Privacy Policy
Version 2 · Effective Sept. 3, 2026 · Version history
Closient Search Inc. ("Closient," "we," "us," or "our") operates a Global Standards One (GS1) Digital Link resolver and local-first product search engine at closient.com and related domains (the "Service"). This Privacy Policy explains what personal information we collect, why, how long we keep it, who we share it with, and the choices and rights available to you.
Closient Search Inc. is a company incorporated in British Columbia, Canada, with its registered office at 1027 Englewood Ave, Langford, BC V9B 5R3, Canada. Contact details for privacy matters are in Contact us below.
This is version 2 of this policy, effective 2026-09-03. A visitor's or account holder's specific consent record always references the exact version they saw — see Prior versions of this policy.
Who this policy covers, and how
Closient serves several different kinds of visitor, and what we collect depends on which one you are:
- Marketing-site visitors. Anyone browsing closient.com without an account. We collect only consent-gated analytics (see Cookies and tracking) unless you take a further action (e.g. signing up).
- Consumer (shopper) accounts. People who create a Closient account to save preferences, subscribe to product alerts, or scan and follow products. We collect your email address, and — if you sign in with Google, Microsoft, or LinkedIn — the profile information that provider shares with us (name, email, profile photo). We do not offer password-based accounts.
- Anonymous scanners. People who scan a GS1 Digital Link barcode or QR code (e.g. on a product's packaging) without signing in. We record the scan event itself (which product, approximate location, and time) in a form designed not to identify you personally — see Anonymous scan and visit data.
- Brand and organization accounts. Businesses that use Closient to manage product listings, resolve GS1 Digital Links, or run their storefront presence. We collect business contact information, billing details, and the product/organization data the account holder enters. A business account is typically operated by one or more individual users, each covered by this policy as an account holder in their own right.
- People who submit a product safety or adverse-event report. See Product safety and adverse event reports below — this is a distinct, typed data flow with its own handling rules.
What we collect, and why
| Category | Examples | Who | Lawful basis (GDPR/UK GDPR) |
|---|---|---|---|
| Account identity | Email address; name, email, and profile photo from your chosen sign-in provider (Google, Microsoft, or LinkedIn) | Consumer and brand/org account holders | Contract (providing the account you asked for) |
| Business and billing information | Organization name, business address, tax information, subscription plan, payment method (held by our payment processor, not by us — see Who we share information with) | Brand/organization account holders | Contract; legitimate interest (billing administration) |
| Product and catalog data | Product listings, GTINs, images, certifications, and other data you enter | Brand/organization account holders | Contract |
| Scan and visit events | Which product a GS1 Digital Link resolved to, approximate location (region-level, never precise GPS unless you grant browser location for a feature that needs it), device/browser family, timestamp | Anyone who scans a product or visits a hosted product page | Legitimate interest (operating and improving the Service); consent, where required for the analytics layer (see below) |
| Cookie and tracking preferences | Your consent choices themselves, the policy version you agreed to, and (region-permitting) an anonymous device identifier | All visitors | Consent, where consent is the legal basis for the underlying activity; otherwise legitimate interest in recording the choice itself |
| Communications | Support tickets, emails, and voice/text feedback you send us | Anyone who contacts us | Legitimate interest; consent for optional communications (e.g. a product newsletter) |
| Product safety and adverse event reports | See the dedicated section below | People who file a report | Legitimate interest (product safety); see that section for detail |
We do not knowingly collect government identity numbers, financial account numbers (Stripe holds your payment method, not us), precise real-time location, or special-category data (health, biometric, etc.) as part of normal Service operation. If you voluntarily include such information in free text (e.g. a support message or an adverse-event report describing a medical symptom), we retain it only as part of that specific record and only for the purpose you provided it.
Cookies and tracking
We use a small number of first-party cookies that are strictly necessary to operate the Service (sign-in, security, and remembering your cookie choice), plus optional functional and analytics cookies that require your consent in most jurisdictions. The full list of cookies, trackers, and categories — along with exactly how consent is requested in your region — is in our separate Cookie Policy, which this Privacy Policy incorporates by reference.
