Legal

Privacy Policy

How Veast X LTD collects, uses, shares, and protects your personal data. Compliant with GDPR and CCPA.

Last updated: May 2026 Effective date: September 18, 2026 Contact: veganbeast@veast.life

1. Introduction

Veast X LTD ("Veast," "we," "us," or "our") operates the Veast Life mobile application and the veast.life website (collectively, the "Platform"). This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, how long we retain it, and what rights you have over it.

This policy applies to all users of the Platform globally and satisfies the requirements of the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) as amended by CPRA, and Canada's PIPEDA.

By using the Platform, you confirm that you are at least 16 years of age and that you have read and understood this policy.

2. Data We Collect

2.1 Account and Identity Data

Name, email address, date of birth, country/region, gender (Male or Female), profile photo (optional), and password hash (never stored in plaintext).

2.2 Health and Fitness Data

Workout logs (exercise type, duration, GPS coordinates, accelerometer/motion patterns); food log photos; water intake logs; meditation session durations; sleep data cross-referenced from iOS HealthKit or Android Health Connect (read-only); injury disclosures and health notes from onboarding (treated as special-category sensitive data under GDPR Article 9).

2.3 Journal and Content Data

Journal entries, Veast Pulse daily check-ins, community posts and comments, and private coach chat messages (Premium subscribers).

2.4 Financial and Payment Data

Subscription tier and billing records, Stripe payment tokens (we do not store raw card numbers — Stripe handles PCI compliance), in-app purchase receipts, and Stripe Identity KYC data where required for coach onboarding.

2.5 Blockchain and Token Data

Solana wallet address (if you join the $VEAST ecosystem), $VEAST token balances, transaction history (recorded on-chain — see Section 11), and Founding Member NFT status.

2.6 Technical and Device Data

IP address, device identifiers, OS version, app version, crash logs, location data (GPS for workout validation), background accelerometer/motion data, and push notification tokens.

2.7 Coach-Specific Data

Coach specialty planes, credentials, bio, client roster metadata (counts, not PII), and revenue and payout records.

3. How We Use Your Data

PurposeData UsedLegal Basis (GDPR)
Providing and operating the PlatformAccount, health, content, device dataContract (Art. 6(1)(b))
$VEAST token reward validationLocation, motion, health, photosContract + Legitimate Interests
AI-powered coaching and routine generationQuestionnaire, health, activity dataContract (Art. 6(1)(b))
Coach matching and routine handoffQuestionnaire, plane preferencesContract (Art. 6(1)(b))
Processing paymentsFinancial, identityContract + Legal Obligation
Fraud prevention and securityIP, device, location, activity patternsLegitimate Interests (Art. 6(1)(f))
Legal and tax record-keepingSubscription and payment recordsLegal Obligation (Art. 6(1)(c))
Improving the Platform (anonymized)Aggregated analyticsLegitimate Interests (Art. 6(1)(f))
Marketing communications (opt-in only)EmailConsent (Art. 6(1)(a))
Health data processing (special category)Injury disclosures, health questionnaireExplicit Consent (Art. 9(2)(a))

We do not use your data to train third-party AI models. Data passed to Anthropic for real-time inference is not used to train their foundation models under our enterprise agreement.

4. Legal Basis for Processing (GDPR)

For users in the EEA and United Kingdom, our processing rests on:

  • Contract (Art. 6(1)(b)): Processing necessary to provide the Platform services you signed up for.
  • Legal Obligation (Art. 6(1)(c)): Processing required to comply with applicable laws (e.g., CRA 7-year minimum for financial records).
  • Legitimate Interests (Art. 6(1)(f)): Fraud prevention, security monitoring, and anonymized analytics — where our interests do not override your fundamental rights.
  • Consent (Art. 6(1)(a)): Marketing emails and optional data collection. You may withdraw consent at any time.
  • Explicit Consent (Art. 9(2)(a)): Special-category health data (injury history, medical conditions). You may withdraw this consent, but doing so may limit AI coaching features.

5. Data Sharing and Third-Party Processors

We do not sell your personal data. We share data only with the processors below, each under a Data Processing Agreement with appropriate safeguards.

ProcessorRoleLocationData Shared
SupabaseDatabase hosting (PostgreSQL) on AWSAWS us-east-1, United StatesAll structured user data
Apple HealthKitOn-device health data read (iOS)On-device onlyActivity data for token validation
fal.ai3D avatar generationUnited StatesSingle profile photo per call; not retained by fal.ai beyond inference
AnthropicAI agent (Veast Agent)United StatesConversation context, questionnaire data
StripePayment processing and KYCUnited StatesFinancial and identity verification data
CloudflareCDN, DDoS protection, bot detectionGlobal edge (no PII stored)Request metadata, IP addresses (ephemeral)
Twilio VerifyPhone OTP verificationUnited StatesPhone number (transient)
YouTube / GoogleLive coaching session broadcastUnited StatesStream delivery; no Veast user PII passed to YouTube

Coaches access member data only within the scope of their coaching relationship and are bound by the Veast Data Processing Agreement.

