Entity notice. From 1 July 2026, Ethical Brand Ventures, Inc. (“EBV”) became the exclusive commercial partner of Ethical Brand Foundation Limited (“EBF”) and the operator of ethicalbrand.com and related commercial platform services. EBF remains the owner or steward of the eb™ trademark, research methodology, certification framework and public-interest mission. EBV operates the commercial platform under authority from EBF.
1. Purpose
This Privacy Policy explains how Ethical Brand Ventures, Inc. (“EBV”, “we”, “us” or “our”) collects, uses, stores and shares personal information when you use ethicalbrand.com, EBV-operated subdomains, the eb mobile app, membership services, scanning tools, Personal Brand Portfolio features, AI-assisted tools, support services and other EBV-operated platform services.
Ethical Brand Foundation Limited (“EBF”) owns, controls or stewards the eb™ trademark, research methodology and certification framework. EBV may share relevant information with EBF where necessary for research integrity, certification review, methodology oversight, trademark protection, legal compliance, dispute management or public-interest purposes.
2. Who is responsible for your information
EBV is responsible for personal information collected through EBV-operated commercial platform services, including accounts, memberships, app services, scanning features, Personal Brand Portfolio services, payments, support, analytics, commercial communications, platform security and related workflows.
EBF may be separately responsible, jointly responsible or a recipient of information where information is used for methodology oversight, research integrity, certification governance, trademark protection or foundation activities.
Where EBV processes information for EBF, or where EBF receives information from EBV, those arrangements are governed by internal data-sharing, confidentiality, access-control and retention controls.
3. Definitions
For this Privacy Policy:
- “App” means the eb mobile application and related mobile services operated by EBV.
- “Candidate” means a person, organisation, brand, product, service or other entity nominated, identified, scanned, submitted or reviewed for admission, assessment, certification, directory listing, licensing or monitoring.
- “PBP” means the Personal Brand Portfolio feature that records, organises and displays brands discovered by a user through scanning, manual entry or other App-supported workflows.
- “PBP History” means the historical record of brands added to a user’s PBP, including scan mode, timestamp, score snapshot, favourite status, rotation status and engagement signals.
- “Personal information” means information that identifies you or can reasonably be linked to you.
- “Persona Idealis” means a planned or future analytics feature intended to compare a user’s stated priorities and tolerance thresholds with actual brand choices.
- “Platform” means ethicalbrand.com, EBV-operated subdomains, the App, account systems, mobile services, APIs, scanning tools, Personal Brand Portfolio services, AI-assisted tools, support channels, directories, partner portals, membership services and related digital services.
- “Portfolio Data” means current PBP entries, favourites, QVSEE score snapshots, timestamps, rotation state, limit state, engagement signals and related metadata.
- “Scan Data” means information generated when a user scans a barcode, QR code, logo, label, image, product or brand identifier.
- “Sensitive information” means information that receives additional protection under applicable law, such as health information, biometric information, government identifiers, precise location data, political opinions, religious beliefs or similar information.
4. Information we collect
We may collect the following categories of information.
4.1 Account information
This includes your name, email address, username, password or authentication details, telephone number, profile information, account status, communication preferences and security settings.
4.2 Membership information
This includes membership type, plan, status, referrals, credits, tokens, access rights, account history, community activity and membership preferences.
4.3 Payment and transaction information
This includes billing information, transaction records, payment status, invoices, receipts, tax information, refund records, payment processor references and app store transaction records. EBV does not intentionally store full payment card details where those details are handled by a payment processor or app store.
4.4 Brand, product and certification activity
This includes nominations, endorsements, challenges, reports, ratings feedback, monitoring preferences, brand portfolio entries, certification evidence, Candidate information, source links, documents, comments, images and related research submissions.
4.5 App, device and scan information
This includes information generated through the App, including device type, operating system, app version, device identifiers, crash logs, diagnostic data, push notification tokens, camera or image-permission status, barcode scans, QR code scans, logo scans, label scans, product images, brand identifiers, scan timestamps, scan mode, scan result, QVSEE score snapshot and related metadata.
