TRLLY Get Extension

Contribution terms

CONTRIBUTION
TERMS

Version: v1.2.0

Published at: https://trlly.co.uk/legal/contribution-terms/v1.2.0

Supersedes: v1.1.0 (2026-08-11) and v1.0.0 (2026-08-11), which stay on record

This version has been superseded and is published only so that anyone who accepted it can still read what they agreed to. It is not the version in force.

If this document and the software ever disagree, the software is wrong and we want to hear about it: privacy@trlly.co.uk.

The short version

Trlly records the prices shown on the Ocado pages you visit, the items in your basket, and — this is new — what you actually paid, from your own Ocado order history.

Your order history is used for one thing: showing you your own shopping. "You paid £2.50 for this, it's £3.00 now", and price history depth for you. We do not sell it, and we are not going to. Chrome's rules for extensions prohibit selling or handing user data to third parties, and no amount of agreeing on your part can change that — so rather than ask you for permission we could not use, we are telling you it is off the table.

That is a narrower promise than we make about basket contents in section 5, and the difference is deliberate.

v1.1.0 of this document said we would never collect your order history. This version changes that, which is why we are asking you again rather than assuming your last yes still covers it.

You can say no and still use everything you can see without an account. You can change your mind at any time, and stopping takes one click.

1. What we collect

From product pages you visit: the product number and name, barcode if the page publishes one, category, image, the price shown, the previous price if it's on offer, Smart Pass and unit prices, the offer text, and whether it said "in stock". Plus when we saw it, which kind of page it came from, and how confident our parser was.

From your basket page: each line — product, quantity, price per unit, line total, previous price and offer if there is one. Plus the subtotal Ocado showed, so we can check our own arithmetic.

From your order history: for each order, the date and each line on the receipt — product, quantity, the price you actually paid, the line total, the pre-offer price where the receipt shows one, and whether the item was delivered, substituted, missing or returned. Plus the order total Ocado showed, so again we can check our arithmetic.

If our numbers don't match the page, we throw the capture away rather than store something that looks right and isn't.

From your use of Trlly: which graphs and links you interact with, in Trlly's own interface. Never what you do on Ocado.

That's the whole list. The database rejects anything else.

2. Which pages we read, and which we refuse to open

This is the part that actually protects you, so it's worth being specific.

Order collection reads exactly two web addresses:

  • ocado.com/orders — your list of orders
  • ocado.com/orders/<order number>/details — the receipt for one order

Every other page is excluded by its address and is never read at all. Not filtered, not stripped, not "we ignore those fields" — never opened. That includes:

  • ocado.com/orders/<order number>/delivery — this is the page with your delivery address and delivery instructions on it
  • ocado.com/orders/<order number>/refund-request
  • ocado.com/checkout and ocado.com/checkout/summary
  • ocado.com/failed-payment/...
  • ocado.com/addresses and ocado.com/settings/...

We chose it this way round on purpose. The alternative — read every page and filter out the sensitive bits — breaks silently the first time Ocado renames a field, and you'd never know. A list of allowed addresses fails the safe way: a page we haven't named doesn't get read.

3. What we never collect

  • your Ocado username, password, cookies or session
  • your name, address, phone number or delivery details
  • your delivery slot or delivery instructions
  • card, bank or payment details
  • your Ocado order number itself — the extension turns it into a scrambled value in your browser and only that leaves your computer, so we can tell two captures of the same order apart without ever holding the number
  • anything you type into forms
  • anything on any website other than www.ocado.com

We also don't try to work out anything about your health, religion or private life from what you buy, and we won't build products that do.

4. Your shopping says a lot about you

Worth saying plainly: a food shop can reveal medication, allergies, religious dietary choices, pregnancy, alcohol use, and roughly how many people you feed. Three months of orders says it more clearly than one basket does, because it shows what you buy repeatedly rather than once.

That's why this is described here rather than buried, and why we don't sell anything that could be traced to one person. If you'd rather we didn't have it, don't accept — you keep price history, graphs, watches and alerts either way.

5. What we do with it

For everyone: price history, trends, coverage figures and price-drop alerts. Product information only — never who saw it.

For you: your basket savings, and "compare at price" — what you paid last time beside what it costs now. Only you can see your orders.

Your order history is never sold. Not in aggregate, not anonymised, not grouped, not any other way. There is no report it feeds and no view that reads it, and the database refuses to reclassify it as sellable. If that ever changed it would need a new version of this document, and honestly it isn't going to, because Chrome's Limited Use rules for extensions prohibit it outright and treat your agreement as irrelevant to the question.

