Privacy Policy
Effective date: [to be inserted upon publication]
This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use SmartPantry (the "Service"), and describes the rights available to you under the EU General Data Protection Regulation ("GDPR") and applicable Polish data protection law.
Data controller: Mateusz Rogalski, a sole trader conducting business under the trade name "mrogal.ski" (Polish: jednoosobowa działalność gospodarcza), entered in the Central Register and Information on Economic Activity of the Republic of Poland (CEIDG), NIP [NIP], REGON [REGON], principal place of business at [registered address], Poland ("SmartPantry", "we", "us"). Contact regarding this Policy: [privacy contact email]. Data Protection Officer (if appointed): [DPO name and email].
1. Introduction
This Privacy Policy applies to all users of SmartPantry's website and applications, including the recipe, pantry, meal planning, community, health and nutrition, and subscription features (together, the "Service").
By creating an account or otherwise using the Service, you acknowledge that you have read and understood this Policy. Where we rely on your consent for a specific processing activity — most notably health data, described in Section 5 — we will always ask for that consent separately and explicitly, and using the Service generally does not itself constitute consent to that processing.
2. Scope
This Policy covers personal data processed by SmartPantry as data controller. It does not cover the practices of third-party websites or services you may reach through links in the Service, including recipes or content posted by other users, which are governed by their own terms and policies.
This Policy should be read together with our Terms of Service and Service Agreement, which govern your use of the Service more broadly.
3. What Personal Data We Collect
Account data: email address, password (stored as a salted hash, never in plain text), display name, and account preferences such as language and allergen settings.
Profile and content data: recipes, images, pantry contents, shopping lists, meal plans, and any other content you create, upload, or import, together with metadata such as visibility settings and sharing grants.
Health and nutrition data: metrics you choose to log, such as weight, blood pressure, blood sugar, cholesterol, height, and body fat, and nutrition data derived from meals you log or prepare. This is "special category" data under Article 9 GDPR and is subject to the additional protections in Section 5.
Social data: your follows/followers, and notifications generated by activity from accounts you follow.
Billing data: your selected subscription plan, billing cycle, and transaction history. Full payment card details are collected and processed directly by our payment processor (Stripe); we do not store your full card number on our servers.
Technical and usage data: IP address, device and browser information, log data, timestamps, and diagnostic information generated when you use the Service, collected automatically for security and reliability purposes.
Communications: messages you send us, such as support requests, and our replies.
4. Legal Bases for Processing
We process your personal data on the following legal bases under Article 6(1) GDPR: performance of a contract (to create your account and provide the features you use, such as recipe, pantry, and planner functionality); your consent (for health data and optional marketing communications, each of which you can withdraw at any time); our legitimate interests (to secure the Service, prevent abuse, and improve reliability, balanced against your rights); and legal obligation (for example, retaining billing records for tax and accounting purposes).
Where we rely on consent, withdrawing it will not affect the lawfulness of processing carried out before withdrawal, but may mean certain features (such as health dashboards) become unavailable to you.
5. Special Category Data — Health Information
SmartPantry allows you to optionally log health metrics (weight, blood pressure, blood sugar, cholesterol, height, body fat) and view nutrition information derived from meals you prepare. This qualifies as "special category" personal data concerning health under Article 9(1) GDPR.
We only collect and process this data where you have given explicit, informed, opt-in consent (Article 9(2)(a) GDPR), obtained separately from your general Terms of Service acceptance during onboarding or when you first use a health-tracking feature. Providing health data is entirely optional and is never required to use the core recipe, pantry, or planner features of the Service.
Health data is used solely to power the dashboards and features you explicitly enable (such as displaying your logged metrics and macro/nutrition summaries) and is not used for advertising, sold, or disclosed to third parties for their own purposes. It is not shared with other users unless you explicitly choose to share content that contains it (for example, a meal plan you mark as shared).
You may withdraw your health data consent, and delete previously logged health data, at any time from Account Settings. Withdrawing consent stops future collection but does not automatically retroactively delete already-logged entries unless you separately request their deletion, which we will action promptly.
6. How We Use Your Data
We use personal data to: provide, operate, and maintain the Service and its features (recipes, pantry inventory, shopping lists, meal planning, community follows, notifications, and health/nutrition tracking); process subscription payments and manage your billing relationship; authenticate you and enforce the sharing and visibility permissions you configure for your content; communicate with you about your account, security notices, and — only with your consent — product updates or marketing; detect, investigate, and prevent fraud, abuse, and security incidents; and comply with our legal obligations.
