Spot Privacy Policy
Last updated: 2026-07-18. Version: 1.2.0.
This policy explains what personal data Spot collects, why, who can see it, and the rights you have over it. It is written to meet the disclosure requirements of the EU GDPR, the UK GDPR + Data Protection Act 2018, the CCPA/CPRA (California), and PIPEDA (Canada).
1. Who we are (Controller)
- Spot is a shared, real-time grocery / to-do list app for two partners with a Manual Veto photo confirmation flow. The controller is Spot App (a trading name).
- Privacy contact: privacy@spotgrocery.com. Email us for any privacy matter, including exercising any of your rights under this policy.
2. What data we collect
| Category | Why | Where | Deleted |
|---|---|---|---|
| Account credentials: your email and a password hash (never your plaintext password). | Sign-up, sign-in, partner invites. | Our backend processor's authentication service (EU; see § 5). | When you delete your account (§ 7), or after 36 months of inactivity. |
| List contents: list and item names, done state, who created what. | The service itself: storing and syncing your lists. | Our backend database (EU). | 31 days after the list is created (pinned Premium lists never expire), or the moment you delete it. Deletion is permanent. |
| Verification photos: photos you take in the Manual Veto flow. | Showing your partner the item you're verifying. | Our backend photo storage (EU). | Within 5 minutes of the item or list being deleted. |
| Invitation records: inviter and invitee emails. | Delivering invites between partners. | Our backend database (EU). | When the invite is accepted or declined, or your account is deleted. |
Tier metadata: which tier you're on (free / premium once monetization ships). | Enforcing per-tier limits. | Our backend database (EU). | When your account is deleted. |
| Purchase records: if you buy Spot Premium, the store where you bought it (Google Play / App Store), an opaque purchase token, the plan you chose, the subscription’s state and expiry date, and, because one purchase covers both partners, which partner it covers. We never receive or store your payment card, bank details, or billing address. Google Play (or the App Store) is the merchant of record and processes all payment data under its own privacy policy. | Knowing you have Premium and applying it on every device you (and your covered partner) sign into, regardless of store. | Our backend database (EU). | When your account is deleted; the store retains its own transaction records per its policy. |
| Push token: a device token issued by Google's Firebase Cloud Messaging (FCM) if you enable notifications. | Waking your device when your partner acts. The payload is opaque metadata (event type + record ids): names, list contents, and photos never transit Google; your device fetches details from our backend and composes the notification locally. | Our backend database (registry) + Google FCM (transport). | When you sign out, delete your account, or the token goes ~9 months unused. |
| Consent record: timestamp and version of this policy you accepted. | Proving consent at sign-up (GDPR Art. 7(1)). | Our backend processor's authentication service (user metadata). | When your account is deleted. |
| Diagnostic logs: server error logs may include your user id. We do not log message bodies. | Diagnosing bugs. | Server logs (managed by our backend processor). | ≤ 30 days (automatic rotation). |
| Optional crash & error reports: only if you turn on Settings → Share diagnostics automatically (off by default): crash stack traces, handled-error reports, recent app activity with email addresses and tokens removed, and device/app metadata (model, OS version, app version, locale). Never message bodies, list contents, photos, or your account identity. | To find and fix bugs faster. | Our error-monitoring processor, EU data region; see § 4 and § 5. | Error events are retained for 90 days. Turning the toggle off stops all new reports immediately. |
User-initiated problem reports. Settings → Report a problem (or the prompt after a crash) prepares an email to support@spotgrocery.com with an on-device diagnostics file (recent app activity with email addresses removed) plus any screenshot you choose to attach. You send it from your own mail app; nothing leaves your device unless you send it.
Optional automatic diagnostics (off by default). If, and only if, you enable Settings → Share diagnostics automatically, the app uploads crash reports and handled-error reports as described in the table above. Reports are redacted on your device before upload: email addresses and authentication tokens are removed. While the toggle is off (the default), the error-reporting component is never even initialized: nothing is collected, transmitted, or fingerprinted. You can turn it off at any time, which takes effect immediately.
What we do NOT collect: plaintext passwords · location data (no location permission) · advertising identifiers (IDFA/AAID; Spot ships no advertising or analytics SDKs) · payment card or bank details (purchases are processed entirely by the app store) · contact lists · browsing history · biometric data.
3. How we use your data
Processing purposes and lawful bases (GDPR Art. 6):
| Purpose | Lawful basis |
|---|---|
| Run the service (sign-in, sync lists, deliver invites, show verification photos) | Contract (Art. 6(1)(b)). |
| Enforce tier caps | Contract. |
| Apply your Premium subscription across your and your covered partner’s devices | Contract (Art. 6(1)(b)). |
| Diagnose bugs and abuse | Legitimate interests (Art. 6(1)(f)). |
| Optional automatic diagnostics (§ 2) | Consent (Art. 6(1)(a)): the Settings toggle; withdrawable there at any time. |
| Respond to privacy requests | Legal obligation (Art. 6(1)(c)). |
| Send transactional emails (invites, password reset) | Contract. |
| Mandatory CSAM reporting (§ 9) | Legal obligation. |
We do not use your data for advertising, sell it, or profile you for automated decisions with legal effects.
