Privacy & Cookie Policy

Last Updated: 29 March 2026

GrubScan, a service provided by ArKoDo Group ("we", "us", or "our"), is committed to protecting the privacy of our users. This policy explains how we collect, use, and protect your data, as well as our use of cookies, in compliance with UK GDPR and PECR.

1. Data We Collect

We collect information necessary to provide food intelligence services and manage your subscription:

Account Data: Name, email address, and hashed passwords.

Billing Data: Processed securely via Stripe. We do not store full credit card numbers on our servers.

Usage Data: IP addresses, browser types, and API usage logs for security, billing calibration, and rate limiting.

Uploaded Content: Food photos submitted for AI analysis, stored in secure, tenant-specific directories.

2. How We Use Your Data

We use your information to:

  • Provide the Service: Deliver food search, barcode lookups, and AI scans.
  • Billing & Support: Manage subscriptions, prevent fraud, and respond to support queries.
  • Platform Improvement: Use anonymised usage data and aggregated scan results to improve our AI vision models and platform performance.
  • Market Insights: We may use anonymised, non-identifiable aggregate data for market research. We do not sell personal data to third parties.

3. Third-Party Processors

To deliver GrubScan, we share specific data with the following sub-processors:

Stripe: For secure payment processing and subscription management.

AI Vision Providers (OpenAI/Novita): Photos are sent to these providers for nutritional identification.

Open Food Facts: Barcode data may be shared to retrieve product info when not found in our local database.

4. Data Retention & Deletion

Active Accounts: We retain data as long as your tenant account is active.

Soft Deletion: If a tenant or member is deleted, data is "soft-deleted" and may be recoverable by a Super Admin for a limited period before permanent purging.

Individual Scans: Photos are stored so you can access your history. You may delete individual scan records at any time via the dashboard or API.

5. Your UK GDPR Rights

Under UK law, you have the right to access, correct, or erase your personal data. You may also object to processing or request data portability. To exercise these rights, please contact gdpr@grubscan.io.

6. Cookie Policy

We use cookies to ensure GrubScan functions correctly and securely. By using our site, you agree to our use of the following cookies:

Strictly Necessary Cookies

These are essential for the website to function (e.g., keeping you logged in). They cannot be switched off.

Cookie Name Provider Purpose Duration
grubscan_session GrubScan Maintains your login session across the dashboard. Session
XSRF-TOKEN GrubScan Security cookie used to prevent CSRF attacks. 2 Hours
stripe_mid Stripe Used for fraud prevention and secure payment processing. 1 Year

Functional & Performance Cookies

These help us remember your preferences or improve site performance.

Cookie Name Provider Purpose Duration
remember_web_... GrubScan Optional "Remember Me" login preference. 5 Years
ai_scan_pref GrubScan Remembers your preferred AI provider settings. 1 Month

Managing Cookies: You can manage or block cookies through your browser settings; however, disabling strictly necessary cookies will prevent you from accessing the GrubScan dashboard.

7. Contact Us

For any questions regarding this policy or your data, please contact:

ArKoDo Group

[Insert Registered UK Business Address]

Email: contact@grubscan.io