SafeCart · GPSR Hub

Privacy Policy

Your privacy matters to us. Learn how we collect, use, and protect your personal information.

Last updated: July 2026
GDPR Compliant

Data Encryption

All data encrypted in transit and at rest

Transparency

Clear information about data collection and use

User Control

Full control over your personal data and privacy settings

Your Privacy Rights

Under GDPR, you have extensive rights over your personal data. You can access, correct, delete, or transfer your data at any time. Contact our privacy team at [email protected] to exercise your rights.

1. Introduction

SafeCart ("we," "our," or "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, process, and protect your information when you use our services, including our website, Chrome extension, and business dashboard. This policy complies with the General Data Protection Regulation (GDPR) and other applicable privacy laws.

2. Information We Collect

We collect several types of information: Personal Information: • Name and email address (when you create an account) • Company information (for business users) • Contact preferences and communication history Payment Information: • Subscription and billing details for paid plans, processed securely by our payment provider (Stripe). We do not store full payment card numbers. Store Connection Data (for business users): • When you connect an online store (for example, via our WooCommerce plugin), we process your store URL and the credentials or access tokens needed to sync products, together with the product data that is synced. Store Scan Data (free store scanner): • When you use our free store scanner (/scan) — which requires no login or store connection — we read and store publicly available product information from the store you submit: the store's web address (host), product names, product page URLs, and product identifiers such as GTINs/barcodes, along with scan-outcome metadata (for example, whether a potential recall match was found). The scan itself collects no personal data about you; your IP address is stored only as a salted hash used to rate-limit scans and prevent abuse. Chrome Extension Data: • The Chrome Web Store currently serves legacy version 2.1.4 while the maintained v3 replacement is being built. Version 2.1.4 can automatically read product identifiers and relevant ingredient text on shopping pages to provide product, ingredient, and personal-safety notices; detected product identifiers can be sent to the SafeCart safety service. • Version 2.1.4 can store selected personal-safety preferences through Chrome sync and local event counts in webpage browser storage. These values are not used for advertising or cross-site profiling. • A manual safety check sends the product name or barcode you enter. • The maintained v3 candidate keeps recall results and its limited EU cosmetics rule visibly separate. Ingredient guidance is regulatory information, not proof that a product is safe or legally compliant. Pregnancy guidance is not included in v3. • A page check temporarily reads Schema.org product data, explicit GTIN metadata, and bounded product and ingredient elements in the active tab. Ingredient text is evaluated locally and not stored or sent. Only up to 10 detected product names and valid GTINs are sent to the recall service; the URL, full page text, ingredients, variants, prices, and quantities are not. • A cart check temporarily reads structured identity and bounded cart-item and ingredient elements. Ingredient text is evaluated locally and not stored or sent. Only up to 20 detected product names and valid GTINs are sent to the recall service; the page URL, full page text, ingredients, variants, prices, quantities, cookies, payment details, and unrelated form entries are not. • Manual checks occur only after you press the corresponding check button. The maintained v3.1 candidate requests access to ordinary http and https pages at install or update so automatic alerts can work without a permission click on every shopping site. Automatic product evidence remains inactive until you complete a prominent one-time global consent in the popup, and you can turn it off or on globally afterward. • After global consent, automatic checks read only GTIN properties on bounded structured Product data and explicitly labelled GTIN, barcode, EAN, or UPC elements. They send at most 10 valid GTINs per page load and show a page alert only for an API-confirmed exact GTIN match. Missing GTINs, no matches, possible name matches, service failures, and ingredient guidance remain silent in automatic mode. Product names, ingredient text, page URLs, origins, variants, prices, quantities, form entries, and scan history are not included in the automatic application payload. • Maintained v3 can store one preferences object through Chrome sync: whether EU cosmetics checks are enabled, schema version 2, and the fixed EU regulatory region. It contains no health information, products, ingredients, URLs, or scan history. On first access, v3 removes the old development preference field for pregnancy guidance and deletes the legacy preference key. Chrome may sync the EU cosmetics display choice across your signed-in browsers; the extension provides a reset control. • Maintained v3.1 stores the automatic-alert schema version and only two booleans—whether global consent was granted and whether alerts are enabled—in local extension storage, not Chrome sync. It stores no enabled-site list, page paths, products, ingredients, timestamps, or results and does not send this setting to SafeCart. The old development-era per-site origin list is deleted and does not become global consent. • Maintained v3 sends checks to SafeCart's first-party API at safecart.eu, hosted by Cloudflare. The API accesses our EU-hosted Supabase safety database server-to-server; the extension contains no database credential and does not read the database directly. • Requests also include network metadata supplied by your browser, including IP address. For abuse protection, a one-way hash of the connecting IP is kept in Cloudflare rate-limit storage for about 65 seconds; the raw IP is not stored there. Technical Information: • Usage patterns and feature interactions for our website and business services; the current Chrome extension baseline does not send measurement events • Device, browser, and log data, including IP address, collected for security and troubleshooting • Diagnostic and error data captured by our monitoring tools to keep the service reliable Product Data: • Product searches and safety checks • Barcode scans and product identifiers • Safety alert preferences • Business product catalogs (for business users)

