Privacy

Last updated August 23, 2026

Basketr reads grocery flyers and works out where to buy what. Doing that well needs your grocery list and roughly where you live. It does not need an advertising profile, and this page is the whole account of what is collected and why.

What we store about you

Every field, and why it exists. If something is not on this list, it is not kept.

WhatWhyHow long
Email addressSo you can sign in and reset your password.Until you delete your account
NameOptional. Shown back to you on your own settings page and nowhere else.Until you clear it
Postal code — first three characters onlyFinds stores near you. “N1M”, not “N1M 2W3”: enough for a neighbourhood, not enough for an address.Until you change it
Approximate coordinatesThe distance from your area to each shop, so a plan does not send you across the city. Never shared.Until you change your postal code
Your basket, stores and travel settingsThe list to price and the shops you are willing to visit.Until you delete them
Weekly plansSo you can see what a shop cost and whether you saved.Until you delete your account
Receipt line itemsOnly for receipts you choose to scan. Product names and prices become part of a shared price catalogue; the image is not kept.Until you delete your account

What we deliberately do not store

Minimising afterwards is harder than not collecting, so these are decisions rather than intentions.

  • Your full postal code. The last three characters identify roughly a city block. They are used once, to place your area on a map, and are never written down.
  • Your address, phone number or date of birth. None of them are asked for, because none of them price a basket.
  • Your IP address, as an identifier. The anonymous id in analytics is a random value in a cookie. It is not derived from your IP, your browser or anything else about you.
  • Anything identifying inside an analytics event. Values are checked before they are written, and an email address, a full postal code or an account id is dropped — checked on the value itself, not on what the field happens to be called.
  • Query strings from page addresses. A password-reset link carries a token in its address; recording the page you were on would record the token with it, so the address is cut off at the question mark.
  • Receipt images. The text is read out and the picture is discarded.

Using Basketr without an account

You can build a basket without signing up. That basket is kept in your own browser and is never sent to us — it reaches our database only if you later create an account, and only then because you asked us to save it.

To show prices we need to know which stores you can reach, so we ask for a postal code. Only the first three characters are used, the part that identifies a neighbourhood rather than an address, and we use them to look up where that area is and which stores are near it. The postal code you type stays in your browser. What we keep on our side is a map of Canadian postal areas to coordinates, which is public geography and is not connected to you or to your basket.

Analytics, and the one cookie

To know which parts of Basketr are actually used, we record a small set of events: pages viewed, and a short list of actions such as adding a basket item or generating a plan. The full list of event names is fixed in the code — nothing else can be recorded, even by accident.

To count returning visitors, a first-party cookie named bskt_vid stores a random identifier that expires after 90 days. It contains no information about you: it is a random number generated on your first visit, and it is stored in our database only in hashed form. No IP address, browser fingerprint, or device identifier is used.

Analytics events are stored with a pseudonym rather than your account id, and location is reduced to the first three characters of a postal code — an area covering thousands of households, never a street.

There is no third-party analytics. No Google Analytics, no advertising pixels, no session recording, no data brokers. The events are stored in our own database and read by nobody outside Basketr.

How to opt out

If your browser sends a Do Not Track or Global Privacy Control signal, we record nothing and set no cookie. Both are settings in your browser or an extension, and both are honoured automatically — you do not need to tell us.

Clearing your cookies removes the identifier. A new one is generated on your next visit, and it cannot be linked to the old one.

What we never do

We do not sell your data, and we do not share it with advertisers.

We do not store full postal codes on anything analytical, do not keep your home coordinates outside your own household record, and do not use your basket to target you with anything.

Where the data goes

Basketr runs on Cloudflare Workers, with data in a Supabase Postgres database. Flyer prices come from publicly available flyer listings. Store locations are looked up through Google's Places API using the store address — never your address.

Your data is yours

You can delete your account from settings, which removes your household, basket, plans and receipts. Analytics events, being pseudonymous, cannot be traced back to you afterwards — tell us before you delete if you would like them removed too.

Questions, a copy of your data, or a request under PIPEDA: contact@basketr.ca.