Legal

Grenshopper Privacy Policy

Version 3.0, in effect from 7 October 2026

This translation is provided for convenience. If the two versions differ in their interpretation, the Dutch version prevails.

1. Who are we?

Grenshopper is a mobile application developed and operated by Grenshopper B.V., based in the Netherlands. Grenshopper B.V. is the controller responsible for processing your personal data as described in this privacy policy.

For questions about this privacy policy you can get in touch at: hello@grenshopper.nl

2. What data do we collect?

2.1 Data you give us yourself

  • Name and email address (when you create an account), and your password, which is only stored in encrypted form
  • Profile data you enter yourself, such as date of birth, gender, country and language
  • Phone number (only if you provide and confirm it yourself)
  • Vehicle data: number plate, make, model, year of manufacture, colour, fuel, tank size and consumption (up to three vehicles)
  • Saved places: home, work, favourites and recent destinations
  • Settings and preferences, including your notification preferences and price alert
  • Reviews of filling stations that you write
  • Feedback you send, possibly with a screenshot of the screen. When a screenshot comes in, we automatically remove all metadata in the file, such as location and device details.

2.2 Data collected automatically

  • Location data (only with your permission): your current position and, if you allow it, also while the app runs in the background during navigation
  • Device data: device type, operating system, app version and language
  • A push token for your device, if you allow notifications
  • IP address: temporarily, to secure our services and prevent misuse (see articles 7 and 9)
  • A check that the app is genuine: when you open it, the app proves through Apple (App Attest) or Google (Play Integrity) that it is the genuine Grenshopper app on a genuine device. For this we only store a random code for your installation, on iOS together with its public key, and the outcome of the check (see article 9)

2.3 Data that arises from using the app

  • Fuel receipts: the filling station with its address and location, the fuel, the number of litres, the price per litre, the total amount and the calculated saving
  • Transactions when paying at the pump: amount, litres, status and a reference to your mandate or card (see 6.1)
  • Notifications we send you and whether you have read them; for a price alert also which station and which price triggered it
  • Free fuel: your participation and consent, your turns and tickets, your invitation code and who you invited with a code

2.4 Voice search and dictation

If you use voice search or dictate your feedback, the speech recognition on your device turns what you say into text. Apple (iOS) or Google (Android) does this, and the audio may be sent to their servers under their own privacy terms. Grenshopper only receives the text and does not keep any audio recordings.

2.5 Data from third parties

  • Vehicle data from the Dutch vehicle authority RDW (open data), based on the number plate you enter
  • Fuel prices and station information from public and purchased price sources
  • Traffic information from the Dutch National Road Traffic Data Portal (NDW); this contains no personal data

3. What do we use your data for?

We only use your data for clear purposes, each with a legal basis under the GDPR:

Performance of the contract (Art. 6(1)(b) GDPR): maintaining your account, comparing prices and calculating your saving and detour time, navigating, storing your vehicles, places and fuel receipts, enabling payment at the pump and running Free fuel.

Consent (Art. 6(1)(a) GDPR): using your location and sending you push notifications, such as a price alert. You can withdraw this consent at any time in your device settings or in the app.

Legitimate interest (Art. 6(1)(f) GDPR): securing our services and preventing misuse, for example by limiting the number of requests per user or IP address and checking that requests come from the genuine app; fixing errors and improving the app with your feedback; and creating aggregated, anonymised statistics.

Legal obligation (Art. 6(1)(c) GDPR): for example our accounting and the obligations that come with a promotional game of chance.

4. Location data

Grenshopper asks for access to your location in order to:

  • Show filling stations and prices near you
  • Calculate your saving and detour time
  • Navigate you, also with the screen off if you allow it
  • Point out a good price to you on the road

4.1 Storing location data

We use your current location at that moment only. We do not keep a location history. To calculate prices and routes, we send coordinates to our own servers, without building a location history from them. What you save yourself, such as home, work, favourites and recent destinations, and the location of the station on your fuel receipts, we keep for as long as your account exists.

4.2 Withdrawing permission

You can withdraw location access at any time in your device settings. You can delete saved places yourself in the app, or by deleting your account.

5. Internal analysis and statistics

5.1 Grenshopper uses data, aggregated and anonymised where possible, to improve the app and understand how it is used, for example which regions and fuels are popular and what savings users achieve.

5.2 Individual data is used internally only and never shared with third parties for commercial purposes.

5.3 The basis for this processing is legitimate interest (article 6(1)(f) GDPR). We have an interest in improving our service and in understanding how people use the app. We always weigh your privacy against that. You can object to this processing (see article 8).

5.4 Anonymised data for third parties

Grenshopper may share anonymised and aggregated statistics with, or make them available to, third parties, including research institutions, governments and commercial parties. This only concerns data that cannot in any way be traced back to individual people, such as:

  • Average fuel prices per region per day
  • Average savings per region
  • Popularity of fuels per region

Personal data is never sold or shared with third parties for commercial purposes without your explicit permission.

