GoCerise Privacy Policy
17695969 Canada Inc., doing business as GoCerise, (“GoCerise,” “gocerise,” “we,” “us,” or “our”) operates the GoCerise mobile application and website (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our Service.
Protecting your privacy is important to us. Therefore, the GoCerise mobile application has no accounts and no sign-in. There is no registration screen, no password, and no social login. Your lists and your shopping history are stored on your phone, not on our servers.
Please read this Privacy Policy carefully. By accessing or using the Service, you consent to the practices described in this policy. If you do not consent, do not use the Service.
No Account Required
We do not create user accounts or intentionally associate app activity with a named individual. However, our service providers may process technical information, such as IP addresses, request paths, and timestamps, as described below. The app does not intentionally send an account ID, advertising ID, device ID, or installation ID with its requests.
Information You Provide or Choose to Record
- Shopping information: grocery lists, list names, products, quantities, prices, shopping-trip history, and savings information that you choose to enter or save.
- Location information: GPS coordinates when you grant location permission, or coordinates derived from an address or postal code that you enter.
- Search and planning information: product searches, store searches, selected store preferences, search radius, language, and the items and quantities used for trip planning.
- Settings: language, currency, tutorial progress, location-consent choice, and other app preferences.
- Feedback and correspondence: messages or other information you send to us, including information contained in support emails.
- Mailing-list information: your name and email address if you subscribe through our website.
Information Collected Automatically or by Service Providers
- Technical information: IP address, request date and time, request path, response status, response time, browser or app information, and other information recorded by our hosting and infrastructure providers.
- Security and diagnostic information: information used to prevent abuse, enforce rate limits, troubleshoot errors, and protect the app and website.
- Website information: technical information about visits to our website, including information processed by the website hosting provider.
- Third-party service information: information sent to mapping, geocoding, routing, exchange-rate, product-image, email, hosting, and other providers when needed to provide the requested feature.
Information Stored Locally on Your Device
The app stores certain information locally, including grocery lists, shopping-trip history, spending calculations, address or postal-code searches, store preferences, settings, and exchange-rate data. This information is not stored on our application servers unless specifically described in this policy. Device backups, operating-system services, and other apps may handle locally stored information according to their own settings and policies.
How We Use Information
| Information | Where it comes from | Purpose |
|---|---|---|
| Coordinates, or the address you type | App | Finding grocery stores near you, pricing your list at those stores, and drawing driving routes |
| Product search terms and item names | App | Returning matching products and their prices at nearby stores |
| Store-banner preferences and search radius | App | Limiting results to the chains and distance you care about |
| Trip-planning snapshot | App | Keeping the prices you were shown consistent while you choose a route, for up to 15 minutes |
| Name and email address | Website mailing list sign-up | Sending you the mailing list emails you asked for, and nothing else |
| Server logs, including IP address | App and website | Security, abuse prevention, rate limiting, and debugging |
We use this information only for the purposes above. We do not use it for advertising, profiling, or automated decision-making, and we do not sell or rent it to anyone.
Business Transfers
If GoCerise is involved in a merger, acquisition, financing, reorganization, or sale of all or part of its assets, information held by us may be transferred as part of that transaction. In such event, we will endeavor to direct the transferee to information in a manner that is consistent with this policy in effect at the time such information was collected.
International Processing and Transfers
Our application servers and our database is hosted by Railway on infrastructure in United States (us-east4). The information sent to Railway by us are disclosed in subsection “Information collected automatically or by service providers”. The active mailing-list database is configured in Supabase’s Canadian region. We do not intentionally configure that database to store mailing-list names and email addresses outside Canada. Our website is served by Vercel from a global edge network, so the page you are reading may be delivered from a server outside Canada, and Vercel keeps standard web request logs including IP addresses under its own retention arrangements. Route coordinates are additionally sent to the routing service named in section 4, which processes them on servers in Switzerland, and is operated by an organization based in Germany, subject to European data protection law. The map, geocoding, exchange-rate, and product-image services named earlier may also process requests outside Canada.
Before using providers that process personal information outside Canada, we assess the proposed processing, including the sensitivity of the information, the purposes, the retention periods, the provider’s security and contractual safeguards, the applicable laws in the destination locations, and whether the provider’s sub-processors create additional transfers.
Data Security
We protect information using measures including:
- Encryption in transit. All communication between the app and our servers, and between your browser and our website, uses HTTPS/TLS.
