1. Who operates Pantry
Sam Agnew is the data controller for Pantry. Questions or data-protection requests can be sent to [email protected].
2. Information Pantry uses
Account and sign-in information
When you create or use a cloud account, Pantry may process:
- your email address, including an Apple private relay address if you choose one;
- your display name;
- a unique Pantry account identifier;
- the sign-in method you use, such as email, Apple or Google;
- authentication and session information; and
- security records such as sign-in times, IP address, user agent and authentication events.
Pantry does not ask you to create a separate password. Email links, Sign in with Apple and Sign in with Google are handled using Supabase authentication and the provider you choose.
Household and app content
Pantry processes information you create or share through the app, including:
- household names, icons, membership roles and membership dates;
- shopping-item names, quantities, purchased status and urgency;
- stock-item names, quantities, storage locations and expiry dates;
- household invitations and, when an invitation is restricted to one person, the invited email address;
- NFC tag names, actions, associated locations or shopping-item templates;
- record identifiers, timestamps, revisions and synchronisation status; and
- support messages and any information you choose to include in them.
Pantry is not designed for storing health information, payment information, government identifiers or other highly sensitive personal information. Please do not place that information in household names, item names, locations or other free-text fields.
Camera and NFC
Camera access is optional and is used only when you choose to scan a household invitation QR code. QR frames are processed on your device. Pantry does not save or upload camera images. You can instead enter an invitation manually.
NFC access is optional and is used when you choose to scan a Pantry tag. The tag contains a random Pantry code. The readable code is processed on your device and is not stored in the cloud; Pantry sends and stores only a cryptographic hash used to recognise the tag.
Storage-location labels such as “Kitchen cupboard” are names entered by users. Pantry does not collect your device’s GPS location.
Website and technical information
When you use the website or cloud features, service providers may process technical request information such as IP address, device or browser type, requested URL, timestamps, routing information and errors. This is used to deliver, secure and troubleshoot the service.
The Pantry app does not contain advertising or third-party analytics SDKs and does not use personal information to track you across other companies’ apps or websites. The Pantry website does not use advertising cookies or analytics.
3. Where the information comes from
Most information comes directly from you. Some account information comes from Apple or Google when you choose their sign-in service.
Other household members may create shared content that concerns your household. A household owner may provide your email address to restrict an invitation to you. Pantry uses an invited email only to secure and manage that invitation, not for marketing.
4. Why Pantry uses personal information
Pantry relies on the following UK data-protection lawful bases:
- Contract: to create and maintain your account; save and synchronise your data; support household sharing; process invitations; and provide features you request.
- Legitimate interests: to keep Pantry secure and reliable, prevent fraud and abuse, enforce reasonable service limits, diagnose faults, answer support requests and protect users’ shared households. These interests are balanced against your rights.
- Legal obligation: where information must be retained or disclosed to comply with applicable law, a court order or a valid regulatory request.
- Consent: where consent is specifically requested. You can withdraw it at any time. Device permissions can be changed in iOS Settings.
If you do not provide account information, you can continue using Pantry’s local-only features, but cloud synchronisation and shared households will not be available.
Pantry does not make decisions about you that produce legal or similarly significant effects. Automated security controls may temporarily or permanently limit unusually high account, household, invitation or data activity.
5. Shared households
Pantry is collaborative. Members of a household can see its shared shopping, stock, location and NFC-tag information, together with the display names, roles and joining dates of other members.
Household owners can manage members and view active invitations, including an invited email address where one was supplied. Pantry does not disclose a member’s account email address to other members merely because they share a household.
6. Service providers and disclosures
Pantry uses:
- Supabase for authentication, the London-hosted primary database, synchronisation, realtime updates and account deletion;
- Apple for App Store distribution and Sign in with Apple when selected;
- Google for Sign in with Google when selected; and
- Cloudflare for the website, domain services, security and email forwarding.
These providers process information under their own terms and privacy arrangements. You can read the Supabase Privacy Policy, Apple Privacy Policy, Google Privacy Policy and Cloudflare Privacy Policy.
Information may also be disclosed where reasonably necessary to professional advisers, regulators, courts or law-enforcement authorities, or to protect Pantry, its users or others.
Pantry does not sell personal information and does not share it for third-party advertising.
7. Where information is processed
Pantry’s primary Supabase project data is stored in London, United Kingdom. Some authentication, support, website-delivery and security processing may take place outside the UK because Pantry’s providers and their subprocessors operate internationally.
Where UK personal information is transferred internationally, an applicable adequacy regulation or appropriate contractual safeguard is used as required.
8. How long information is kept
Pantry keeps information only for as long as needed for the purposes described above:
- Active account, profile, membership and household information is normally retained while the relevant account or household remains active.
- Deleted shopping and stock records may remain as synchronisation tombstones for approximately 90 days so offline devices can learn that they were deleted.
- Synchronisation, NFC and location-operation receipts are normally removed after approximately 91 days.
- Expired, accepted or revoked household invitation records are normally removed approximately 30 days after their final status.
- Household-deletion receipts are normally removed after approximately 180 days.
- Authentication and technical logs are retained according to the security needs and retention settings of the relevant service provider.
- Support correspondence is kept for as long as reasonably necessary to answer the request, maintain an appropriate support record and handle related legal or security matters.
For abuse prevention, Pantry retains a pseudonymous security identifier derived using a secret key from a verified sign-in address, together with a compact record of household creation. These records do not contain the readable email address or phone number, but may recognise the same verified identity if it creates another account. They are retained for the lifetime of the service to enforce lifetime abuse and capacity limits.
Backups and provider systems may take a limited additional period to cycle deleted information out of protected backup storage.
9. Account deletion
You can request permanent account deletion inside Pantry from the account screen.
Before deleting an account, you must transfer ownership of every household you own or archive and permanently delete it. Account deletion then:
- revokes the account’s sessions;
- removes the cloud authentication account and profile;
- removes the account from households where it was a member; and
- removes account-linked cloud data cached by Pantry on that device.
The app lets you separately choose whether to erase local-only households and items from that iPhone.
Content in a shared household may remain available to its other members after you leave or delete your account because the content belongs to the shared household and individual item records do not identify their author. Delete content you do not want to remain before leaving, where appropriate.
The pseudonymous anti-abuse records described above are not removed through ordinary account deletion.
10. Your rights
Depending on the circumstances, UK data-protection law may give you rights to:
- receive a copy of your personal information;
- correct inaccurate or incomplete information;
- request erasure;
- restrict processing;
- object to processing based on legitimate interests;
- receive certain information you provided in a portable format; and
- withdraw consent where consent is the lawful basis.
These rights are not absolute, and an identity check may be required before acting on a request. Send requests to [email protected]. Requests will normally be answered within one month.
You can also complain to the Information Commissioner’s Office if you are unhappy with how your information is handled.
11. Children
Pantry is a general household utility and is not specifically designed for children. It does not currently ask users for their age. A parent or guardian should supervise a child’s use of Pantry and decide whether the child should have an account or household access.
If you believe a child’s personal information has been provided without appropriate involvement from a parent or guardian, contact [email protected].
12. Security
Pantry uses access controls, encrypted network connections, restricted database permissions and other technical measures intended to protect information. No internet service can guarantee absolute security.
Never send Pantry your Apple or Google password, email sign-in link, household invitation code or complete NFC tag code.
13. Changes and contact
This notice may be updated when Pantry’s features, providers or legal obligations change. The latest version and its update date will appear on this page. Material changes will be highlighted in the app or by another appropriate method.
Questions and privacy requests can be sent to [email protected].