Terms and Conditions
By installing, accessing, or using ShopyList you accept these Terms and Conditions. ShopyList is a personal tool to create shopping lists, share them, and estimate household expenses. We do not sell products, process payments, or provide financial advice.
If you do not agree with this document, please do not use the app or the related services.
Definitions
- Application or App: ShopyList and the web services required for it to operate.
- User: Natural person who uses the App for personal or family purposes.
- Account: Registered profile with email address and credentials to access features that require authentication.
- Content: Lists, products, notes, prices, and any data you upload or generate.
- Personal Data: Information that allows you to be identified or associated, such as name, email, or device identifiers.
- Third-Party Services: External platforms used for authentication, hosting, analytics, notifications, or other support functions.
Scope and acceptable use
- The App is a helper to organize shopping. Price accuracy depends on data provided by users and may vary between stores.
- You must be of legal age in your country or use the App under the supervision of a responsible adult.
- Use is personal and non-commercial. Do not resell the service, automate it without authorization, or use the brand without written permission.
- Do not send malware, attack the infrastructure, reverse engineer, or collect data from third parties without consent.
Accounts and security
- Some features require an account with email and password. You are responsible for keeping them confidential and updated.
- If you detect unauthorized access, change your password and let us know at shopylist.app@gmail.com.
- We may suspend or close accounts that violate these terms, show suspicious activity, or due to legal requirements. Suspension does not remove prior responsibilities.
Intellectual property
- ShopyList, its logo, code, design, and documentation are the property of their owners. You receive a limited, personal, non-exclusive, and revocable license to use the App according to these terms.
- The content you enter remains yours; you grant us a limited license to store, process, and display it in order to provide the service.
- You may not copy, reproduce, or create derivative works of the App without written authorization.
Changes and availability
- We may improve, modify, or remove features without prior notice and perform scheduled maintenance.
- We will publish the current version of this document at https://legal.shopylist.app/. Continued use implies acceptance of the latest version.
- These terms are governed by the laws of the Republic of Panama. Disputes will be resolved before the competent courts of Panama, without prejudice to any additional rights you may have as a consumer.
Privacy Policy
This Privacy Policy explains in a clear and concise way which categories of data ShopyList collects when you use our mobile applications and related web services, for what purposes we process that data, on which legal bases we rely, and what choices and rights you have under applicable data protection laws. ShopyList is developed and operated from the Republic of Panama, and we apply standards that are consistent with Panamanian data protection law and with other data protection regulations that may apply depending on where you are located. This document complements our Terms and Conditions and should be read together with them.
Data we may collect
We only collect the data that is reasonably necessary to operate ShopyList, improve the service, and comply with our legal obligations. Depending on how you use the App, we may process the following categories of information:
- Data you provide directly. This includes your optional name, email address, and any information you choose to enter in your shopping lists, such as products, prices, notes, tags, categories, and configuration preferences. If you contact us (for example, by email or via support forms), we also process the content of that communication and any information you decide to share. We do not request or store payment card numbers, national identity numbers, or other highly sensitive personal data through the App.
- Technical and device data. For example, type and model of device, operating system and version, language settings, unique device or installation identifiers, approximate IP address, the version of the App you are using, timestamps, and basic log information about how the App interacts with our servers. This information helps us understand in which environments ShopyList is used, adapt the App to different devices, and detect technical problems.
- Usage and interaction data. Such as the features you use, the screens you visit, frequency and duration of use, interaction patterns with lists and products, and basic diagnostic events (for example, if a synchronization fails or if the App closes unexpectedly). We usually analyze this information in aggregated or pseudonymized form in order to improve stability, performance, and usability.
- Generated and inferred data. This includes the history of your lists, changes made over time, aggregated statistics (for example, how many items you typically add or mark as purchased), and internal price comparisons or indicators derived from the data you enter. These elements allow us to offer you functionalities such as history, suggestions, or summaries without needing to acquire such information from third parties.
