Privacy Policy

How we process the personal data of people who use the Super Convenienza app and website, under Regulation (EU) 2016/679 (GDPR).

Last updated: 24 September 2026

This is an English translation provided for convenience. The Italian version is the legally binding one.

1. Data controller

SR MARKET S.R.L. — Super Convenienza supermarket
Via Giovanni Falcone, 38 — 92021 Aragona (AG), Italy
VAT and tax code 02879760847 — REA AG-212870, Agrigento Chamber of Commerce
Email supporto@superconvenienza.com · PEC srmarketsrl@pec.it · Phone +39 0922 38088

We have not appointed a Data Protection Officer (DPO). For any question about your data, write to the addresses above.

2. Data we collect

We only collect the data needed to run the loyalty card and online grocery shopping. We do not collect your location, address book contacts, photos or payment details.

Data When Why
Email address Sign-up with email and password, or sign-in with Google or Apple Identify the account, authenticate you, send you service messages
Display name Sign-up, or sign-in with Google or Apple (Apple only provides it if you choose to share it) Recognise you at the checkout and on orders
Password Sign-up with email Authentication. It is stored only in hashed form and cannot be read by us. With Google or Apple sign-in we never receive the password of those accounts.
Apple account identifier and, if used, the anonymous relay email address (“Hide My Email”) Only when signing in with Apple Link your Apple ID to your app account
Loyalty card code (QR) Account creation Link in-store purchases to your account
Points balance, transactions and redemptions Every time points are earned or redeemed Run the loyalty programme and show you your balance
Orders: products, amounts, delivery or pickup, delivery address When you place an order Prepare and deliver your groceries, handle complaints
In-app notifications When an order changes status or a promotion is published Show you the history of alerts in the app
Device notification token and platform (iOS/Android) Only if you allow push notifications Send you push notifications
Technical data: IP address, device and browser type, date and time On every request to our servers Our providers' technical logs, for security and troubleshooting

We do not use data for advertising profiling and we do not make automated decisions that produce legal effects concerning you.

3. Device permissions

Notifications

The app asks for permission to send you notifications. It works just the same if you decline, and you can change your mind at any time in your phone's settings.

Camera

The camera is used only by store staff to scan QR codes at the checkout, and is requested only when the scanner is opened. Codes are recognised on the device; images are neither saved nor transmitted.

  • Performance of a contract (Art. 6(1)(b) GDPR): account, loyalty programme and orders.
  • Consent (Art. 6(1)(a)): push notifications, which you can withdraw at any time in your phone's settings.
  • Legal obligation (Art. 6(1)(c)): retention of accounting and tax records.
  • Legitimate interest (Art. 6(1)(f)): security of our systems and prevention of abuse of the points programme.

5. Service providers and recipients

We do not sell your data or share it with third parties for commercial purposes. It is processed on our behalf by the technical providers that run the app, acting as data processors bound by contract to guarantee the same level of protection described here:

Provider Service
Supabase, Inc. Database, authentication and storage of the app's content
Google Ireland Ltd. / Google LLC Sign-in with Google (optional), push notifications on Android (Firebase Cloud Messaging), hosting of this website and of the web version of the app (Firebase Hosting)
Apple Inc. Sign in with Apple (optional), push notifications on iPhone and iPad (Apple Push Notification service)

Data may be disclosed to professionals and authorities where required by law (for example for tax obligations). Some providers are based in the United States: in those cases the transfer relies on the EU-US Data Privacy Framework or on the European Commission's Standard Contractual Clauses.

6. Cookies and tracking

The website uses no profiling cookies and no analytics tools. The app contains no advertising, uses no analytics or marketing SDKs and does not track you across other companies' apps or websites.

On your device we only store what the app needs to work: your sign-in session, the chosen language and the contents of your cart.

7. Retention

  • Account, points, orders and notifications: for as long as the account is active; they are deleted together with the account.
  • Push notification tokens: for as long as the device stays registered; we remove them when you sign out or when the platform reports them as no longer valid.
  • Technical logs: for the limited period set by our providers.
  • Tax and accounting records: for the period required by Italian law, even after the account is deleted.

8. Your rights

You can exercise the rights granted by Articles 15–22 GDPR: access, rectification, erasure, restriction, portability, objection and withdrawal of consent. Write to supporto@superconvenienza.com from your account's email address: we reply within 30 days.

You can also lodge a complaint with the Italian Data Protection Authority, the Garante per la protezione dei dati personali.

9. Account deletion

You can delete your account at any time from the app: Profile → Delete account. Deletion is immediate: profile, points, transactions, orders, redemptions, notifications and push tokens are erased right away and, if you used Sign in with Apple, we also revoke the authorisation you granted to the app. Only the tax records required by law are kept.

If you cannot sign in to the app, write to supporto@superconvenienza.com from the address you registered with: we delete the account within 30 days.

Full procedure: Deleting your account.

10. Security

Communication between the app and the servers is encrypted (HTTPS/TLS). Access to data is limited by database rules: each customer can only see their own data, and every points operation is verified by the server. Only authorised store staff can access the data they need for their job.

11. Children

The app is not intended for children under 14 and we do not knowingly collect their data. If you believe a child has given us their data, write to us and we will delete it.

12. Changes

If we change how we process data we update this page and the date at the top; significant changes are also announced in the app.