Legal
Privacy Policy
Last updated: 1 October 2026
This Privacy Policy explains how Roots Collective processes personal data when you use Snap → Sheet, in line with the EU General Data Protection Regulation (GDPR) and Belgian data protection law. We collect as little data as possible and never sell it.
1. Who is responsible
The controller is Roots Collective, Frère-Orbanlaan, 9000 Ghent, Belgium, enterprise and VAT number BE 1004.064.123, email redventures1113@gmail.com. For any privacy question or request, email redventures1113@gmail.com.
For personal data of other people that you include in your screenshots, you are the controller and we act as your processor (see section 9).
2. What data we process
- Account data: your email address, a securely hashed password (never the password itself), sign-up date and the date and version of the Terms you accepted.
- Plan and usage data: your plan, number of conversions, top-ups and subscription status.
- Your Content: the screenshots you upload, the product data extracted from them (names, quantities, prices, order numbers, photos) and the lists you save, including list names.
- Payment data: Stripe processes your payment. We receive only a customer and subscription reference, the amount, the payment status and the date. We never receive your full card number.
- Technical and security data: IP address (used briefly to limit login and password-reset attempts), failed login counters, and the essential cookies described in our Cookie Policy.
- Communications: emails we send you (welcome, low balance, password reset) and messages you send us.
3. Why we process it and on what legal basis
- To provide the Service: create your account, convert your screenshots, save your lists and send service emails. Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR).
- To handle payments, invoicing and accounting. Legal basis: contract and legal obligations (Art. 6(1)(b) and (c)).
- To keep the Service secure and prevent fraud and abuse (rate limiting, enforcing plan limits and our Terms). Legal basis: our legitimate interest in a safe and reliable service (Art. 6(1)(f)).
- To defend legal claims. Legal basis: legitimate interest (Art. 6(1)(f)).
We do not send marketing emails without your consent, we do not use advertising or tracking, and we do not sell or rent personal data.
4. AI processing
To read your screenshots, each image is sent to an AI model (Claude by Anthropic, via our hosting provider's AI gateway), which returns the product data. According to the providers' commercial terms, this data is not used to train their models. The AI only extracts data for your spreadsheet; no decisions with legal or similarly significant effects are made about you (Art. 22 GDPR).
5. Who receives your data
We only use carefully selected service providers (processors) that are bound by data processing agreements and confidentiality:
- Emergent Labs: application hosting, database, file storage, email delivery and AI gateway;
- Anthropic: AI model that reads the screenshots;
- Stripe: payment processing and subscription management (Stripe is also an independent controller for its own legal obligations, such as fraud prevention and anti-money-laundering).
Shared lists: if you create a share link for a saved list, everyone who has that link can view the list (name, products, photos, quantities, prices and total) and download it as Excel. Only you can create or stop a share link.
We may also disclose data when the law requires it, to protect our rights or the safety of others, or to a successor if our business is transferred (you will be informed).
6. International transfers
Some providers process data outside the European Economic Area, for example in the United States. In that case the transfer is protected by an adequacy decision (such as the EU-U.S. Data Privacy Framework for certified companies) and/or the European Commission's Standard Contractual Clauses, with additional safeguards where needed.
7. How long we keep data
- Uploaded screenshots and temporary processing files: deleted automatically within about 1 hour after the conversion.
- Saved lists (including product photos): 90 days after the last change, or earlier when you delete the list or your account. When a list is deleted or expires, its product photos are erased (overwritten) immediately and the list is removed; any remaining copies in our providers' backups are removed in line with their backup cycles.
- Account data: as long as your account exists. When you delete your account it is erased immediately.
- Password-reset links: 1 hour. Login attempt counters: up to 15 minutes after the last attempt.
- Payment and invoicing records: 7 years, as required by Belgian accounting and tax law.
8. Your rights
You have the right to access, rectify and erase your data, to restrict or object to processing, to data portability, and to withdraw any consent at any time. You can delete your account and all saved lists yourself via "Delete my account" in the footer of the app, or email us at redventures1113@gmail.com. We answer within one month.
You also have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), Drukpersstraat 35, 1000 Brussels, dataprotectionauthority.be, or with the authority in your own EU country.
9. Personal data of others in your screenshots
Screenshots can contain personal data of other people, such as customer names, addresses or order details. You are responsible for having a lawful basis to process that data and for informing those people where required. We process it only on your behalf, only to provide the Service, keep it confidential and secure, use only the sub-processors listed above, delete it as described in section 7 and assist you with data subject requests and security incidents where required by Art. 28 GDPR. Please do not upload sensitive data, identity documents or payment card details.
10. Security
We use encryption in transit (HTTPS), hashed passwords (bcrypt), secure httpOnly cookies, brute-force protection, access controls and short retention periods. No system is 100% secure; if a data breach affects you, we will inform you and the authorities as required by law.
11. Children
The Service is not intended for anyone under 16. We do not knowingly collect data of children.
12. Changes
We may update this Privacy Policy. The latest version is always on this page with its date; we will notify you by email of material changes.
13. Contact
Roots Collective · Frère-Orbanlaan, 9000 Ghent, Belgium · BE 1004.064.123 · redventures1113@gmail.com