses.

We do not sell your data to any third party.

B6. Your Rights Under the GDPR

As a user in the EU/EEA you have the following rights:

  • Right of access — request a copy of all your personal data.
  • Right to rectification — correct inaccurate or incomplete personal data.
  • Right to erasure — delete your account and all data within 30 days (via Account Settings → Delete Account).
  • Right to restriction — limit how we use your personal data.
  • Right to withdraw consent — at any time for consent-based processing.
  • Right to data portability — receive your personal data in a machine-readable format (via Account Settings → Download My Data).

To exercise any of these rights: email support@verdelabapp.com. We will respond within 30 days. In addition, you have the right to lodge a complaint with your national data protection authority.

Data in scope for portability requests:

  • Account profile: email address, display name, account creation date.
  • Recipe ratings and reviews.
  • Shopping list items.

B7. Users Under 16

The App is intended for users aged 16 and over. In the Netherlands, the age of digital consent is 16. Users confirm their age at registration. If we discover a user under 16 has created an account without parental consent, we will delete the account and all related personal data immediately.

B8. Data Security

  • All data transmitted is encrypted using HTTPS/TLS.
  • Passwords are hashed and never stored in readable form.
  • Database access is restricted to authorised personnel only.
  • Regular security practice reviews are conducted.

In the event of a personal data breach, we will notify the relevant data protection authority within 72 hours as required by Article 33 GDPR.

B9. Changes to This Policy

We may update this policy from time to time. When we make significant changes we will notify you by email and display a notice in the App.

B10. Contact and Complaints

Troha — Eat smart, spend less.

verdelabapp.com · support@verdelabapp.com