Skip to main content
Privacy

Privacy Policy

This policy explains what personal data we process, for what purposes, on what legal bases, and what rights you have.

1. Data Controller

Eatoro is your data controller. For privacy questions, write to: info@eatoro.lt.

Eatoro is a registered trademark.

2. What data we collect

  • Account data: email, account ID, plan information, authentication data.
  • App data: products, expiry dates, notes, reminder settings.
  • Technical data: IP, device/client information, security and diagnostics logs.
  • Usage data: technical analytics (e.g. performance metrics, error event types).
  • Email receipt data: by forwarding an electronic receipt to cekis@eatoro.lt, the user agrees that receipt data (items, prices, quantities, store) will be processed to create their food inventory and provide related Eatoro features.

3. Processing purposes and legal bases

  • Service provision and account administration: contract performance (GDPR 6(1)(b)).
  • Processing receipt data (items, prices, quantities) following your actions: contract performance (GDPR 6(1)(b)).
  • Security, fraud prevention, incident analysis: legitimate interest (GDPR 6(1)(f)).
  • Fulfilment of mandatory legal obligations: legal obligation (GDPR 6(1)(c)).
  • Communication about important service changes: contract performance / legitimate interest.

4. Data retention periods

  • Account and product data: until account deletion or until you delete them yourself.
  • Receipt import data and OCR results: until account deletion or until you remove the related records.
  • Session cookies: up to 7 days of inactivity.
  • Analytics events: per configured retention period (currently up to 90 days).
  • Security and diagnostics logs: only as long as needed for incident investigation and system security.

5. Data recipients and subprocessors

  • Hosting and infrastructure (e.g. application and DB platforms).
  • Error monitoring and observability (e.g. Sentry).
  • Technical analytics (e.g. Vercel Analytics and internal analytics endpoints).
  • Email delivery (e.g. transactional emails for account actions).

Data is not sold or used for third-party advertising profiling.

The full list of vendors is provided here: Subprocessors.

6. Transfers outside the EEA

Where data is transferred outside the EEA, we apply appropriate safeguards (e.g. European Commission SCCs) or rely on another GDPR-permitted transfer basis.

7. Your rights

  • Receive a copy of your data (export).
  • Request correction, restriction, or deletion of data.
  • Object to processing based on legitimate interest.
  • Right to data portability, where applicable.

To exercise your rights, write to: info@eatoro.lt.

8. Cookies and similar technologies

We use only necessary technical cookies for login and session maintenance. Advertising cookies are not used.

9. How we use receipt and price data

  • We use data only for service functions: import, inventory, reminders, and related analytics.
  • We do not sell data or use it for third-party advertising profiling.
  • Receipt data is not used for automated decisions with a legal or similarly significant effect on you.

10. Minors

The service is not intended for children under 13. If you believe a child's data was submitted without a lawful basis, contact us and we will remove it.

11. Changes

This policy may be updated. Significant changes will be published on the site and, if required, we will ask for renewed consent.

Policy version: 2026-02-21. Last updated: 2026-02-21