Privacy Policy
Last updated: 26 July 2026GrocerCheck is a grocery price-comparison service for New Zealand shoppers. This policy explains how we collect, use, store and share personal information when you use the GrocerCheck mobile app, website and related support services (together, the “Service”). It also explains the choices and rights available to you.
Privacy at a glance
- You stay in control. Location, camera and notifications use device permissions that you can change at any time.
- We collect for a reason. We use information to operate your account, compare local prices, maintain lists and alerts, and improve reliability.
- We do not sell your data. We display Google AdMob banner ads, which may process device, advertising, usage and diagnostic data as described below.
- You can leave. You can request access, correction, account deletion or deletion of associated personal data.
1. Who is responsible for your information?
GrocerCheck is operated in New Zealand and is responsible for personal information collected through the Service. For questions, requests or complaints, contact our privacy contact at kiaora@paulnz.tech.
2. Information we collect
Account and profile information
If you create an account, we collect your email address, display name, Firebase account identifier and authentication-provider details needed to sign you in. Authentication is handled through Firebase Authentication and, when you choose them, Apple or Google sign-in. We do not have access to your password in readable form.
Location and selected area
With your permission, the app may process your device's precise location to identify nearby supermarket branches. You may instead search for and choose a suburb or area manually. Your selected latitude, longitude, area label, city, search radius and preferred store identifiers are saved on your device and, while you are signed in, may be synchronised with your GrocerCheck account through Cloud Firestore. We use this information to personalise local prices, specials, store distances and basket comparisons.
We do not provide your precise device location to Google AdMob. An IP address processed by a service provider may be used to estimate a coarse or general location.
Camera and barcode information
With your permission, the app uses the camera to scan product barcodes. Camera images used for barcode recognition are processed on your device and are not saved to your account or uploaded by GrocerCheck. The resulting barcode number may be used to find the matching product.
Shopping activity and preferences
We store information you choose to create or save, including shopping-list names, list items, product names, quantities, checked-item status, selected stores, price-alert targets and shopping-completion timestamps. This information lets us synchronise your data, restore it on another signed-in device, calculate basket comparisons and deliver requested price alerts. It may indicate intended purchases or completed shopping activity, but GrocerCheck does not receive supermarket receipts, payment information or confirmation that a retailer transaction occurred.
Recent product searches are stored only on your device. They are not synchronised with your account or retained by GrocerCheck, and you can clear them from the Search screen.
Device and security identifiers
GrocerCheck generates a random identifier for each app installation. It is not a hardware identifier. While you are signed in, it is associated with your Firebase account and used to protect account sessions and enforce the app's single-active-device rule. Reinstalling the app normally creates a new identifier.
Firebase App Check also processes app or device attestation information through Apple's App Attest or DeviceCheck services. We use this to verify that requests come from an authentic GrocerCheck installation, prevent abuse and protect the Service.
Notifications
If you enable notifications, we obtain an Expo push token associated with this app installation and store it with your account identifier, selected-store scope and alert preferences. GrocerCheck, the Expo Push Service and Apple Push Notification Service process this information to deliver requested price-drop or service messages. The token is detached from your account when you sign out where the request succeeds, and you can disable notifications in your device settings.
Advertising, usage and diagnostics
Google Mobile Ads may process an IP address and coarse location, app and ad interactions, device or app-scoped identifiers, ads displayed, crash information and performance information such as launch time, hangs or energy usage. Google may use this information for third-party advertising, analytics, ad measurement, fraud prevention, security and improving the advertising SDK. Section 5 explains this processing and your choices in more detail.
Website and support communications
Our hosting provider may process standard request information when you visit the website, such as IP address, browser type and requested page. If you contact us, we collect your contact details and the content of your message so we can respond.
3. How we collect information
We collect information directly from you when you create an account, build lists, choose preferences or contact us; automatically from your device when you use enabled features; and through service providers acting for us. Some collection is optional and occurs only after you grant a device permission or choose to sign in, enable notifications or create saved content. Grocery prices, product details and branch information are not personal information about you.
4. How we use personal information
We use personal information only where reasonably necessary to operate and improve GrocerCheck, including to:
- create, secure and support your account;
- show relevant prices, specials and branches near your chosen location;
- save and synchronise lists, products, preferences and alerts;
- compare basket totals and generate shopping plans;
- send notifications and service communications you have requested;
- answer support, privacy and data-correction requests;
- measure advertising and technical performance, diagnose crashes and improve reliability;
- display and measure banner advertising, and prevent advertising fraud;
- detect misuse, protect the Service and comply with legal obligations.
We do not sell personal information. The app displays third-party advertising through Google AdMob; the data used for advertising is explained in the next section.
5. Advertising and Google AdMob
GrocerCheck displays third-party banner advertisements supplied by Google AdMob. When the app requests, displays or measures an ad, the Google Mobile Ads SDK may automatically collect and share certain information with Google and participating advertising partners for advertising, analytics, ad measurement, fraud prevention, security, compliance and SDK performance. This may include:
- IP address and approximate location. An IP address may be used to estimate the general location of the device. GrocerCheck does not intentionally pass your precise GPS location to AdMob for advertising.
- App and ad interactions. Information such as app launches, ad impressions, taps, clicks and video views where applicable.
- Diagnostics. Information about the performance of the app and advertising SDK, such as launch time, hangs, crashes or energy usage.
- Device and app identifiers. These may include an Android advertising ID, app set ID, iOS advertising identifier (IDFA) where Apple authorisation has been granted, identifier for vendors (IDFV), or other app- or developer-scoped identifiers.
Google may use this information to deliver and select ads, measure ad performance, limit repeated advertising, evaluate advertising and SDK performance, and detect invalid traffic or fraud. Ads may be personalised, non-personalised or limited depending on applicable law, consent, device settings and the identifiers available to Google.
