Welcome to Toke! Before you use our platform, please take a moment to read our Privacy Policy. These Privacy Policy outline the rules for you (“User”) using Toke and our related services. By accessing our platform, you agree to these Terms and our Acceptable Use Policy. We also encourage you to review our Privacy Policy, which explains how we handle your personal information.
Version 1.1 · Effective Date: 1 September 2026
Applicable jurisdictions: United Kingdom · European Economic Area
Important Notice: This Privacy Policy explains how Toke AI Ltd processes personal data, including sensitive (special-category) health-related information, in connection with our cannabis community and marketplace platform. Please read it carefully before using the Toke platform. It should be read together with our Terms of Service and our Cookie Policy.
Which parts of this Policy apply to you
The Toke platform is released in stages, and not every feature described in this Policy is available in every release or in every territory. Where a feature is not available to you, the processing described in connection with it does not take place.
Sections marked Feature-dependent describe processing that occurs only if the relevant feature is available to you and you choose to use it. If you are unsure which features are available to you, contact us at support@toke.ai.
Toke AI Ltd ("Toke", "we", "us", or "our") is a company incorporated in England and Wales. We operate the Toke platform (the "Platform"), which provides strain, dispensary and brand information, user reviews, and community features. Depending on the release and territory, the Platform may also provide peer-reported experience data, and facilitate connections and transactions with licensed business partners including medical consultations and prescription fulfilment. See “Which parts of this Policy apply to you” above.
Toke AI Ltd is the data controller responsible for the personal data described in this Policy. We are a company registered in England and Wales, company number 15816742, at 167-169 Great Portland Street, 5th Floor, London, W1W 5PF, United Kingdom. We are registered with the Information Commissioner's Office under reference ZC232290. For questions about this Policy or about how we handle your personal data, contact us at support@toke.ai. Our representative in the European Union, appointed under Article 27 GDPR, is named in Section 14.
This Policy applies to all personal data we process in connection with the Platform (our website, mobile applications, and related services); consumer accounts, orders, and reviews; information you choose to provide for optional features; data from business partners and their representatives; and our marketing, support, and research activities.
It applies to individuals located in, or whose data is processed under the laws of:
Where these laws differ, we apply the standard most protective of your rights, and we set out jurisdiction-specific provisions in Section 14.
Full name; username and password (stored in encrypted form); email address; date of birth (to verify you meet the minimum age to access the Platform); optional account photo.
Feature-dependent.
Postal address(es); phone number; delivery preferences and instructions.
Feature-dependent.
Order history, product selections, and order values; payment method details (card payments are processed by our third-party payment provider — we do not store full card numbers); delivery status; communications with business partners and our support team about orders.
Reviews, ratings, and written commentary; responses to structured review prompts (for example, effect ratings, flavour profiles, onset time). Feature-dependent. Where the ability to attach a photograph or other media to a review is available to you, that media too.
Feature-dependent.
Some features involve information about you that may be health-related. Where such information is attributed to you — that is, linked to your account or otherwise capable of identifying you — it is special-category personal data, and is collected only where you give explicit, separately-refusable consent (see Section 4.3). This includes:
Information you volunteer in free text. We do not ask for health information in free-text fields such as support messages, technical problem reports, or reports about a review, and we ask you not to include it. If you do include it, we do not search, filter, aggregate, or draw inferences from it. We hold it under the same access controls and retention periods as the rest of that correspondence, and where it relates to a complaint or dispute we may keep it to resolve the matter or defend a legal claim. You can use the core Platform without providing any of this. We aggregate and anonymise "Uses" input before it is shown on the Platform, so that the "Uses" information displayed to eligible users does not identify any individual (see Section 3.9).
Feature-dependent.
To confirm your age and identity, verification is carried out by a third-party identity verification provider. We do not store your identification documents on the Platform; verification is processed by the provider under its own safeguards, and we retain only confirmation of the outcome.
IP address; browser type and version; device type and operating system; app version and build; app language; session tokens and device labels. Device location where you permit it (see Section 4.7). We do not use advertising identifiers, and we do not operate a crash reporting tool. Information stored on your device rather than sent to us is described in Section 11 and in our Cookie Policy.
