How we protect your label data.
RangeClear is used by food and drink teams to upload artwork, recipes and retailer plans before they are public. This page explains, in plain language, how that data is stored, who can access it, and what we will never do with it.
This page is maintained by the RangeClear team to answer common security and privacy questions. It is not an independent certification.
EU hosting
Your database, file uploads and application backend are hosted in the European Union. Data is not moved out of the EU for processing.
The underlying cloud platform is operated by Lovable Cloud, which runs on managed EU infrastructure with redundancy, daily backups and monitoring.
Encryption
All traffic between your browser and RangeClear is encrypted with TLS 1.2+.
Files uploaded to RangeClear and database storage are encrypted at rest using industry-standard AES-256 by the underlying cloud provider.
Per-organisation isolation
Every account belongs to one organisation. Every product, artwork file, compliance check, issue, market and report is tagged with that organisation.
We enforce isolation in the database itself with row-level security policies, so even a bug in the application code cannot let one organisation read another's data.
Within your organisation, members of your team can collaborate on products and reports.
Authentication
Sign-in uses email & password or Google. Sessions are issued as short-lived bearer tokens and refreshed automatically.
Passwords are never stored in plain text. We can enable a check against the Have-I-Been-Pwned breached-password database on request.
Role-based access (compliance manager, viewer, admin) is enforced server-side, not just in the UI.
How we learn from uploaded labels
We do learn from the labels you upload: we use them to improve how RangeClear reads artwork, recognises ingredients and claims, and matches them against compliance rules. This is what makes the tool more accurate over time for food and drink labels.
That learning happens on our own infrastructure inside the EU. Your files and product data are not shared with third parties and are not handed to external AI providers to train their public models.
The compliance rule set itself is maintained from public legal sources and retailer policies, not from your files.
What we store
Account: email, name, organisation, role.
Product data you upload: artwork files, ingredient lists, claims, markets, internal notes.
Compliance output: checks, issues, suggested fixes, manual review tasks, reports.
Operational: audit logs of significant actions, billing events. Audit logs are written by the backend only - users cannot insert or modify entries.
Deletion & retention
You can request deletion of your account and your organisation's data at any time. We will remove it from production systems within 30 days.
Encrypted backups are rotated and expire on their normal cycle (typically within 30 days after deletion). After that point, no copy of your data remains.
If you only want to delete a single product or file, you can do that yourself from inside the app.
Audit trail
Significant actions - uploads, clearance checks, rule changes, exports, role changes - are recorded in an audit log scoped to your organisation.
Audit log entries can only be written by the backend service, never by end users, so the log stays trustworthy for internal compliance reviews.
Subprocessors
RangeClear relies on a small number of subprocessors to operate:
- Lovable Cloud - application hosting, database, file storage, authentication (EU region).
- Lovable AI Gateway - secure access to large language models used for label text extraction and rule matching. Prompts are not used for model training.
If we add or change a subprocessor that handles customer data, we will update this page before the change takes effect.
Shared responsibility
We are responsible for: keeping the platform secure, isolating organisations, encrypting data, applying security patches, and handling subprocessors carefully.
You are responsible for: protecting your sign-in credentials, choosing who in your organisation has access, deciding what files to upload, and confirming that final compliance decisions are reviewed by qualified people where needed. RangeClear is a pre-clearance tool, not a legal opinion.
Reporting a vulnerability
If you believe you have found a security issue in RangeClear, please email security@getrangeclear.com with a description and, if possible, steps to reproduce.
We will acknowledge the report, investigate, and keep you updated. Please do not publicly disclose the issue until we have had a reasonable chance to fix it.
Security & privacy contact
For data-protection questions, deletion requests, or to request a Data Processing Agreement (DPA), email privacy@getrangeclear.com.
We aim to respond to all privacy and security requests within 5 working days.
Still evaluating?
Start with a free check on a single product. You can delete it - and your account - at any time. Your data stays in the EU and is never shared with third parties.