4.6 Personal Brand Portfolio information
We may collect and maintain PBP information, including current portfolio entries, historical portfolio entries, brand IDs, brand names, scan mode, timestamps, favourite status, rotation timestamps, QVSEE score snapshots, engagement signals, PBP limits, Limitless Mode status, current count, rotation count, rate-limit status and related metadata.
4.7 PBP History
The active PBP and PBP History are different. A brand may be rotated out of the active PBP but remain in PBP History.
PBP History may be retained to provide account history, analytics, Persona Idealis features, product improvement, research integrity, support, fraud prevention, auditability and dispute management.
4.8 Support information
This includes messages, tickets, attachments, categories, subject lines, support history and metadata associated with support requests.
4.9 Technical and usage information
This includes IP address, browser type, device information, operating system, referring pages, page views, session data, log files, cookies, analytics events, error reports and security logs.
4.10 AI interaction information
This includes prompts, messages, queries, uploaded content, scan inputs, AI outputs, feedback, moderation records and internal summaries generated or assisted by AI-enabled tools.
4.11 Marketing and communication information
This includes marketing preferences, email engagement, subscription status, survey responses, campaign participation and communication records.
4.12 SMS consent and messaging information
This includes mobile telephone numbers, SMS opt-in records, consent wording shown to you, consent source pages, timestamps, one-time verification code request records, delivery status, opt-out and help keyword records, and related support or security records.
4.13 Compliance and security information
This includes audit logs, fraud-prevention records, abuse reports, moderation records, verification records, sanctions or restricted-party screening where applicable, legal requests and dispute records.
5. How we collect information
We collect information:
- directly from you when you use the Platform;
- from your device, browser or App;
- from scans, PBP activity, favourites and engagement signals;
- from payment processors and app stores;
- from service providers;
- from public sources;
- from other users, members, Candidates, partners or third parties;
- through cookies and similar technologies;
- through AI-assisted workflows;
- through support and compliance processes; and
- through research, certification, directory and monitoring workflows.
6. Why we use information
We use information to:
- operate the Platform;
- operate the App;
- create and manage accounts;
- provide membership and App services;
- process payments and refunds;
- manage app store subscriptions and transaction records;
- provide support;
- process scans and identify brands;
- create, display and maintain PBPs;
- maintain PBP History;
- manage favourites, limits, Limitless Mode, rotation and rate limits;
- manage nominations, endorsements, challenges and reports;
- support certification, rating, directory and licensing workflows;
- conduct research and methodology development;
- support EBF methodology oversight and trademark protection;
- provide personalised user experiences;
- develop Persona Idealis, Choice Gap or similar analytics features;
- send user-requested SMS account verification codes and process HELP, STOP, START or similar text messaging keywords;
- communicate service, legal, security and account information;
- send push notifications where enabled;
- send marketing communications where lawful;
- prevent fraud, abuse, manipulation and security threats;
- moderate content and enforce policies;
- use AI-assisted tools for permitted purposes;
- comply with legal obligations;
- manage disputes; and
- protect the rights, safety, reputation and integrity of EBV, EBF, users, Candidates, partners and the public.
7. Lawful basis for processing
Where UK or EU data protection law applies, we rely on one or more of the following lawful bases:
| Purpose | Example data | Lawful basis |
|---|---|---|
| Account operation | name, email, authentication data | contract; legitimate interests |
| Membership services | plan, billing status, preferences | contract |
| Payments | transaction records, invoices | contract; legal obligations |
| App operation | device data, app version, crash logs | contract; legitimate interests |
| Scanning | scan data, image inputs, brand identifiers | contract; consent where required; legitimate interests |
| PBP operation | PBP entries, favourites, score snapshots | contract; legitimate interests |
| PBP History | historical entries, rotation records, engagement signals | legitimate interests; contract; consent where required |
| Persona Idealis and personalised insights | priorities, tolerance thresholds, PBP History | consent where required; legitimate interests; contract |
| Certification workflows | nominations, evidence, challenges | legitimate interests; consent where required |
| Research and methodology oversight | submissions, source material, reviews | legitimate interests; public-interest mission; consent where required |
| AI-assisted services | prompts, scans, outputs | contract; consent; legitimate interests |
| Security and fraud prevention | IP address, device logs, audit records | legitimate interests; legal obligations |
| SMS account verification | mobile number, SMS consent records, verification events | consent; contract; legitimate interests |
| Marketing | email, preferences, engagement records | consent; legitimate interests where lawful |
| Legal compliance | records, requests, audit logs | legal obligations; legitimate interests |
Where another privacy law applies, we process personal information under the equivalent lawful ground or permitted purpose recognised by that law.