In short: visitors in the EU/EEA, UK, and Canada see an opt-in banner (nothing but strictly-necessary cookies runs until you choose); visitors in California see a notice with an opt-out; everywhere else sees a notice only. You can change your choice at any time from the "Manage Cookie Preferences" link in the site footer, or, if signed in, from your account preferences page.
Anonymous scan and visit data
Scanning a product's GS1 Digital Link (barcode or QR code) does not require an account. To power features like "how many people scanned this near me" and to detect potential misuse, we record scan events using a hashed combination of your IP address and browser family — not your IP address itself, and not a persistent per-visitor identifier — aggregated into privacy-preserving statistical sketches. These raw events are purged after 90 days.
If you have consented to analytics cookies for your region, we additionally set a pseudonymous, first-party visitor_id cookie (a randomly generated identifier, not derived from any personal information) so that a sequence of scans by the same browser can be attributed to one visit history. This cookie's lifetime is capped at 90 days to match the raw-event retention above, and it is never set without consent.
Who we share information with
We share personal information only as needed to operate the Service, and never sell it. The processors we use, and why, are listed in full — including their approximate location — on our public Subprocessors page, which we keep current and which you should treat as part of this policy. In summary, categories of processor include:
- Infrastructure and hosting — the servers, content delivery network, and object storage that run the Service and hold uploaded media and backups.
- Payment processing — for brand/organization billing. We never see or store your full card number.
- Communications — sending you transactional email and, if you've opted in, SMS product-recall and safety-alert text messages.
- Sign-in providers — Google, Microsoft, and LinkedIn, if you choose to sign in with one of them.
- Consent-gated analytics — only after you grant analytics consent for your region.
If a brand you follow issues a recall or safety notice for a product you've asked to follow, we share the minimum information needed to deliver that alert to you (e.g. your alert-delivery contact and which product it concerns) — we do not share your full account profile with the brand for this purpose.
We will disclose personal information where required by law, to protect the rights, property, or safety of Closient, our users, or the public, or in connection with a merger, acquisition, or sale of assets (in which case we will make reasonable efforts to require the recipient to honor this policy).
International data transfer
Closient Search Inc. is a Canadian company. Some of our infrastructure and processors are located in Canada; others — including our production hosting, backup storage, and content delivery network — are operated by processors located in, or with infrastructure in, the United States. Where personal information originating in the EU/EEA, UK, or Switzerland is transferred to a country without an adequacy decision, we rely on our processors' standard contractual clauses or equivalent safeguards. Contact us using the details below if you would like more information about a specific transfer.
How long we keep information
- Account data is kept for as long as your account is active, plus a limited period afterward to comply with legal, tax, or dispute-resolution obligations.
- Raw scan and visit events are purged after 90 days; the pseudonymous
visitor_idcookie (where set) expires on the same schedule. - Aggregated search analytics used to improve the Service are retained for up to 24 months, after which the underlying event-level data is dropped from the relevant partition; brand-level rollups used for reporting are retained longer in de-identified, aggregated form.
- Consent records (what you agreed to, when, and under which policy version) are kept indefinitely as an append-only audit trail — this is the evidentiary record described in Prior versions of this policy, and it cannot be shortened without undermining its purpose.
- Product safety and adverse event reports are retained under the schedule described in that section, reflecting the regulatory record-keeping obligations that apply to that data.
Your rights
EU/EEA, UK, and Switzerland
If you are located in the EU/EEA, the UK, or Switzerland, you have rights under the GDPR, the UK GDPR, or the Swiss Federal Act on Data Protection (FADP), including the right to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to withdraw consent at any time without affecting the lawfulness of processing before withdrawal. You also have the right to lodge a complaint with your local data protection supervisory authority.
Brazil
If you are located in Brazil, you have rights under the Lei Geral de Proteção de Dados (LGPD), including confirmation of processing, access, correction, anonymization, deletion of unnecessary or excessive data, portability, and information about the entities we share your data with.
United States
Depending on your state of residence, you may have rights under a state privacy law (e.g. the California Consumer Privacy Act, as amended by the CPRA) to know what personal information we collect, to delete it, to correct it, and to opt out of its "sale" or "sharing" as those state laws define them. We do not sell personal information for money. Where a state law defines certain analytics or advertising cookie activity as "sharing," we honor a "Do Not Sell or Share" choice through the cookie preference controls described in our Cookie Policy.
