Privacy and Cookie Statement
Updated 26-05-2026
Version 1.4 | 26 May 2026 (drafted in accordance with the GDPR and ePrivacy Directive)
Data Controller: Built Different Studio (general partnership), trading under the name Mandje.
Chamber of Commerce (KvK) number: 99496127. Plantage Middenlaan 54 E 5, 1018 DH Amsterdam.
Email: [email protected]
1. Scope of application
This privacy statement applies to the use of the Mandje app and related web pages under mijnmandje.nl, including shared shopping lists and any API services.
Built Different Studio, trading under the name Mandje ("Mandje", "we", "us"), is the data controller within the meaning of the GDPR and is responsible for processing personal data within these services.
2. Categories of users and data
2.1 Logged-out users
When you use the app without an account, Mandje automatically collects limited technical data necessary for the app's operation and security. This includes your IP address, device or installation ID, operating system version, crash logs, network and connection data, and language and country settings. Usage statistics (such as behavioral analysis) and a push token are only processed after you have given your consent (see §3 and §4); without your consent, this processing will not take place.
2.2 Logged-in users
When you register (via Apple, Google, or email), Mandje processes your name, email address, and an authentication ID. If available, we may receive additional profile information from Apple or Google, such as your profile name or avatar. Users can also upload a profile picture from their photo library. This is stored in our secure file storage; the photo URL is publicly accessible.
We also link preferences, favorites, saved lists, loyalty cards, optional profile data (such as gender and year of birth), and settings to your account. This allows us to provide a personalized experience and synchronize your data across devices.
2.3 Loyalty cards & Wallet passes
Loyalty cards or Wallet passes can be added by you or offered by default by Mandje. These display store and card information, including barcodes that you have entered or that Mandje has pre-generated based on public store data. No real-time points or transaction details are retrieved.
Loyalty cards are linked to your account and stored with our hosting provider in the EEA (Frankfurt). We store the store ID, barcode number, barcode format, and creation date so your cards sync across your devices. This data is encrypted at rest (see §6); the barcode itself is not additionally encrypted. A local copy is also saved on your device for offline use.
The app may use your device's camera to add barcodes. Camera images are processed strictly locally to recognize barcodes and are not stored, transmitted, or shared with third parties.
2.4 Campaign links (mijnmandje.nl/r/*)
When you click on promotional links (mijnmandje.nl/r/*), Mandje automatically collects limited statistical data. This includes your country and city (based on geo-IP via our infrastructure provider), device type (mobile, desktop, or tablet), and traffic source (referring domain). We do not store IP addresses, full user agents, cookies, or device IDs. This data is not linked to app accounts, user profiles, or app behavior.
2.5 Shared shopping lists
Users can share shopping lists with others via an invitation link. When you join a shared list, your display name and profile picture will be visible to the other members of that list. List contents (products, quantities, and check-off status) are synchronized among all members. The recipients of this data are strictly the other members of that specific list.
2.6 Location data
To show nearby supermarkets, Mandje can use your device location (via the operating system) or a postcode that you enter. Location data is only retrieved at your active request (by tapping "Use my location") and never in the background. We request approximate accuracy (~100 meters), not a precise location. The location permission requested by your operating system is separate from consent under the GDPR; both can be enabled and disabled at any time in your device settings.
Coordinates are stored locally on your device (AsyncStorage) and sent with the API request to retrieve nearby stores. When you enter a postcode, it is sent directly by your device to an external geocoding service to convert the postcode into coordinates (see §5). Location data is not used for profiling, advertising, or tracking.
2.7 Shared products
When you share a product via a share link, Mandje generates a share link and stores your account ID, the shared product, and the creation time. Recipients of the link will see your display name ("shared by ...") and the shared product. We only keep an aggregated count of how often a share link is opened; we do not record the IP address, identity, or any other data of the people who open the link. This processing enables the sharing feature and measures its usage.
3. Purposes and legal bases (GDPR Art. 6)
Mandje only processes personal data for specific purposes and on a valid legal basis as referred to in Article 6 of the GDPR.
App functionality and security: Performance of a contract / legitimate interest
Account login and synchronization: Performance of a contract
Analytics / performance measurement: Consent
Push notifications: Consent
Error and crash monitoring: Legitimate interest
Loyalty card storage: Performance of a contract
Aggregated or pseudonymous analysis: Legitimate interest
Legal obligations: Legal basis
Campaign link analysis: Legitimate interest
Showing nearby stores: Consent
Shared product links: Performance of a contract
To the extent that analytics data can no longer be traced back to an individual, it does not qualify as personal data and its processing falls outside the scope of the GDPR. Where data is still pseudonymous or indirectly identifiable, we process it based on our legitimate interests, with appropriate safeguards such as aggregation, access restrictions, and defined retention periods.
For strictly necessary technical processing when using the app without an account, we rely on our legitimate interest in providing a properly functioning and secure service. For logged-in users, this processing is carried out to perform our user agreement.
4. Cookies, SDKs, and local storage
4.1 Consent levels
On first use, a consent screen will appear where you can easily accept, decline, or adjust your choices.
Levels:
Essential (required): necessary for the app to function.
Analytics (opt-in): statistical measurement and improvement.
Users can grant full, partial, or minimal consent. Your choice is saved until you clear the app data, reinstall the app, or until there is a material change to this policy, which will prompt a new request for consent.
