1. Scope and who we are
This Privacy Policy applies to the EasyCart / 買餸易 mobile application (the “App”), developed and provided by DCMA.APP (“we”, “us”, or “our”). EasyCart helps households record shopping receipts, organise spending, and track wallets.
This policy does not cover Apple, Supabase, Cloudflare, Z.AI, RevenueCat, or other services that publish and control their own privacy notices.
2. Information handled by EasyCart
Account and household information
When you create an account, EasyCart handles your email address, chosen display name, password authentication records, language, user identifier, household membership and role, invite activity, and account timestamps. Passwords are handled by Supabase Auth; EasyCart does not store readable passwords.
Receipts, purchases, and wallets
EasyCart handles receipt photographs and the details you scan, review, or enter, including merchant, date and time, items, quantities, prices, discounts, totals, currency, loyalty points, and any printed card balance. A receipt image may incidentally contain an address, card fragment, or other text printed by the merchant.
Wallet records can include a user-chosen wallet name and type, opening and current balance, top-ups, adjustments, receipt charges, reconciliation entries, notes, and the person who made an entry. EasyCart does not receive or process your full payment-card number and does not move money.
AI receipt processing
When you choose to scan a receipt, the App resizes and compresses the selected image, then sends it with your language and a pseudonymous account identifier through an EasyCart service on Cloudflare Workers. The service sends the image to Z.AI for optical character recognition and sends the resulting receipt text to a Z.AI language model to structure the items and totals. If you select a shopping list, its identifier, name, and outstanding item identifiers, names, requested quantities, and remaining quantities are also sent to Z.AI to match receipt items to that list. The App asks for your explicit permission before sending each selected receipt for AI processing. Receipt scanning is optional; manual entry is available without sending an image to the AI service.
Subscriptions and free allowance
EasyCart uses a pseudonymous account identifier with RevenueCat to check Apple subscription status, restore purchases, and apply subscription access across devices signed in to the same EasyCart account. We also store the number of AI receipt uploads used from the account’s lifetime allowance of 10. Apple processes payment and billing details; EasyCart does not receive your full payment-card information.
Device and support information
The App keeps limited information on your device, including the authenticated session, language preference, active-household marker, and temporary pending-upload records needed to recover or clean up an interrupted save. If you contact support, we handle the information you include in your message and attachments.
3. How information is used
We use information to authenticate accounts; create and secure household membership; scan, review, store, search, and display receipts; calculate spending insights; maintain wallet balances; enforce role-based access; provide 10 free AI uploads; validate subscription access; prevent abuse; respond to support requests; and maintain the security and operation of the App.
AI output can be inaccurate. EasyCart shows extracted receipt details for review and correction before the user saves them.
4. Device permissions
EasyCart may request:
- Camera — to photograph a receipt you choose to scan;
- Photos — to select a receipt image from your library.
Granting a permission does not upload your whole library. EasyCart handles only the image you capture or select. You can deny or revoke a permission in device settings and continue using manual receipt entry.
5. Service providers and international processing
- Supabase provides authentication, a hosted PostgreSQL database, realtime updates, Edge Functions, and private receipt-image storage. The current EasyCart project is hosted in Singapore. See the Supabase Privacy Policy.
- Cloudflare provides the receipt-processing Worker and AI Gateway. EasyCart disables AI Gateway response caching and request/response content logging. Cloudflare may still process limited network, security, and operational information. See the Cloudflare Privacy Policy.
- Z.AI processes receipt images and extracted text through its API to provide OCR and structured results. Its API data-processing terms state that customer-provided API content is processed in real time and is not stored, and that enterprise/developer content is not used to improve services without explicit agreement. Processing is generally provided from Singapore. See the Z.AI Privacy Policy and API Data Processing Addendum.
- RevenueCat receives a pseudonymous EasyCart account identifier and Apple purchase/subscription information to provide entitlement status and restoration. See the RevenueCat Privacy Policy.
- Apple distributes the App and processes App Store purchases, subscription billing, receipts, and related store information under Apple’s policies. See the Apple Privacy Policy.
These providers may process information outside Hong Kong. Their locations and subprocessors can change; consult their current notices for details.
7. Storage, security, and retention
Account, household, receipt, wallet, and subscription-allowance records remain in EasyCart’s hosted systems while the account or relevant household record exists, unless deletion is requested or a longer period is required for security or legal reasons. Receipt images are stored in a private bucket with role-based access.
When you delete your account in the App, EasyCart deletes the authentication account, applicable receipt images, and associated App data. If you are a household’s only owner, the household and its receipts are also deleted. Some information may remain temporarily in provider backups or security logs under provider retention practices or legal requirements. Subscription cancellation does not itself delete an EasyCart account. Deleting an EasyCart account does not cancel an Apple subscription; Apple may continue billing until you cancel in Apple subscription settings.
Cloudflare AI Gateway content caching and request/response content logging are disabled for receipt AI calls. The Worker records limited operational events such as a pseudonymous user hash, request identifier, duration, item count, and error category—not receipt text or images. No storage or transmission method can be guaranteed completely secure.
8. Your choices and rights
You can use manual entry instead of AI scanning; correct extracted receipt fields before saving; revoke camera or photo access; leave a household; ask an owner to remove a helper account from a household; restore or manage Apple subscriptions; sign out; and delete your account from Settings after password confirmation.
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of personal information. Contact us to make a request. We may need to verify your identity before acting.
9. Children’s privacy
EasyCart is not directed to children under 13, and we do not knowingly collect personal information from children under 13. A parent or guardian who believes a child provided information should contact us.
10. Changes to this policy
We may update this policy when EasyCart, our providers, or legal requirements change. We will revise the date on this page and provide additional notice where required.
11. Contact us
For privacy questions or requests, contact:
DCMA.APP
11 Li Tak Street
Kowloon, Hong Kong
support@dcma.app
Please use the subject line “EasyCart privacy request”.