BatchPoint

Privacy Policy

Last updated: September 1, 2026

BatchPoint is farm record-keeping software for small produce farms and the organizations that support them. It stores crop, harvest, inventory and food-safety compliance records, and produces the traceability and audit documents buyers and inspectors ask for.

This policy explains what we collect, why, who we share it with, and how long we keep it. It applies to the BatchPoint web application at batchpoint.app and to the BatchPoint mobile apps for iOS and Android.

1. Who we are

BatchPoint is operated by BatchPoint, based in Fresno County, California, USA. We are the controller of the data described below. Contact: support@batchpoint.app.

2. What we collect

Account information

Your email address and password (stored only as a cryptographic hash — we never see or store the password itself), plus the farm or organization name you provide at signup.

Farm records you enter

Everything you record in the app, including:

Records about other people. Contact entries and worker training logs contain personal information about people who are not BatchPoint users. You are responsible for having a lawful basis to record it, and for telling those people where their information is held. We process it only on your behalf.

Payment information

If you accept payments through BatchPoint, Stripe collects and holds your identity and bank details directly in order to verify you and pay you out. We never see or store card numbers or bank account numbers. We keep only the Stripe account identifier, payout status, and the invoice records the payment relates to.

Technical information

Standard server logs from our hosting providers (IP address, timestamp, requested URL, browser user-agent), kept for security and troubleshooting. We do not use advertising trackers, third-party analytics, or cross-site tracking cookies. The only browser storage we use is what keeps you signed in and remembers your language and interface preferences.

3. How we use it

We do not sell your data, share it with data brokers, or use it for advertising. We do not use your farm records to train AI models.

4. Organizations and shared access

BatchPoint lets a supporting organization — a co-op, food hub or nonprofit — sponsor farms. This only happens when you accept an invitation.

Once you accept, that organization can view your crop, inventory, harvest and compliance records so they can aggregate supply and confirm you are audit-ready. They cannot see your bank or payout details. Your data is never shared with any other farm on the platform.

You can ask us to end an organization's access at any time. Doing so returns your account to a read-only state until you join another organization or subscribe directly; your records remain yours and stay exportable.

5. Public traceability pages

When you publish a batch for traceability, BatchPoint creates a public web page reachable by QR code or link, so a buyer or inspector can verify the produce. This page is public by design and requires no login. It shows the crop, batch and lot identifiers, harvest date, cooling and storage details, your farm name, and any "about the farm" text you add.

Do not put anything in those fields you would not want publicly visible. To generate the QR image, the batch link is sent to a third-party QR service (see below). Only publish batches you intend to be public.

6. Service providers

We use a small number of providers to run the service. They act on our instructions and are not permitted to use your data for their own purposes.

ProviderWhat it handles
SupabaseDatabase, sign-in, and photo storage — the primary store for all farm records
VercelWeb and API hosting; server request logs
StripePayments and payouts; collects identity and bank details directly from you
ResendDelivery of transactional email (invitations, invoices, reports, messages)
Google (Gemini)Powers the in-app AI assistant — see section 7
QR ServerRenders QR code images; receives the public batch link, and nothing else
Apple / GoogleApp distribution, if you install the mobile app

These providers process data in the United States. We may also disclose information if required by law, or to protect the rights and safety of our users.

7. The AI assistant

The in-app assistant is powered by Google's Gemini API. When you send it a message, we transmit the text of your conversation together with a small amount of context — whether you are a farmer or an organization user, and which page you are on.

Your farm records are not automatically sent to the AI provider. Only what you type in the chat is transmitted, so avoid pasting anything sensitive. Your conversations are not used to train Google's models.

8. Camera, photos and location

In the mobile app we request these permissions, each only when you use the feature and each refusable:

9. Retention and deletion

We keep your records for as long as your account is open. You can export everything you have entered, at any time, from within the app.

You can delete your account yourself, at any time, from Settings › Danger Zone. Deleting your account permanently removes your crops, inventory, contacts, invoices, compliance logs, photos, farm settings and sign-in credentials. This cannot be undone.

One exception: published traceability records are retained, anonymised. Traceability QR codes are printed on labels that are already inside boxes of produce in the supply chain. If those records were destroyed with your account, a buyer or inspector scanning a carton months later would get a dead link — and the food-safety trail behind produce already in circulation would disappear, which is exactly what traceability exists to prevent.

So when you delete your account, published traceability records are anonymised rather than deleted. Your farm name is replaced with "Farm (account closed)", the "about the farm" description is removed, and the record is no longer linked to any user account. The food-safety fields a buyer needs — crop, batch and lot identifiers, harvest date, cooling and storage — are kept, along with the date of anonymisation. Once anonymised, these records no longer identify you.

If your account is deleted while your organization still has farms enrolled under it, we will ask you to unenroll those farms first. This protects the other farms' records and the invoice history of payments already made to them.

Backups are retained for a short period for disaster recovery and are overwritten on a rolling basis. Server logs are retained by our hosting providers for their standard retention window.

10. Your rights

You can access, correct, export and delete your data directly in the app at any time — no request needed. If you would rather we did it, or you want to know what we hold, email support@batchpoint.app and we will respond within 30 days.

California residents have rights under the CCPA/CPRA, including the right to know, delete, and correct personal information, and the right not to be discriminated against for exercising them. We do not sell or share personal information as those terms are defined under California law. If you are in the EEA or UK, you also have rights of access, rectification, erasure, restriction, portability and objection, and may lodge a complaint with your supervisory authority.

11. Security

Data is encrypted in transit (HTTPS) and at rest by our hosting providers. Access to your records is enforced at the database level, so one account cannot read another's data. Passwords are hashed and never stored in readable form. No system is perfectly secure, but if a breach affects your personal information we will notify you and the relevant regulators as required by law.

BatchPoint is early-stage and is not yet SOC 2 or ISO 27001 certified.

12. Children

BatchPoint is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 13. If you believe a child has provided us information, contact us and we will delete it.

13. Changes to this policy

If we make a material change we will update the date at the top of this page and, where the change meaningfully affects how we handle your data, notify you in the app or by email.

14. Contact

Questions, requests, or anything that looks wrong: support@batchpoint.app.