Privacy Policy
Last Updated: 1 August 2026
1. Overview & Scope
This Privacy Policy explains how Vizorent Ltd, operating Veggeo™, collects, uses, and protects your personal data when you use the Veggeo mobile application(s), the Veggeo websites and connected web resources we use to provide the Service, including veggeo.com, veggeo.eco, veggeo.app, their service-related subdomains, and related services (collectively, the “Service”). Vizorent Ltd is the data controller for personal data where it determines how and why that data is processed.
For the contractual terms that govern use of the Service, please also see our Terms of Service.
2. Information We Collect
Depending on how you use the Service, we may collect the following categories of personal data:
- Account and profile information: contact details, account identifiers, display information, preferences, and eligibility information that you choose to provide.
- Location information: precise device location when you enable it, approximate location derived from network information, and location-related information that you choose to provide or save. See Section 5 (“Location Permissions”).
- Technical and diagnostic information: device, app, and network information; service and installation identifiers; push-notification tokens; security records; and crash or diagnostic data needed to operate, protect, and troubleshoot the Service.
- Service activity and saved content: information generated when you use requested features and content or settings that you choose to save. Optional analytics information is collected only when Analytics is enabled.
- Third-party account information: if you choose to sign in through a supported provider, we receive the account and profile information that the provider makes available for authentication and account display.
- Submissions and communications: information you provide when contacting us or asking us to review, correct, or add information. We may retain its association with your account for moderation, audit, security, and compliance. Verified factual information incorporated into the Service is not attributed to you.
We collect personal data directly from you, automatically through your use of the Service, from supported account providers you choose to use, and from service or information providers where relevant to a requested feature.
Preference settings are intended to tailor how the Service operates. They are not designed to collect medical information or infer religious or philosophical beliefs. Please do not provide sensitive personal data unless a feature specifically requests it and gives you appropriate information at that time.
Cookies & SDKs
On our websites, non-essential cookies and similar technologies are off until you opt in. Manage website choices at any time via Cookie Settings and see our Cookie Notice. Website Cookie Settings do not control native-app SDKs; app analytics choices are managed separately in the App.
Firebase services. We use Google Firebase Cloud Messaging to deliver push notifications and Firebase Crashlytics to diagnose technical issues and support the reliability and security of the Service. Depending on the service, Google may process installation identifiers, push tokens, device and app information, and diagnostic data. Firebase Analytics is used only where it is enabled in accordance with your analytics choice. We do not use Firebase Analytics for targeted advertising.
3. How We Use Your Information
We use personal data where necessary to:
- provide, configure, and personalise the Service and the information or recommendations you request;
- create, authenticate, and manage accounts;
- operate, secure, support, troubleshoot, and improve the Service;
- deliver operational communications and any optional communications you choose to receive;
- review and moderate submissions and maintain the information presented through the Service; and
- comply with law, enforce our Terms, and protect the rights and safety of the Service and others.
Where you enable analytics, we use tools such as Firebase Analytics to understand how users interact with the Service and improve it. We use diagnostics such as Firebase Crashlytics to identify crashes, improve reliability, and fix technical faults.
We may use algorithms and machine-learning tools (AI) to analyse trends and improve or personalise recommendations. These tools support Service features and our operations but do not make decisions that produce legal or similarly significant effects about you.
We may use and share aggregated or de-identified information to understand general usage, improve the Service, conduct research, and produce statistical insights. We do not use this information to identify individual users.
We do not sell or rent your personal data or share it for targeted advertising. We disclose personal data to service providers where needed to provide, secure, maintain, and improve the Service; to professional advisers, regulators, law enforcement, or other authorities where disclosure is lawful and necessary; and to a successor in connection with a merger, acquisition, reorganisation, or sale of all or part of our business, subject to appropriate safeguards.
4. Legal Bases
Under the UK GDPR—and, where applicable, the EU GDPR—we rely on the following legal bases:
- Consent – for precise location, optional analytics, optional promotional communications, and any other processing for which we specifically ask for consent. You may withdraw consent at any time.
- Contract – to create and manage your account and provide the features and personalised experience you request.
- Legitimate interests – to operate, secure, support, troubleshoot, and improve the Service; prevent misuse; moderate submissions; and maintain accurate Service information, provided those interests are not overridden by your rights.
- Legal obligation – where we must keep records, comply with applicable law, or respond to a lawful request.
5. Location Permissions
When enabled, device location supports location-based features that you request. You can withdraw permission at any time in your device settings. We limit location processing to what is reasonably necessary for the relevant feature and do not use precise location to build a continuous history of your movements. Location-related information may be retained where you choose to save it or where reasonably necessary to provide a requested feature, subject to Section 6.
6. Data Security & Retention
- We use appropriate technical and organisational safeguards, including encryption in transit and, where appropriate, at rest.
- Data is hosted with reputable cloud service providers. Processing locations vary by service and provider, as explained in Section 7.
- Account data is generally kept while your account remains active, and saved-item data until you remove it or delete your account. When an account is deleted, we delete or de-identify associated personal data unless limited retention is reasonably necessary for a legal obligation, security, fraud prevention, or dispute resolution.
- Update requests, support correspondence, consent records, and security records are kept only for as long as reasonably necessary to resolve the request, maintain an audit trail, demonstrate compliance, or protect the Service.
