Operator / data controller:Mirelis Food Systems, LLC (“Mirelis,” “we,” “us,” “our”)
Service: The Regulatory Horizon Tracker web application at app.mirelisfood.com(the “Service”)
Effective date: July 11, 2026
This Policy is reviewed periodically and may be updated under Section 11.
Contact: contact@mirelisfood.com
Scope note. This Privacy Policy covers the Regulatory Horizon Tracker application at app.mirelisfood.com — the authenticated SaaS product with user accounts and transactional email. It is separate from the marketing-site privacy summary at mirelisfood.com/privacy.html (which covers the public website and consulting intake). For business customers who send Mirelis their own confidential business data under a consulting engagement, the separate Data Processing Addendum (DPA) governs that data; this Policy governs the personal information processed to operate the Tracker application itself.
1. Who we are
Mirelis Food Systems, LLC is an Arizona, USA single-member limited liability company that operates the Regulatory Horizon Tracker, a subscription tool that monitors publicly available US food-regulatory developments. For the personal information described in this Policy, Mirelis is the controller (and, under California law, the “business”).
2. What we collect, and why
We aim to collect only what we need to provide and support the Service. The categories below reflect how the Service is built and operated.
2.1 Account information
- What:your name, email address, and (if provided) your organization / company name; your hashed password and authentication credentials; your role within an organization (owner, admin, or member) and team membership; and team-invitation information (such as an invited person’s email address) when an account owner invites colleagues.
- Why: to create and secure your account, authenticate you, associate you with the correct subscription and organization, enforce seat limits and tier access, and communicate with you about the Service.
- Legal basis / purpose (where applicable): performance of our contract with you and our legitimate interest in operating and securing the Service.
2.2 Usage and preference information you create in the Service
- What: your saved views (named combinations of filters — categories, jurisdictions, and agencies — stored to make the dashboard reusable); your bookmarks (individual tracker entries you flag to find again); your tracked categories / jurisdictions of interest and onboarding category selections; your email digest preferences (frequency and send status); and any support messages or feedback you submit through the Service.
- Why: to deliver the dashboard, remember your preferences, send the digests you have selected (digest frequency varies by subscription tier), and respond to your support requests.
2.3 Transactional email
- What:we send service-related (“transactional”) email — for example, account verification, password reset, team invitations, and, depending on tier, the regulatory-change digest. To do this we process your email address and the message content.
- Why: these messages are necessary to operate the Service or are the feature you subscribed to. Digests include an unsubscribe mechanism; certain account and security emails (e.g., password reset) are required and are not optional while you hold an account.
2.4 Technical / log information
- What: standard server and security log data generated when you use the Service, which may include IP address, browser/user-agent, timestamps, and pages or actions within the app, as generated and retained by our hosting and infrastructure providers (Vercel and Supabase). We do not configure custom logging beyond what these providers generate by default, and we do not send these logs to any third-party logging or analytics service.
- Why: security, abuse prevention, debugging, and maintaining the integrity and performance of the Service.
2.5 Billing information
- What: for self-service Founding Access, card billing is processed by Stripe, Inc.; Stripe — not Mirelis — collects and processes your card details under Stripe’s own privacy terms, and Mirelis receives only limited billing metadata (e.g., subscription status, last four digits, billing contact). For an Organization Pilot or other written order billed by invoice, Mirelis holds invoice and payment-routing information (such as your billing contact and organization) and our bank (Mercury) processes the payment; Mirelis does not collect or store full payment-card numbers for invoiced subscriptions.
- Why: to bill you and record payment for your subscription.
2.6 What we do not intentionally collect
We do not seek sensitive personal information (such as government identifiers, precise geolocation, health, biometric, or demographic categories) to operate the Tracker, and the Service is designed for business use rather than for children. Please do not submit sensitive personal information through the Service.
3. How we use information
We use the information above to: provide, operate, secure, and improve the Service; authenticate users and manage organizations, seats, and tiers; deliver saved views, bookmarks, and the email digests you have selected; respond to support requests; send required account and security communications; bill and collect for subscriptions; comply with law; and protect the rights, safety, and property of Mirelis, our users, and the public.
We do not sell your personal information, and we do not “share” it for cross-context behavioral advertising (as those terms are used under California law). We do not use your account or usage data to serve you third-party advertising.
4. Service providers / subprocessors
To run the Service we rely on the third-party providers below. Each acts as our service provider / subprocessor, processes information only to provide its function to us, and is engaged under terms (including a data processing agreement, where applicable) that restrict its use of the data.
| Provider | Function for the Service | Primary location |
|---|---|---|
| Supabase (Supabase Inc.) | Authentication and primary application database (account data, organizations, saved views, bookmarks, preferences) | United States |
| Vercel (Vercel Inc.) | Application hosting, edge delivery, and TLS termination for app.mirelisfood.com | United States |
| Render (Render Inc.) | Hosting for the background regulatory-scanning service that updates tracker content. The scanner processes public regulatory data only, not customer personal information. | United States |
| Resend (Resend Inc.) | Sending transactional and digest email (processes recipient email address + message content) | United States |
| Cloudflare (Cloudflare Inc.) | Authoritative DNS (nameserver) for the mirelisfood.com domain. For app.mirelisfood.com, Cloudflare provides DNS resolution only — it is not a proxy, CDN, or web-application-firewall in the application’s data path (the app is served directly by Vercel), so Cloudflare does not see application request content. | United States |
| Anthropic (Anthropic PBC) | AI-assisted analysis of public regulatory source text (e.g., agency notices, the Federal Register, bill text) to help classify and summarize tracker entries. Anthropic is not sent your account, usage, or other personal information, and the user-facing application contains no Anthropic integration. | United States |
| Mercury (Mercury Technologies Inc.) | Business banking for subscription invoicing / payment routing | United States |
| Stripe (Stripe, Inc.) | Self-service card billing (card processing for subscriptions) | United States |
We may add or change subprocessors as the Service evolves; for business customers under a signed DPA, the DPA’s change-notification process applies. We will update this Policy to reflect material changes to this list.
