Aisle

Privacy and data handling

What Aisle knows about you, and what it refuses to.

Draft for the pilot · last updated 11 September 2026 · not yet reviewed by a lawyer

This notice describes what the app and its service actually do today, written from the code. It is a draft. Before Aisle is available to anyone outside the pilot it will be reviewed by somebody with GDPR experience, and this line will be removed.

The short version

Who is responsible

Aisle is operated by [legal name and address to be filled in], the Netherlands. Contact: [email protected].

What is processed, and why

DataWhere it livesWhyLegal basis
The barcode you scan or typeSent to the API; the product record is cached on the server for every shopperTo look the product up and score itPerformance of the service you asked for
Your goal, nutrition priorities and allergensOn your phone. Sent as request headers with each scan. Stored on the server only if you create an accountTo personalise the verdict and to warn you about allergensPerformance of the service; allergen data is processed on your explicit request when you enter it
Recent scans and a saved copy of each resultYour phone onlySo you can find a product again, and read a saved verdict when there is no signalNot transmitted
Usage events: a scan happened and how it ended, a comparison was viewed, whether you said a recommendation changed your choice, how long a verdict tookServer, against a random installation idTo learn whether Aisle is useful. The North Star is whether a recommendation changed a purchaseLegitimate interest in improving the product; the id is resettable from the profile screen and carries no profile data
Account: email, password hash, your profile, household members and their allergens, prices you enterServer, only if you create an accountTo keep your profile across devices, to buy for other people, and to attribute prices you contributePerformance of a contract you entered; allergens of household members on your explicit request
Products you add for an unknown barcodeServer, in the shared catalogue, attributed to your account if you have oneSo the next shopper who scans it finds itPerformance of the service; you are told before submitting
Error reportsSent to an error-tracking service, with your profile stripped from every reportTo find crashesLegitimate interest

What Aisle deliberately does not do

Your rights

If you have an account you can export everything Aisle holds about you and delete the account from inside the app, without emailing anybody. Deletion removes your account, profile, household, prices and tokens. Products you added to the catalogue stay in the catalogue, with your name removed: they are useful to other shoppers and carry nothing about you once the link is severed. The app shows you exactly this before you confirm.

Without an account, the only server-side data is the usage events against your installation id. Resetting the id from the profile screen makes your installation indistinguishable from a new one. If you want the events deleted as well, send the id shown on that screen to [email protected].

You can also lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens.

Retention

Where

The service runs on servers in the European Union. Error reports, if enabled, go to [provider and region to be confirmed].

Changes

When what the app does changes, this page changes first, and the date above moves.