Privacy Policy
Effective July 15, 2026
BannedPantry (“we”, “us”, “our”) operates the website bannedpantry.com and the BannedPantry mobile applications (collectively, the “Service”). The data controller is BannedPantry, a sole proprietorship based in Louisiana, United States. For privacy questions, email [email protected]. This page explains what information we collect and how we use it.
1. Information we collect
- Account information — email address only, used to sign you in and send transactional emails.
- Scan history — barcodes you scan and the resulting product information. Stored so you can revisit past scans.
- Camera access — used only to read barcodes locally on your device. Images are never uploaded or stored on our servers.
- Payment information — handled entirely by Stripe; we never see or store your card number.
- Usage data — anonymous request logs, IP address, browser/device type, and basic analytics. Used to prevent abuse and improve the Service.
2. How we use information
- To provide and improve the Service.
- To send sign-in emails, receipts, and important service notices.
- To enforce free-tier limits and prevent abuse.
- To respond to support requests.
3. Sharing of information
We do not sell your personal information. We share information only with the service providers required to operate the Service:
- Supabase — database hosting and authentication.
- Vercel — application hosting and serverless infrastructure.
- Stripe — payment processing (Stripe receives only the data needed to complete checkout; we never see your full card number).
- Resend — transactional email delivery (sign-in links, receipts, service notices).
- Klaviyo — marketing email and lifecycle messaging. We send your email address and basic account events (signup, upgrade) so you can receive product updates and newsletters. You can unsubscribe from any marketing email; that does not affect transactional messages.
- OpenAI — server-side OCR for Pro photo scans. When a Pro user uploads an ingredient-label photo, the image is sent to OpenAI's vision API for one-time text extraction only. The image is not stored by us or OpenAI and is not used to train any model. Free and anonymous photo scans run entirely on-device and are never sent to OpenAI.
- Open Food Facts and similar product databases — barcode lookup. We send only the barcode, never your personal data.
- Google Analytics — aggregate, privacy-respecting usage analytics (page views, scan events) to understand and improve the Service. Loaded under Consent Mode; if you decline analytics cookies, analytics storage is disabled.
- Microsoft Clarity — anonymized, aggregated usage and session analytics to diagnose UX issues. Subject to the same consent control as above.
- RevenueCat — subscription and in-app-purchase management for the mobile apps. Receives your account identifier and purchase/entitlement events to keep your Pro status in sync across devices.
4. Data retention
Account information is retained while your account is active. Scan history is retained until you delete it or close your account. Anonymous logs are kept up to 90 days for security purposes.
5. Your rights
You can request export or deletion of your data at any time by emailing [email protected]. We honor GDPR and CCPA requests.
6. Children
The Service is not directed to children under 13. We do not knowingly collect data from children under 13.
7. Changes
We may update this policy. Material changes will be announced on this page; the “effective” date will be updated.
8. Contact
Questions: [email protected]