Privacy Policy
SwipeCart ("we", "us", or "our") helps you plan meals, build grocery lists, and shop through partner retailers. This Privacy Policy explains what information we collect, how we use it, and the choices you have.
Information we collect
- Account information. When you create an account, we collect your email address and an encrypted password through our authentication provider, Supabase. We do not store your plain-text password on our servers.
- Preferences. Household size, weekly budget, cook-time preference, dietary restrictions, food likes and dislikes, leftover preferences, and meal-plan counts you enter during onboarding or in Profile.
- Swipe and rating history. Meals you accept, skip, or rate so we can personalize recommendations. When you are signed in, this history syncs to your Supabase account.
- Meal plans and grocery lists. Meals you add to your plan and ingredients on your grocery list, stored on your device and used to power shopping features.
- Retailer connections. If you sign in to Kroger, OAuth tokens and your selected store location are stored on your device to search products and add items to your Kroger cart. We do not receive your Kroger password.
- Shopping activity. Product search terms derived from your grocery list may be sent to Kroger or Walmart (via our backend proxy) to find matching products. If you use Walmart checkout, you leave the app to complete purchase on walmart.com.
- Technical data. Standard request metadata (such as IP address) may be processed by our Cloudflare Worker proxy for rate limiting and security. We do not use this data for advertising or cross-app tracking.
How we use information
- Authenticate you and keep your session secure.
- Save and sync your preferences and swipe history across devices when signed in.
- Recommend meals and build grocery lists tailored to your household.
- Search retailer catalogs and help you add items to a cart or checkout flow.
- Respond to support requests and comply with legal obligations.
We do not sell your personal information. We do not use your data for third-party advertising or cross-app tracking.
Third-party services
We rely on trusted providers to operate SwipeCart. Each receives only the data needed for its function:
- Supabase — account authentication; storage of user profiles and swipe events when you are signed in.
- Kroger — product search, pricing, store locations, and cart actions when you connect your Kroger account.
- Walmart — affiliate product search and add-to-cart deep links as a region-agnostic shopping option.
- Cloudflare — hosts our backend proxy that keeps retailer and database secrets off your device.
- Cloudinary — serves meal photos bundled in or loaded by the app.
These providers have their own privacy policies. Your use of Kroger or Walmart checkout is also subject to their terms.
Local storage
SwipeCart stores app state on your device (including preferences, meal plans, grocery lists, and retailer tokens) using secure storage and local persistence so the app works offline and loads quickly.
Data retention and deletion
We retain account-linked data while your account is active. You can delete your account at any time from Profile → Delete account. That permanently removes your Supabase auth user, profile, and swipe history from our database and clears local app data on your device.
Security
We use industry-standard practices including HTTPS, secure token storage, and server-side secret management. No method of transmission or storage is 100% secure; please use a strong, unique password.
Children
SwipeCart is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Contact us if you believe a child has provided us data.
Changes
We may update this policy from time to time. We will revise the effective date above when we do. Continued use of SwipeCart after changes means you accept the updated policy.
Contact
Questions about this policy? Email contact@swipecart.app.