Privacy Policy
Last updated: November 30, 2025
1. Introduction
PantryLink ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our web application and browser extension (collectively, the "Service").
Please read this privacy policy carefully. By using the Service, you consent to the data practices described in this policy.
2. Information We Collect
2.1 Information You Provide
We collect information that you voluntarily provide to us, including:
- Account Information: Name, email address, and password when you create an account
- Profile Information: Optional profile details you choose to add
- Inventory Data: Items you add to your pantry, including product names, quantities, barcodes, and images
- Shopping Lists: Lists you create and items on those lists
- Recipes: Recipes you save, including ingredients and instructions
- Payment Information: Billing details processed through Stripe (we do not store full credit card numbers)
- Communications: Messages you send through our contact form
2.2 Information Collected Automatically
When you access the Service, we automatically collect:
- Device Information: Browser type, operating system, device type
- Log Data: IP address, access times, pages viewed, referring URL
- Usage Data: Features used, actions taken within the Service
- Cookies and Similar Technologies: As described in our Cookie Policy
2.3 Information from Third Parties
- Social Login: If you sign in via Google, we receive your name, email, and profile picture from Google
- Browser Extension: Product information from retailer websites when you use our extension
- Barcode Lookups: Product data from third-party databases when you scan barcodes
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Process transactions and send related information
- Send you technical notices, updates, and security alerts
- Respond to your comments, questions, and support requests
- Communicate with you about products, services, and events (with your consent)
- Monitor and analyze trends, usage, and activities
- Detect, investigate, and prevent fraudulent transactions and other illegal activities
- Personalize and improve your experience
- Operate gamification features (badges, points, leaderboards)
4. Sharing Your Information
We may share your information in the following circumstances:
4.1 With Your Consent
- When you share lists or inventory with other users or "Crews"
- When you make recipes public
4.2 Service Providers
We share information with third-party vendors who provide services on our behalf:
- Stripe: Payment processing
- Amazon Web Services: Cloud hosting
- Google: Authentication services
4.3 Legal Requirements
We may disclose your information if required by law or in response to valid requests by public authorities.
4.4 Business Transfers
If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
5. Data Security
We implement appropriate technical and organizational measures to protect your personal information, including:
- Encryption of data in transit (HTTPS/TLS)
- Encryption of sensitive data at rest
- Regular security assessments
- Access controls and authentication
- Secure password hashing
However, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
6. Data Retention
We retain your information for as long as your account is active or as needed to provide you services. Specifically:
- Account Data: Until you delete your account
- Inventory & Lists: Until you delete them or your account
- Transaction Records: 7 years (for legal/tax purposes)
- Log Data: 90 days
- Deleted Account Data: Permanently removed within 30 days
7. Your Rights and Choices
7.1 Access and Portability
You can access your data at any time through your account settings. You may request an export of your data in a portable format.
7.2 Correction
You can update or correct your account information at any time through your profile settings.
7.3 Deletion
You can delete your account at any time through account settings. This will permanently remove your personal data within 30 days.
7.4 Opt-Out of Marketing
You can opt out of marketing communications by clicking "unsubscribe" in any email or adjusting your notification preferences.
7.5 Cookie Preferences
You can manage cookie preferences through our cookie consent banner or your browser settings. See our Cookie Policy for details.
8. California Privacy Rights (CCPA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):
- Right to Know: You can request information about the categories and specific pieces of personal information we have collected about you
- Right to Delete: You can request deletion of your personal information
- Right to Opt-Out: We do not sell personal information, but you have the right to opt-out of any future sales
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights
To exercise these rights, please use our contact form.
9. European Privacy Rights (GDPR)
If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):
- Legal Basis: We process your data based on consent, contract performance, and legitimate interests
- Right to Rectification: Correct inaccurate personal data
- Right to Erasure: Request deletion of your data ("right to be forgotten")
- Right to Restrict Processing: Limit how we use your data
- Right to Object: Object to processing based on legitimate interests
- Right to Portability: Receive your data in a machine-readable format
- Right to Lodge a Complaint: File a complaint with your local data protection authority
10. Children's Privacy
The Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.
11. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. By using the Service, you consent to such transfers.
We ensure appropriate safeguards are in place for international transfers, including standard contractual clauses approved by relevant authorities.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the new Privacy Policy on this page
- Updating the "Last updated" date
- Sending an email notification for significant changes
We encourage you to review this Privacy Policy periodically.
13. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us through our contact form.