8. Cookies and similar technologies
We use cookies and similar technologies to operate the Platform, identify returning users, secure accounts, remember preferences, measure traffic, support analytics, improve services, validate research activity, prevent abuse and provide personalised features.
You can control cookies through your browser settings. If you block cookies, some Platform features may not work properly.
9. Device permissions and push notifications
The App may request device permissions such as camera access, image access, notifications, network access and local storage. You can control permissions through your device settings. If you disable permissions, some App features may not work.
If you enable push notifications, we may process push tokens and notification preferences to send service, account, portfolio, scan, security, support or feature-related notifications.
10. Scans and images
When you use a scanning feature, EBV may process the scan input and related metadata to identify a brand, product, logo, QR code, barcode, label, packaging or other identifier.
Scan inputs may be processed by EBV systems, AI-assisted tools, third-party service providers or image-recognition systems. Scan results may be retained in account records, PBP records, PBP History, research signals and service logs.
You should not scan or upload images containing other people’s personal information, confidential information, trade secrets or sensitive information unless you have authority and the scan is necessary.
11. Persona Idealis and personalised insights
Future features may use PBP History, engagement signals, stated priorities, tolerance thresholds and QVSEE-related information to generate personalised insights, including comparisons between stated ethical preferences and actual brand choices.
These insights are intended to support personal reflection and discovery. They are not professional advice, moral judgement, financial advice, employment advice or purchasing instructions.
Where required by law, EBV will seek consent or provide controls before using personal information for new materially different personalisation or profiling features.
12. Migration and backfill of existing scan history
If PBP features are introduced to existing users, EBV may use existing scan history, account activity and related records to create initial PBP entries and backfill PBP History. This allows continuity of user experience and supports account history, analytics and future personalisation.
13. AI-assisted processing
We may use AI-assisted tools to classify, summarise, translate, search, moderate, analyse, prioritise or respond to information submitted through the Platform.
AI tools may support:
- brand, product, barcode, QR code, label or logo scanning;
- brand matching and duplicate detection;
- PBP classification;
- research workflows;
- OSINT source review;
- support responses;
- moderation;
- personalisation;
- nomination, endorsement, challenge and report workflows;
- QVSEE-related analysis;
- Persona Idealis or Choice Gap features; and
- internal workflow automation.
Where AI tools process personal information, we apply safeguards and limit the information shared to what is reasonably necessary for the relevant purpose. We do not intentionally submit sensitive personal information to third-party AI systems unless necessary and lawful.
Use of AI-assisted tools is also governed by the AI Policy.
14. Marketing communications
We send marketing communications only where we have your consent or where applicable law allows us to contact you about similar services and you have not opted out.
You may unsubscribe from marketing communications at any time. We may still send non-marketing service, legal, security, billing, support, portfolio, App, scan or account communications.
15. SMS account verification and mobile messaging
During account registration or account setup, if you enter your mobile number and select the dedicated SMS consent checkbox, EBV may send a one-time passcode or related account verification text to the mobile number you provide. These messages are transactional, user-requested and are not used for marketing. Message frequency varies based on your verification requests. Message and data rates may apply.
No SMS message is sent merely because a phone number is entered. A verification text is sent only after you affirmatively provide SMS consent and request a code.
You can reply HELP for help or STOP to opt out of further text messages from the relevant texting program. If you opt out, you may need to use another verification method or contact support to complete account recovery or verification.
Consent to receive text messages is not a condition of purchase or account creation. Users who open the secure email activation link may complete account activation without selecting SMS verification.