4.2 Essential storage (necessary)
Session token / authentication: until logout
Consent status: permanent
Caching for performance: 24 hours
4.3 Analytics (subject to consent)
Analytics provider: 12 months
4.4 Marketing / tracking
We do not currently use any marketing or tracking SDKs. If this changes in the future, this policy will be updated.
4.5 Used technologies and consent
Mandje does not use browser cookies, but instead uses local storage on your device (such as AsyncStorage) and third-party software development kits (SDKs). Strictly necessary storage (session token, consent status, and caching) and the error and crash monitoring SDK are always active, as they are required for the app to function and remain secure (see §3).
The analytics SDK is only activated after you have given consent for analytics; no processing happens before that. If you withdraw your consent, it is deactivated immediately. Our analytics provider anonymizes IP addresses. Your consent choice is stored locally on your device.
5. Processors and data transfers outside the EEA
Mandje uses external service providers:
Hosting and infrastructure provider: backend API, database, storage, and CDN. Location: EEA (and global edge network)
Analytics provider: usage statistics (only after consent). Location: EEA
Error monitoring provider: crash and error monitoring. Location: EEA
Push notification provider: sending push notifications. Location: US (DPF)
Email delivery provider: account and verification emails. Location: US (DPF)
The majority of our processors process personal data within the EEA, meaning no transfer outside the EEA takes place. For push notifications and email delivery, we use providers in the United States that are certified under the EU-US Data Privacy Framework, which serves as the legal basis for transfer. Additionally, traffic may route through a global edge network; where this involves transfers outside the EEA, standard contractual clauses (SCCs) and/or the Data Privacy Framework are applied.
Mandje does not sell or rent personal data. Only anonymized insights may be shared for statistical purposes.
To convert an entered postcode into coordinates, the app directly calls a public, external geocoding service. This service is not a processor under our instructions, but an independent third party with its own privacy policy. During this request, the service receives the entered postcode and your device's IP address. We do not send any account or profile data with this request.
Processing by the aforementioned providers is governed by data processing agreements in accordance with Article 28 of the GDPR. These processors may engage sub-processors; where this involves transfers outside the EEA, we assess whether additional safeguards are necessary.
6. Security
Mandje implements appropriate technical and organizational measures:
Encryption in transit: TLS 1.2+
Encryption at rest: AES-256 + OS level
Authentication: JWT authentication
Access control: role-based access control
Token validation: short timeouts + automatic refresh
Logging: structured logging
Data breach notification: notification to the Dutch Data Protection Authority (AP) within 72 hours; affected individuals informed without undue delay in case of high risk
7. Retention periods & Deletion
Mandje applies retention periods that align with the principles of data minimization and storage limitation.
Account data: as long as the account is active
Favorites and lists: as long as the account is active
Analytics data: 12 months
Local app storage: until logout/uninstallation
Inactive accounts: deleted after 24 months
Campaign link click data: maximum of 24 months
Location data (local): until logout/app uninstallation
Loyalty cards: as long as the account is active
Shared product links: kept anonymized after account deletion
Account deletion
When you delete your account, the following data is immediately removed from our active systems:
Account and authentication data
All local app storage (favorites, cache, preferences)
Analytical identifier (will be reset)
Shared lists owned by you (including for other members)
Your profile picture from our file storage
Your membership in shared lists owned by others
In addition, certain non-identifying data (such as favorites, preferences, sharing stats, and session data) will not be deleted but will be anonymized: the link to your account is severed so that they can no longer be traced back to you.
After deletion, data may remain in encrypted backups for a short period until it is overwritten in accordance with our regular backup cycle. We may also retain data for longer if necessary to comply with legal obligations, for security, fraud prevention, or the resolution of disputes.
Log files
Server-side log files for security and fraud prevention are kept for a maximum of 90 days. Campaign link click data is kept for a maximum of 24 months and deleted automatically thereafter.
8. Rights of data subjects
Users of Mandje can exercise their rights as set out in Articles 12 to 22 of the GDPR:
Right of access
Right to rectification
Right to erasure ("right to be forgotten")
Right to restriction of processing
Right to data portability
Right to object
Right to withdraw consent
You can exercise your rights by sending a request to [email protected]. We generally respond within one month of receipt. For complex or numerous requests, we may extend this period by up to two months, and we will inform you of this in a timely manner. To protect your data, we may ask you for additional information to verify your identity.
You can withdraw or change your consent for analytics at any time via Settings › Privacy in the app. You can manage push notifications and location access in your device settings. Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal.
Automated decision-making
There is currently no automated decision-making or profiling. Product recommendations are based in general on product relation (such as the category or context of the product being viewed), rather than your personal preferences or behavior.
9. Minors
Mandje is intended for a general audience and does not intentionally collect data from individuals under the age of 16. We advise parents to monitor their children's app usage and restrict it where necessary.
When using the app without an account, age is not verified. Consent-based features (analytics, push notifications, and location) are optional and can be turned off at any time; for individuals under 16, these should only be used with the consent of a parent or guardian.
10. Alcohol / age-restricted content
Mandje may display pricing or promotional information for alcoholic products or other age-restricted promotions. This information is purely informative and is sourced from supermarkets; Mandje does not process data related to consumption or purchasing behavior.
11. Contact & Supervision
If you have questions or complaints about this privacy statement, please contact us at [email protected]. You always have the right to file a complaint with the Dutch Data Protection Authority (www.autoriteitpersoonsgegevens.nl).
12. Changes
Mandje may update this privacy statement. In the event of material changes, users will be reasonably informed (via an in-app notification or the website).
Last updated: 26 May 2026
