# Trlly privacy policy Version: `v1.3.0` Published at: https://trlly.co.uk/legal/privacy-policy/v1.3.0 Supersedes: `v1.2.0`. Earlier versions remain available. ## 1. Who we are Trlly is the data controller. Contact privacy@trlly.co.uk about your data or support@trlly.co.uk about the service. This version adds Tesco product and basket collection alongside Ocado. It does not enable Tesco receipt collection, commercial use or billing. ## 2. Reading without contributing You can read available price history without an account. History requests identify the product you ask for, but do not submit a price observation or basket. Trlly does not track browsing across unrelated websites. Its retailer content scripts are limited to `www.ocado.com` and `www.tesco.com`. Local display preferences and basket organisation can remain in browser storage. ## 3. Account and contribution records | Record | Purpose | Retention | |---|---|---| | Email and authentication records | Sign-in and account security | Until account deletion | | Settings, watches and alert records | Your chosen Trlly features | Until removed or account deletion | | Consent versions, text references, grants and withdrawals | Record and enforce your choices | Until account deletion | | Product observations, retailer, prices and catalogue attributes | Public product history and trends | While useful for product history; contributor link removed on account deletion | | Search query, result count, product position and sponsored placement | Search-result and product tracking | Under the product contribution retention rules | | Basket products, quantities, prices, totals and capture dates | Your basket savings | Until basket or account deletion | | Enabled Ocado receipt captures and scrambled receipt identifiers | Your private paid-price history | Until receipt or account deletion | | Submission source, counts, outcomes and timestamps | Rate limits and audit | Under the service's audit retention rules | The contribution terms list catalogue fields, including brand, barcode, pack size, promotions, stock, ratings, nutrition, ingredients and allergens where available. Clubcard prices are separate from Smart Pass prices. Search queries come from supported search pages, not keyboard monitoring. Product submissions carry account and pseudonymous identifiers for consent and deletion checks. They are not anonymous while those links exist. Public price history does not reveal who contributed it. Basket and receipt rows belong to your account. Other members cannot read them. ## 4. What we exclude We do not collect retailer credentials, cookies, sessions, contact details, delivery addresses or instructions, payment details, raw order numbers or arbitrary form contents. We read named catalogue fields, not complete retailer application caches. Account, checkout and payment routes are excluded from product collection. Baskets use separate route and consent checks. Ocado receipt capture, when enabled, reads only `/orders` and `/orders//details`. It excludes delivery, refund, payment and settings pages. Tesco receipt collection remains disabled. Food purchases can reveal sensitive information. We do not infer health, religion or other sensitive traits from your basket or receipts. ## 5. Uses and service providers We use contributions to provide price history, trends, badges, watches and your basket savings. Receipt information serves your private paid-price history, not public shelf-price history. Features may remain gated while they await verification. Consent does not turn those gates on. Supabase hosts authentication, database and function services. Trlly sign-in tokens go to those services, never to retailer pages. Stripe integration remains disabled. The extension does not use advertising or analytics SDKs. Commercial use of community contributions remains off. This version does not authorise selling or transferring shopping data, including aggregate data derived from it. Any proposal to change that needs separate policy review and fresh consent. Purchase history is never sold or used in commercial reports. ## 6. Control and deletion Contribution uses consent. The server checks product-price, basket and purchase-history scopes separately. Adding Tesco widens the first two scopes and requires fresh acceptance. You can stop contributing in the extension, withdraw consent, delete baskets or receipts, or delete your account. Account deletion removes your account data and severs links to retained product observations. Public product history may remain. Reading that history does not require contribution. Clearing local extension storage removes local preferences and organisation, but does not itself delete server records. You may request access, correction, erasure, restriction, portability or object to processing by emailing privacy@trlly.co.uk. You can complain to the Information Commissioner's Office at ico.org.uk. ## 7. Security and changes Server functions validate submissions, derive identity from the signed-in session, check consent and enforce limits. Database access rules restrict private records to their owner. Anonymous clients cannot write contributions directly to tables. Public history does not expose authentication or contributor data. We retain versioned documents and checksums. Material changes require fresh consent for the affected collection scope. Earlier accepted versions remain available. If software behaviour conflicts with this policy, contact us.