Privacy Policy
In short
- We do not sell your data. Not to anyone, not ever.
- There are no ads. We do not track you across other apps or websites.
- You confirm your area yourself. We do not run continuous GPS tracking.
- Allergens are asked for only with your separate consent, and you can withdraw it at any time.
- Your loyalty cards stay on your own phone. The card number goes nowhere else by default.
- The app is free for the user. There is no mandatory subscription.
- You can delete your account with one tap in the app or here on the web, without installing anything.
- Questions: privacy@bitesmart.eu, we answer within 30 days.
This is a summary. The full text below is the one that applies. If the summary and the full text ever differ, the full text prevails.
1. Who is responsible for your data
BSMP Platforms OÜ, company registry code 17537218
Laki 6, Kristiine district, 10621 Tallinn, Estonia
Privacy contact: privacy@bitesmart.eu
This policy covers the BiteSmart mobile application and the website bitesmart.eu.
2. What we collect, why, and for how long
| Data type | Examples | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Account data | Email address, name or nickname, chosen region | Creating and securing your account, notifications | Performance of contract, GDPR Art. 6(1)(b) | Until you delete your account |
| Food profile | Allergens, intolerances, excluded ingredients, favourites, calorie goal | Filtering recipes and personalised suggestions | Your explicit consent, GDPR Art. 6(1)(a) and Art. 9(2)(a) | Until account deletion or consent withdrawal |
| Cart and usage events | Items added, chosen store, category, timestamp, region | Price comparison, shopping list, product improvement | Contract and legitimate interest, GDPR Art. 6(1)(b) and 6(1)(f) | 24 months in identifiable form, then anonymised |
| Technical and diagnostic data | Device type, OS and app version, crash reports, approximate region from IP | Security, debugging, compatibility | Legitimate interest, GDPR Art. 6(1)(f) | 12 months |
| Consent log | What you agreed to and when, policy version number | Demonstrating lawful processing | Legal obligation, GDPR Art. 6(1)(c) | 3 years after consent ends |
| Support correspondence | Your message and our reply | Answering your question | Legitimate interest, GDPR Art. 6(1)(f) | 2 years |
| Website pre-registration | Email address, chosen language, country from IP address | So we can send one notice when the app goes live | Your consent, GDPR Art. 6(1)(a) | Until the notice is sent or you unsubscribe, at most 12 months after launch |
Allergies and intolerances are special category health data. The rules for them are in the separate box at the top of this page.
3. Loyalty cards in the app
The app can hold your shop loyalty cards so you can show them from your phone at the till. Separate rules apply to them.
| What we keep | Where | Why |
|---|---|---|
| Chain name, card number, barcode format, the label you gave it | On your phone, in the device secure store (iOS Keychain, Android Keystore) | So you can show the card at the till and so the comparison can use card prices |
| The same, encrypted | On our server, only if you switch on backup yourself | So your cards survive a new phone. Off by default. |
Legal basis: performance of a contract, GDPR Article 6(1)(b). Retention: until you delete the card or the account.
A loyalty card number is not a payment card number. It is a loyalty account identifier. We never ask for or hold payment details.
Our rules, written into the code:
- The card number is never written to any log, crash report or analytics.
- Our support sees only the last four digits, never the whole card.
- Card data is passed to nobody: not to shops, not to chains, not to ad networks.
- We never ask for or hold your shop account passwords. We do not log into a shop system on your behalf.
- Deleting your account deletes the cards immediately, from the phone and from the backup.
When the cashier scans the card from your screen, the points accrue in the shop's system as usual. We neither see nor touch that. We do not display the points balance.
4. What we will never do
- We never sell or rent personal data.
- We never share data with data brokers.
- We use no advertising networks, tracking pixels or third party advertising SDKs.
- We do not track you across other companies' apps and websites. In Apple's terms, we do no tracking.
- We do not collect precise GPS location. We use only the region you select yourself.
