Privacy Policy
Effective: 18 May 2026 · Last updated: 30 May 2026
1. Introduction
Arisdy Limited, trading as CartGo ("we", "our", or "us"), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application ("App").
By using CartGo, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our App.
2. Information We Collect
2.1 Information You Provide
- Account Information: Email address when you sign in with Google or Apple (OAuth authentication)
- Purchase Data: Receipt images, stock card images, product codes, prices, and purchase dates that you scan
- Watchlist Data: Products you choose to follow for price alerts
2.2 Information Collected Automatically
- Location Data: Approximate location to determine which Costco warehouse you are near (used only for warehouse detection, not tracked continuously)
- Device Information: Device type, operating system, and app version for troubleshooting
- Usage Data: Features used, scan frequency, and app interactions
2.3 Information from Third Parties
- Price Data: Crowdsourced product prices from other CartGo users
2.4 Anti-Fraud Identifiers
To protect our rewards system from abuse, CartGo generates and stores two irreversibly hashed identifiers when you sign in:
- OAuth Subject Hash: A one-way hash derived from your Google or Apple account identifier (the
subclaim). It cannot be reversed into your email, name, or any contactable detail. - Device Fingerprint Hash: Where available, a one-way hash derived from non-resettable device attributes. It cannot identify the physical device beyond matching it to itself.
These hashes are stored separately from your CartGo profile and persist beyond account deletion. See Section 9 for full retention details and your right to object.
3. How We Use Your Information
We use the information we collect to:
- Provide and maintain the CartGo service
- Track your Costco purchases and detect price drops within 30 days
- Send you rebate alerts and price drop notifications
- Improve the accuracy of our crowdsourced price database
- Determine which Costco warehouse you are near for location-specific pricing
- Operate the membership lifecycle, including awarding trial-extension days for qualifying scans (see Section 5)
- Send the optional weekly warehouse digest email to Pro members who explicitly opt in (see Section 6)
- Process referral codes you generate or enter (see Section 6.1)
- Detect and prevent abuse of our rewards system (see Section 9)
- Provide customer support and respond to inquiries
- Analyze usage patterns to improve the App
4. AI Processing
CartGo uses AI services (such as Google Gemini) to extract product information from receipt and stock card images. When you scan a receipt or stock card:
- The image is uploaded to our secure servers for processing
- AI extracts product codes, names, and prices from the image
- Receipt images are stored temporarily (up to 7 days) while you review the extracted data, then automatically deleted
- Stock card images are stored temporarily while processing, then automatically deleted after successful extraction or within 7 days
- Only the extracted product data is retained long-term
- Google's AI processes data according to their privacy policy
5. Membership Lifecycle and Trial Extensions
CartGo offers three membership states — Free, Trial, and Pro — that determine which features you can use. Your membership state is stored on your CartGo profile and changes over time based on your activity and subscription status.
5.1 Free, Trial, and Pro
- Free: Default state. You can browse deals, scan price tags, and earn trial-extension days. Receipt rebate monitoring, watchlist alerts, and receipt OCR are not available on Free.
- Trial: Granted once per account on your first successful stock-card scan and lasts 30 days. Each subsequent successful scan can extend your Trial by 1–5 days, subject to a diminishing-returns multiplier and weekly/monthly caps.
- Pro: A paid subscription at NZ$2.99 / AU$2.99 per month, billed through the App Store or Google Play. Pro members have unconditional access to all features. Pro scans do not earn additional trial days.
5.2 When a Trial ends or a Pro subscription is canceled
- Watchlist items are deleted
- Saved receipts are paused (the receipts themselves are preserved, but rebate monitoring stops)
- Paused receipts can be reactivated all at once for a cost of 5 earned trial days
- You become a Free member and can resume earning trial-extension days
5.3 Trial extension activity log
Each time a scan earns trial-extension days, we record:
- The scan event reference
- The number of days awarded
- The reason (first scan at a warehouse, new promo spotted, verified by community, daily streak)
- The timestamp
This log is associated with your CartGo account. It exists to apply the diminishing-returns curve accurately, to assist customer support if a reward looks wrong, and to defend against gaming our rewards system. When you delete your account, this log is deleted with it. (The pseudonymous anti-fraud hashes described in Section 9 are retained separately.)
5.4 Subscription terms
- NZ$2.99 / AU$2.99 per month
- Auto-renews monthly unless canceled
- Cancel anytime via App Store or Google Play subscription management
- No charge during the Trial period
- Subscriptions are processed by Apple or Google, not by CartGo or Arisdy Limited
6. Weekly Warehouse Digest Email (Pro)
CartGo offers an optional weekly email summary every Sunday morning to Pro members (including users on a Pro trial) who explicitly opt in. The email is scoped to your home warehouse and may include: items members are scanning, promotions ending or newly listed at your warehouse, and a small personal summary (rebates you claimed, receipts you saved, items you contributed). The email does not identify individual members or expose their personal data.