- Analytics and diagnostic information is retained according to the configured service period and applicable provider terms, subject to our data-minimisation and retention requirements.
7. International Data Transfers
We and our service providers may process personal data in the United Kingdom and in other countries where they or their subprocessors operate. When personal data is transferred outside the United Kingdom, we use an applicable transfer mechanism, which may include:
- UK adequacy regulations, including the UK Extension to the EU-US Data Privacy Framework where the recipient is an active participant;
- the UK International Data Transfer Agreement (IDTA);
- the EU Standard Contractual Clauses (SCCs) together with the UK Addendum; or
- another lawful transfer mechanism or exception.
Contact us if you would like more information about the transfer mechanism applicable to your personal data.
EEA/Switzerland residents: The App is not currently intentionally offered or marketed in the European Economic Area (EEA) or Switzerland. Our public websites remain accessible there. Where EU or Swiss data-protection law applies to website use, we provide the rights and consent choices required by that law. Before intentionally offering the App in an additional jurisdiction, we will assess and implement any additional privacy requirements that apply.
8. Third-Party Services & Integrations
We use third-party providers to support the operation and delivery of the Service, including infrastructure, account, communications, location, diagnostics, optional analytics, security, content-delivery, and feature-support services. Depending on its role and the processing involved, a provider may act as our processor or as a separate controller under its own privacy terms.
- Depending on the feature, relevant providers process only the personal data reasonably necessary for their role. For example, infrastructure providers may process location data on our behalf when an enabled location feature sends it to our systems.
- We require every third party with whom the App shares personal data to provide the same or equivalent protection for that data as described in this Policy and required by applicable law. Depending on the provider’s role, this may be ensured through our contract, applicable service terms, or the provider’s own legal obligations.
We do not guarantee the accuracy, completeness, or availability of third-party information displayed in the Service.
If you choose Google Sign-In, processing is subject to Google’s terms and privacy policy; you can revoke access in your Google account settings.
Use of Google user data obtained through Google API Services complies with the Google API Services User Data Policy, including the Limited Use requirements. We do not allow human access to Google user data except where required by law, for security purposes (e.g. investigating abuse), or with your explicit consent (such as when you contact support).
More information about Firebase data processing, identifiers, retention, and processing locations is available from Google’s Firebase privacy and security information.
9. Your Privacy Rights
UK & EEA Rights
If you are in the UK or the European Economic Area, you have the right to:
- Request access to, correction of, or deletion of your personal data.
- Withdraw consent at any time without affecting prior processing.
- Receive a portable copy of your data.
- Object to certain processing or request restriction.
- Lodge a complaint with the UK Information Commissioner’s Office (ICO) or, if you are in the EEA, with your local data-protection authority.
To exercise any right, email us at [email protected].
You can withdraw consent through the relevant in-app control, unsubscribe method, or device setting made available for that feature.
Data Protection Complaints
To complain about how we use your personal data, email [email protected] with the subject “Data protection complaint”. We will acknowledge a UK data-protection complaint within 30 days and, without undue delay, investigate it appropriately, keep you informed of progress, and tell you the outcome. You may also complain to the UK Information Commissioner’s Office.
Rights in Other Jurisdictions
Depending on where you live and whether local law applies to our processing, you may have additional rights concerning your personal data. We will honour those rights where required, including any applicable right to appeal our response. We do not sell personal data or use or share it for targeted advertising. To make a request, email [email protected].
10. Business Owners and Venue Requests
If you are a business owner or authorised representative and wish to update, correct, claim, or request removal of a venue listing, please contact us at [email protected].
We may require reasonable verification of your authority, such as proof of business ownership or control of the listed venue.
We review all requests and aim to respond within a reasonable timeframe.
11. Children and Minors (Under 18)
We do not knowingly collect or retain personal data from children under the age of 13. If we learn that we have collected personal data of a child under 13, we will promptly delete that data.
Persons aged 13–17 (“Minors”) may use the Service. We take a risk-based approach to age and use privacy-protective defaults and proportionate safeguards appropriate to the Service. Where applicable law requires parental or legal-guardian consent, we will request it before the relevant processing.
We may use proportionate measures to establish or verify an age range where appropriate. We do not use personal data for targeted advertising.
12. Account and Data Deletion
You can request deletion of your account and associated personal data at any time by:
- using in-app account deletion settings, or
- contacting us at [email protected] with your request.
We will process deletion requests without undue delay and within applicable legal timeframes. Deleting an account removes the account and associated personal data unless we must retain particular information for a legal obligation, security, fraud prevention, or dispute resolution.
13. Changes to This Policy
We may update this Privacy Policy to reflect changes to the Service, our practices, or applicable requirements. We will notify you of material changes through an appropriate channel, such as the App, the Site, or email. Minor editorial updates that do not materially affect your rights may be posted without additional notice. The “Last Updated” date at the top indicates the latest revision.
14. Contact Us
Vizorent Ltd (operator of Veggeo)
Company No. 16245898
86‑90 Paul Street, London, EC2A 4NE, United Kingdom
Email: [email protected]
ICO Registration No. ZB898140
This Policy applies to veggeo.com, veggeo.eco, veggeo.app, their respective service-related subdomains, the Veggeo mobile app(s), and any public beta or test versions we make available as part of the Service.
Veggeo is a registered trademark of Vizorent Ltd in the United Kingdom, United States and certain other jurisdictions.