Who We Are
Bandit is a grocery price comparison app operated by Chris Raas ("we", "us", "our"), based in British Columbia, Canada. This policy explains what personal information we collect, why we collect it, and how you can control it.
This policy is governed by the BC Personal Information Protection Act (PIPA). By using Bandit, you agree to this policy.
What We Collect
- Account: email address and password (stored securely via Supabase Auth).
- Location: postal code only โ used to show stores near you. We never access GPS.
- Shopping list: items you add to your in-app list.
- Price reports: product name, price, store name, and date โ submitted voluntarily by you to help the community.
- Receipt scans: see dedicated section below.
- Push notification token: used only to send you price alerts you have set up.
- Points and activity: your points balance and contribution history within the app.
- Usage data: anonymous analytics via Google AdMob (free tier). No personally identifiable data is shared with Google.
Receipt OCR โ How It Works
Your receipt photo never leaves your device. Text recognition runs locally. Nothing is shared until you review and confirm each item.
When you choose to scan a receipt:
- Your camera takes a photo. That photo stays on your device.
- Text is extracted on-device using ML Kit (Google's on-device OCR โ no data sent to Google).
- You see a review screen listing every item and price detected. You can edit, remove, or exclude any item before anything is submitted.
- Only the items you explicitly confirm are sent to Bandit's servers: product name, price, store name, and purchase date. No customer name, card number, or tax ID is ever collected or transmitted.
- In the community database, your price reports are stored with your user ID (anonymized) โ your name and email are never exposed to other users.
Why We Collect It
- To provide and improve the Bandit app.
- To build a community price database that helps all users find the best grocery deals.
- To send price drop alerts for items you are tracking.
- To award points for community contributions.
We do not sell your data. We do not use your data for advertising targeting.
How We Store Your Data
All data is stored on Supabase cloud servers located in the United States. Supabase uses industry-standard encryption in transit (TLS) and at rest (AES-256).
We retain price report data indefinitely as part of the community database. Account data is retained until you delete your account. You can request deletion at any time (see Your Rights below).
Who We Share With
- The Bandit community: your price reports contribute to the shared database. Individual reports are aggregated โ a price for a product is only shown to other users when at least 3 independent reports exist for that item.
- Supabase: our database and authentication provider.
- Resend: our email delivery provider, used for transactional emails (e.g., password reset).
- Expo: our push notification delivery provider.
- Google AdMob: anonymous usage analytics (free tier).
No other third parties have access to your personal information.
Your Rights
Under BC PIPA, you have the right to:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Delete your account and associated personal data.
- Withdraw consent at any time (see below).
To exercise any of these rights, email us at support@getbandit.ca.
Withdrawing Consent
You can withdraw consent for specific data collection at any time:
- Receipt OCR: simply do not use the Scan Receipt feature. Every scan requires your explicit confirmation before any data is sent.
- Price reports: you are never required to submit a price report. All contributions are voluntary.
- Push notifications: disable in your device's notification settings.
- Your account: email us to request full account deletion. All personal data will be removed within 30 days. Anonymized, aggregated community price data may be retained.
Security Breach Notification
In the event of a data breach that poses a real risk of significant harm to users, we will:
- Notify affected users by email within 72 hours of becoming aware of the breach.
- Report the breach to the Office of the Information and Privacy Commissioner of BC as required by law.
- Provide clear information about what happened, what data was affected, and what steps we are taking.