1. Who we are
Shopping Buddy is an independent UK price-comparison service and the data controller for personal data collected through this service.
2. What we collect and why
- Account data (name, email, password hash) — to create and secure your account. Legal basis: contract performance.
- Profile data (postcode, loyalty card status, weekly budget) — to tailor price comparisons. Legal basis: contract performance.
- Shopping data (lists, comparison history, shop history) — to provide the service. Legal basis: contract performance.
- Usage and device data (IP, device type, errors, page views) — for security, troubleshooting and product improvement. Legal basis: legitimate interests.
- Support messages — to respond to enquiries. Legal basis: legitimate interests.
Payment data (card details, billing address) is collected directly by our Merchant of Record, Paddle, and is not visible to us.
3. Who we share data with
- Paddle — Merchant of Record. Handles payments, subscription management, tax compliance and invoicing.
- Hosting and infrastructure providers — to run and store data.
- Analytics and error monitoring — to keep the service working.
- Authorities — only where required by law.
4. International transfers
Some of our service providers process data outside the UK / EEA. Where this happens we rely on appropriate safeguards such as Standard Contractual Clauses or adequacy decisions.
5. How long we keep data
We keep account data while your account is active. If you delete your account, we delete or anonymise your personal data within 30 days, except where retention is required by law (e.g. tax records held by Paddle for up to 7 years).
6. Your rights
Under UK GDPR you have the right to:
- access your personal data;
- have inaccurate data corrected;
- have your data erased ("right to be forgotten");
- restrict or object to processing;
- data portability;
- withdraw consent at any time;
- complain to the UK Information Commissioner's Office (ICO).
We respond to requests within one month. Email admin@shoppingbuddy.co.uk.
7. Security
We use industry-standard technical and organisational measures including encryption in transit, hashed passwords, and access controls.
8. Cookies
We use only essential cookies (and equivalent local storage) needed to keep you signed in and to remember your preferences. We do not use advertising cookies.