6. Retention Timelines

Data CategoryRetention PeriodNotes
Health data, journal, posts, chat30-day grace period after deletion request, then hard purgeSoft delete on request; permanent erasure after 30 days
Account profile data30-day grace period, then hard purgeSame soft-delete flow
Auth records, subscriptions, payment records7 years from last transactionRequired by Canada Revenue Agency minimum
Security event logs2 yearsFraud investigation and legal compliance
Anonymized aggregate analyticsIndefinitelyCannot be re-identified; not personal data under GDPR

7. Your Rights Under GDPR

If you are located in the EEA or United Kingdom, you have the following rights:

Right of Access (Art. 15)

Request a copy of all personal data we hold about you. We will respond within 30 days.

Right to Rectification (Art. 16)

Correct inaccurate or incomplete data at any time via Profile settings or by contacting us.

Right to Erasure (Art. 17)

Request deletion of your account and all associated personal data. We initiate a soft delete and permanently purge all data after 30 days, except records retained for legal obligation and on-chain data (see Section 11).

Right to Restriction of Processing (Art. 18)

Request restriction of processing in certain circumstances (e.g., while a dispute is pending).

Right to Data Portability (Art. 20)

Request an export of your personal data in machine-readable JSON format. Available via Settings > Export My Data in the app, or by contacting us.

Right to Object (Art. 21)

Object to processing based on legitimate interests (e.g., analytics). We will cease such processing unless we can demonstrate compelling legitimate grounds.

Right to Withdraw Consent (Art. 7(3))

Where processing is based on consent (marketing, health data), you may withdraw at any time. Withdrawal does not affect the lawfulness of prior processing.

Right to Lodge a Complaint

You have the right to lodge a complaint with your local supervisory authority (EU: national DPA; UK: Information Commissioner's Office).

To exercise any GDPR right, email veganbeast@veast.life with subject line "Privacy Rights Request." We respond within 30 days (up to 45 for complex requests, with notice of extension).

8. Your Rights Under CCPA (California Residents)

Right to Know

Request disclosure of the categories and specific pieces of personal information we have collected, the sources, our business purpose, and third parties with whom we share it.

Right to Delete

Request deletion of personal information we have collected, subject to the same retention exceptions in Section 6.

Right to Correct

Request correction of inaccurate personal information.

Right to Opt-Out of Sale or Sharing

We do not sell or share personal information for cross-context behavioral advertising. No opt-out is required, but you may contact us to confirm.

Right to Limit Use of Sensitive Personal Information

We use sensitive personal information (health data, precise geolocation) only for Platform functionality and token reward validation, not for inferring characteristics unrelated to the service.

Non-Discrimination

We will not discriminate against you for exercising any CCPA rights.

To submit a CCPA request, email veganbeast@veast.life with subject line "CCPA Rights Request."

9. Data Residency and International Transfers

Your data is hosted on AWS us-east-1 (North Virginia, United States) via Supabase. Backups remain within the same AWS region.

For users in the EEA: Your data is transferred to the United States under Standard Contractual Clauses (SCCs) pursuant to GDPR Article 46(2)(c), as executed between Veast X LTD and Supabase. Copies of relevant SCCs are available on request.

EU data residency pinning (dedicated eu-west region) is on the roadmap for v1.1 (2027).

For third-party processor locations, see veast.life/privacy or the full Data Residency document.

10. Cookies and Tracking Technologies

The veast.life website uses cookies. We obtain your consent before loading non-essential cookies via our cookie consent banner. Categories:

  • Strictly Necessary: Session management, security, CSRF protection. Always active.
  • Functional: Language preference, consent preferences. Active only with consent.
  • Analytics: Google Analytics (anonymized). Active only with consent.
  • Marketing: Advertising attribution (not currently used). Active only with consent.

Your preference is stored in cookie veast_consent_v1 for 365 days. Change your preferences at any time via the link.

The mobile app does not use cookies. Platform analytics in the app are handled via server-side event logging.

11. On-Chain Data Disclosure

The $VEAST token economy operates on the Solana blockchain — a public, decentralized, and immutable ledger.

The following data is recorded on-chain and cannot be erased by Veast or any party:

  • $VEAST token balances and transaction history
  • Founding Member NFT ownership records
  • Any on-chain token transfers you initiate

Upon account deletion: Veast will disassociate your wallet address from your user ID in Veast's internal database. The on-chain records remain permanently on the Solana blockchain and are publicly visible to anyone with your wallet address.

Before joining the $VEAST ecosystem, you are shown a clear disclosure of this immutability during onboarding (Step 9). Proceeding constitutes informed consent.

12. Children's Privacy

The Platform is not directed to persons under the age of 16. We do not knowingly collect personal data from anyone under 16. Users must confirm their age during signup.

This age threshold reflects GDPR Article 8 (digital consent age) and aligns with the majority of EU member states that have set their age of digital consent at 16.

If we become aware that we have collected data from a person under 16, we will delete that data immediately. Contact us at veganbeast@veast.life if you believe we have inadvertently collected such data.

13. Security

We implement appropriate technical and organizational measures including:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Row-Level Security (RLS) enforced in Supabase PostgreSQL
  • Multi-factor authentication for admin access
  • Security event logging with 2-year retention
  • Regular security reviews and penetration testing (scheduled pre-launch)

In the event of a personal data breach, we will notify affected users and relevant supervisory authorities within 72 hours of becoming aware, where required by GDPR Article 33.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via in-app notification and/or email at least 14 days before the change takes effect. Continued use of the Platform after the effective date constitutes acceptance of the updated policy.

15. Contact

Veast X LTD
Vancouver, BC, Canada
Email: veganbeast@veast.life
Website: veast.life

For privacy-specific requests, use subject line "Privacy Rights Request."