- Location data (optional). ShopyList does not access your precise location unless you explicitly enable the corresponding permission on your device for features that reasonably require it (for example, suggesting nearby stores or adjusting currency or regional settings). When location is enabled, we may process an approximate geolocation derived from technical signals. You can deactivate this permission at any time in your device settings; the App will continue to work, although some location-based features may be limited.
- Data about children. ShopyList is intended for use by adults or by minors under the supervision of a responsible adult, in line with our Terms and Conditions. We do not knowingly collect Personal Data from children under the minimum age established by applicable laws. If we become aware that we have collected such data inadvertently, we will take reasonable steps to delete it and, where appropriate, to disable the related account.
Purposes of the processing
We use the data described above only for specific, explicit, and legitimate purposes. In particular, we may process your information to:
- Provide and operate the core functionalities of the App. This includes creating, editing, synchronizing, and displaying your shopping lists and related content; saving your configuration; and ensuring that the service works as described in our documentation and user interface.
- Personalize your experience. For example, remembering your preferred language and settings, showing you lists and products you recently used, and suggesting options based on your previous activity, always within the scope of ShopyList’s functionalities and without building marketing profiles unrelated to the App.
- Synchronize lists across devices and with authorized people. When you choose to share a list or collaborate with others, we process the necessary data (such as list identifiers, email or user identifiers, and changes made) so that all authorized participants see updated information on their devices and can work on shared content.
- Maintain security and prevent misuse. This includes detecting and mitigating fraud, abuse, or unauthorized access; protecting the integrity and availability of our systems; and monitoring activity patterns that may indicate technical or security issues. For example, we may analyze logs to detect repeated failed access attempts or abnormal traffic.
- Improve the App and develop new features. We analyze aggregated or pseudonymized usage data and technical logs to understand how ShopyList is used, prioritize improvements, resolve errors, and measure the impact of changes or new functionalities. Whenever possible, we apply techniques such as minimization and aggregation to reduce privacy risks.
- Communicate with you. We may send you strictly necessary service messages, such as security alerts, important changes to the App or to this Privacy Policy, or responses to your support requests. We will not send you marketing communications through the App unless you have clearly agreed to receive them and you can opt out at any time through the channels provided.
- Comply with legal obligations and respond to valid requests. For example, keeping minimal records necessary to comply with accounting or tax rules, combating fraud, or responding to legitimate requests from competent authorities, courts, or regulators, in accordance with applicable law and subject to appropriate safeguards.
Legal bases for processing
When data protection laws require it, we only process your Personal Data when we have a valid legal basis. Depending on the context, this may include:
- Your consent. In situations where you actively choose to provide or enable certain data, such as when you create an account, enter optional profile information, enable location services, or agree to receive specific communications. You can withdraw your consent at any time through the settings of the App or your device, or by contacting us. Withdrawal of consent does not affect the lawfulness of processing carried out before that withdrawal.
- Performance of a contract or pre-contractual steps. We process data that is strictly necessary to provide the service you requested under our Terms and Conditions, for example to create and maintain your account, synchronize your lists across devices, show your content, or deliver other core features of the App that you choose to use.
- Legitimate interests. We may process certain technical, usage, and security-related data to improve and protect the App, to understand how it is used, and to develop new functionalities, provided that these interests are not overridden by your fundamental rights and freedoms. When we rely on legitimate interests, we assess the impact on your privacy and apply appropriate safeguards, such as minimization, aggregation, or pseudonymization of data, and access controls.
- Compliance with legal obligations. In some cases, we must process and retain certain information to comply with obligations arising from applicable laws, regulations, or judicial and administrative decisions, including those related to personal data protection, consumer protection, accounting, security, or the duty to cooperate with competent authorities.
The following sections of this Privacy Policy provide additional details about how we share data, how long we keep it, which rights you have, and how you can exercise them.
Personal data and security
Sharing and transfers
We treat your Personal Data as confidential and only share it when it is genuinely necessary for the purposes described in this document, when you have given your consent, or when we are legally required to do so. In particular, we may share data as follows:
- Technology providers. We use trusted third-party service providers for functions such as authentication, data hosting and storage, analytics, notifications, and crash reporting. These providers process Personal Data on our behalf, under written agreements, and are required to apply appropriate technical and organizational measures to protect your information. We do not authorize them to use your data for their own unrelated purposes.