- Little to steal. The app holds no passwords, tokens, or account identifiers, and our application database holds no user accounts.
- Coordinates kept out of URLs where practical. Trip planning and driving directions send coordinates in the request body rather than the URL, so they do not appear in request logs.
- Short-lived server-side data. Trip-planning snapshots expire after 15 minutes and are purged automatically.
- A shielded routing path. The routing provider never receives your IP address or device information, only coordinates relayed by our server.
- Rate limiting on public endpoints to prevent abuse.
No method of transmission or storage is completely secure, but we work to protect information using industry-standard practices, and you provide information to us with that understanding.
Data Retention
| Information | Retention |
|---|---|
| Grocery lists, trip history, spending insights, settings | On your device only, until you delete them or uninstall the app (trip history keeps the 500 most recent trips) |
| Coordinates and search terms sent for a store or product search | Not stored in our database; processed for the request and discarded, apart from server logs |
| Trip-planning snapshot (coordinates, item names, candidate prices) | 15 minutes, then deleted automatically |
| Coordinates sent to the routing service | Governed by that provider’s own retention practices; we send no identifier with them |
| Mailing list name and email address | Until you unsubscribe, after which they are removed from the list |
| Record that you unsubscribed (email address only) | Kept on a suppression list so you are not emailed again, until you ask us to erase it |
| Record of your consent (sign-up date and what the form said) | Kept while you are subscribed and for 3 years afterwards, so we can demonstrate that you asked to hear from us if we are ever required to |
| Application server logs, including URLs with search terms and coordinates | No more than 30 days, then deleted automatically by our hosting provider |
| Hosting provider’s platform request logs, including originating IP addresses | No more than 30 days, then deleted automatically |
| Website server logs, including IP addresses | Held by Vercel under its own retention arrangements |
Your Rights
You have the right to access the personal information we hold about you, to have it corrected, to have it deleted, to withdraw consent to its use, and to receive a copy of the computerized personal information you provided to us, in a structured and commonly used format. You can unsubscribe from our mailing list at any time by emailing us or clicking unsubscribe on one of marketing mail. You can delete all your data by deleting the GoCerise app, which stores all your data locally. You can withdraw consent to location sharing or decline all together. To exercise any of these rights, or to ask a question about this policy, email privacy@gocerise.com. We will respond within 30 days. If you believe your privacy rights have been violated, you may contact the Office of the Privacy Commissioner of Canada at www.priv.gc.ca
Third-party Links
GoCerise sometimes hands you off to an app or website we do not operate. When that happens, you leave our control and the other service’s own privacy policy governs what it collects. We do not receive a report back about what you do there.
This happens when:
- You tap directions to a store. GoCerise offers to open Apple Maps, Google Maps, or Waze, and passes the store’s coordinates or name to the app you pick. That app then knows where you are heading, under its own privacy policy.
- You send feedback. The app opens your own email application with a message addressed to help@gocerise.com. Your email provider handles it; it does not pass through our servers.
- You share GoCerise with a friend. The app opens your device’s share sheet, and whichever app you choose handles the message.
- You open a link out of the app, which opens in your device’s browser.
Product images shown inside the app are loaded from the grocery retailers’ own servers, as described in section 4. We do not own, operate, or control any of these services, and we are not responsible for how they handle your information. We encourage you to review their privacy policies, and to contact them directly with any concerns about their practices.
Children’s Privacy
GoCerise is not intended for children under 14. We do not knowingly collect personal information from children. If you believe a child has sent us personal information, or has been signed up to our mailing list, and you would like it removed, contact us immediately at privacy@gocerise.com and we will delete it.
Changes to Policy
We may update this policy from time to time. If we make material changes, we will notify you through the app and on our website before the changes take effect, and we will tell mailing list subscribers by email. We will also update the dates at the top of this page. Continued use of GoCerise after changes take effect constitutes acceptance of the updated policy.
Contact Us
For privacy related inquiries, please contact us at privacy@gocerise.com. If you have any other questions, please contact us at: help@gocerise.com.
Privacy Officer: Jon Barlas, privacy@gocerise.com. Under Quebec’s Act respecting the protection of personal information in the private sector (Law 25), this person is responsible for the protection of personal information at GoCerise.
17695969 Canada Inc. Montreal, Quebec, Canada.