Reporting a technical problem. If you report a technical problem from within the app, we collect a closed set of seven items: your written description, your device model, the operating system name and version, the app version and build number, and the app language. The report is sent from your account, so it is linked to you. The screen tells you exactly what will be sent before you send it. We do not read any device identifier for this, and we do not collect your device name.
Emails, in-app messages, and support tickets; survey responses and feedback; marketing preferences.
We aggregate and anonymise data — including "Uses" input — to produce statistics and the denominated "Uses" information shown on the Platform. Once data has been aggregated and anonymised so that it no longer identifies you and we cannot reasonably re-identify you, it is no longer personal data, and the restrictions in this Policy that apply to personal data do not apply to it. The "Uses" information shown to eligible users is aggregated and anonymised in this way and is not attributed to any individual.
Legal basis: performance of a contract (UK/EU GDPR Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)).
Creating and managing your account; processing orders and facilitating fulfilment; enabling you to browse information and read and submit reviews; providing customer support; operating community features you opt into.
Legal basis: performance of a contract / legitimate interests; consent (for collecting your attributed "Uses" input — see 4.3). Aggregated, anonymised "Uses" information is not personal data (see Section 3.9).
Displaying your reviews and ratings, associated with your username (and profile photo, if enabled) unless you post anonymously; producing aggregated, de-identified statistics, ratings, and "Uses" information. Aggregated data does not identify you individually.
Legal basis: explicit consent (UK/EU GDPR Art. 9(2)(a) and Art. 6(1)(a)).
We process special-category data — including your attributed "Uses" input and any health-related information you choose to provide — only where you have given explicit, specific, and separately-refusable consent through the dedicated consent controls in your account. This consent covers the collection and use of that information while it is attributed to you. Your general use of the Platform is not treated as consent to this processing. Once the information has been aggregated and anonymised (see Section 3.9) it is no longer personal data. You may withdraw consent at any time through your account settings; withdrawal does not affect the lawfulness of processing before withdrawal, or the use of data already anonymised, but may remove access to the relevant features. A Data Protection Impact Assessment covering this processing has been (or will be, before the relevant processing begins) completed.
Legal basis: legal obligation (Art. 6(1)(c)); vital interests (Art. 6(1)(d)).
Verifying you meet the minimum age to access the Platform; complying with law and regulatory requests; responding to lawful requests from authorities; detecting, preventing, and investigating fraud, abuse, and illegal activity; enforcing our Terms.
Legal basis: legitimate interests (Art. 6(1)(f)).
Understanding how the Platform is used so that we can improve it, using anonymised or pseudonymised data wherever possible, and testing new features. We do not operate an analytics provider and we set no analytics cookies. Our map provider operates its own service telemetry, which is described in our Cookie Policy.
Legal basis: consent (Art. 6(1)(a)); and, where the soft opt-in applies, legitimate interests (Art. 6(1)(f)).
We do not currently send marketing communications, and we do not collect marketing consent or store marketing preferences. If we introduce marketing, we will ask for your consent at the point of collection, separately from account registration, and every message will carry a means of unsubscribing. We will update this Policy before we begin.
Legal basis: consent (Art. 6(1)(a)) for device location, whether used for the map or to confirm you are at a dispensary; legitimate interests (Art. 6(1)(f)) for approximate location worked out from your IP address.
We use location in three separate ways, and they are worth keeping apart. We ask your permission before using your device location for any of them, and you can withdraw it at any time in your device settings.
Device location, to show the map. We use your device location to show dispensaries near you on the map. We ask your permission first, and we only do this while you are using the app — we do not ask for background location access, and the app cannot see where you are when it is closed. You can decline. The map will then use a location you set manually, or a general city location, and the rest of the Platform works normally. You can withdraw permission at any time in your device settings.
Device location, for features that depend on where you are. Some features are only available while you are at a particular dispensary. Live menus for some dispensaries work this way, and so do reviews for some of them. Where a feature works this way, your position is checked against that dispensary at the moment you use it. The check is performed by our map provider, Mapbox, so your location is sent to Mapbox to carry it out. Nothing about the check is stored, whether it succeeds or fails. If you do not allow location access, or you are not there, that feature is unavailable to you and the rest of the Platform works normally. Reviews you have already left stay up.
Approximate location, to show the right market. When you open the app we read the IP address of your connection and use it to work out roughly where you are — at city level at best. That decides which market's dispensary and brand content we show you, so that what you see is lawful and relevant in the place you are. We do not keep a record of the approximate location we work out, and we do not build a history of where you have been. The IP address itself appears in our diagnostic logs and is kept for three days (see Section 8).
