PrivacyTermsSupportΕΛ

Privacy policy

Effective October 11, 2026. Applies to the naparo app (Android and web).

1. Who is responsible

The data controller is DATANODE & ΣΙΑ Ε.Ε. (limited partnership), Navarchou Votsi 69 & Psaroudaki 5, 104 45 Athens, Greece, VAT ID 800479159, GEMI No. 124699901000. For data matters write to gdpr@naparo.gr.

2. What data we process

AccountEmail, name (optional), unique user ID. If you sign in with Google, we receive your email and name from your Google account. Your password is held by the authentication service (Firebase Authentication) and we cannot see it.
ContentLists, products (name, quantity, price, weight, note), categories, aisles, your “My products” collection and the barcodes you link to products.
SettingsTheme, language, color, font and other preferences, on your device and in your account.
SharingWhen you share a list, its members see your name and email.
TechnicalIP address and technical identifiers processed by Google/Firebase services to run the service and keep it secure.
CameraOnly when you choose to scan a barcode (Android). Images are not stored or sent; only the code number is read.

We show no ads, we do not sell data and we do not build advertising profiles.

3. Why, and on what legal basis

To provide the service (performance of a contract, Art. 6(1)(b) GDPR), for security and abuse prevention (legitimate interests, 6(1)(f)), and, for the camera, with your permission on the device. If paid features are offered, we also keep data required for tax obligations (6(1)(c)).

4. Who we share data with

Google (Firebase): hosts the database, authentication and the web app, as a processor. Data may be transferred outside the EEA with the appropriate safeguards.
Open Food Facts: when a barcode is not among your products, its number is sent to the public openfoodfacts.org database to find the product name. We do not send account details.
Google Play: if payments are offered, Google handles them; we do not receive card details.
Members of shared lists: as described above.
Service administrators can access account details (email, name, usage limits) only for support and administration.

5. How long we keep data

As long as you have an account. When you delete it (see how), your account, profile, lists you own, product collection, categories and aisles are deleted. You are removed automatically from other people's lists. Any backups held by the infrastructure provider expire under their own lifecycle.

6. Your rights

You have the right of access, rectification, erasure, restriction, objection and portability (e.g. CSV export in the app). Send a request to gdpr@naparo.gr; we reply within one month. You may also lodge a complaint with the Hellenic Data Protection Authority.

7. Security

Communication is encrypted (HTTPS), data access is protected by security rules, and each user sees only their own data and the lists shared with them.

8. Children

The app is not directed to children under 15 and we do not knowingly collect their data.

9. Changes

If this policy changes we will update this page and, for material changes, notify you in the app.