Privacy Policy
This Privacy Policy explains how HyenaPack LLC (“MyListResort”, “we”, “us”, or “our”) collects, uses, discloses, retains, and protects personal information when you use our websites, applications, and related services (the “Service”). HyenaPack LLC is the controller or business responsible for the practices described here, unless another notice says otherwise.
1. Information you provide
- Account and settings: email address, display name, authentication information handled by our authentication provider, acceptance records for our Terms, timezone, reminder hour, theme and app preferences. We do not receive your password in readable form. If Google sign-in is enabled and you choose it, Google and our authentication provider may supply an account identifier, email, name, and profile image.
- Household content: list and board names, items, quantities, notes, categories, dates, freshness choices, recipes and ingredients, maintenance tasks, chores, assignees, allowance tallies, completion state, and other content you enter or import.
- Sharing and activity: invitations, household memberships, roles, ownership, and records of changes made on shared lists.
- Communications: name, email, topic, message, and any optional exit-survey answers you submit through support, feedback, billing, privacy, or account-deactivation forms.
- Billing: plan, trial and subscription status, Stripe customer and subscription identifiers, price and renewal details, invoice and payment status, and billing-support history. Stripe collects payment-card details on its hosted pages; we do not receive or store your full card number.
2. Information collected automatically
- Service and security logs: request date and time, network and IP address, browser or user-agent information, requested host/path, response status, and diagnostic or security events collected by our hosting, database, and infrastructure providers.
- Error and crash reports: when something goes wrong inside the signed-in app, we send an error report to Sentry, an error-monitoring service hosted in the United States. A report contains the error and where in the code it happened, the page address, browser and device information, and the release you were running. We configure it to leave out your account details, cookies, request headers and bodies, address query strings, and the contents of your lists.
- First-party product events: event type (for example, list created, freshness set, invite accepted, or upgrade clicked), account ID when signed in, time, and limited counts or categories needed to understand feature use. We intentionally exclude list names, item names, notes, and message text from product-event metadata.
- Site and app-shell analytics and attribution: page path, including authentication and other app-shell routes, a short campaign tag in a link, and a coarse source category derived from the referring hostname (for example, search, direct, or a named referral platform). Cloudflare Web Analytics may also process ordinary web-analytics information about visits, devices, and performance on HTML responses for both the public site and app shell.
- Barcode requests: the barcode you choose to scan and product lookup responses. Lookup requests may be sent to USDA FoodData Central and UPCitemdb through our server, and to Open Food Facts from your browser.
- Notification data: if you enable push notifications, a push endpoint and encryption keys, notification preferences, device/browser description or label, timezone, reminder hour, and delivery records. Notification text, including list/item names, assignments, or activity, may appear on a lock screen or other device surface controlled by your operating system.
3. Connected Google calendars (optional)
If your plan includes calendar sync, you can connect your Google account so events from calendars you choose appear inside MyListResort. This is optional, off by default, and separate from Google sign-in. We request read-only Google Calendar permissions: the list of calendars on your account, and event details for the calendars you select.
- What we store: for each selected calendar, events inside a rolling window of roughly 30 days past and 180 days ahead, limited to event title, start and end, location, status, calendar name and color, and the email address of the connected account. We do not store event descriptions, attendee lists, or attachments. A Google credential that lets us refresh this data is stored encrypted and is never shown in the app.
- How we use it: only to display your events beside your household dates in the app calendar and to keep them current on a periodic schedule. Synced events are view only in the app; to change one, you edit it in Google Calendar.
- Who can see it: only you. Synced events are not shared with other household members, are not used for advertising or profiling, are not used to train artificial-intelligence models, and are not sold. They are processed by the infrastructure providers that host the Service (Section 6), and we do not allow humans to read them except for security, abuse investigation, support you request, or where law requires.
- Your controls: choose which calendars sync, pause a calendar by unselecting it, or disconnect the account at any time from the Profile page. Disconnecting deletes the stored credential and all synced events. You can also revoke access in your Google Account security settings, which stops the sync from our side at its next attempt. Synced events age out automatically as the rolling window moves.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
4. Browser and device storage
The Service uses local storage, session storage, service-worker caches, and similar browser storage for authentication sessions, your selected list, theme and color preferences, view/sort/filter choices, collapsed sections, recently used hints, pending invitations or imports, campaign/source attribution, barcode-result cache, route recovery, and installed-app files. These technologies help the app remember your choices and work reliably. They are not third-party advertising cookies.