The digest is off by default. We only send it to users who actively turn it on. You can opt in or opt out at any time:
- In the App: Settings → Weekly warehouse digest
- From any digest email: click the "unsubscribe" link in the footer
Unsubscribing does not affect any other CartGo functionality.
6.1 Refer a Friend
CartGo offers a refer-a-friend program where Free and Trial members can earn additional Pro time by inviting other members. When you generate a referral code, we store it on your account so we can credit you when a referred friend qualifies.
When a friend enters your code and completes their first scan at Costco, we record the referral claim (your referrer ID, the referee's referrer ID, the claim status, the resulting trial extension, and the qualifying timestamp) so we can attribute the reward correctly and prevent double-claims or fraud.
Referral claim records are associated with both the referrer and the referee accounts. When you delete your account, your referral claim records are deleted with it. The irreversibly hashed anti-fraud identifier described in Section 9 is retained separately and prevents the same person from re-signing up to claim multiple referee rewards.
7. Data Sharing
We may share your information with:
- Service Providers: Supabase (database hosting), Firebase (push notifications), Google (AI services), Brevo (transactional and digest email delivery), RevenueCat (subscription management)
- Other Users: Anonymized price data contributes to the community database (your identity is never shared)
- Legal Requirements: When required by law or to protect our rights
We do not sell your personal information to third parties.
8. Data Retention
We retain your data as follows:
- Account Data: Until you delete your account
- Purchase History: 12 months, then automatically deleted
- Receipt Images: Temporarily stored for up to 7 days while you review extracted data, then automatically deleted
- Stock Card Images: Temporarily stored while processing, then automatically deleted after successful extraction or within 7 days
- Trial Extension Log: Until you delete your account
- Referral Claims: Until you (or your referee) delete the account
- Paused Receipts: Preserved until the underlying purchase ages out of the 12-month retention window
- Price Contributions: Indefinitely (anonymized)
- Anti-Fraud Hashes: Indefinitely — see Section 9
9. Anti-Fraud Retention After Account Deletion
CartGo retains a small amount of pseudonymous information about your account even after you delete it. This information cannot reveal your name, email, or other contact details — it is used only to match a returning account — and exists solely to prevent abuse of our rewards system.
9.1 What we retain
When you sign in with Google or Apple, we store an irreversibly hashed identifier derived from your OAuth provider's account ID, alongside (where available) an irreversibly hashed device identifier. We also retain a count of trial-extension days that have been earned across all CartGo accounts associated with these hashes.
These hashes cannot be reversed into your name, email, phone number, or any other identifying information. They cannot be used to contact you or to recover your account.
9.2 Why we retain it
CartGo's rewards system grants free trial time in exchange for contributing price-tag scans. Without this measure, a user could repeatedly delete their account and create a new one to reset their diminishing-returns rate. This data exists solely to prevent that abuse.
9.3 Lawful basis for retention
We rely on our legitimate interest in protecting our rewards system from abuse (GDPR Article 6(1)(f)). We have weighed this interest against your right to deletion and determined that retaining only pseudonymous hashes — which cannot be linked back to your name, email, or other identifying details — does not infringe on your fundamental rights. You retain the right to object to this processing by contacting us at support@cartgo.app.
9.4 Retention period
The anti-fraud record is retained indefinitely. Because it cannot be linked back to your identity or contact details, the risk to you from its retention is minimal. We will delete the record upon explicit request to support@cartgo.app; deletion will cause your CartGo trial-extension rate to reset if you re-register.
10. Your Rights
You have the right to:
- Access: Request a copy of your personal data
- Correction: Update inaccurate information
- Deletion: Request deletion of your account and data
- Portability: Export your purchase history
- Opt-out: Disable push notifications, or unsubscribe from the weekly digest, at any time
- Objection: Object to the anti-fraud retention described in Section 9
To exercise these rights, contact us at support@cartgo.app.
11. Data Security
We implement appropriate technical and organizational measures to protect your data, including encryption in transit (HTTPS/TLS), secure database storage with Supabase, and Row Level Security policies ensuring users can only access their own data.
12. Children's Privacy
CartGo is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child, please contact us immediately.
13. International Users
CartGo operates in New Zealand, Australia and Korea. Your data may be processed in countries where our service providers are located (including the United States). By using CartGo, you consent to such transfer and processing.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy in the App or sending an email. Your continued use of CartGo after changes constitutes acceptance of the updated policy.
15. Contact Us
If you have questions about this Privacy Policy, please contact us:
- Company: Arisdy Limited
- Email: support@cartgo.app
- Website: cartgo.app
— The CartGo Team