ShopMaps Legal Information
Privacy Policy
ShopMaps can be used locally without creating an account. Data is sent to cloud services only when using features that require an internet connection, such as signing in, groups, sharing lists and deposit vouchers, publishing store maps, and searching for stores near an address.
1. Data Controller
The controller of personal data processed in connection with the ShopMaps app is Dawid Ogły Software.
Dawid Ogły Software, Tax ID (NIP): 6653049635, Business Registry Number (REGON): 522604461, address: ul. Święty Marcin 29/8, 61-806 Poznań, Poland
For privacy-related matters or to exercise your rights, contact: dawidogly@gmail.com.
2. Data We Process
The scope of the data depends on how the app is used.
Data stored locally on the device
- private grocery lists and their items;
- private store maps, categories, and their order;
- local deposit vouchers;
- history, frequently used items, and app settings.
This data remains on the device unless the user chooses to share it. It may be deleted by uninstalling the app, clearing its data, or using the appropriate feature in the app.
Account and sign-in data
- the account identifier and data provided by the selected sign-in provider, such as an email address or name, depending on the account settings;
- the public ShopMaps username and its assigned tag;
- session data required to keep the user signed in;
- the device notification token if the user allows push notifications.
Group data and shared content
- group names, memberships, roles, and invitations;
- shared grocery lists, including list names, items, categories, and quantities;
- shared deposit vouchers, including the code, format, amount, store, scan date, and validity or redemption information.
Publicly shared store maps
- the store name and standardized address;
- geographic coordinates and source location identifiers;
- the layout and order of categories in the store;
- the map creator's name or designation;
- the publication date and the number of times other users added the map.
- the User's private preference identifying creators whose maps the User chose to hide.
Address and store searches
When searching for an address, the app sends the entered query, the selected address or its coordinates, and the query language to a ShopMaps intermediary service that uses Geoapify. After selecting “Find near me,” the device's current location is used only to sort public stores locally and is not sent to or stored by ShopMaps.
Technical data
Infrastructure, authentication, and location search providers may process technical data such as the IP address, device information, timestamps, request logs, session identifiers, and diagnostic data in accordance with their privacy policies.
3. Purposes and Legal Bases
Data may be processed to:
- create and manage an account and provide selected ShopMaps features at the user's request;
- synchronize and share data with other group members;
- publish and download shared store maps;
- search for addresses and nearby stores;
- ensure security, prevent abuse, and diagnose errors;
- comply with legal obligations.
The legal basis is primarily the necessity of processing for the performance of a contract or to take steps at the user's request (Article 6(1)(b) of the GDPR), the controller's legitimate interest in securing and maintaining the service (Article 6(1)(f) of the GDPR), and, where applicable, compliance with a legal obligation (Article 6(1)(c) of the GDPR). If consent is required for a specific activity, it will be obtained separately.
4. Data Visibility and Sharing
- Private local data is not automatically sent to the cloud.
- Content shared within a group is visible to its members and may be updated or deleted by them according to their permissions.
- Public store maps are visible to signed-in ShopMaps users.
- A User's list of hidden map creators is private and is not visible to other Users.
- Data may be disclosed to authorized authorities when required by law.
5. Service Providers
ShopMaps uses the following third-party services:
- Supabase - authentication, database, real-time synchronization, and server-side functions;
- Google and Apple, and Facebook - optional sign-in providers;
- Geoapify - address search and standardization and nearby store searches;
- Firebase Cloud Messaging - delivery of notifications about new items on shared lists;
- app stores and operating system providers - app distribution and technical operation of the device.
Providers may process data outside the European Economic Area. The scope, location, and safeguards of such processing are governed by the relevant provider's terms and privacy policies.
6. Retention Period and Account Deletion
Account and cloud data is retained while the service is in use and is then deleted or anonymized unless continued retention is required by law, for service security, or to establish, exercise, or defend legal claims. Infrastructure providers may retain logs and backups for the periods specified in their own policies.