3. How We Use Your Information

We use your information to: Provide Services: • Deliver product safety alerts and notifications • Maintain and improve our Chrome extension • Process shopper-initiated product, page, and cart checks against EU Safety Gate records • Provide business dashboard functionality • Process your account registration and authentication • Store and reuse free store-scan results to avoid re-crawling stores unnecessarily, speed up repeat scans, and power recall alerts for the products we scanned Communication: • Send important service updates and security notices • Respond to your support requests and inquiries • Share relevant product safety information • Send marketing communications (with your consent) Legal and Security: • Comply with legal obligations and regulations • Protect against fraud and security threats • Enforce our Terms of Use • Resolve disputes and legal claims

4. Legal Basis for Processing (GDPR)

Under GDPR, we process your personal data based on: • Consent: When you explicitly agree to processing (e.g., marketing emails) • Contract: To fulfill our services and Terms of Use • Legitimate Interest: To improve our services and prevent fraud • Legal Obligation: To comply with applicable laws and regulations You have the right to withdraw consent at any time where we rely on consent as the legal basis.

5. Data Sharing and Disclosure

We may share your information with: Service Providers (Subprocessors): We rely on a small number of trusted providers who process data on our behalf under data processing agreements: • Supabase — database, authentication, and hosting infrastructure (EU region) • Stripe — payment and subscription processing • Sentry — application error and performance monitoring • Google (Generative AI / Gemini) — AI-assisted compliance analysis features • Cloudflare — web application hosting and content delivery • Our email provider — delivery of transactional and notification emails A current list of subprocessors is maintained in our Data Processing Agreement (DPA at /dpa). Business customers can request a signed DPA at [email protected]. Automated and AI Processing: Some optional features use AI services to analyse product information and generate compliance insights. We send only the data needed for the feature, and your data is not used to train third-party models. Legal Requirements: • Government authorities when required by law • Law enforcement for legitimate investigations • Legal proceedings and regulatory compliance Business Transfers: • In case of merger, acquisition, or sale of assets • With your consent or as permitted by law We never sell your personal data to third parties for marketing purposes.

6. Data Security

We implement robust security measures to protect your data: Technical Safeguards: • Encryption in transit and at rest • Secure authentication and access controls • Regular security audits and monitoring • Vulnerability assessments and penetration testing Organizational Measures: • Employee training on data protection • Access controls and need-to-know basis • Incident response procedures • Regular policy reviews and updates Despite our efforts, no system is 100% secure. We encourage users to use strong passwords and keep their accounts secure.

7. Data Retention

We retain your data for different periods based on: Account Data: • Active accounts: Until account deletion or service termination • Inactive accounts: Up to 3 years, then anonymized or deleted Usage Data: • Analytics data: Up to 2 years for service improvement • Log files: Up to 1 year for security and troubleshooting Scan Data: • Free store-scan results (scan outcomes and the product evidence read from public pages) are automatically deleted 60 days after the scan • Chrome extension product identifiers are processed transiently and are not written as application-level search or scan history • A one-way hash used to rate-limit Chrome extension requests expires after about 65 seconds • Chrome extension request metadata may appear in security and troubleshooting logs retained for up to 1 year • In maintained v3, the safecartSafetyPreferencesV2 Chrome-sync value contains only the EU cosmetics display choice, schema version, and fixed EU region. It remains until you reset or change it, clear extension data, or uninstall. SafeCart does not receive this value. On first preference access, the extension removes the old pregnancy-guidance field and deletes the legacy safecartSafetyPreferencesV1 key. • In maintained v3.1, the local safecartAutomaticScanningV2 value contains schema version 2 and only the consentGranted and enabled booleans. It remains until you change the global setting, clear extension data, or uninstall. SafeCart does not receive this value. The legacy safecartSiteScanningV1 origin list is deleted and is not treated as global consent. • In published extension version 2.1.4, synced personal-safety preferences remain until changed or cleared through the extension/browser, and local event counts remain until the applicable website data is cleared or the browser evicts it Legal Requirements: • Some data may be retained longer to comply with legal obligations • Anonymized data may be retained indefinitely for research purposes

