Privacy Policy

1. Introduction

CartyUp ("we", "us", or "our") operates the CartyUp mobile application (the "App"). This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our App.

By using CartyUp, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Information You Provide

  • Email address — Used for account creation and passwordless authentication (magic link sign-in).
  • Display name — Optional. Used to identify you to other members of shared lists.
  • Profile photo — Optional. Displayed on your profile and visible to members of shared lists.

2.2 Information Collected Automatically

  • Push notification tokens — Device tokens used to send you notifications about changes in shared lists. You can disable notifications at any time through your device settings.
  • Device language preference — Used to display the App in your preferred language (English, Portuguese, or Dutch).

2.3 Information We Do NOT Collect

  • We do not collect precise location data.
  • We do not collect financial or payment information.
  • We do not collect contacts from your phone.
  • We do not use cookies or third-party advertising trackers.

3. How We Use Your Information

We use the information we collect to:

  • Authenticate your identity and manage your account.
  • Enable you to create, manage, and share shopping lists.
  • Send push notifications about changes in shared lists (e.g., items added or checked off).
  • Display your name and photo to other members of lists you share.
  • Improve the App and fix issues.

4. Data Sharing

We do not sell, trade, or rent your personal information to third parties.

Your information is shared only in the following limited circumstances:

  • With shared list members — When you share a list, other members can see your display name and profile photo.
  • Service providers — We use Firebase (Google Cloud) for authentication, database, storage, and cloud functions. Google processes data in accordance with their Firebase Privacy Policy.
  • Push notifications — We use the Expo Push Notification service to deliver push notifications to your device.

5. Data Storage and Security

Your data is stored securely using Google Firebase infrastructure, including Cloud Firestore (database), Firebase Authentication, and Firebase Storage. All data is transmitted over encrypted connections (HTTPS/TLS).

Local data on your device is stored using encrypted local storage for offline access.

6. Data Retention

We retain your data for as long as your account is active. When you delete your account (available in the App under Profile → Delete Account), we permanently delete:

  • Your profile information (name, email, photo).
  • All lists you own and their items.
  • Your membership from shared lists.
  • All share invites you created.
  • Your Firebase Authentication record.

7. Your Rights

You have the right to:

  • Access your personal data — visible in the App's Profile screen.
  • Update your display name and profile photo at any time.
  • Export your data — available in the App under Settings → Export Data.
  • Delete your account and all associated data at any time.
  • Opt-out of push notifications through your device settings.

8. Children's Privacy

CartyUp is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have collected such information, please contact us so we can delete it promptly.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new policy on this page and updating the "Last updated" date. We encourage you to review this policy periodically.

10. Contact Us

If you have any questions about this Privacy Policy, please contact us at:

Email: contact@aionios.studio