Legal

Privacy Policy

Last updated: 10 March 2026  ·  Effective: 10 March 2026

At Expiro, we take the privacy of your data seriously. This policy explains what data we collect, how we use it, and the rights you have over your information under GDPR.

1. Information We Collect

We collect information you provide directly when you create an account, including your name, email address, business name, phone number, and billing information.

We automatically collect certain technical data when you use Expiro, including IP address, browser type, operating system, pages visited, and device identifiers.

Product and inventory data you enter into Expiro — including product names, barcodes, expiry dates, quantities, and store locations — is stored securely on our servers.

We may collect usage analytics to understand how features are used and to improve the platform. This data is aggregated and does not personally identify you.

2. How We Use Your Information

To provide, maintain, and improve the Expiro platform and its features.

To process transactions and send related information, including purchase confirmations and invoices.

To send operational communications such as expiry alerts, stock notifications, and daily summaries, based on your notification preferences.

To respond to comments, questions, and requests and provide customer support.

To monitor and analyse trends, usage, and activities in connection with our services.

To comply with legal obligations and enforce our Terms of Service.

3. Sharing of Information

We do not sell, trade, or rent your personal information to third parties.

We may share your information with third-party service providers who perform services on our behalf, such as payment processing (Stripe), cloud hosting (AWS), and customer support tooling. These providers are contractually bound to protect your data.

We may disclose information if we believe disclosure is in accordance with, or required by, applicable law or legal process.

In the event of a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred to the acquiring entity.

4. Data Storage & Security

All data is stored on servers located within the European Union (EU) in compliance with GDPR requirements.

We use industry-standard encryption (TLS 1.3) for all data in transit. Data at rest is encrypted using AES-256.

Access to production systems is restricted to authorised Expiro personnel using multi-factor authentication.

We conduct regular security audits and penetration tests. Any security vulnerabilities are remediated promptly.

Despite our measures, no security system is impenetrable. We will notify affected users of any data breach within 72 hours in compliance with GDPR Article 33.

5. Your Rights (GDPR)

Right of Access: You may request a copy of all personal data we hold about you.

Right to Rectification: You may request correction of any inaccurate data we hold.

Right to Erasure ('Right to be Forgotten'): You may request deletion of your personal data. Note that certain data may be retained for legal compliance purposes.

Right to Data Portability: You may request your data in a structured, machine-readable format.

Right to Object: You may object to certain types of data processing, including direct marketing.

To exercise any of these rights, contact us at privacy@expiro.food. We will respond within 30 days.

6. Cookies

We use essential cookies to maintain your login session and remember your preferences.

We use analytics cookies to understand how users interact with the platform. You may opt out of analytics cookies at any time via your account settings.

We do not use advertising cookies or share cookie data with advertising networks.

You may configure your browser to refuse cookies; however, some features of Expiro may not function correctly without them.

7. Data Retention

Account data is retained for the duration of your subscription plus 90 days after account closure to enable recovery.

Audit logs and traceability records are retained for 5 years to comply with food safety regulations.

Billing information is retained for 7 years to comply with French and EU tax law.

After the applicable retention period, data is permanently deleted from all systems.

8. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by email or via an in-app notification at least 30 days before the changes take effect.

Your continued use of Expiro after the effective date of a revised policy constitutes your acceptance of the updated terms.

9. Contact

If you have any questions about this Privacy Policy or our data practices, please contact our Data Protection Officer at: privacy@expiro.food

Expiro SAS, 123 Rue de la DLC, 75001 Paris, France.