Legal
Privacy Policy
What we collect, why we need it, who else sees it, and how to have all of it deleted.
Last updated 8 September 2026
On this page
- 01Who is responsible for your data
- 02What we collect, and why
- 03Payments
- 04Newsletter
- 05Cookies and browser storage
- 06Third-party images
- 07Who else sees your data
- 08Transfers outside the EU
- 09How long we keep things
- 10Exactly what happens when you delete your account
- 11Your rights
- 12Security
- 13Children
- 14Changes to this policy
This policy explains what VerdeNova does with your personal data when you visit the site, create an account, order, subscribe to the newsletter or send us a message. It's written to be read – if any part of it doesn't make sense, tell us and we'll rewrite it.
Who is responsible for your data
VerdeNova is not a company. It is the trading name of one person, working as a sole trader, so the controller of the personal data described in this policy is that person:
- Name: Vera Patrícia Morais Gonçalves
- Tax number (NIF): 240650158
- Place of business: Rua Portela de Baixo, 4425-533 São Pedro Fins, Maia, Portugal
- Email: suporte@verdenova.pt
- Phone: +351 914 639 115
For anything to do with privacy, write to suporte@verdenova.pt. We reply in Portuguese, Spanish or English.
We have not appointed a Data Protection Officer: given our size and what we do, we aren't required to. Requests reach the same mailbox and are handled by us.
What we collect, and why
We only ask for what the thing you're doing actually needs. There are no optional fields we quietly use for something else, and we don't buy contact lists.
| What | When | Why | Legal basis (GDPR Art. 6) |
|---|---|---|---|
| Email and password | When you create an account | To authenticate you and give you access to your account | Performance of a contract |
| Name and email from your Google account | If you sign in with Google | An alternative to creating a password with us | Performance of a contract |
| Name, address, postcode, city, phone | When you check out | To deliver the box and reach you on the day | Performance of a contract |
| Order contents, amounts, VAT, delivery date and window, language | When you order | To prepare, deliver and invoice the order | Contract and legal obligation |
| Subscription preferences (cadence, day, products) | If you subscribe | To prepare the next box at the right time | Performance of a contract |
| Loyalty stamp count | When you pay for a one-off order | To apply the discount once the card is full | Performance of a contract |
| Email address | When you subscribe to the newsletter | To send you the newsletter | Consent |
| Name, email, subject and message | When you use the contact or business form | To reply to you | Legitimate interest in answering people who write to us |
| IP address | On every public form submission | To stop automated bulk submissions | Legitimate interest in keeping the site up |
| IP address and browser version, turned into a value that can't be reversed | On every page view | To count visits without storing anything on your device | Legitimate interest in knowing how the site is used |
| The fact that you opted in, and the measurement cookie it set | Only if you tick the measurement box on a form | To connect your visits to you, so we can see what actually leads to an order | Consent |
Your IP address is the only thing we process that you didn't type, and it is never written to a database or attached to your account. On a form submission it sits in server memory for one minute, purely to count how many submissions came from the same place. On a page view it is read once, mixed with your browser's version and a secret that changes nightly to produce a value that can't be turned back into either, and discarded in the same breath. Both uses are explained in full under Cookies and browser storage.
Payments
We never see your card details. Payment happens in Stripe's hosted Checkout, which is what collects and processes card, MB WAY and Multibanco details. They don't pass through our servers and we have no way to reach them.
What stays on our side is enough to recognise the payment and help you if something goes wrong: Stripe's own references for the session, the payment, the invoice and the customer, plus the status of the order. Stripe handles payment data as a controller in its own right, under its privacy policy.
Newsletter
The newsletter is opt-in: you're only on it if you typed your email and pressed subscribe. The list is held at Resend, separated by language, so you get what we write in the language you signed up in.
Every newsletter we send carries an unsubscribe link. Unsubscribing takes you off the sends immediately; the contact is marked as unsubscribed at Resend and is deleted after 14 days by an automated job. Those 14 days exist for a practical reason: a contact deleted outright can walk back onto the list through an old import, and the unsubscribe mark is what prevents that.
If you delete your account, we also sweep your address out of every list before removing the account itself – and if we can't reach Resend at that moment, the account deletion fails rather than leaving you on a list with no account.
Cookies and browser storage
We do measure how the site is used – which pages get visited, which buttons get clicked – because otherwise we're guessing about what to fix. What we don't do is advertising, social pixels, or anything that follows you to other sites, and we never sell or share what we measure. It runs on Nosis, a measurement platform built for us and, like us, based in Portugal – so the counting never leaves the country, let alone the EU. Your browser never talks to another company's website for it either: it all happens through this site's own address.
It works in two stages, and the difference between them matters.
Before you opt in, nothing at all is written to your device. To tell one visit apart from another, the counter derives a value on our server from your IP address, the make and version of your browser, and a secret that is thrown away and regenerated every night at midnight UTC. Your IP address is never stored – it exists only for the instant that value is computed. Because the secret changes daily, yesterday's visits can't be joined up with today's, and there is nothing in any of it that leads back to you. That is why you won't see a cookie banner as you arrive: at that point there is nothing on your device to ask you about.
