Privacy Policy
TrolleyCYis a Cyprus grocery price-comparison app. This policy explains what personal data we collect, why, the legal basis, who we share it with, how long we keep it, and the rights you have under the EU General Data Protection Regulation (GDPR) and Cyprus data-protection law. We keep the app privacy-friendly: we don't use advertising or tracking, and we don't sell your data.
Who is responsible for your data
The data controller is LudeHQ (Cyprus). For any privacy question or to exercise your rights, contact us at contact@ludehq.com.
What we collect
- Account data — your email address, and if you use Google sign-in, the basic account identifier Google returns. Needed to create and secure your account.
- Subscription & payment data — if you subscribe, a Stripe customer and subscription reference and your subscription status. Payments are processed by Stripe; we never receive or store your card number.
- AI feature inputs — the messages you type to the assistant and any shopping-list photo you choose to scan. These are sent to our AI providers to generate a response and are not stored on our servers after your request is handled.
- Community submissions — any price report you send (e.g. a product, store and the message you write).
- Approximate location — only if you grant location permission, used momentarily to show nearby-store prices. We do not store your coordinates.
- Technical & security data — limited data such as your IP address is processed by our hosting and used for security and to enforce fair-use/rate limits.
- Preferences on your device — language, theme, city, basket and settings are stored in first-party cookies / local storage on your device (see Cookies below).
Why we use it and our legal basis
- To provide the app, your account and AI features — legal basis: performance of our contract with you.
- To take payment and manage your subscription — legal basis: performance of our contract; and compliance with tax/accounting law for billing records.
- To keep the Service secure and prevent abuse (rate limiting, fraud/abuse prevention) — legal basis: our legitimate interests in a safe, working service.
- To use your location — legal basis: your consent (you can decline in your browser).
- To send you service emails (sign-in links, essential account notices) — legal basis: performance of our contract.
Cookies and local storage
We use only first-party, strictly-necessary and functional cookies / local storage: your sign-in session, and your language, theme, city, basket and settings preferences. We do notuse advertising, analytics or cross-site tracking cookies, so no cookie-consent banner is required. You can clear these any time in your browser, though signing in and some preferences won't work without them.
Who we share it with (processors)
We share data only with service providers that process it on our instructions under data-processing agreements, to run the app:
- Stripe — payments and subscription management.
- Neon — our database hosting.
- Vercel — app hosting and delivery.
- LudeMail — our self-hosted service for sign-in and transactional emails.
- OpenRouter and our AI gateway — processing your AI-feature requests (chat messages and scanned list photos) to generate responses.
We may also disclose data where required by law. We do not sell your personal data or use it for advertising.
International transfers
Some of our processors operate outside the EU/EEA (for example in the United States). Where data is transferred outside the EEA, it is protected by an appropriate GDPR safeguard, such as the European Commission's Standard Contractual Clauses or an adequacy decision.
How long we keep it
- Account data: until you delete your account, after which it is erased.
- AI feature inputs (chat messages, scanned photos): not retained on our servers after your request is handled.
- Billing records: retained by Stripe and by us as needed to meet tax/accounting obligations, even after account deletion.
- Security / rate-limit data: kept only short-term.
- Community submissions: kept while they are useful to the Service.
Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased (you can delete your account in the app at any time);
- restrict or object to certain processing;
- receive your data in a portable format;
- withdraw consent (e.g. location) at any time, without affecting prior processing.
To exercise any of these, email contact@ludehq.com or use the delete-account option in the app. You also have the right to lodge a complaint with the Cyprus supervisory authority, the Office of the Commissioner for Personal Data Protection (dataprotection.gov.cy).
Automated decisions
AI features assist you with grocery shopping; they do not make automated decisions that produce legal or similarly significant effects about you.
Children
The Service is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.
Security
We protect your data with encryption in transit, access controls, and by keeping what we collect to a minimum. Payments are handled by Stripe, a PCI-DSS-certified provider, so card details never reach our servers. No system is perfectly secure, but we work to keep your data safe.
Changes to this policy
We may update this policy as the Service evolves. We will update the date below and, for material changes, give reasonable notice.
Contact
Questions or requests about your data? Email contact@ludehq.com. Controller: LudeHQ, Cyprus.
Last updated: 15 July 2026