Who operates Stockup Run
Stockup Run is an independent service operated in Washington, United States. Privacy questions can be sent through the private support form.
Information we collect
We store your Google-backed account identifier, name, email address, optional profile image, household memberships, warehouse choices, list items, trip outcomes, optional managed-profile nicknames and preferences, optional receipts, product settings, and information you submit through the support form. We do not ask for or store Costco account credentials.
How information is used
We use this information to authenticate you, provide private or shared shopping lists, order items by your route, synchronize shopping changes, learn personal restock patterns, extract receipts you choose to upload, prevent abuse, and operate the beta.
Service providers
Clerk provides sign-in and invitations; Supabase provides database, private file storage, and realtime transport; Vercel hosts the application and provides cookieless analytics and performance data; Google Places supports optional warehouse search; and Vercel AI Gateway sends eligible smart-add text or consented receipt files to the configured model provider. We limit the data sent to each provider to the feature being used.
Cookies and local device storage
Clerk uses essential authentication cookies. Vercel Web Analytics is configured without advertising cookies. Stockup Run uses IndexedDB and a service worker to keep an active trip usable with poor connectivity. Authenticated pages are not stored in the shared web cache, and local trip data can be removed in Settings.
Sharing and community learning
Lists start private. Other people see a list only after an invitation is accepted. Community learning is off by default. If a household opts in, only canonical product co-occurrence from completed trips may be aggregated; notes, people, preferences, allergies, receipts, and household identity are excluded, and a pair is not exposed below ten contributing households.
Retention and security
Account and household data remains until deleted, subject to backup retention. Receipt files remain private to the household until removed. Operational errors are retained for about 90 days; product events and support requests are retained for up to 18 months. Access is protected by server-side membership checks, row-level database policies, private storage rules, and encrypted transport.
Your choices
You may export your data, delete receipts and managed profiles, leave shared households, opt out of community learning, clear offline data, or request account deletion. Use the in-app Data & privacy page or email us.
Children
Accounts are for adults. An adult may create a managed nickname for a child or dependent only when authorized to do so. Do not enter a birth date, contact information, precise location, medical records, or a legal name when a nickname will work.
Changes
Material changes will be announced in the product or by email when appropriate. Continued use after an effective date means the updated policy applies.