The user can delete their account from within the app. Account deletion deletes or dissociates account data, memberships, invitations, and published maps, and deletes shared lists and deposit vouchers created by the user. If the user owns a group, ownership may be transferred to another member, and a group without a successor may be deleted.
Deleting the account does not delete private data stored locally on the device. This data can be deleted in the app or by uninstalling the app or clearing its data. Content created by other users is not deleted with the account.
7. User Rights
Subject to the conditions set out in the GDPR, the user may have the right to access, rectify, and erase their data, restrict processing, receive data portability, object to processing, and withdraw consent where processing is based on consent. Withdrawing consent does not affect the lawfulness of processing carried out before its withdrawal.
Requests can be sent to dawidogly@gmail.com. The user also has the right to lodge a complaint with the President of the Personal Data Protection Office in Poland.
8. Security
ShopMaps uses measures designed to restrict access to data, including authentication, database access rules, and encrypted transmission provided by service providers. However, no method of transmitting or storing data can guarantee complete security.
9. Analytics and Advertising
ShopMaps currently does not use advertising or SDKs for user behavior analytics. Infrastructure providers may collect technical data necessary for the operation, security, and diagnostics of their services.
10. Children's Privacy
ShopMaps is not a service specifically directed at children. A person who, under applicable law, cannot independently accept the terms of service should use the service only with the consent and supervision of a parent or guardian.
11. Changes to This Privacy Policy
This policy may be updated due to changes in app features, providers, or applicable law. The current version and the date of the latest update will be published on this page.
12. Contact and Support
Questions about privacy or how the app works, as well as bug reports, can be sent to dawidogly@gmail.com.
Terms of Service
1. General Provisions
- These Terms of Service govern the use of the ShopMaps mobile application, including services provided electronically.
- The service provider is Dawid Ogły Software, Tax ID (NIP): 6653049635, Business Registry Number (REGON): 522604461, address: ul. Święty Marcin 29/8, 61-806 Poznań, Poland, email: dawidogly@gmail.com (“Service Provider”).
- A “User” is any person using the Application.
- Basic features can be used without an account. Creating an account is optional and is required only for the cloud features described in these Terms.
- The Application is currently provided free of charge. Any paid feature will be presented together with its terms and price before a purchase is made.
2. Definitions
- Application means the ShopMaps mobile app.
- Account means the User's individual account used to access cloud features.
- Local Data means data stored only on the User's device, including private shopping lists, store maps, and deposit vouchers.
- Group means a collaboration space created by a User that invited Users may join.
- Shared Data means shopping lists, list items, and deposit vouchers shared with Group members.
- Public Store Map means a publicly shared arrangement of store categories connected to a store name and address.
- User Content means data and information entered, shared, or published by a User through the Application.
3. Scope of Services
-
The Application provides features that include:
- creating and editing local shopping lists;
- creating store maps that define the order of product categories;
- sorting shopping lists according to a selected store map;
- saving and managing deposit vouchers;
- optionally creating an Account and signing in with supported identity providers;
- creating Groups, inviting Users, and sharing data;
- publishing and browsing Public Store Maps;
- adding Public Store Maps to the User's local maps; and
- searching standardized addresses and nearby stores.
- The features and appearance of the Application may change as the Application develops.
- The Service Provider may restrict or discontinue a feature when necessary for security, legal, or technical reasons, or because a third-party service is no longer available.
4. Technical Requirements
- The Application requires a compatible mobile device with a supported operating system and a current or otherwise supported Application version.
- Cloud features require an internet connection.
- The User is responsible for securing their device and Account and for keeping their software up to date.
- Use of the Application may involve data transmission and charges imposed by the User's network provider.
5. Account and Sign-In
- Creating an Account is optional.
- An Account may be created or authenticated with supported third-party identity providers, including Google, Apple, or Facebook.
