Privacy Policy
1. Who is responsible for your data
The data controller is Grocery2 Market UAB, registered at Savanoriu pr. 14, LT-03116 Vilnius, Lithuania. You can reach us at hello@grocery2.example or +370 5 210 4000. This policy covers the grocery2 website, our ordering and delivery service, and the four stores in Vilnius, Kaunas and Klaipeda.
2. What data we collect
- Account data: your name, email address, phone number and password hash.
- Order data: what you bought, the delivery or collection address, the slot you chose, picker notes, substitutions accepted or refused, and the receipt.
- Payment data: the amount, the currency, the time, and a token plus the last four digits of the card. We never see or store a full card number.
- Delivery data: the recipient name and phone we pass to the driver, doorway notes you leave, and the handover time.
- Support data: messages you send through our forms or by email, and any photo you attach to a refund claim.
- Technical data: IP address, device and browser type, and pages visited, collected through cookies and server logs.
3. Why we use it, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Taking, picking and delivering your order; refunds | Performance of a contract |
| Accounting, invoicing and tax records | Legal obligation |
| Age verification for restricted goods | Legal obligation |
| Answering support messages | Performance of a contract, or legitimate interest |
| Fraud prevention and site security | Legitimate interest |
| Marketing email and offer newsletters | Consent, withdrawable at any time |
| Non-essential analytics cookies | Consent |
4. Cookies
We use cookies that are strictly necessary to run the basket, the login and the checkout, and β only with your consent β analytics cookies that tell us which pages people abandon. The categories, examples and retention periods are listed in the Cookie Policy, along with how to change or withdraw your consent.
5. Who else sees your data
We do not sell personal data and we do not share it for anyone else's advertising. We do use processors that act only on our instructions:
- Couriers and our own drivers receive the recipient name, phone number, address and doorway notes for the order they are delivering, and nothing else.
- Payment providers process the card or bank transaction. They are independent controllers for the transaction data they must keep.
- Hosting, email and SMS providers store or transmit order confirmations and slot notifications on our behalf.
- Our accountants and auditors see invoice-level data as required by Lithuanian bookkeeping rules.
- Public authorities where the law requires disclosure, for example a tax or consumer-protection inspection.
6. How long we keep it
- Order and invoice records: ten years from the end of the financial year, as required by Lithuanian accounting law.
- Account data: for as long as the account exists, then 12 months, then deleted.
- Support messages and refund photos: 24 months after the case is closed.
- Delivery notes and driver handover records: 6 months.
- Marketing consent records: for as long as the consent stands, plus 3 years as proof that it was given.
- Server logs: 12 months.
7. Your rights
Under the GDPR you may ask us to give you a copy of your data, correct it, delete it, restrict or object to our processing of it, or send it to another provider in a portable format. Where we rely on consent, you can withdraw it at any time without affecting anything we did before. Write to hello@grocery2.example and we will answer within one month. If you are unhappy with the outcome you can complain to the State Data Protection Inspectorate of the Republic of Lithuania.
8. Children
The service is intended for people aged 18 and over, because an order can include age-restricted goods and because payment requires a card or bank account. We do not knowingly create accounts for children. If you believe a child has registered, tell us and we will delete the account and its data.
9. Security
The site runs over TLS, passwords are stored only as salted hashes, and access to order data inside the company is limited by role β a picker sees the list and the address, not your payment history. Administrative access requires two-factor authentication, backups are encrypted, and we log and review access to customer records. If a breach ever puts your rights at real risk, we will notify you and the supervisory authority as the GDPR requires.
10. Transfers outside the EEA
Our servers and our primary email provider are in the European Union. A small number of processors β for example an SMS gateway or an error-monitoring service β may process data outside the EEA. Where that happens we rely on an adequacy decision or on the European Commission's standard contractual clauses, and we can send you a summary of the safeguards on request.
11. Changes to this policy
We update this page in place rather than publishing a new document each time. Material changes β a new purpose, a new category of recipient, a longer retention period β are announced by email to account holders at least 14 days before they take effect. The date of the current version is at the bottom of this page.
12. Contacting our data protection officer
Our data protection officer can be reached by email at hello@grocery2.example with "DPO" in the subject line, or by post at Grocery2 Market UAB, DPO, Savanoriu pr. 14, LT-03116 Vilnius. For anything about a specific order, the contact page is faster.
Current version: 1 March 2026.