- Authorities and legal requirements. We may disclose limited information when we reasonably believe that such disclosure is necessary to comply with a legal obligation, a court order, or a valid request from competent authorities, or to protect our rights, the rights of other users, or the security of the service in accordance with applicable law.
- No sale of Personal Data. We do not sell your Personal Data. We may use aggregated or anonymized information, which does not allow you to be identified, for statistical or analytical purposes.
- International data transfers. Our hosting providers and technology partners may be located in different countries. When this implies transferring Personal Data to jurisdictions with different levels of protection, we take reasonable steps to implement safeguards consistent with applicable regulations, such as contractual commitments, minimization of data, and security controls, so that your information remains protected.
Security and retention
We apply reasonable security measures designed to protect your information against unauthorized access, loss, misuse, or alteration. These measures may include encryption in transit, restricted access based on roles, authentication controls, and monitoring of our systems. However, no system is completely infallible. For this reason, we also depend on you to help keep your information secure by:
- Using strong and unique passwords for your accounts.
- Keeping your devices, operating system, and applications updated.
- Informing us promptly if you suspect any unauthorized access or incident related to ShopyList.
We keep your data only for as long as it is necessary for the purposes described in this document or for the period required by applicable law. In general:
- We keep account-related data while you maintain an active account.
- We may retain certain information for a reasonable additional period after you close your account in order to comply with legal obligations, resolve disputes, enforce our terms, or maintain necessary technical and security logs.
- When data is no longer needed, we delete it or irreversibly anonymize it, applying reasonable measures to prevent re-identification.
Rights and requests
Depending on the laws that apply where you live, you may have one or more of the following rights regarding your Personal Data:
- Access: to obtain confirmation of whether we process your data and receive a copy of it.
- Rectification and update: to correct inaccurate data or complete incomplete information.
- Deletion (“erasure”): to request that we delete certain data, subject to legal limitations.
- Restriction: to request that we temporarily limit certain types of processing.
- Portability: to receive certain data in a structured, commonly used, and machine-readable format, and to transmit it to another controller where technically feasible.
- Objection: to object to certain processing based on legitimate interests.
- Withdrawal of consent: to withdraw your consent at any time when processing is based on consent.
To exercise your rights, you can contact us at shopylist.app@gmail.com and clearly indicate:
- Your request (for example, access, correction, deletion).
- The email address associated with your ShopyList account.
- Any additional information we reasonably need to verify your identity.
We will review and respond to your request within a reasonable time and in accordance with applicable laws. In some cases, we may not be able to fully comply with your request—for example, if we must retain certain data to comply with legal obligations or to defend legal claims—but, in those cases, we will explain the main reasons, to the extent allowed by law.
Account and data deletion
If you decide that you no longer want to use ShopyList, you can request that we delete your account and the associated Personal Data. We try to keep this process simple and transparent, while also protecting you against unauthorized deletion requests.
You can request deletion by writing to shopylist.app@gmail.com and including:
- The email address registered with your ShopyList account.
- A clear statement that you want us to delete your account and associated data.
Before completing the deletion, we will carry out a basic validation to confirm that the request actually comes from the account holder, for example by:
- Asking you to send the request from the same email address registered in the account, and/or
- Sending a confirmation message to that email address and requiring a simple confirmation step, and/or
- Requesting that you perform a verification action through the App, when available.
We do not accept deletion requests from third parties who cannot prove that they are acting on your behalf with proper authorization.
Once we have verified your identity and confirmed the request:
- We will delete or irreversibly anonymize the account, your lists, products, notes, and other personal content associated with your profile from our active systems, normally within a short period (for example, a few business days), except where the law requires a longer retention.
- We will send you a confirmation email when the process has been completed.
Contact
If you have questions about these terms, privacy, or how your data is handled, contact us.