16. Sharing information
We may share information with:
- EBF, where necessary for methodology oversight, certification governance, trademark protection, public-interest research, legal compliance or dispute management;
- service providers, including hosting, analytics, email, support, payment, identity, security, cloud, AI, storage, image recognition, app infrastructure, fulfilment and infrastructure providers;
- app stores and mobile platform providers;
- payment processors and financial service providers;
- professional advisers, including lawyers, accountants and auditors;
- researchers, reviewers, moderators, contractors and staff bound by confidentiality obligations;
- Candidates, where necessary to progress a nomination, certification, challenge, report, appeal or licensing workflow;
- regulators, courts, law enforcement or public authorities where required or reasonably necessary;
- successors, acquirers or restructuring participants, subject to appropriate protections; and
- other parties where you have consented or directed us to share the information.
We do not sell personal information to advertisers.
Mobile information and SMS consent data will not be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third party, except service providers that process the information solely to operate and deliver the messaging program on our behalf. We do not sell mobile numbers or SMS consent records.
17. Aggregated and de-identified information
EBV may use aggregated or de-identified information for research, analytics, app performance, market insight, certification prioritisation, methodology development, product improvement, public-interest research, reporting and commercial planning.
This may include aggregated scan frequency, PBP additions, favourites, engagement signals, portfolio trends and commonly encountered brands.
18. International transfers
Your information may be transferred to, stored in or accessed from countries other than the country where you live, including the United States, United Kingdom, Australia and countries where our service providers operate.
Where required, we use appropriate safeguards such as contractual protections, transfer assessments or equivalent measures.
19. Retention
We retain information for as long as reasonably necessary for the purposes described in this Privacy Policy.
Retention periods may depend on:
- account status;
- membership status;
- payment, tax and accounting requirements;
- App usage and scan history;
- PBP operation and PBP History;
- Persona Idealis or analytics requirements;
- certification, rating, directory and licensing integrity;
- research and methodology needs;
- legal and regulatory requirements;
- security and fraud-prevention requirements;
- dispute-management needs; and
- whether information has been anonymised or aggregated.
We may retain certain information after account closure where reasonably necessary for legal compliance, certification integrity, fraud prevention, dispute management, research audit, trademark protection, service integrity, app integrity or public-interest purposes.
20. Deletion, anonymisation and retained integrity records
If you request account deletion, EBV may delete, anonymise or de-identify personal information where required by law and reasonably possible.
EBV may retain certain records where necessary for legal compliance, payment records, security, fraud prevention, certification integrity, dispute management, research audit, service integrity or where the information has been anonymised or aggregated.
PBP rotation or removal from the active PBP does not necessarily delete PBP History.
21. Your rights
Depending on where you live, you may have rights to:
- access your personal information;
- correct inaccurate information;
- request deletion;
- restrict processing;
- object to processing;
- withdraw consent;
- receive a copy of your information;
- request portability;
- opt out of marketing;
- control device permissions;
- control push notifications;
- complain to a regulator; and
- request review of certain automated or AI-assisted outcomes.
To exercise privacy rights, contact [email protected].
Requests concerning EBF research or methodology records may be referred to EBF where EBF is the relevant controller or where retention is required for certification integrity, legal compliance or dispute management.
22. Security
We use reasonable technical, organisational and administrative safeguards to protect information. These may include access controls, encryption, authentication, logging, monitoring, secure hosting, staff controls, confidentiality obligations and vendor safeguards.
No internet or mobile service can be guaranteed as completely secure. You are responsible for using strong passwords, keeping credentials confidential, maintaining device security, updating the App and reporting suspected unauthorised access.
23. Children
The Platform is not directed to children under 16. We do not knowingly collect personal information from children under 16 without appropriate consent. If you believe a child has provided personal information to us, contact [email protected].
24. Third-party sites and app stores
The Platform may link to third-party websites or services. The App may be distributed through third-party app stores and may rely on operating systems, mobile networks or device providers.
We are not responsible for their privacy practices. You should review their privacy policies before using them.
25. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be notified where reasonably practical. The updated version will be posted on the Platform with a new “last updated” date.
26. Contact
For privacy questions or requests:
Ethical Brand Ventures, Inc.
Email: [email protected]
Support: https://support.ethicalbrand.com
For matters specifically concerning EBF methodology, trademark stewardship or foundation records, EBV may refer your request to EBF or coordinate a response with EBF.