- The User must provide truthful information where required and protect access to their Account.
- An Account may be created by a person capable of entering into an agreement to use the Application. A minor may require consent from a legal guardian under applicable law.
- The public username is used, among other purposes, to invite Users to Groups. It must not be unlawful, offensive, misleading, or infringe third-party rights.
- The User may sign out or delete the Account at any time using the relevant Application feature.
- Account deletion removes Account-related data as described in the Application, Privacy Policy, and Account Deletion section. Local Data may remain on the device.
- Data created or shared by other Group members is not deleted solely because the User deletes their Account.
6. Local Mode and Local Data
- The Application can be used without an Account in local mode.
- Local Data remains on the User's device and is not automatically synchronized or recovered after uninstalling the Application, losing the device, or clearing Application data.
- The User is responsible for backing up the device if they wish to reduce the risk of losing Local Data.
- The Service Provider does not guarantee recovery of Local Data.
7. Groups and Shared Data
- A User may create a Group or join one after receiving an invitation.
- Shared Data is available to Group members and may be modified or deleted by them according to the Application's features.
- Changes to Shared Data may be synchronized in near real time across Group members' devices.
- Sharing a local shopping list may move it to the Group and remove the private copy from the device.
- Stopping sharing may remove data from the Group and restore it as private data on the User's device, according to the current behavior of the Application.
- Users should share deposit vouchers only with people they trust. The Service Provider is not responsible for use of a voucher by a Group member or for consequences of sharing it with the wrong person.
8. Public Store Maps
- A signed-in User may publish a store map together with the store name and address.
- A Public Store Map may be viewed and added to local maps by other signed-in Users.
- The Application may display the creator's initial, the map layout, store address, and download count.
- The creator may update or stop sharing a Public Store Map. Removing the public version does not necessarily remove copies previously added locally by other Users.
- Users may report a Public Store Map and may hide maps published by a selected creator.
- The User confirms that a published map is accurate to the best of their knowledge and does not violate law or third-party rights.
- The Service Provider does not guarantee the accuracy, completeness, or timeliness of Public Store Maps, store names, addresses, or category order.
9. Third-Party Providers
-
Cloud features use third-party providers, including:
- Supabase for authentication, storage, synchronization, and server-side functions;
- Google, Apple, and Facebook as optional sign-in providers;
- Geoapify for address search, standardization, and nearby store search; and
- Firebase Cloud Messaging for push notifications.
- Some features may depend on the availability of third-party services.
- The Privacy Policy explains how third-party providers process data.
10. Rules for Using the Application
- Users must use the Application in accordance with law, these Terms, generally accepted standards of conduct, and the intended purpose of the Application.
-
In particular, Users must not:
- provide unlawful or offensive content or content that infringes third-party rights;
- impersonate another person or entity;
- publish deliberately false or misleading information;
- attempt to gain unauthorized access to Accounts, data, infrastructure, or Application code;
- disrupt the Application, send automated requests at scale, or bypass security measures; or
- use the Application for unlawful activity.
- The User is responsible for their User Content and the consequences of sharing it.
- Violations may be reported to dawidogly@gmail.com or by using “Report map” next to a Public Store Map.
11. Moderation and Access Restrictions
-
The Service Provider may remove or restrict access to User Content
if it:
- violates law, these Terms, or third-party rights;
- threatens the security of the Application or its Users; or
- is subject to a credible report or a request from a competent authority.
- For a material or repeated violation, the Service Provider may temporarily restrict cloud features or delete the Account where permitted by law.
- Where circumstances permit, the User will be informed of the reason for the action.
12. Intellectual Property
- Rights to the Application, its name, interface, code, and materials belong to the Service Provider or the relevant rights holders.
- The User receives a non-exclusive, revocable, and non-transferable license to use the Application for its intended purpose and in accordance with these Terms.
- The User retains rights to their User Content.
