Peanut Shopper
Privacy Policy
Effective July 1, 2026
Privacy is a product commitment for Peanut Shopper. We collect as little user data as practical, we do not want plaintext shopping-list or favorite-store contents on our server, and we do not sell, rent, or target ads from your private account data.
1. Privacy Commitment and Data We Avoid
We do not ask for payment information, government ID numbers, home address, household profile, grocery receipts, or imported store loyalty accounts. You should not put sensitive personal, medical, financial, or password information into Peanut Shopper.
Our default product direction is data minimization: keep public flyer data public, keep private user workflow data encrypted, and keep operational analytics separate from the contents of shopping lists, favorites, private notifications, and map preferences.
2. Data We Store for Signed-In Accounts
When you sign in, we may store account and sync data needed to operate the service:
- Pseudonymous account identifier, login method, and basic sign-in state.
- Login history and security metadata such as timestamps, browser/device information, and operational request logs.
- Search counts and store query values used to understand whether store search is working.
- Support tickets, reports, admin replies, status, and related message history.
- Encrypted account documents for shopping lists, favorites, notifications, and map preferences.
3. Encrypted Account Documents
Shopping lists, favorites, account notifications, and map preferences are encrypted in the browser before they are stored as account documents. The server stores encrypted envelopes and sync metadata such as document type, revision, updated time, and device mutation IDs.
New-flyer notices for favorite stores are generated from public flyer metadata. The server can provide public flyer notice candidates, but matching those notices to your favorite stores happens after your encrypted favorites are decrypted in your browser. Notice read-state is stored as part of your encrypted notifications document.
This design is intended to keep private shopping-list and favorites content out of analytics, support tooling, and routine server-side processing. No security design is perfect, and encryption does not protect data that is visible on your own unlocked device or in your browser session.
4. Guest Data and Local Storage
If you use Peanut Shopper without signing in, shopping-list, favorites, theme, map, and search preferences may be stored in your browser's local storage. Guest data is not intentionally synced across devices. Clearing browser data may delete it.
5. Email and Sign-In Messages
Email magic links and codes are sent only to complete sign-in or account-related actions. These messages may include your email address, a short-lived code or link, delivery metadata, and basic anti-abuse information. Do not share sign-in codes or links.
We do not use sign-in emails as marketing emails. If we later add marketing email, it should require a separate opt-in.
6. Support, Reports, Uploads, and Future Comments
Support tickets, reports, uploaded flyer information, and future comments are not treated as encrypted private shopping-list documents. They may be reviewed by Peanut Shopper operators so we can respond, moderate abuse, improve flyer quality, and fix issues.
- Closed support tickets may be deleted after 30 days.
- Inactive support tickets may be auto-closed after 14 days.
- Do not include sensitive information in support tickets, reports, uploads, or comments.
7. Third-Party Services
We may use third-party providers for OAuth, email delivery, hosting, tunnels/CDN, maps, geocoding, flyer sources, and security. Those providers may process information under their own terms and privacy policies. For example, your OAuth provider can know you used its sign-in flow, and an email provider can process transactional sign-in email delivery.
8. First-Party Operational Telemetry
We may collect limited first-party usage telemetry to understand whether real users can load pages, find stores, open flyers, and use account features without friction. This may include page path, page timing, referrer host, source or QR campaign parameters, language, time zone, device class, browser-provided bot hints, and same-origin API timing summaries.
This telemetry does not include shopping-list text, favorites contents, private account document contents, support message text, or raw IP addresses. Network and browser identifiers used for counting are hashed before storage, and configured owner/home IP addresses can be excluded from product statistics.
9. How We Use Data
- To sign you in and keep sessions working.
- To sync encrypted account documents across your devices.
- To show support tickets, replies, notifications, and service notices.
- To debug, secure, monitor, and improve store search, flyer loading, and account sync.
- To prevent abuse, spam, fraud, scraping attacks, and unauthorized access.
10. Sharing and Selling
We do not sell or rent personal information. We do not use private shopping-list or favorites contents for targeted advertising. We may share limited data with service providers that help operate Peanut Shopper, when required by law, or to protect the service and users from abuse.
11. Retention
Encrypted account documents may remain until you delete or replace them, stop using the account, or request deletion. Login, security, operational, and support records may be kept for a reasonable period for debugging, security, abuse prevention, and legal compliance.
12. Your Choices
- You can use many store and flyer pages without signing in.
- You can clear local browser data to remove guest-only data from that device.
- You can stop using email sign-in by not requesting a new code.
- You can request account deletion or privacy help by contacting us.
13. Children
Peanut Shopper is not directed to children under 13. If you believe a child provided personal information, contact us so we can review and delete it where appropriate.
14. Changes
We may update this Privacy Policy as Peanut Shopper changes. We will update the effective date when the policy changes.
15. Contact
Privacy questions can be sent to [email protected].