None of this is the same as your country of residence. You tell us your country of residence when you sign up, and it stays the same wherever you go. It determines which territory's terms apply to you and whether you can use particular features. Location only affects what you see and which location-dependent features you can use. If you live in the United Kingdom and travel to Amsterdam, you will see Dutch content while you are there, but you remain a United Kingdom user for every other purpose.
What we do not do. We do not keep a record of where you have been, and no location record is created by the dispensary check. A location you set manually, and the fallback city, are stored on your device and removed when you delete the app. We do not use location for advertising, profiling, or analytics, and we do not combine it with other information to build a profile of you.
Our map is provided by Mapbox, and address search suggestions are provided by Google Maps Platform, which receives the address text you type. Both collect location data as part of operating their own services. You can object to the approximate-location processing at any time (see Section 9); if you do, we will show you content for your country of residence instead.
We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you. We do not carry out profiling for that purpose.
Where we introduce any such processing, we will tell you before it begins and you will retain your rights under applicable data protection law, including to obtain human intervention, to express your point of view, and to contest the decision.
Feature-dependent. Any decision about what is clinically appropriate for you rests with a Registered Healthcare Professional and is not made by the Platform.
We do not sell your personal data. We share it only as follows, with appropriate safeguards:
Special-category data is never shared with third parties, including business partners, in a form that identifies you. Aggregated, anonymised information (see Section 3.9) is not personal data and may be shared as described above.
Personal data collected through the Platform is stored on infrastructure located in Frankfurt, Germany, within the European Economic Area.
Toke AI Ltd is established in the United Kingdom, and our personnel access that infrastructure from the United Kingdom. Transfers from the EEA to the United Kingdom are made on the basis of the European Commission's adequacy decision for the United Kingdom, renewed on 19 December 2025 and valid until 27 December 2031 unless extended or withdrawn.
We use a small number of service providers to operate the Platform: cloud hosting and database, transactional email, business email from which support correspondence is handled, hosting for our staff administration portal, map rendering and address search suggestions, and age and identity verification. Several of these providers are established in the United States. Personal data may be accessible to them from there, where that is legally required or operationally necessary to carry out the functions of the Platform. Where that is the case we rely on EU Standard Contractual Clauses together with the UK International Data Transfer Addendum. Our age and identity verification provider is established in the European Economic Area.
Our map and address-search providers, our verification provider, and the app stores that supply the age signal, also determine their own purposes for part of what they do. For that part they act as independent controllers and their own privacy notices apply.
A current list of the service providers we use, and the safeguard applied to each, is available on request by emailing support@toke.ai.
We keep personal data only for as long as we need it for the purposes described in this Policy, or for as long as the law requires. When it is no longer needed, we delete it or anonymise it so that it no longer identifies you.
Aggregated and anonymised data (see Section 3.9) is not personal data and may be retained indefinitely.
In practice that means:
Dormant accounts. If you do not sign in for 36 months, we email you to ask whether you want to keep your account. If we do not hear from you within 30 days, we close and anonymise it. This does not apply while you hold an active subscription or a lifetime entitlement; in that case your account remains open for as long as that entitlement lasts, and only the data listed above with a shorter period is removed.
You can delete your account at any time from within the app. Your account closes immediately and cannot be restored.
We then remove the information that identifies you and sever the link between your account and anything you contributed. This completes within 35 days, in line with our backup cycle described below, and cannot be reversed.
What is removed: your name, email address, date of birth, username, profile photo, saved items, and the free text of any reviews you wrote. Feature-dependent. Where friend connections are available to you, those too.
What remains: your ratings and structured scores, anonymised, which remain part of the aggregate figures shown to other users with nothing connecting them to you; where messaging is available to you, messages you sent to other users, which stay in the recipient's conversation shown as coming from a deleted user, because they also form part of that person's record of a conversation they took part in; and anything the law requires us to keep, for only as long as required.
Support correspondence. If you have emailed our support team, that correspondence is held separately from your account and is not removed by deleting your account in the app. Routine support correspondence is deleted three years after your last contact on it. Correspondence relating to a complaint or dispute is kept, still attributed to you, for six years from your last contact, because we may need it to resolve the matter or defend a legal claim. You can ask us to delete your support correspondence at any time by emailing support@toke.ai, and we will do so within one month unless we need it for a legal claim.
