🛒 Apuntao

Privacy Policy

Last updated: July 2026

1. Data controller

The controller responsible for the personal data collected through the Apuntao application is:

Fernando González García
Email: apuntao.privacidad@tindeka.com

2. Data we collect

When you use Apuntao we collect the following personal data:

Additionally, when you scan or add products to the shopping list, we record the product name and its barcode in a fully anonymised way for statistical purposes. This data is never linked to your identity.

3. Purpose of processing

Personal data is used exclusively to:

Anonymised product data is used to produce aggregate consumption statistics. It is never associated with identified or identifiable individuals.

4. Legal basis

The processing of your data is based on the performance of the contract you accept when registering (Art. 6(1)(b) GDPR) and on your explicit consent given during the registration process (Art. 6(1)(a) GDPR).

5. Data retention

Your personal data is kept for as long as you maintain an active Apuntao account. If you delete your account, all of your personal data is erased immediately and irreversibly.

6. Sharing data with third parties

Your personal data is not shared or sold to third parties. We do not use analytics or advertising services that access your personal data.

Optional sign-in via Google is handled by Google LLC under its own privacy policy. In that case, Google only provides us with your name and email address in order to create your account.

Optional sign-in via "Sign in with Apple" is handled by Apple Inc. under its own privacy policy. In that case, Apple only provides us with an identifier and, if you authorise it, your name and an email address — which may be an Apple private relay alias if you choose to hide your email — in order to create your account.

7. Your rights

Under the GDPR and Spanish data protection law (LOPDGDD), you have the right to:

To exercise any of these rights, write to us at apuntao.privacidad@tindeka.com.

If you believe the processing does not comply with the GDPR, you have the right to lodge a complaint with the Spanish Data Protection Agency (aepd.es) or with the supervisory authority in your country of residence.

8. Security

Data is stored on servers located in the European Union. Passwords are stored encrypted using bcrypt and never in plain text. Communications between the app and the server use HTTPS.

9. Changes to this policy

Any material change to this policy will be notified to users through the application.