Effective May 3, 2026
Overview
ShopBuddy (the "app", "we", "us") is a personal shopping list utility for couples and families. This policy describes the limited data we collect, how we use it, and how you can remove it. We collect only what we need to make shared lists work; we do not sell or rent any of it.
Data we collect
- Account data from Google Sign-In: your email address, display name, and profile picture URL. We use these to identify you, populate your profile, and let family members find you to send invites.
- Content you create: shopping lists, items, family names, and invitations you send or accept. This is the data the app exists to manage.
- Preferences: selected language and avatar color.
- Authentication metadata: session cookies and access tokens issued by our auth provider so you stay signed in.
We do not collect contacts, location, photos, voice, browsing history, or any information beyond what is listed above.
How we use it
- To authenticate you and keep your session active.
- To show family members your name and avatar so they can recognize you.
- To sync your lists between your devices and your family members in real time.
- To respond to your support requests if you contact us.
Where it is stored
App data is stored in a Supabase project (Postgres database hosted on AWS, Singapore region). Authentication is handled by Supabase Auth. The app itself runs on Railway. Each provider applies its own infrastructure-level security (encryption in transit and at rest, access controls). Row-Level Security policies on the database ensure that you can only read or modify rows that belong to you or to a family you are a member of.
Sharing
We do not sell or rent personal data. We do not share data with third parties for marketing. Data is shared only with:
- Family members you have added or accepted into a family group, who see your name, avatar, and lists you marked as Family.
- The infrastructure providers above (Supabase, Railway, Google for sign-in), strictly as processors for the purpose of running the service.
- Authorities, only if compelled by valid legal process.
Your choices and rights
- You can sign out at any time from Settings.
- You can edit your display name and avatar from your Profile.
- You can leave a family or remove yourself from one at any time.
- To delete your account and all associated data, email huyhoang2809@gmail.com and we will erase your row, your owned families and lists, within 7 days.
Cookies and local storage
We use cookies for authentication only (no advertising or analytics cookies). We use IndexedDB on your device to queue offline edits so they sync when you reconnect; this data lives on your device and is not transmitted except to re-apply your own changes.
Children
ShopBuddy is not directed at children under 13 and we do not knowingly collect data from them.
Changes
If we change this policy meaningfully we will update the effective date at the top and, where appropriate, notify you in-app.
Contact
Questions or requests: huyhoang2809@gmail.com.