Browser storage can remain on a shared device after you close the app. Sign out when you are finished and use your browser or device controls to clear local app data if needed.
5. How we use information
- create and authenticate accounts and record legal acceptance;
- store, sync, organize, share, import, and export household content;
- provide suggestions, product lookups, freshness estimates, and reminders;
- manage invitations, permissions, subscriptions, trials, payments, and refunds;
- operate, troubleshoot, secure, prevent abuse of, and improve the Service;
- measure public-site and feature performance and understand acquisition sources;
- respond to support, feedback, privacy, and legal requests; and
- enforce our Terms and comply with legal, tax, accounting, and safety obligations.
6. When we disclose information
- People you choose: household content, display names, assignments, and activity are disclosed to members of the relevant shared list. Those members can retain copies of information they were allowed to see.
- Service providers: Supabase provides managed database, authentication, realtime sync, and server functions; Cloudflare provides hosting, delivery, security, analytics, request logs, and email delivery; Sentry provides error and crash monitoring as described in Section 2; Stripe provides checkout, billing, fraud prevention, and payment processing; Google may provide optional sign-in and, if you connect it, Google Calendar data as described in Section 3; and your browser’s or device’s push service delivers notifications. These providers process information for the purposes described here under their own terms and our arrangements with them.
- Data and content sources: when you request a barcode lookup or third-party import, relevant identifiers or URLs and ordinary network information may be disclosed to USDA FoodData Central, Open Food Facts, UPCitemdb, or, when a server-side import feature is enabled, the website you direct the Service to access.
- Authorized operations and support: a limited number of authorized administrators may search accounts, review account or household data needed to investigate a request, and use audited support impersonation or deletion tools. Access is limited to support, safety, security, billing, legal, and operational purposes.
- Legal, safety, and corporate events: we may disclose information when reasonably necessary to comply with law or legal process, protect rights and safety, investigate abuse or security incidents, collect amounts owed, or complete a financing, merger, acquisition, reorganization, or sale of assets. A recipient in a corporate event may use information subject to this Policy or a notice of changes.
7. Legal bases (EEA, UK, and similar laws)
Where the GDPR or UK GDPR applies, we process personal data on these bases: contract, to provide the account and features you request; legitimate interests, to secure, support, measure, and improve the Service and communicate with you, balanced against your rights; consent, where the Service asks for it, such as device permission for push notifications; and legal obligation, such as tax, accounting, and lawful-request requirements. We may also process information to establish, exercise, or defend legal claims and to protect vital interests when applicable. You may withdraw consent through the relevant device setting or by contacting us, without affecting earlier processing.
8. International transfers
We and our providers may process information in the United States and other countries whose laws may differ from yours. Where a law requires a transfer mechanism, we and our providers use a legally recognized mechanism or other appropriate safeguard. Contact us if you need more information about safeguards relevant to your information.
9. Retention
We keep information for as long as reasonably necessary for the purposes described above, then delete, anonymize, or isolate it unless a longer period is required for legal, tax, accounting, security, fraud-prevention, dispute, or backup purposes. Retention depends on the record:
- account, current household content, memberships, and settings are generally kept while the account is active;
- shared-list activity is automatically pruned over time; records older than about 180 days are generally removed, although a small recent history may remain;
- notification delivery logs are generally removed after about 60 days;
- item-name suggestion history is kept while it remains associated with the account or a list and may be pruned when it is no longer useful;
- cached barcode results are reused in that browser for about 30 days after a successful lookup and 7 days after a miss. Expired entries may remain in browser storage until replaced, evicted by the browser, or cleared with site data, but the Service does not rely on them as current results; and
- billing, legal-acceptance, security, support, analytics, and transaction records are kept for the period reasonably needed for their purpose and applicable law.
Provider backups and logs may persist for a limited time after data leaves active systems. Information that has been aggregated or deidentified so it no longer identifies you may be retained and used for legitimate purposes.
10. Deactivation and permanent deletion
The in-app Deactivate account action is not permanent erasure. It removes your memberships, deletes owned lists you do not transfer, replaces your display name with a generic label, removes registered push devices, notification preferences and delivery logs, removes your personal item-suggestion history, disconnects any connected calendar and deletes the events synced from it, disconnects your account from first-party product events, blocks all existing sessions from product access, and signs out this device. We retain the authentication account and email; profile and app settings; legal acceptances; billing, subscription and transaction records; support, privacy and exit-survey communications; and authorship or activity references that remain on content kept by other members. Security logs and backups may also remain for the periods described above. Signing in again with a new session reactivates the login and profile, but does not restore memberships, notification settings, suggestion history, or deleted lists.