Basket contents are different, and you should know the difference. We do intend to sell aggregate insights built from basket data — how often a product is discounted, what gets bought together. That is switched off today and turning it on needs a new version of this document and a fresh yes from you. When it is on, four things limit it, each built into the database rather than promised here:

  • No identity. The commercial view of basket data has no account id and no contributor id in it. Baskets are grouped by a scrambled key.
  • Dates, not times.
  • Small groups are hidden. A product is left out entirely until at least five different people have it.
  • It returns nothing at all while the switch is off.

We don't sell records about individuals, and we don't sell anything that would let a buyer reconstruct one person's shopping.

6. Price paid is not the same as price on the shelf

Your receipts contain real prices from before you installed Trlly — Ocado keeps about three months.

But what you paid isn't what the shelf said. Multibuys allocate across lines, weighed items settle up at the till, and substitutions change what arrived. So we keep the two apart: prices from your receipts are stored separately and are never folded into the public price history other people read. Your receipts improve what *you* see. They don't become everyone's price history, and they don't become anybody's report.

One thing consent can't undo, and it applies to the basket data in section 5 rather than to your orders: once a figure is published in an aggregate report, deleting your data removes you from future reports but can't withdraw one already issued. That's true of all statistics; we'd rather say it.

7. Saying yes, and saying no

Accepting this turns contribution on. One decision covers everything in section 1 — there's no second screen.

To stop: switch contribution off in the extension. It takes effect immediately, and the server refuses anything further from your account.

To remove what's already there: you can delete your stored baskets and your stored order history at any time from the extension, separately or together. Price observations stay, because they're anonymous product facts other people's price history depends on.

To delete everything: delete your account. That removes your profile, watches, alerts, baskets, orders and consent records, deletes your login, and permanently cuts the link between you and every price observation you sent.

8. How you're identified

Price observations carry a pseudonymous identifier — a one-way hash of your account id — plus your account id, so we can check consent and honour deletion.

Basket lines and order lines are stored against your account directly. There's no pseudonymisation on the stored row, because the features only work if we can show you your shopping and nobody else's. The database restricts every row to the account that owns it, and the write path takes your identity from your signed-in session rather than believing a claim from your browser.

Pseudonymisation applies when this data reaches an aggregate view, not before. None of this is anonymous and we won't call it that.

9. The legal bit

Trlly is the data controller. The legal basis is your consent — this version, with a timestamp. We store the full text you accepted with a checksum, so what you agreed to can be evidenced later even if the website changes.

You can withdraw at any time, for any reason or none, without losing read access to price history.

10. What we don't promise

Prices are what a web page showed at a moment in time, read by a parser that can be wrong. We record a confidence score and show freshness. Trlly is not a substitute for the price at checkout.

Observations from before 11 August 2026 are marked legacy-0.0.0 and are unreliable for stock, Smart Pass pricing and category. They're excluded from commercial use for that reason.

We don't currently compare against any other supermarket. If we ever do, we'll show the basis for any saving we quote.

11. Fair use

Don't submit fabricated observations or captures, or submit faster than ordinary browsing would. Ingestion is rate limited and audited per account.

12. Trlly and Ocado

Trlly is independent — not affiliated with, endorsed by, or operated by Ocado. "Ocado" and "Smart Pass" belong to their owner and are used only to describe what the extension does.

Ocado's own terms say the material on their website is for your personal use in placing orders, and that commercially exploiting it needs their written permission. Trlly reads those pages in your browser, as you, while you are looking at them. We think that is a materially different act from crawling the site, but we are telling you what their terms say so the decision to contribute is an informed one rather than a surprised one.

13. Changes

Every version has a version string and is stored with its full text. Material changes get a new version, contribution stops until you accept it, and your old acceptance doesn't carry over. We don't quietly widen what you agreed to — which is exactly why this version exists rather than a quiet edit to v1.1.0.

14. Contact

  • Privacy and data requests: privacy@trlly.co.uk
  • Anything else: support@trlly.co.uk

Checking this text is the text you accepted

Trlly stores the full text of every version in its database together with a SHA-256 checksum of it, and records which version you accepted and when. The text on this page is that stored text, rendered.

Byte-for-byte source: /legal/contribution-terms/v1.2.0.txt

SHA-256 of that source: 4e911a4607ed982760c945469932d790de31abf124c81c6eaeb587e111a11cdf

The related document is the privacy policy.

TRLLY

Track prices. Spot deals. Save money.

Privacy policy Contribution terms Terms of Service

© Trlly. Not affiliated with Ocado or Tesco.

Made with ❤ in the UK