The Food GroupVerify

Privacy

Privacy Policy

How information is collected and used in The Food Group Verify.

Last updated: August 9, 2026

The Food Group Verify (the “Service”) is operated for The Food Group by CMJ Consulting LLC (“CMJ Consulting,” “we,” “us”). The Food Group decides what participant information goes into the Service and what happens to it; we hold and process that information on The Food Group’s instructions. Our Data Processing Agreement sets out the commitments we owe The Food Group about those records — security, retention, export, deletion, and breach notification — and this policy explains our practices alongside it.

If you are a participant and you have a question about your own record — what The Food Group has, how to correct it, or how to have it removed — contact The Food Group directly at 763-450-3860. They control the record; we can only act on their instruction.

Information in the Service

  • Participant records. The Food Group uploads survey responses it has already collected. A record can include name, email address, phone number, mailing address, household size, and the original response as it appeared in the uploaded file. We keep the original row so a record can be traced back to its source and re-checked.
  • Verification sessions. When someone opens a verification link we emailed them and confirms it, we record the IP address the request came from, the approximate location derived from that address, whether the connection appears to be a VPN, proxy, Tor exit, or datacenter, the network operator, the browser user-agent string, a bot-risk score from reCAPTCHA, and the time. This is what distinguishes a real person confirming their own survey response from an automated submission.
  • Email delivery events. Our email provider reports back whether a verification message was delivered, bounced, was opened, or was marked as spam. We store those events against the record so staff know whether an address is reachable.
  • Gift card records. When The Food Group issues a gift card, the Service records the amount, the date, the staff member who issued it, and a reference number from the vendor that sent the card. Gift cards are purchased and delivered outside the Service; we do not process payment card or bank account information.
  • Staff accounts. For Food Group staff who sign in, we store name, email address, role, and sign-in activity.

How the information is used

To match duplicate survey responses to a single person, to send and check verification links, to give staff the evidence they need to decide whether a response is genuine, to administer gift card issuance, to keep the Service secure, and to support The Food Group’s use of it.

We do not sell personal information, we do not use it for advertising, and we do not use it to train AI models. The Service has no AI features and runs no web analytics, advertising trackers, or session-replay tools.

Automated scoring and human review

The Service scores records for signs of duplicate or fraudulent submission and sorts them into low-risk, needs-review, and high-risk. That score is automated; the decision is not. Records that the system is not confident about go to a review queue for a Food Group staff member, and no record is ever deleted automatically on the strength of a score.

A score is evidence for a person to weigh, not a verdict. Using a VPN, sharing an address with other households, or having a phone number that also appears on another record are all ordinary things that raise a flag without meaning anything is wrong.

Cookies

Staff sign-in sets a single session cookie so a signed-in staff member stays signed in. It is not readable by JavaScript and is not used for tracking. The public verification page loads Google’s reCAPTCHA, which sets its own cookies for bot detection. We use no other cookies.

Service providers

We rely on third-party providers to host the Service, authenticate staff, send verification email, and assess whether a verification request looks automated. All are listed, with what each one receives, on our Subprocessors page.

Retention, security, and location

Participant records are stored in the United States on Google Cloud infrastructure. They are encrypted in transit and at rest, no participant data is readable directly by a browser (every read passes through our servers, which check the requester’s role first), and verification links are single-use, time-limited, and stored only as a hash — the link itself exists nowhere but in the email we sent.

The Food Group decides how long its records are kept. When The Food Group asks us to delete records, or when our agreement ends, we delete or de-identify them on the schedule in the Data Processing Agreement.

Requests about your information

Requests to see, correct, or delete a participant record are directed to The Food Group, which controls the record. We give The Food Group the tools and help it needs to answer those requests. If you write to us directly, we will forward your request to The Food Group and tell you we have done so.

Children

The Service is used by adults responding to a Food Group survey and by Food Group staff. It is not directed at children, and we do not knowingly collect information from children. A participant record may state a household size, which can include children, but it does not identify them.

Changes

We may update this policy. When we do, we revise the “Last updated” date above.

Contact

CMJ Consulting LLC · cmjconsultingmn@gmail.com. For questions about a participant record, contact The Food Group at 8501 54th Ave. N, New Hope, MN 55428, or 763-450-3860.