PRIVACY
What Restock does with your data, in plain language.
Last updated 2 August 2026
The short version
Restock stores your household's checklist, meal plan and shopping data so the app works. The browser extension adds items to your supermarket cart using the site's own controls — it never checks out, never sees your supermarket password, and never sells or shares your data with anyone.
Subscription payments are handled entirely by Stripe. We never see or store your card details.
What we collect
Restock is a household account, not an individual one — data belongs to whoever's signed in to that household.
- Account info — your email address, used for login (email and password, or Google sign-in) and nothing else.
- Subscription status — whether your account is on the paid plan, and a Stripe customer reference. Card numbers are handled by Stripe and never reach us.
- Your lists — checklist items, meal plans, pantry-check state, and the shopping products you've linked to them.
- Purchase history — prices and quantities observed either from a receipt you upload or from a TrolleyFill run, so the app can show price history and suggest what you usually buy.
- Feedback — anything you send through the in-app feedback button (category + message).
We don't collect anything from you beyond what's needed to run these features. There's no ad tracking, no data broker relationships, and nothing is sold.
Receipts
When you upload a grocery receipt (PDF), we read it once to extract the line items — product, price, quantity — and use that to update your household's purchase history. The receipt file itself is never stored. Only the structured line items, plus one lightweight record of the store and date, are kept.
The browser extension (TrolleyFill)
The Restock extension is a separate, optional install. It only activates on the three New Zealand supermarket sites it supports — Pak'nSave, New World and Woolworths — and only when you've asked it to do something from your own Restock account. Specifically:
- It reads the product page's own name, size, price, availability and cart-state information — the same things you'd see with your own eyes — to add each item and confirm it landed in your cart.
- It clicks the page's own "Add to cart" control. It never enters payment details, never places an order, and never touches checkout.
- It uses whichever supermarket tab you already have open and signed in to. The extension doesn't have — and can't create — its own supermarket account or session, and it never sees your supermarket password.
- If you ask Restock to import your shopping history, it reads your own previous-products and past-order pages on that supermarket's site, and sends the products and prices it finds to your own Restock account so your product list reflects what you actually buy. This only happens when you start it — it never runs on its own.
- Your shopping run's state (the queue, progress, prices observed) is stored locally in your browser, and prices are sent back to your own Restock account so your household's price history stays current. Nothing is sent anywhere else.
Who else sees your data
A few external services help Restock run. Each only sees the minimum it needs to do its job:
- Supabase hosts our database and handles login. All data is scoped so only your own household can read or write it.
- Anthropic (Claude) processes recipe text and receipt content you submit, to turn it into a structured ingredient or line-item list. It isn't used to build any Anthropic product or model.
- Sentry receives error reports if something breaks in the app, so we can fix it — extension and marketing site excluded.
- PostHog receives basic product-usage events (e.g. that a meal plan was confirmed) so we know which parts of Restock people actually use — no receipt content, product prices, or list contents are sent.
- Stripe handles subscription payments. Your card details go straight to Stripe and are never stored by Restock — we keep only a customer reference and whether the subscription is active.
- Google (Gmail) sends account-invite and feedback emails on our behalf.
None of these are given permission to use your data for their own purposes, and none of them are ad networks.
Your control over your data
You can ask us to delete your household's account and all associated data at any time — email hello@restock.nz. Since Restock is invite-only within a household, only someone with account access can request this for that household.
Changes to this policy
If what Restock collects or does with your data changes in a meaningful way, we'll update this page and change the date at the top.