If you opt in, one cookie. Where a form on this site offers you the measurement tick-box, ticking it stores a single cookie in your browser. It holds nothing but a long random number – no name, no email, nothing readable, and nothing that means anything to anyone who hasn't got our records in front of them. It is locked down three ways: the page itself can't read it, so a flaw in the site can't leak it; it only travels over an encrypted connection; and it is only ever sent back to this site, never to anyone else. It lasts 400 days. Your name and your email are not part of any of this and never reach Nosis; what the cookie does is let the counting recognise the same browser coming back, so that ten visits from you read as one person deciding rather than ten strangers glancing. A number that follows your browser for 400 days is still yours to grant and yours to take back, which is why it is a tick-box and not a default. Clearing the cookie in your browser ends it, and so does deleting your account from that browser; or write to suporte@verdenova.pt and we'll have the record deleted. Leaving the tick-box alone keeps you in the first stage entirely.
| What | Where | What for | How long |
|---|---|---|---|
verdenova-locale |
Cookie | The language you picked in the switcher | 1 year |
| Supabase session cookies | Cookie | Keeping you signed in | Until you sign out or the session expires |
Measurement cookie (nv) |
Cookie | Recognising your browser for usage measurement – only if you ticked the box | 400 days |
| Cart | localStorage |
So you don't lose your cart when you close the tab | Until you empty the cart |
| Checkout form details | sessionStorage |
To restore what you'd already filled in if you come back from payment | Until you close the tab |
You can clear all of it at any time in your browser settings. You'll lose the cart and the session; the site carries on working.
Third-party images
The photographs on the site are loaded from
Unsplash (images.unsplash.com), which means your
browser makes a request to that server and it learns your IP address, as happens with
any external image. It's the only third-party domain the site's content security
policy allows – there is nothing else loading from outside.
Who else sees your data
We don't sell personal data, and we don't hand it to anyone who wants it for their own purposes. We share only with those who process data on our behalf, for the purposes above:
| Who | What for | Where |
|---|---|---|
| Supabase | Database and authentication | EU (Paris) |
| Stripe | Payments and subscriptions | EU / US |
| Resend | Transactional and newsletter email | EU / US |
| Vercel | Site hosting | EU / US |
| Nosis | Usage measurement | Portugal |
| Only if you choose to sign in with Google | US |
Beyond these, we may have to disclose data to public authorities where the law requires it – for instance to the Portuguese tax authority, in meeting the tax obligations attached to a sale.
Transfers outside the EU
Some of the providers above are US companies and may process data outside the European Economic Area. Where that happens, the transfer relies on the Standard Contractual Clauses approved by the European Commission and/or certification under the EU-U.S. Data Privacy Framework, as applicable to each provider.
How long we keep things
- Account: for as long as you keep it. You can delete it whenever you like, from your profile.
- Orders: invoices and transaction records carry statutory retention periods – in Portugal, as a rule, ten years. That's why an order doesn't vanish when you delete your account; see the next section.
- Newsletter: until you unsubscribe, plus 14 days.
- Contact form messages: they stay in the support mailbox for as long as they're useful to the history of the matter.
- IP address: one minute, in memory, and never at all in the page counter – there it is used and dropped within the request.
- Usage measurement: the daily secret that makes visits countable is destroyed every midnight UTC. If you opted in, the measurement cookie lasts 400 days on your device and the record connecting it to you lasts until you withdraw or delete your account.
Exactly what happens when you delete your account
Deleting an account has to erase your personal data without erasing the sale – the right to erasure does not override a legal obligation to keep records (GDPR Art. 17(3)(b)). In practice:
- Your email is swept out of every newsletter list.
- If you had opted in to measurement, the record connecting the measurement cookie to you is deleted at Nosis, and your past visits go back to being counts with nobody's name on them.
- On each past order, the delivery details – name, email, address, phone – are blanked. Not "anonymised as far as practical": erased.
- What remains is the amounts, the line items and the dates, which is what accounting requires. The order is detached from you: with no link to the account and no delivery details, the row no longer identifies you.
- The account and its credentials are deleted.
Your rights
You have the right to access your data, to correct it, to ask for its erasure, to ask us to restrict processing, to object to processing based on legitimate interests, and to receive your data in a structured format (portability). Where processing rests on consent – the newsletter – you can withdraw it at any time, without affecting what was lawfully done beforehand.
Several of these are already in your hands: you change your details in your profile, unsubscribe with one click from any email, and delete your account yourself. For anything else, write to suporte@verdenova.pt – we answer within one month, as the GDPR requires, and usually far sooner.
If you think we've handled your data badly, you can complain to the competent supervisory authority. In Portugal that is the Comissão Nacional de Proteção de Dados (CNPD), www.cnpd.pt; if you live in another member state, you can also go to your own country's authority – in Spain, the AEPD, www.aepd.es.
Security
The site is served over HTTPS only, with HSTS. Passwords are managed by Supabase and stored hashed – we have no access to yours. Access to the database tables is restricted row by row, so an account can only read its own data. Pages declare a content security policy that blocks third-party scripts.
No system is impregnable. If there is ever a data breach that poses a high risk to you, we will tell you and notify the CNPD within the deadlines the law sets.
Children
The site is not aimed at anyone under 16 and we don't knowingly collect children's data. If you know a child has left data with us, write to us and we'll delete it.
Changes to this policy
If we change anything that matters, we update this page and the date at the top. If a change affects processing that rests on your consent, we'll ask for consent again rather than assume the old one carries over.
Something here unclear?
These pages are meant to be readable, not just published. If anything on them doesn't make sense, ask us and we'll explain it – and fix the wording.