Opt-out preference signals. We honor the Global Privacy Control signal as a valid request to opt out of "sale" or "sharing": if your browser sends it, analytics cookies stay off for you unless you later switch them on yourself in the cookie banner ("Manage Cookie Preferences" in the footer). You do not need to create an account or take any other step for the signal to be honored, and the banner tells you when it has been.
Canada — PIPEDA
Closient Search Inc. is a Canadian organization and, in the course of our commercial activities, is subject to the federal Personal Information Protection and Electronic Documents Act (PIPEDA), and — for activities regulated provincially — British Columbia's Personal Information Protection Act (PIPA).
Under PIPEDA, we collect, use, and disclose your personal information only for purposes a reasonable person would consider appropriate in the circumstances, and only with your knowledge and consent, except where the law permits collection, use, or disclosure without consent. For most of the Service, we rely on your express consent (e.g. creating an account, subscribing to alerts) or implied consent (e.g. the anonymous, aggregated scan analytics described above, which a reasonable visitor would expect from using a barcode-scanning product-lookup service, and which you can further control through the consent-gated analytics choice described in Cookies and tracking).
You have the right to access the personal information we hold about you, to challenge its accuracy, and to have it corrected. To exercise these rights, or to make a complaint about our handling of your personal information, contact us using the details in Contact us below. If you are not satisfied with our response, you have the right to file a complaint with the Office of the Privacy Commissioner of Canada (OPC), at priv.gc.ca, or with the equivalent office in your province.
Making a request (all jurisdictions)
To exercise any of the rights above — access, correction, deletion, export/portability, or a complaint — email [email protected] with "Privacy request" in the subject; if you have a Closient account, you can also sign in and open a support ticket the same way. For a brand/organization account, an org owner can also export a structured copy of most organization-scoped data directly from account settings. We aim to acknowledge every request within a reasonable time and, absent a legal reason to extend it, to respond within 30 days. We may need to verify your identity before acting on a request.
Children's privacy
The Service is not directed to children under 16, and we do not knowingly collect personal information from children under that age. If you believe a child has provided us with personal information, contact us and we will take steps to delete it.
Product safety and adverse event reports
Closient offers a feature that lets a consumer submit a typed report about a product they scanned — for example an illness, injury, allergic reaction, foreign object, spoilage, or packaging defect — which is transmitted to the relevant brand together with the product lot context from the scan, along with a reference ID for the reporter. This feature exists to give brands a fast, structured early-warning signal, alongside (never instead of) the reporter's own right to contact a public health authority directly.
Closient's role and the terms governing this specific data flow are addressed in a dedicated Brand Terms Addendum and consumer terms supplement, which are being finalized separately and will be linked from this section once published. In the meantime: we retain adverse-event reports for the period required to support product-safety recordkeeping and traceability obligations; we route reports to the brand associated with the product; and — because a report can itself become part of a regulatory or safety record — deleting a report on request is handled as redaction of your personal identifiers rather than removal of the underlying report, which we disclose to you before you submit one. We are not a submitter to any regulator on your behalf, and nothing in this Service is medical advice.
Security
We use industry-standard technical and organizational measures — encryption in transit, access controls, and regular review of our infrastructure — to protect personal information. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
Changes to this policy
We may update this policy as our practices, the Service, or the law changes. When we publish a new version, we record its effective date and it becomes the current version at privacy/; the version you actually agreed to remains available at Prior versions of this policy — see below. For a material change, we will provide reasonably prominent notice (e.g. the consent banner reappearing, or an email to account holders) before the new version takes effect where required by law.
Prior versions of this policy
Because your consent record references the specific version of this policy that was in effect when you gave it, every published version stays available, unedited, indefinitely — this is what makes the consent record legally meaningful evidence rather than a description of today's rules applied retroactively. See the full version history.
Contact us
Closient Search Inc. 1027 Englewood Ave, Langford, BC V9B 5R3, Canada
- Privacy and general inquiries: [email protected]
- Support (sign-in required): /support/
See also our Imprint for our full corporate disclosure, and our Subprocessors page for the current list of parties who process personal information on our behalf.