- We never see or store your bank card details. Any future paid features are processed by Apple App Store or Google Play.
- We make no automated decisions that produce legal or similarly significant effects for you.
5. Use of artificial intelligence
BiteSmart uses AI to tag recipes, interpret search queries and generate suggestions. Our rules:
- Requests sent to the AI provider contain no name, email address or account identifier.
- Our requests are not used to train AI models. This is contractually excluded.
- AI suggestions are helpful guidance, not medical or nutritional advice. If you have an allergy, always check the actual product packaging. Manufacturers change recipes and databases can be out of date.
- Displayed prices are indicative. The final price is the one at the store checkout.
6. Who we share data with
We use carefully selected providers who process data only on our instructions under a data processing agreement (GDPR Art. 28).
| Provider | Role | Data location | Safeguard |
|---|---|---|---|
| Google Firebase (Google Ireland Limited) | Database, authentication, crash reporting | European Union | Data processing agreement, EU Standard Contractual Clauses where needed |
| OpenAI Ireland Limited | Recipe tagging and search processing | EU and USA | DPA, SCC, requests contain no personal data, training excluded |
| Open Food Facts | Public product database | European Union | Queries contain no personal data |
| Apple and Google | App distribution, crash reports, possible future purchases | EU and USA | Their own privacy terms |
| Microsoft Ireland Operations Limited | Storing the pre-registration list (Microsoft 365) | European Union | Data processing agreement, EU Data Boundary |
| Vercel Inc. | Website hosting | EU servers, company in the USA | Data processing agreement, EU Standard Contractual Clauses (SCC) |
Beyond this list we disclose data only where the law requires it, for example a lawful request from a court or investigative authority. We will notify you unless the law prohibits it.
7. Where your data is stored
Your data is stored in the European Union. Where a provider must process data outside the European Economic Area, it happens under the European Commission's Standard Contractual Clauses or a valid adequacy decision.
8. Security
- Data is encrypted in transit (TLS 1.3) and at rest.
- Access to personal data is named and strictly need to know, protected by two factor authentication.
- Access to personal data is logged.
- Account data and usage events are stored separately, so deleting an account leaves no trace.
- In the event of a breach we notify the Estonian Data Protection Inspectorate within 72 hours and you without undue delay where the risk to your rights is high.
9. Your rights
At any time you have the right to:
- Access the data we hold about you and receive a copy.
- Correct inaccurate or incomplete data.
- Erase your data, the right to be forgotten.
- Restrict or object to processing.
- Port your data in a machine readable format.
- Withdraw consent at any time, without affecting the lawfulness of earlier processing.
- Lodge a complaint with the Estonian Data Protection Inspectorate: aki.ee, info@aki.ee, +372 627 4135.
Write to privacy@bitesmart.eu. We reply within 30 days, free of charge.
10. Deleting your account and data
You can delete your account in three ways:
- In the app: Profile, then Settings, then Delete account.
- On the web: bitesmart.eu/konto-kustutamine, no installation needed.
- By email: privacy@bitesmart.eu.
Deleted within 30 days: account, email address, name, food profile, carts, shopping lists and all usage events linked to you.
Retained: accounting records where the law requires them.
Delete your account11. Cookies on the website
By default bitesmart.eu uses only strictly necessary cookies that keep the site working. Analytics cookies are set only with your consent, which you can withdraw at any time. We use no advertising cookies and no third party trackers.
12. Children
BiteSmart is intended for users aged 16 and over. We do not knowingly collect personal data from anyone under 16. If we learn that an account belongs to a younger user, we delete the account and its data without delay.
13. Changes to this policy
If we make a significant change, we notify you in the app and by email at least 14 days before it takes effect. Where the change affects processing that requires consent, we ask for consent again. Every version carries a number and a date.
14. Contact
BSMP Platforms OÜ, Laki 6, 10621 Tallinn, Estonia
Privacy: privacy@bitesmart.eu
General: hello@bitesmart.eu