4. Who can see your data
| Recipient | What and why |
|---|---|
| Your partner(s) on a shared list | List and item names, done state, and the verification photos on that list; this is the service. Because a shared list is between two people who invite each other, each member can also see the other member's display name and account email address, so you can confirm who you're sharing with. |
| Our backend hosting processor (§ 5) | All data in § 2's table; they host the database, storage, and auth under a Data Processing Agreement, only on our instructions. |
| Our error-monitoring processor (§ 5) | Only if you enable the optional diagnostics toggle: the crash & error reports described in § 2. Processed under a Data Processing Agreement, only on our instructions, in its EU data region. |
| Google LLC (FCM push transport) | Your push token and opaque event metadata only, never names, emails, list contents, or photos; notifications are composed on your device. |
| Law enforcement / regulators | Specific records when legally compelled, and proactive CSAM reports (§ 9) where the law requires them. |
| A successor entity (hypothetical merger/acquisition) | The same data, bound by the same commitments. |
We do not share your data with advertising networks, data brokers, or cross-service analytics platforms.
If your partner’s purchase covers you, the app shows each of you that the coverage exists (“You have Premium via your partner”), never any payment details.
5. International transfers
Our backend is hosted by our processor in the European Union (Frankfurt, Germany). From the EU/EEA/UK, your data stays in the EEA; from anywhere else, it is processed in the EU with the same protections.
Any onward transfer of EU/UK personal data outside the EEA (e.g. a sub-processor engaged by our backend processor) is covered by the EU Standard Contractual Clauses in our data-processing agreements with our processors, including, if you enable optional diagnostics, our error-monitoring processor (EU data region). You may request a copy of the SCCs, and the identity of our processors, by email.
6. How long we keep your data
§ 2's "Deleted" column is authoritative. In short: account data until deletion or 36 months of inactivity; lists 31 days after creation, or immediately when you delete them; photos within 5 minutes of deletion; logs ≤ 30 days; reported CSAM 90 days per the applicable preservation statute, or longer under a law-enforcement preservation order.
7. Your rights
These apply to all users, using the strictest (GDPR) wording; CCPA/PIPEDA equivalents share the same paths. Unless noted, invoke by emailing privacy@spotgrocery.com from your account email; we respond within 30 days (extendable by 60 for complex requests, with notice).
| Right | How |
|---|---|
| Access: get a copy of your data | Email. |
| Erasure | In-app: Settings → Delete my account. A single list can be erased immediately from its delete dialog. Uninstalled? See the account-deletion page or email. |
| Rectification | Account fields are editable in-app; email for anything else. |
| Portability (machine-readable copy, JSON) | Email. |
| Restriction: pause processing during a dispute | Email. |
| Objection: to legitimate-interests processing | Email; we stop unless an overriding basis exists. |
| Withdraw consent | Diagnostics: the Settings toggle, instant. Anything else: email. Withdrawal doesn't affect prior processing. |
| Complain to a regulator | Your national DPA (EU), the ICO (UK), the CPPA (California), or the OPC (Canada). |
| Non-discrimination (CCPA) | Automatic; exercising rights never degrades your service. |
8. Security
Encryption in transit (TLS 1.2+) and at rest (AES-256), on our backend processor's infrastructure. Access is enforced server-side: Row-Level Security on every table, and all state changes flow through server-side functions a modified client cannot bypass.
In the event of a personal-data breach we will notify the supervisory authority within 72 hours (GDPR Art. 33) and you directly where the breach is likely to put your rights at high risk (Art. 34).
9. Mandatory CSAM reporting
If we discover child sexual abuse material on the service, via a user report (§ 10) or operator review, we report it to the designated authority in the applicable jurisdiction (for example, NCMEC's CyberTipline in the United States, per 18 U.S.C. § 2258A). We preserve the reported content for 90 days (or longer under a preservation order) so investigators can secure legal process. We do not notify the uploader: the statutes impose a non-disclosure obligation that overrides this policy's transparency commitments for this class of report. We do not proactively scan uploads with hash-matching tools; the law does not require monitoring, and we rely on user reports and operator review.
10. Reporting other unlawful or objectionable content
For non-CSAM content you believe violates our terms or the law (harassment, hate speech, IP infringement, …), use the in-app Report affordance on the affected item. EU users: we treat an in-app report as a notice under Art. 16 of the Digital Services Act. We act on substantiated reports promptly; where we remove content, the uploader receives a statement of reasons (DSA Art. 17) unless disclosure is legally prohibited.
11. Children
Spot is not intended for users under 13 (US) or under 16 where EU member states set a higher digital-consent age, and we do not knowingly collect children's data. If you believe a child has created an account, email privacy@spotgrocery.com; we will investigate and delete accounts that we determine belong to children.
12. Changes to this policy
We update this policy as Spot evolves. Material changes increment the version number at the top. A change that adds an optional practice (like automatic diagnostics) applies only if you opt in; any other material change will be presented in-app for renewed consent before it applies to you. Non-material edits (clarifications, typo fixes) update only the "Last updated" date. If you do not accept a new version, you can delete your account (§ 7).
13. Contact
privacy@spotgrocery.com for all privacy matters.