Deactivation does not cancel a subscription or create a refund. The in-app flow requires Stripe to confirm that future renewal is canceled before deactivation can continue. Paid-through access and billing records may remain through the applicable period and for lawful accounting, tax, dispute, and transaction-record purposes.
You can permanently delete your own account from the Profile page, under Delete account permanently. We ask you to confirm your email address and re-confirm who you are before anything is deleted, and a live subscription is cancelled first. If you cannot sign in, use the privacy contact form instead and we will verify the request before acting on it. Either way we delete or anonymize covered account data unless retention is permitted or required by law. Content owned by another household member may remain, and other members may retain copies they previously made. A fuller description of what is removed and what is kept is on the account deletion page.
We keep a deletion receipt. It records that the account was deleted, when, the email address the account used, and a reference to any subscription it held. It contains none of your list, item, or message content. We retain it on the basis of our legitimate interest in being able to demonstrate that a deletion request was carried out, and to resolve billing or dispute questions that arrive after the account is gone.
After permanent deletion, we may retain a minimal, pseudonymous legal-acceptance receipt containing the former account identifier, document versions, acceptance time, and acceptance surface for the period reasonably needed to establish, exercise, or defend legal claims. The live authentication-account link is removed.
Some records survive deletion in a form that is no longer linked to you. First-party product events remain as aggregate counts with the account link removed. A support, privacy, or exit-survey message you sent keeps only its coarse topic, with your name, address, and the text you wrote removed. Delivery logs keep their internal reference but not your email address. Billing and transaction history is held by our payment processor, Stripe, for accounting, tax, and dispute purposes; the subscription record in our own database is deleted with your account.
Deleting from the Profile page takes effect immediately. A request sent through the contact form is actioned once we have verified it, and we aim to complete it within 30 days.
11. Your privacy choices and rights
Depending on where you live, you may have rights to access, correct, delete, obtain a portable copy, object, restrict, or withdraw consent, and to appeal our response. The in-app export provides list names, item basics, and categories; use the contact process for a broader access or portability request.
You can edit your display name, manage notifications and devices, export the described list data, deactivate the account, or contact us through the privacy form. Tell us the right you want to exercise and the jurisdiction you live in. We may ask for information reasonably necessary to verify you and may deny or limit a request where law permits. To appeal a denial, reply to our response or submit a new privacy message labeled “Appeal.” Authorized agents may submit requests where applicable, subject to verification of their authority and your identity.
We will respond within the time required by applicable law and will not discriminate against you for exercising a privacy right. EEA/UK residents may also complain to their local supervisory authority. California and other U.S. state residents may have rights to know, correct, delete, and obtain covered data. Because we do not sell personal information or process it for targeted advertising, there is no sale or targeted-advertising opt-out to exercise for this Service.
12. Children
The Service is a general-audience service and is not directed to children under 13. Children under 13 may not create or use an account, and we do not knowingly collect personal information directly from them. A parent or guardian may add a younger child’s name, chore, or assignment through the adult’s account; we treat that as household content controlled by the account holder. If you believe a child under 13 created an account or submitted information directly, contact us so we can investigate and delete it as appropriate.
13. Security
We use administrative, technical, and organizational safeguards designed for the nature of the Service, including encrypted network transport, authentication, database access controls, and restricted administrative functions. No system is completely secure. We cannot guarantee that unauthorized access, loss, or misuse will never occur. Protect your account and device, use a unique password, and notify us if you suspect a problem. We will provide legally required security notices.
14. Automated decision-making
We do not use personal information to make solely automated decisions that produce legal or similarly significant effects. Suggestions, limits, freshness estimates, and reminders are product functions and should be reviewed by you.
15. Third-party sites and services
This Policy does not govern a third party’s independent practices, including sites you import from, barcode-data providers, Stripe-hosted pages, app stores, browsers, or operating-system push services. Review their privacy notices and controls before providing information.
16. Changes to this Policy
We may update this Policy as the Service and law change. We will post the revised Policy and update its effective date. If a change is material, we will provide reasonable additional notice and seek consent where applicable law requires it.
17. Contact
Privacy questions, requests, complaints, and appeals may be sent through the privacy contact form or to support@mylistresort.com. Operator: HyenaPack LLC, Texas, United States.