Loamy Loamy
How It Works Traceability Compliance Pricing Blog
Sign In Get Early Access

Privacy Policy

Last updated: June 15, 2026

1. Introduction

Loamy, Inc. ("the Company," "we," "us," or "our") operates the website inloamy.com and the Loamy traceability platform (collectively, the "Service"). Loamy is an AI agrifood traceability and recall compliance platform: our core function is to ingest supplier certificates submitted by food producers and supply chain teams and to build a structured traceability graph so that, when a recall notice arrives, affected lots can be identified in minutes. This Privacy Policy explains what information we collect through the Service, how we use and protect it, and your rights with respect to it.

The Company is headquartered at 500 First Street, Suite 200, Davis, CA 95616, United States. You can reach our privacy contact at [email protected].

This Policy covers personal information collected through inloamy.com and through direct communications with us. It does not cover third-party websites that may be linked from the Service.

2. Information We Collect

2.1 Information You Provide

We collect information you submit directly when you interact with the Service, including:

  • Contact details (name, email address, phone number) when you fill out a demo request, contact form, or early-access registration;
  • Company and role information you choose to share (organization name, job title, production volume, supply chain context) to help us configure the platform appropriately for your operation;
  • Supplier certificate documents and associated metadata (lot IDs, harvest dates, certificate types, supplier names, handling records) that you upload or connect to the Loamy platform as part of the traceability service;
  • The content of any messages, support tickets, or feedback you send us.

The supplier certificate data you submit is business document data: it describes food lots, supplier relationships, and compliance records rather than personal information about individuals. We process it solely to build and maintain your traceability graph and to generate recall queries and FSMA 204 compliance exports on your behalf. We do not use certificate document content to train machine learning models without your explicit written consent.

2.2 Information Collected Automatically

When you visit inloamy.com, we automatically collect limited technical information:

  • IP address and approximate location (city and region level, not precise coordinates);
  • Browser type, operating system, and device class;
  • Pages visited, referring URLs, and time on page;
  • Cookie and similar identifiers (see Section 5 and our Cookie Policy).

2.3 We Do Not Knowingly Collect Children's Data

inloamy.com is a business-to-business platform directed at food producers and supply chain professionals. It is not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact [email protected] and we will delete it.

3. How We Use Information

We use the information we collect to:

  • Respond to inquiries, demo requests, and support questions from food producers and supply chain teams;
  • Operate and maintain the Loamy traceability platform, including parsing uploaded certificates, building supplier-lot graphs, and generating recall query results and FSMA 204 Key Data Element exports;
  • Improve the accuracy of our certificate extraction models and the reliability of the graph database, using aggregated and anonymized performance data only;
  • Send service-related communications (onboarding guidance, certificate expiry alerts, platform updates) and, with your consent where required, marketing communications about Loamy features;
  • Detect, investigate, and prevent fraud, abuse, or unauthorized access to the platform;
  • Comply with applicable legal obligations, including FDA recordkeeping requirements relevant to our operations.

We do not sell personal information for monetary value. Where applicable state law treats certain advertising arrangements as a "sale" or "share," see Section 9 below for your California rights.

4. Sharing of Information

We share personal information only with:

  • Service providers acting on our behalf (for example, cloud hosting, email delivery, and anonymized site analytics) under contractual confidentiality and data-processing terms that limit their use of your data;
  • Government authorities or law enforcement, when required by law, court order, or to protect the rights, safety, or property of the Company or others;
  • A successor entity in the event of a merger, acquisition, or asset sale, subject to this Policy and prior notice to you where required by law.

We do not sell personal information to third parties. We do not disclose supplier certificate content or traceability graph data to any party other than the account holder who submitted it, except as required by law.

5. Cookies and Tracking

We use cookies and similar technologies to operate the site, remember session preferences, and measure aggregate usage. We use notice-only consent for non-EU visitors: non-essential cookies may load on first visit, and a banner informs you of this use. For full details and choices, see our Cookie Policy.

6. Data Retention

We retain personal contact information (names, email addresses, inquiry records) only as long as needed to maintain our business relationship with you and to comply with legal or accounting obligations. Inactive marketing-list contacts are purged after 24 months. Server access logs are retained for 90 days, then aggregated.

Supplier certificate data and traceability graph data that you upload to the platform is retained for the duration of your active account and for a period after account closure as may be necessary to respond to FDA or FSMA 204 audit requests on your behalf. We will provide notice of our post-closure retention schedule in your account agreement.