Financial records. Feature-dependent. Where payments are available to you and you have made one, we keep the financial and transaction records the law requires us to keep, for as long as it requires. Those records are not removed by deleting your account. Where no such records exist, none survive deletion.
Backups. Your data is removed from our live systems immediately. Our backups are held for 35 days on a rolling cycle and cannot be edited once written. Copies of your data held in them are not accessed for any other purpose and are removed when those backups are overwritten, within 35 days.
Deleting the app from your device does not delete your account. Full instructions are at toke.ai/help-articles/deleting-your-toke-account.
Depending on your jurisdiction, you have rights to be informed; of access; to rectification; to erasure; to restrict processing; to data portability; to object; rights relating to automated decision-making; and to withdraw consent (including for special-category data) at any time without affecting your ability to use core Platform functions.
To exercise any right, email support@toke.ai or use your account settings. We respond within one calendar month (extendable by two further months for complex requests, with notice). We may verify your identity first, requesting only what is necessary. We do not charge for valid requests.
We use technical and organisational measures including: encryption in transit (TLS 1.2+) and at rest (AES-256 or equivalent); credentials and cached account details held in your device's keychain or keystore; role-based access control, with personal data masked by default in staff interfaces and revealed only by an explicit, logged action; sensitive fields excluded from diagnostic logs; multi-factor authentication for staff access to production systems; staff data-protection training; incident-response procedures aligned with the 72-hour breach-notification requirement; and backup procedures with a 35-day rolling cycle. Feature-dependent. Where special-category data is collected, it is held in separate, access-controlled storage. No system is entirely secure; use a strong, unique password and notify us immediately of any suspected unauthorised access.
We set only strictly necessary cookies on our website, and the app sets no cookies at all. Because we set nothing beyond what is strictly necessary, there is no cookie banner and no preference centre — there is nothing to consent to. The app does store some information on your device rather than sending it to us: your session, your language preference, the last dispensary you looked at, your recent searches, and any location you set manually. All of it is removed when you delete the app. A full breakdown is in our Cookie Policy at toke.ai/policies
The Platform is not intended for anyone under the minimum legal age applicable in their jurisdiction, and in no case for anyone under 18. We do not knowingly collect personal data from anyone below that age.
Age assurance operates in stages:
We store the age signal and the method by which it was established. We do not store a copy of any identification document.
If we learn that an account belongs to a person below the minimum age, we close it and delete the associated data. If you believe a minor has registered, contact us at support@toke.ai.
For special-category data while it is attributed to you (including your "Uses" input), in addition to the above:
Once data has been aggregated and anonymised (see Section 3.9) so that it no longer identifies you and cannot reasonably be re-identified, it is no longer personal data; these safeguards and the deletion timeline apply to the attributed form, not to anonymised aggregates.
Toke is the data controller under UK GDPR and the Data Protection Act 2018. You may complain to the Information Commissioner's Office (ICO): ico.org.uk · 0303 123 1113 · ICO, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
Toke is the data controller under EU GDPR. Our EU representative under Article 27 GDPR is: Europe Services, SE, Na Cecelicce 425/4, Smichov, 150 00 Praha 5, Czech Republic. Data subjects may contact the representative at info@gdprrepresentative.com regarding the processing of their personal data. You may contact our representative on any matter relating to the processing of your personal data, in addition to or instead of contacting us directly. You may also lodge a complaint with the supervisory authority in your country of residence (list at edpb.europa.eu).
We may update this Policy from time to time. We will notify you of material changes by a prominent notice on the Platform, by email, and/or by requesting renewed consent where consent is the legal basis. The date at the top shows when it was last updated.
| Contact | Details |
|---|---|
| Privacy team | support@toke.ai |
| Data Protection Lead | Tristan Mallinson — dpo@toke.ai |
| Postal address | Toke AI Ltd, 167-169 Great Portland Street, 5th Floor, London, W1W 5PF, United Kingdom |
| Subject Access Requests | support@toke.ai or via your account settings |
We aim to respond to privacy enquiries within five business days, and to formal rights requests within one calendar month as required by law.
© Toke AI Ltd 2026. All rights reserved. Version 1.1.