8. Your Rights (GDPR)

Under GDPR, you have the following rights: • Right of Access: Request copies of your personal data • Right to Rectification: Correct inaccurate or incomplete data • Right to Erasure: Request deletion of your personal data • Right to Restrict Processing: Limit how we use your data • Right to Data Portability: Receive your data in a portable format • Right to Object: Object to processing based on legitimate interests • Rights Related to Automated Decision-Making: Protection against automated profiling To exercise these rights, contact us at [email protected]

9. International Data Transfers

SafeCart operates primarily within the European Union. When we transfer data outside the EU: • We ensure adequate protection through approved mechanisms • We use Standard Contractual Clauses (SCCs) where appropriate • We conduct transfer impact assessments • We implement additional safeguards as necessary Our primary data processing occurs within EU/EEA countries.

10. Cookies and Essential Technologies

We use cookies and similar technologies only for essential website functionality: Essential Cookies (No Consent Required): • User authentication and session management • Security and fraud prevention (CSRF protection) • Basic website functionality and navigation • Remembering your login status We do not currently use: • Analytics or tracking cookies • Marketing or advertising cookies • Third-party tracking technologies • Social media tracking pixels If we add non-essential cookies in the future, we will update this policy and request your consent where required by law. You can control cookies through your browser settings, but disabling essential cookies may prevent the website from functioning properly. For full details about the cookies and browser storage we use, please see our Cookie Policy (/cookies).

11. Chrome Extension Storage and Limited Use

The Chrome Web Store currently serves legacy version 2.1.4 while we rebuild the maintained v3 release. Version 2.1.4 can store selected personal-safety preferences in Chrome sync and local event counts in webpage browser storage. Users can change available preference controls and can clear the applicable extension or website data through Chrome; contact [email protected] if you need help. Maintained v3.1 does not store search history, scan history, product identifiers, ingredient text, analytics events, results, health information, or enabled-site origins in local storage, page storage, or Chrome sync. It stores one EU cosmetics display choice in Chrome sync and the global automatic-alert consent and enabled booleans in local extension storage as described above. Pregnancy guidance is not included. Closing the popup clears its in-memory results. Broad ordinary-site access is declared at install or update, but automatic product evidence is not read until the one-time prominent global consent; the popup then provides a global off/on control. Any future measurement or broader behavior requires an updated policy, disclosure, and Chrome Web Store privacy review. SafeCart's use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. We use extension data only to provide or improve the disclosed product-safety purpose. We do not use or transfer it for personalized advertising, data brokerage, lending, or creditworthiness. We do not permit humans to read extension data except with specific user consent, where necessary for security, to comply with law, or for properly aggregated and anonymized internal operations.

12. Children's Privacy

SafeCart is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If we discover that we have collected information from a child under 16, we will delete it immediately. Parents who believe their child has provided information to us should contact [email protected]

13. Changes to This Policy

We may update this Privacy Policy periodically to reflect: • Changes in our services or business practices • New legal requirements or regulations • Improvements in our privacy practices • User feedback and concerns We will notify you of material changes by: • Email notification to registered users • Prominent notice on our website • In-app notifications where appropriate The updated policy will be effective 30 days after notification.

14. Contact Information

For privacy-related questions or requests, contact us at: Data Protection Officer: [email protected] Postal Address: SafeCart Privacy Team, Brussels, Belgium Response Time: We aim to respond to all privacy requests within 30 days. If you're not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.

Privacy Questions or Concerns?

Our Data Protection Officer is here to help with any privacy-related inquiries