7. Security

We use administrative, technical, and physical safeguards designed to protect personal information and certificate document data, including TLS encryption in transit, restricted-access databases, and least-privilege access controls. No system is perfectly secure; we cannot guarantee absolute security. If you believe your account or data has been compromised, contact us immediately at [email protected].

8. Your General Rights

Depending on your jurisdiction, you may have rights including access to, correction of, deletion of, and the ability to limit certain processing of personal information we hold about you. To make a request, email [email protected]. We will respond within the timeframe required by applicable law. California residents should also read Section 9 for their specific rights under the CCPA and CPRA.

9. California Residents (CCPA / CPRA)

Because Loamy is headquartered in Davis, California and many of our customers are California-based food producers operating under California agricultural and food-safety regulations, we take our obligations to California residents seriously. Under the California Consumer Privacy Act ("CCPA") and the California Privacy Rights Act ("CPRA"), California residents have specific rights regarding personal information collected about them. This section supplements the rest of the Policy.

9.1 Categories We Collect

In the past 12 months, we have collected the following categories of personal information defined under Cal. Civ. Code section 1798.140: identifiers (name, email address, IP address); commercial information (service inquiries, account records, subscription tier); internet activity (browsing on inloamy.com); and inferences drawn from the above for service-improvement purposes. We do not collect government-issued identifiers, financial account credentials, precise geolocation, biometric data, health information, or other sensitive personal information as defined under CPRA section 1798.140(ae) in connection with the inloamy.com website or early-access registration process.

9.2 Sources, Purposes, Disclosure

We obtain this information from you directly and through automatic site instrumentation. We use it to operate and improve the Service, communicate with you about traceability and recall compliance features, and meet legal obligations. We disclose it only to service providers under written contract and to legal authorities where required.

9.3 Your CCPA / CPRA Rights

  • Right to Know: request the categories and specific pieces of personal information we have collected about you in the past 12 months.
  • Right to Delete: request deletion of personal information we collected from you, subject to legal exceptions.
  • Right to Correct: request correction of inaccurate personal information.
  • Right to Opt Out of Sale or Sharing: we do not sell personal information; we do not "share" it for cross-context behavioral advertising as defined under CPRA.
  • Right to Limit Use of Sensitive PI: we do not use sensitive personal information for purposes beyond those permitted without authorization.
  • Right to Non-Discrimination: we will not deny services, charge different prices, or provide a different level of service because you exercised a right.

9.4 How to Exercise

Submit a verifiable request by emailing [email protected] with the subject line "California Privacy Request." Include enough detail for us to verify you are the person whose information is the subject of the request. We respond within 45 days, with a possible 45-day extension for which we will notify you.

9.5 Authorized Agents

You may designate an authorized agent to make a request on your behalf. The agent must provide proof of authorization; we may also require you to verify your identity directly.

9.6 "Shine the Light"

California Civil Code section 1798.83 entitles California residents to request information regarding our disclosure of personal information to third parties for direct marketing. We do not disclose personal information for third-party direct marketing.

9.7 Do Not Track and Global Privacy Control

Under the California Online Privacy Protection Act (Cal. Bus. & Prof. Code section 22575), we disclose how we respond to "Do Not Track" (DNT) browser signals. Because there is no common industry standard for interpreting DNT signals, we do not currently respond differently to them. We do not authorize third parties to collect personally identifiable information about your activity across different websites when you use the Service. We honor an opt-out preference signal sent by a platform or browser that complies with the CPRA, such as the Global Privacy Control (GPC); when we detect a GPC signal, we treat it as a valid request to opt out of the sale or sharing of personal information for that browser or device.

10. Changes to This Policy

We may update this Policy from time to time. Material changes will be reflected by a new "Last updated" date at the top of this page and, where appropriate, a notice on the Service. Your continued use of the Service after the effective date of an updated Policy constitutes acceptance of the changes.

11. Contact

Questions, requests, or complaints about this Privacy Policy can be sent to:

Loamy, Inc.
500 First Street, Suite 200
Davis, CA 95616, US
Email: [email protected]
Phone: +1 (530) 754-1200
Loamy

AI agrifood traceability and recall compliance for food producers.

500 First Street, Suite 200
Davis, CA 95616, US
+1 (530) 754-1200
[email protected]
Product
How It Works Traceability Compliance Pricing Blog
Company
About Contact Privacy Policy Terms of Service Cookie Policy
© 2026 Loamy, Inc. All rights reserved.
Privacy Terms Cookies Cookie preferences