- By publishing or sharing User Content, the User grants the Service Provider a non-exclusive, royalty-free license to store, display, synchronize, and share it to the extent required by the feature selected by the User.
- This license expires when the data is deleted, except where further retention is required by law or justified to establish, exercise, or defend legal claims.
13. Liability and Availability
- The Service Provider uses reasonable care to keep the Application operating correctly and securely but does not guarantee uninterrupted availability of every feature.
- The Application is an assistive tool. Users should verify deposit vouchers, addresses, store names, and maps before relying on them.
-
To the extent permitted by law, the Service Provider is not liable
for:
- loss of Local Data;
- actions of other Users or Group members;
- inaccurate, outdated, or incomplete User Content; or
- interruptions or errors caused by a device, network, or third-party service.
- Nothing in these Terms limits consumer rights or liability that cannot be excluded under applicable law.
14. Privacy and Personal Data
- The ShopMaps Privacy Policy explains the processing of personal data and use of third-party providers.
- It includes information about the controller, purposes and legal bases, recipients, retention periods, and User rights.
- Acceptance of these Terms does not automatically constitute consent to activities that require separate consent under applicable law.
15. Complaints and Contact
- Complaints about the Application or services may be submitted to dawidogly@gmail.com.
- A report should include enough information to identify the issue, such as a description, Application version, and operating system. Passwords, sign-in tokens, and sensitive voucher codes must not be included.
- The Service Provider will respond without undue delay and no later than 14 days after receiving the complaint.
- The response will be sent to the address used to submit the complaint, unless another contact method is requested.
16. Entering Into and Terminating the Agreement
- The agreement for local mode is entered into when the User starts using the Application.
- The agreement for cloud features is entered into when the User accepts these Terms and creates an Account.
- The User may stop using the Application at any time.
- The agreement for cloud features is terminated by deleting the Account.
- Uninstalling the Application does not delete or terminate the Account.
17. Changes to These Terms
- The Service Provider may change these Terms for valid reasons, including changes in law, Application features, security requirements, technology, or third-party platform rules.
- A User with an Account will be informed about material changes in the Application or through an available contact channel before they take effect.
- If renewed acceptance is required, access to relevant cloud features may depend on accepting the updated Terms.
- Changes do not affect acquired rights or mandatory provisions of applicable law.
18. Final Provisions
- These Terms are governed by Polish law, without prejudice to mandatory consumer rights under the law applicable in the consumer's place of residence.
- A consumer may use available out-of-court complaint and redress procedures under applicable law.
- If any provision is invalid or unenforceable, the remaining provisions remain in effect.
- The current version of these Terms is available at this page's Terms of Service section.
Account Deletion
Delete Your Account in the Application
You can delete your Account directly in ShopMaps. Open Account / Groups, scroll to the bottom of the screen, select Delete account, and confirm the action.
What Will Be Deleted
Deleting the Account removes or dissociates:
- the ShopMaps profile and Account identifiers;
- Group memberships, roles, and pending invitations;
- Public Store Maps published by the User;
- shared lists and deposit vouchers created by the User, subject to the ownership and Group rules described in the Application; and
- notification devices registered to the Account.
If the User owns a Group, ownership may be transferred to another member. A Group without an eligible successor may be deleted. Content created by other Users is not deleted with the Account.
Data Remaining on the Device
Deleting the Account does not delete private Local Data stored on the device. Local shopping lists, store maps, deposit vouchers, history, and settings remain until they are deleted in the Application or the Application is uninstalled or its data is cleared.
If You Cannot Access the Application
Send an account deletion request from the email address associated with the Account to dawidogly@gmail.com. Include enough information to identify the Account. Do not send passwords, access tokens, or deposit voucher codes.
Retention After a Deletion Request
Account and cloud data will be deleted or anonymized unless continued retention is required by law, for service security, or to establish, exercise, or defend legal claims. Infrastructure providers may retain logs and backups for the periods stated in their own policies.