On iOS, GrocerCheck will not access the IDFA or permit tracking as defined by Apple unless the app first presents Apple's App Tracking Transparency request and you authorise tracking. If GrocerCheck does not present that request, or if you decline it, the IDFA is unavailable to the app. You can review or withdraw tracking permission at any time in Settings → Privacy & Security → Tracking. Withdrawing permission does not remove advertising, but it limits the identifiers and information available for personalised advertising and cross-app measurement.
GrocerCheck does not intentionally send your Firebase account ID, name, email address, shopping lists, recent searches or precise GPS location to AdMob. You can manage how Google personalises ads through My Ad Center. Android users can also reset or delete the advertising ID in device privacy settings.
For more detail, see Google's iOS Mobile Ads data disclosure, Android Mobile Ads data disclosure, and explanation of how Google uses information from apps that use its services.
6. Device permissions and your choices
Location, camera, notification and, if presented, tracking access are optional device permissions. The app asks before using them. You can withdraw a permission in your device settings, although the related feature may no longer work or may work with reduced personalisation. You can choose a suburb instead of sharing device location, search for a product instead of scanning its barcode, disable notifications, clear recent searches from the Search screen, and manage iOS tracking permission in Settings → Privacy & Security → Tracking.
7. When we share information
We may disclose personal information only as reasonably necessary for the purposes described above:
- Firebase services. Google Firebase provides account authentication, Cloud Firestore data synchronisation, App Check security and website hosting. Firebase Authentication processes account identifiers, names and email addresses. Cloud Firestore stores signed-in users' selected area, lists, alerts and installation-session information. App Check processes app or device attestation information.
- Notification providers. Expo and Apple process push tokens and notification payloads to deliver requested notifications. GrocerCheck stores the Expo push token with the signed-in account while notification delivery is enabled.
- Place-search provider. GrocerCheck uses OpenStreetMap's Nominatim service for suburb search and as a fallback for converting coordinates into an area label. A search query, or latitude and longitude for a reverse-geocoding request, is sent to Nominatim to return a place result. Nominatim may also receive standard network information such as an IP address.
- Advertising providers. Google AdMob and participating advertising partners receive and process the advertising data described above to provide, select, personalise and measure ads, and to prevent fraud. For Google Play Data Safety purposes, this is treated as data shared with a third party.
- Legal and safety reasons. We may disclose information where required by New Zealand law, a court or lawful authority, or where reasonably necessary to prevent a serious threat, investigate misuse or protect legal rights.
- Business changes. If GrocerCheck is restructured, sold or transferred, information may be transferred as part of that transaction subject to appropriate confidentiality and privacy protections.
We do not give supermarkets or AdMob your account email, shopping lists, product searches or precise device location for their own marketing.
We require service providers that process personal information for GrocerCheck to protect it consistently with this policy, their applicable contractual obligations and applicable privacy law.
8. Overseas storage and processing
Firebase, AdMob, Expo, Apple and OpenStreetMap service infrastructure may process information in New Zealand, the United States and other countries. Some services, including Firebase Authentication and push-notification delivery, use global or provider-selected processing locations. This means your information may be stored or processed outside New Zealand. We take reasonable steps to select providers and arrangements that protect information consistently with the New Zealand Privacy Act 2020. See Firebase privacy and security information, Expo's Privacy Policy, Apple's Privacy Policy and Google's Privacy Policy.
9. Retention and deletion
We keep identifiable information only for as long as it is needed for the purposes described in this policy, to maintain security, or to meet legal obligations. In general:
- account information and synced shopping data are kept while your account remains active;
- the current installation identifier and selected-area data are kept with the account while needed for account security and personalisation, and are deleted from the active account record when the account is deleted;
- an Expo push token is kept while associated with an active signed-in notification session and is detached on successful sign-out or account deletion;
- recent searches remain only on your device until you clear them, clear app data or uninstall the app;
- items you delete may remain temporarily in backups until those backups rotate;
- support records may be retained while needed to resolve the request and maintain an appropriate record;
- advertising, performance and crash information is retained according to the advertising provider's controls and policies and may be kept in aggregated or de-identified form.
You can remove individual lists and alerts in the app. To delete your entire account and associated personal data, choose “Delete account” in the app's Account settings or follow the steps on our account deletion page. We aim to complete verified deletion requests within 30 days unless we must retain limited information for legal, security or fraud-prevention reasons.
Advertising data is retained by Google according to its own retention controls and policies. Deleting your GrocerCheck account does not automatically reset a device advertising identifier or delete advertising information held independently by Google. You can manage iOS tracking permission in device settings, manage Android advertising identifiers in Android privacy settings, and manage Google ad-personalisation choices through My Ad Center.
10. Security and privacy breaches
We use reasonable technical and organisational safeguards designed to protect personal information against loss, unauthorised access, misuse or disclosure. No online service can guarantee absolute security. If a privacy breach has caused or is likely to cause serious harm, we will notify affected people and the Office of the Privacy Commissioner as required by New Zealand law.
11. Access, correction and complaints
Under the New Zealand Privacy Act 2020, you can ask us for access to personal information we hold about you or ask us to correct it. You may also ask questions, object to a particular use, or make a privacy complaint. Email kiaora@paulnz.tech with enough information for us to identify your account and request. We may need to verify your identity before acting.
If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner.
12. Children
GrocerCheck is not directed to children under 13, and people under 13 may not create an account. If you believe a child has provided personal information to us, contact us so we can investigate and delete it where appropriate.
13. Changes to this policy
We may update this policy when the Service, our providers or legal requirements change. We will publish the revised policy with a new “last updated” date and, where a change is material, provide an additional notice in the app or by another appropriate channel.