7. Sharing With Third Parties
We do not sell your personal data. We share personal data only with:
(a) Other users, to the extent you configure a resource (recipe, pantry, meal plan) as Public or Protected-and-shared, or when another user views content you've made visible to them under our authorization model;
(b) Service providers acting as our data processors under written agreements, including our payment processor (Stripe, for subscription billing), hosting and infrastructure providers, and transactional email providers (for account confirmation, password reset, and notification emails) — each is contractually restricted to processing data only as instructed by us and only to provide their service to us;
(c) Authorities, where required by law, court order, or to protect the rights, property, or safety of SmartPantry, our users, or the public; and
(d) A successor entity, in the event of a sale, transfer, or incorporation of the business, subject to this Policy continuing to apply to your data or you being notified of any material change.
8. International Data Transfers
We aim to host and process personal data within the European Economic Area (EEA) wherever possible. Where a service provider processes data outside the EEA (for example, aspects of payment processing), we rely on adequacy decisions or Standard Contractual Clauses approved by the European Commission, together with appropriate technical and organizational safeguards, to ensure your data remains protected to GDPR standards.
9. Data Retention
We retain personal data for as long as your account is active and as necessary to provide the Service. If you delete your account, your account record and personal data are erased immediately and permanently from our production systems — this is an irreversible, hard deletion, not a soft-delete or deactivation.
Certain data may be retained beyond account deletion only where required by law (for example, billing and invoicing records for tax purposes, which we retain for the statutory period under Polish law), or where already contained in encrypted backups that age out and are overwritten on a routine cycle, rather than being individually purged.
10. Your Rights Under GDPR
Subject to the conditions and exceptions set out in GDPR, you have the right to: access the personal data we hold about you; rectify inaccurate or incomplete data; erase your data ("right to be forgotten") — available directly in Account Settings via instant account deletion; restrict or object to certain processing; receive a portable copy of your data in a structured, machine-readable format — available directly in Account Settings via our data export tool; and withdraw consent at any time where processing is based on consent, without affecting prior lawful processing.
To exercise any of these rights, use the relevant in-app tool where available, or contact us using the details in Section 15. We will respond within one month, as required by Article 12(3) GDPR, extendable by a further two months for complex requests.
You also have the right to lodge a complaint with a supervisory authority. In Poland, this is the Prezes Urzędu Ochrony Danych Osobowych (President of the Personal Data Protection Office, "UODO"), ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl — or with the supervisory authority of your own EU member state of residence.
11. Automated Decision-Making
We do not use your personal data for automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR. Features such as nutrition summaries and threshold-based shopping list suggestions are informational calculations based on data you provide, not automated decisions made about you.
12. Cookies and Similar Technologies
We use strictly necessary cookies and similar local storage to keep you signed in and to remember essential preferences such as language and theme. These are required for the Service to function and are not used for cross-site advertising tracking. If we introduce analytics or marketing cookies in the future, we will update this Policy and request consent where required by law.
13. Children's Privacy
The Service is available to individuals aged 13 and older. Users between 13 and 16 years old may only create an account and use the Service with the consent of a parent or legal guardian, consistent with Article 8 GDPR. We do not knowingly collect personal data from children under 13. If we become aware that we have collected personal data from a child under 13 without appropriate consent, we will delete it promptly. A parent or guardian who believes their child has provided us with personal data without consent may contact us to request deletion.
14. Data Security
We apply technical and organizational measures designed to protect your data, including encryption of data in transit, hashed password storage, and a fine-grained, relationship-based authorization model that governs exactly who can view, edit, or manage each recipe, pantry, and meal plan you create or that is shared with you.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential and for using a strong, unique password.
15. Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by Article 33 GDPR. Where the breach is likely to result in a high risk to you, we will also notify you directly without undue delay, as required by Article 34 GDPR.
16. Contact Us
For questions about this Privacy Policy or to exercise your data protection rights, contact us at [privacy contact email] or by post at [registered address]. If we have appointed a Data Protection Officer, you may also contact them directly at [DPO email].
17. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes to the Service or applicable law. If we make material changes, we will notify you by email or an in-app notice before the changes take effect. The "Last updated" date below indicates when this Policy was last revised. Continued use of the Service after changes take effect constitutes acceptance of the revised Policy, to the extent permitted by law; where consent is legally required for a change (for example, an expanded use of health data), we will obtain your consent separately.
Draft prepared: September 15, 2026 — pending legal review prior to publication.