Privacy Policy
Last updated: 12 August 2026
1. Information We Collect
We collect information you choose to give us and information created when you use CartTally. This may include:
- email and account information, such as your email address and name;
- household settings, cooking routine, planning preferences, preferred stores, and budget;
- allergies, intolerances, dietary preferences, dislikes, and other food preferences;
- meal plans, shopping lists, pantry information, and the actions you take in CartTally;
- support, Feedback, privacy, correction, or deletion requests you send us;
- waitlist or marketing signup information where you chose to provide it;
- device, browser, route, performance, analytics, and error information described below.
Food, household, pantry, allergy, intolerance, dietary, and budget information can be personal or sensitive in context. We use it only for CartTally-related purposes and apply the data-minimisation measures described below.
2. Why We Collect It
We use information to:
- provide accounts, meal plans, shopping lists, pantry tools, and directional grocery estimates;
- save your rules, preferences, budget, and preferred store;
- support users and handle access, correction, privacy, and deletion requests;
- understand and improve the product experience during the New Zealand Beta;
- monitor reliability, errors, security, and misuse;
- send marketing updates where you separately agreed to receive them.
3. Service Providers and Overseas Processing
CartTally uses specialist third-party providers for cloud hosting and application data, authentication and supported social sign-in, product analytics, error diagnostics and user-initiated Feedback, aggregate web performance measurement, and transactional or separately selected lifecycle and marketing email. These providers receive only the information needed for their relevant service.
These providers and their subprocessors may process information outside New Zealand, including in the United States, India, and other places where they operate. Depending on the data and service, a provider may process information for CartTally or handle service-generated and account information under its own terms and privacy notice. Our current product-analytics and diagnostic services process their respective data in the United States. Routing data through CartTally's website does not move that downstream processing to New Zealand. We do not sell personal information.
4. Necessary Authentication and Security
Our authentication provider sets and refreshes required session and security cookies when you sign in or sign up. They keep you authenticated, protect the sign-in flow, and cannot be disabled while using an account. CartTally's current production configuration has a maximum session lifetime of seven days, although signing out, clearing browser data, or browser limits can end it sooner. These cookies are not optional analytics or advertising trackers.
Social sign-in is user initiated: the supported sign-in provider you select receives the authentication request only when you choose that option. Provider-controlled transient sign-in state supports security and completion of that request; we do not treat it as CartTally product analytics.
5. Preferences and Operational Browser State
CartTally stores your selected light, dark, or system theme in a first-party cookie for up to one year so pages can render consistently. We also use bounded browser session storage to continue an in-progress plan-generation handoff and to recover account setup. That session state is limited to those operational purposes and normally ends with the browser tab or session. It is not used for advertising.
A versioned first-party browser preference records whether optional product analytics is enabled on that device. It contains only the preference, not an account identifier. When you are signed in, your saved account choice is authoritative and replaces the device copy before product analytics can run.
6. Product Analytics
Our product-analytics provider receives product routes and interactions, referrer and browser or device details, performance and Web Vitals, exceptions, heatmap-style interaction measurements, and coarse context it can derive from network information, including an IP address and approximate location. Remote configuration controls which supported analytics features run. We do not intentionally send raw allergy notes, pantry or shopping-list contents, exact budgets, account email, or name in product analytics.
When signed in, CartTally uses a stable pseudonymous account ID so events can be understood across your account. Signed-out use is not linked to a CartTally account, but the analytics service may retain a browser or device identifier, so we do not describe it as anonymous. Ordinary product analytics is on by default during the New Zealand Beta. Signed-in people can turn it off in Settings; signed-out people can use the device-only control below. Turning it off prevents future optional product-analytics collection on the applicable account or browser. It does not delete historical provider records; privacy requests are handled separately.
Session replay is disabled in both the application and analytics project and is not approved for reactivation. Historical recordings collected before replay was disabled can remain for their original retention period, currently up to 30 days.
Browser storage is unavailable, so product analytics remains off for safety.
7. Diagnostics, Feedback, and Aggregate Performance
Our diagnostic provider receives error details, low-rate performance traces, recent technical breadcrumbs, and a pseudonymous signed-in account ID. Technical delivery can include network and coarse location context. CartTally disables the provider's default PII capture, applies additional sanitisation, and does not send name or email as diagnostic user fields. Diagnostic session replay is off.
If you deliberately open and submit Feedback, the diagnostic provider receives the free text you enter and technical context needed to investigate it. The current widget hides name and email fields and does not allow screenshots. Please do not include allergy, dietary, pantry, shopping, budget, authentication, or other sensitive details in Feedback.
Cookie-free aggregate web analytics and performance measurement remain enabled. They provide aggregate route, referrer, country, browser, device, and operating-system reporting, plus anonymous Web Vitals and related route and technical context. We use them to understand aggregate traffic and performance, not to build individual advertising profiles.
8. Retention
We keep account and service information while needed to provide CartTally, support your account, meet legal obligations, resolve issues, maintain security, and improve the Beta. The product-analytics project currently has 30-day event retention. Historical replay follows the separate 30-day boundary described above. The current diagnostic plan provides 30 days of event retention; Feedback is kept only while useful for support or remediation and is subject to provider deletion capabilities.
The current aggregate web analytics and performance reporting windows are one month and seven days respectively. A reporting window is not necessarily a hard provider deletion deadline. Disabling future collection or changing a preference does not automatically erase historical provider records; deletion requests are handled separately using the controls each provider supports.
After account deletion, we may retain a scrubbed internal account reference, a one-way account-match value, and whether and when a trial was redeemed for up to 730 days. For a supported social sign-in, that limited record may include a protected keyed value that recognises only the exact same provider account. It does not retain the provider account ID or provider tokens and does not restore deleted profile, household, pantry, meal-plan, or shopping-list data.
9. Choices and Your Rights
Under the NZ Privacy Act 2020, you can ask for access to personal information we hold about you, ask us to correct it, or ask us to delete your account and associated data. Account deletion is currently handled manually after verification. Email privacy@carttally.co.nz to make a request.
Marketing and lifecycle email preferences are separate from browser analytics. You can use the unsubscribe link in a marketing email or contact us about email preferences; doing so does not change browser product analytics. Diagnostic error reporting, user-initiated Feedback, necessary authentication and security, and cookie-free aggregate performance measurement are also separate from the optional product-analytics choice. CartTally is designed and marketed for New Zealand users, but we do not promise that the website cannot be accessed from overseas.
10. Privacy Incidents and Contact
If we become aware of a privacy or security incident affecting personal information, we will investigate, take reasonable steps to reduce harm, and notify affected people and the Office of the Privacy Commissioner where required by New Zealand law.
Jordan Blake is CartTally's privacy officer. For privacy questions, support with a privacy right, or a data request, email privacy@carttally.co.nz.
11. AI Features
Runtime AI features are not active during Beta. The current app does not use a live AI provider to process your meal-planning or shopping information. We will update this policy before introducing a live AI-assisted feature that uses that information.