CartCycle, in plain language

Privacy Notice

CartCycle is a grocery ledger and planning tool. It keeps the account and grocery details you choose to record so you can understand your spending, share selected records with your household, and plan the next shop.

In plain language

CartCycle stores the information you enter, upload for review, or confirm in the product. This notice explains what those records are used for, what can be shared with a household, and what happens when you turn tracking off or delete your account.

First-party analytics and browser choices
CartCycle keeps its app-owned first-party analytics enabled by default so existing product measurement remains consistent, but you can opt out on your first visit or later from Privacy & Data Controls. Optional measurement is separate from the data needed to sign in, protect requests, and provide grocery features.
  • When the app-owned path is enabled, CartCycle may set cartcycle_visitor_token for first-touch attribution and cartcycle_analytics_visit for a short visit window. It may write VisitorAttribution, WebsitePageView, anonymous BetaFunnelEvent, and measurement-only PredictionFunnelEvent rows.
  • Opting out clears CartCycle optional analytics cookies and browser identifiers, removes the current visitor attribution, page-view, and anonymous funnel rows, and stops future attribution, page-view, and measurement-only writes. It does not disable Better Auth session or security cookies, and it does not delete grocery, receipt, plan, household, subscription, or requested beta application records.
  • The choice is kept in the first-party cartcycle_analytics_consent preference cookie and on your account when signed in. It survives sign-out; signing in does not silently overturn an explicit browser opt-out.
  • The framework-managed Polsia visitor beacon is separate from CartCycle analytics. When a deployment supplies POLSIA_ANALYTICS_SLUG, the framework uses POLSIA_API_BASE_URL (defaulting to https://polsia.com) to request /api/beacon/pixel and writes localStorage.polsia_vid without checking no choice, opt-out, or opt-in. CartCycle has no app-owned control over that framework behavior; strict end-to-end consent compliance requires the deployment to unset POLSIA_ANALYTICS_SLUG or the platform to provide an approved consent seam.
  • The app-owned control clears localStorage.polsia_vid on opt-out, but that cleanup is not a guarantee against a framework beacon that has already run. Until the deployment control or platform seam is verified, this notice does not claim that CartCycle gates the platform beacon.
  • CartCycle adds no advertising pixels, session replay, third-party trackers, or advertising SDKs.
Account, profile, and grocery ledger data
When you use CartCycle, we store the account and grocery details needed to provide the product:
  • Your account name, email address, and account dates so you can sign in and manage your account.
  • Your household-size preference, when you add it, to estimate grocery spend per household member. CartCycle does not ask for household members' names or ages.
  • Grocery purchase records you enter or confirm, including item name, quantity, price, store, category, purchase date, and record date.
  • Your privacy preferences, including whether grocery tracking is enabled and whether future retailer connections are enabled.
  • First-party source-attribution details such as an initial referrer origin and selected campaign parameters, used for aggregate product measurement.
  • If you apply for the founding beta, your application answers and contact details are kept separately from privacy-safe funnel events used for aggregate reporting.
Planning and replenishment signals
CartCycle uses grocery history, confirmed receipt items, household records, and your saved preferences to make planning suggestions. These records help CartCycle show repeat-item signals and projected spend, and prepare plans for a future pickup or delivery that you review yourself.
  • Normalized item names, recent grocery entries, replenishment reminders, and timing or quantity suggestions.
  • Shopping plans and plan items, including store, timing, fulfillment type, review status, projected spend, and planning details.
  • Household planning snapshots, item assignments, prediction history, and a saved pickup or delivery preference when you choose to use them.
Payments
When you choose a paid CartCycle plan or family add-on, payment details are entered directly on Stripe-hosted Checkout or managed in the Stripe-hosted customer portal. CartCycle does not receive, store, log, cache, transmit, or expose raw card numbers (PAN), CVV/CVC, or full card expiration data. CartCycle retains only the limited billing identifiers, subscription status, amount, billing interval, and period state needed to provide and manage the product.
  • Checkout and payment-method updates stay on Stripe-hosted pages; CartCycle does not provide an in-app card form or collect card credentials.
  • CartCycle does not store raw payment-card data in the account database or include it in analytics, session replay, exports, or application logs.
  • Stripe and the Polsia payment integration handle provider-side payment processing and verification. CartCycle has no inbound payment webhook endpoint in this app.
Household sharing boundaries
Household sharing applies only to records with a household scope. Active household members can see household-scoped grocery records, plans, planning snapshots, and receipt-derived rows. Records without a household scope remain account-scoped and are not shown to household members.
  • CartCycle stores household memberships and invitations so sharing can work and so you can see your household access in an export.
  • A household record can include its store, date, amount, item details, note, and the member who created it.
  • Product handoffs and planning items can include a household, assignee, or creator so shared work stays in the right scope.
Receipt images and extraction
When you upload a receipt, CartCycle validates and normalizes the image, then sends the normalized file through the existing Polsia extraction path to identify a receipt date, store, and grocery items. The image is processed transiently and is not stored. CartCycle does not retain OCR text or extraction confidence scores.
  • Only extracted draft fields are persisted: receipt date, store, item name, normalized item name, quantity, price, category, and the product's review flags.
  • You review the draft before confirmation. Discarding a draft deletes the draft and its item rows.
  • Confirming a draft keeps the reviewed receipt fields and creates the corresponding grocery and household records used by CartCycle planning.
Retailer connections are not enabled
CartCycle does not connect retailer accounts, receive retailer credentials, or place orders. A retailer handoff is a record you review and save: it can contain a retailer name, product link, item, quantity, assignee, and review, opening, completion, and creation dates. CartCycle does not store retailer credentials or tokens.
  • CartCycle never places a grocery purchase or completes checkout.
  • You choose whether to open a saved retailer link in a new tab, and any purchase happens outside CartCycle.
  • The future retailer-connections preference is off by default and does not activate a retailer connection today.
Retention and deletion
Saved grocery, planning, household, preference, handoff, and product records remain available so CartCycle can show your history and plans. Turning grocery tracking off stops new grocery records; it does not erase history. Opting out of analytics removes the current optional attribution, page-view, and anonymous funnel records and stops future optional measurement. CartCycle does not state a fixed automatic deletion timeline for product records.
  • From Privacy & Data Controls, you can download a readable export of your account, preferences, grocery data, plans, household access, receipt drafts and confirmations, handoffs, and related product records.
  • Deleting your account runs the cleanup for your account data, receipt imports, planning records, preferences, measurement events, attribution tokens, and matching page views; missing rows are safe to repeat.
  • If the deleting account owns a household, the household is closed and its household-scoped data is removed. If the deleting account is a member, its membership and the household records it created are removed; other members' records remain.

Privacy & Data Controls

Sign in and open /privacy-controls to manage your privacy preferences, download a copy of your data, or permanently delete your account. The page explains that tracking-off is not retroactive and requires an exact confirmation phrase before account deletion.