6. Sharing data

We never sell your data. We only share data with parties that are needed for our service, and only what they need for that:

  • Supabase: database, accounts, storage and server functions (servers in the EU)
  • Hetzner Online: our own routing server for navigation and travel times (servers in Germany)
  • Cloudflare: protection and forwarding of traffic to our routing server
  • Vercel: hosting of our website
  • Twilio SendGrid: sending emails, such as your confirmation code and invitations
  • Apple and Google: push notifications (Apple Push Notification service and Firebase Cloud Messaging), speech recognition (see 2.4) and the check that the app is genuine (App Attest and Play Integrity, see 2.2)
  • OpenFreeMap, Photon (komoot) and Nominatim (OpenStreetMap): map tiles and address search. They receive the map area or the search term and your IP address, but no account data
  • RDW: looking up vehicle data for the number plate you enter
  • Apple (TestFlight) and Google (Google Play): if you take part in the test phase (see article 11)
  • A specialised security party that examines our security on our behalf and under confidentiality (see article 11)
  • Payment partners, if you pay at the pump (see 6.1)

6.1 Paying at the pump

This section is a draft. It has not been reviewed by a lawyer yet. The processing described here only takes place once you set up a payment method in the app.

If you set up a payment method in the app to pay at the pump, we share data for that purpose with the parties that make the payment possible: CarPay-Diem (KWALYO S.A., Luxembourg) and Twikey. Twikey handles the signing and management of the SEPA mandate.

The mandate is in the name of the fuel station where you fill up. That station is the collecting party and receives your name and account number for that purpose; the amount goes directly from you to the station and not through Grenshopper.

This concerns the following data:

  • Name and address, needed to draw up the mandate
  • Email address, for confirming the mandate and for messages about a transaction
  • A payment token or mandate number, which links a transaction to your payment method

Grenshopper never stores a full card number or a CVC, and never gets to see them either. Your card details go straight to the payment party; we only receive a token, and that cannot be used to pay outside Grenshopper.

You can withdraw your mandate or change your payment method in your profile in the app. What happens to the data held by the payment parties after that is set out in their own privacy statements.

6.2 Transfers outside the EU

Some of these parties are based in the United States or have servers there, such as Cloudflare, Vercel, Twilio SendGrid, Apple and Google. We protect data that goes there with the safeguards of the GDPR, such as the EU-US Data Privacy Framework or the standard contractual clauses of the European Commission.

7. Retention periods

We do not keep your data any longer than is necessary for the purposes it was collected for.

  • Account, profile and vehicle data, saved places, preferences, reviews and fuel receipts: for as long as your account exists. If you delete your account, we delete this data within 30 days.
  • Transactions when paying at the pump: for as long as necessary to process the payment and to meet legal retention obligations.
  • Feedback and screenshots: for as long as necessary to handle your feedback and improve the app, up to a maximum of 24 months.
  • Push tokens: for as long as you allow notifications and use the app.
  • Free fuel data: for as long as the promotional round runs, and afterwards for as long as necessary for the draw, later checks and our legal obligations.
  • IP addresses for security and misuse prevention: up to two hours in our own systems. Technical log files at our suppliers are deleted automatically after a short time.
  • The code for your installation and the public key used to check that the app is genuine: up to twelve months after last use. The proof the app receives with it is valid for 24 hours.
  • Data in the test environment: see article 11.
  • Aggregated and anonymised statistics that can no longer be traced back to individuals: indefinitely.

After the retention periods mentioned, data is deleted or anonymised.

8. Your rights (GDPR)

Under the General Data Protection Regulation (GDPR) you have the following rights:

  • Access: you can ask what data we hold about you
  • Correction: you can have incorrect data corrected
  • Deletion: you can ask for your data to be deleted
  • Objection: you can object to processing based on legitimate interest, including the internal analysis described in article 5
  • Restriction: you can ask for processing to be restricted
  • Portability: you can ask for your data in a readable format
  • Withdrawing permission: you can always withdraw permission you gave earlier, including permission for location data

You can also delete your account and the associated data yourself in the app settings.

You can send requests to hello@grenshopper.nl. We reply within 30 days.

9. Security

We take the security of your data seriously. Among other things, we use:

  • Encrypted connections (HTTPS/TLS) for all app traffic
  • Storage at Supabase in the EU, with per-user access rules at database level (Row Level Security)
  • Passwords that are only stored in encrypted (hashed) form
  • No full card numbers on our side: they go directly to the payment party (see 6.1)
  • A limit on the number of requests per user or IP address, against misuse and mass extraction of data
  • A check that requests come from the genuine Grenshopper app on a genuine device (App Attest by Apple, Play Integrity by Google)
  • Checking screenshots on arrival, with metadata removed
  • Regular security checks, including by an external specialist

10. Minors

Grenshopper is not meant for children under 16. We deliberately do not collect data from minors.

11. Test phase

If you take part in the test phase, the following also applies:

  • You use a separate test environment with servers in the EU. Data in it may be deleted along the way and is removed at the latest at the end of the test phase, unless we ask you beforehand whether you want to take your account with you to the final app.
  • We use your email address to invite you and keep you informed about the test phase. We use Twilio SendGrid for this. You can unsubscribe at any time.
  • Apple (TestFlight) or Google (Google Play) process your email address and the data you share with them yourself, such as crash reports, under their own terms.
  • We use feedback, possibly with a screenshot, to fix errors and improve the app.
  • A specialised security party may examine the test environment on our behalf. In doing so, it may see personal data in the test environment. It works under confidentiality and a data processing agreement, and may only use that data for that examination.

12. Changes

We may update this privacy policy from time to time. If a change is significant, you will get a message about it in the app. The most recent version is always available at grenshopper.nl/privacy.

13. Contact and complaints

Do you have questions or complaints? Get in touch at hello@grenshopper.nl. You also have the right to lodge a complaint with the Autoriteit Persoonsgegevens, the Dutch data protection authority, at autoriteitpersoonsgegevens.nl.