5. Data retention
- Account and account-related data is retained for as long as your account is active and for a reasonable period afterward to wind down the relationship, then deleted or de-identified, except where longer retention is required (see below).
- Billing and tax records(invoices, payment records, signed orders) are retained for at least seven (7) years to meet tax and audit obligations, consistent with Mirelis’s records-retention practice.
- Security and log data is retained at the default level set by our infrastructure providers (Vercel and Supabase) and rotated out on their schedules; Mirelis does not configure a custom retention window and does not export these logs to any third-party service.
- Deletion on request: you may ask us to delete your account information (see Section 7). We will honor the request subject to legal, tax, and security retention obligations and to data already de-identified or aggregated.
- Where a customer’s separate DPAapplies to business data, that DPA’s retention and deletion terms govern that data (default seven-year retention with deletion-on-request within 30 days).
6. How we protect information
Mirelis maintains administrative, technical, and organizational measures designed to protect personal information, including:
- Encryption in transit (TLS) for data moving between you and the Service, and encryption at rest for data stored with our infrastructure providers (e.g., Supabase);
- Authentication and access controls, including hashed passwords, session-based authentication, and database-level tenant isolation (row-level security) so that organizations can access only their own account data;
- Least-privilege access for Mirelis personnel and subprocessors, with credentials managed in a password manager and multi-factor authentication;
- Logging and incident response, including a written breach-notification process. For business customers under a DPA, Mirelis commits to notifying the customer within seventy-two (72) hours of becoming aware of a security incident affecting their data.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7. Your privacy rights
Depending on where you live, you may have rights over your personal information, including the right to access/know, correct, delete, and obtain a copy of your information, and to object to or restrict certain processing. Regardless of whether a specific law currently applies to us, you may exercise the following with respect to the account information we hold about you.
7.1 California residents (CCPA/CPRA) — right to know and right to delete
Mirelis is a small business and does not currently meet the thresholds that make a company a “business” subject to the CCPA (broadly: ~US$26.6M in annual gross revenue, buying/selling/sharing the personal information of 100,000+ California consumers or households per year, or deriving 50%+ of revenue from selling/sharing personal information — none of which apply to Mirelis as of the effective date). As a matter of good practice, we nonetheless offer California-style rights to all users:
- Right to know the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purposes for collecting it, and the categories of third parties / service providers to whom we disclose it (all described in Sections 2–5 above).
- Right to delete the personal information we have collected from you, subject to legal exceptions.
- Right to correct inaccurate personal information.
- No sale / no sharing: we do not sell personal information and do not share it for cross-context behavioral advertising, so no opt-out of sale/sharing is necessary.
- No discrimination for exercising these rights.
How to exercise: email contact@mirelisfood.com with your request and the email address associated with your account. We will verify your request by reference to your account email and respond within the timeframe required by applicable law (for CCPA-style requests, generally within 45 days, extendable once where reasonably necessary). You may use an authorized agent where the law permits.
7.2 Other US states and international users
If you are covered by another US state privacy law (e.g., Virginia, Colorado) or, where applicable, by GDPR/UK GDPR, you may have comparable rights. Contact us at contact@mirelisfood.com and we will respond consistent with the applicable law. For business data processed under a signed DPA, data-subject requests are handled through the DPA’s process (the customer, as controller, directs the request).
8. Cookies and analytics
The Service is an authenticated web application. To keep you signed in and secure, it uses strictly necessary cookies / local session storagefor authentication and session management (set via the app’s Supabase server-side auth). These are required for the Service to function and are not used for advertising.
Analytics. The Service does not use any third-party product-analytics, advertising, or cross-site tracking technologies. We have not enabled Google Analytics, Google Tag Manager, PostHog, Umami, Plausible, Segment, Mixpanel, Amplitude, or any comparable analytics or tag-management service, and the application loads no third-party advertising or tracking scripts. Application error and performance monitoring, where used, is limited to first-party server-side logging captured by our infrastructure providers (Section 2.4); we do not transmit your activity to any third-party analytics platform.
Because the Service sets no non-essential cookies, it does not display a cookie-consent banner; the only cookies and local-storage items it sets are the strictly necessary authentication and session items described above. We do not use cookies for third-party advertising or cross-site tracking.
9. International users and data location
Mirelis operates from the United States, and the Service and its data are hosted in the United States by the providers listed in Section 4. If you access the Service from outside the United States, you understand that your information will be processed in the United States, which may have different data-protection rules than your home jurisdiction. For transfers subject to GDPR/UK GDPR, Mirelis and the relevant customer will rely on an appropriate transfer mechanism (e.g., Standard Contractual Clauses) as provided in the DPA.
10. Children’s privacy
The Service is a business tool not directed to children and is not intended for anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
11. Changes to this Policy
We may update this Policy from time to time. If we make a material change, we will update the effective date and provide reasonable notice (for example, by email or in the Service) before it takes effect. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.
12. Contact
Questions, or to exercise a privacy right:
contact@mirelisfood.com
Mirelis Food Systems, LLC — Arizona, USA.