Privacy policy
Last updated: 2 October 2026
Who we are
Order-Bot is operated by Luke Durrant (contact@lukedurrant.com), an Australian sole trader. “We”, “us” and “our” in this policy refer to Order-Bot.
What this policy covers
- The Order-Bot website at openorder.bot and its regional subdomains (au.openorder.bot, uk.openorder.bot, nz.openorder.bot)
- The Order-Bot Price Compare browser extension (Chrome, Firefox, Safari)
- The Order-Bot API at
*.openorder.bot/api/*
Data we collect
Account data
When you create an account we collect:
- Email address (used for login and account recovery)
- Password (stored hashed, never in plaintext — handled by Supabase Auth)
- Optional postcode (used to show postcode-specific prices)
Saved orders and lists
When you use the “Save cart” feature, the contents of that cart (product names, quantities, retailer) are stored against your account so you can re-open them later.
Filling a basket from inside your own browser
Some retailers publish no link for adding a whole list to a basket. At those stores, when you ask us to send a list, the extension adds it from the retailer’s own page — in the tab you are already signed into, and only after you press “Fill my basket” there.
What that means in practice:
- the request is the retailer’s own, made by your browser in the session you signed into yourself. Our servers never contact a retailer
- we never read, store or receive your retailer login, verification codes, cookies or payment details. Whatever the request needs from the page stays in that tab
- nothing is added until you press the button, and we never continue to checkout or place an order
- what comes back to us is the outcome only: which batch, whether the store accepted it, and how many lines it acknowledged
Browsing data captured by the extension
When you visit a supported retailer’s product, search or cart page and have the extension installed, the extension reads the publicly displayed product, price and pack data from that page and sends it to the Order-Bot API. This data is associated with your Order-Bot account (when signed in) and used to:
- show you the cross-retailer price comparison you requested
- improve the price-history dataset that other shoppers see when they visit the same product page
The extension does not collect:
- any data outside the retailer hosts and openorder.bot listed in the extension’s manifest
- form data, passwords, payment details, or anything you enter on a retailer site
- cookies from any retailer site
- your full browsing history
Server logs
Standard request logs (URL, IP address, user-agent, timestamp) are retained for 30 days for diagnostic and abuse-prevention purposes. They are not shared with third parties.
Telemetry
We use Mixpanel to track aggregated, anonymised product-usage events (e.g. “comparison panel rendered”, “cart saved”). We do not send Mixpanel any personally-identifiable information beyond a per-user pseudonymous ID. When you send a shopping list to a retailer’s cart we record the store, the region and how many lines were sent — never the products or your retailer account.
If you arrive from one of our Google ads (your link carries a Google click identifier or paid campaign parameters), we load Google’s conversion tag so Google can count whether that ad led to an account being created. It runs only for those visits, is configured with ad personalisation off, and is not loaded for anyone who reaches the site another way. If an ad visit follows an earlier visit from another source, we remember the ad visit time in a cookie for 30 days, shared across our regional sites, so signup tracking continues through navigation and sign-in. This does not replace the original source recorded for your first visit.
How we use your data
- To operate the comparison and save-cart features you’ve asked for
- To improve the cross-retailer price dataset that powers the same features for other shoppers
- To detect and prevent abuse of the service
- To contact you about your account if you’ve asked us to (account recovery, service-affecting issues)
We do not use your data for behavioural advertising. We do not sell your personal data.
Aggregated price data
The product, price, pack and availability information the Service collects — from our own systems and from prices the extension or the API captures — is kept as aggregated, de-identified price data: it describes products, prices, places and times, not people. We may publish it, make it available through our API, and license or sell it and datasets derived from it to third parties, including retailers, researchers, developers and AI assistants. Anything that identifies you, your account or that you were the source of a price observation is removed first. Our terms of service set out the licence you grant over prices you contribute.
AI assistants (ChatGPT, Claude and other MCP apps)
You can connect OpenOrder to an AI assistant that supports the Model Context Protocol, such as the OpenOrder plugin in ChatGPT. You sign in to OpenOrder on our own consent page and approve the connection; the assistant never sees your OpenOrder password. You can disconnect it at any time in the assistant’s settings.
When you ask the assistant to use OpenOrder, we return only what that request needs:
- grocery prices, store comparisons and product links from our price data
- your recipe library, meal plans and shopping lists, and the retailer cart links built from them
- the postcode or area your prices are for, when a comparison uses your saved postcode
We do not return your email address, password, payment details or internal account identifiers. To choose which country’s stores to compare, we use the country of your saved postcode or, if you have none, the coarse country hint the assistant sends with the request; we do not store that hint. The assistant’s provider (for example OpenAI or Anthropic) receives the results under its own privacy policy. Requests made through an assistant are rate-limited per account and logged like any other request.
How long we keep data
- Account data, saved lists, recipes and meal plans: until you delete them or your account
- Server request logs: 30 days
Where data is stored
All Order-Bot data is stored with Supabase, hosted in the ap-southeast-1(Singapore) region. Telemetry is sent to Mixpanel (United States).
Sharing with third parties
- Supabase — provides our database and auth. Privacy policy.
- Vercel — hosts the Order-Bot web app and API. Privacy policy.
- Mixpanel — aggregated product analytics only. Privacy policy.
- Google Ads — conversion measurement, only on visits that arrive from one of our Google ads. Privacy policy.
- Retailers, when you send a list to their cart— either a link we build, which opens in your own browser and your own retailer account, or (at stores that publish no such link) a request your own extension makes from the retailer’s page after you press Fill. Either way it carries only the retailer’s product numbers and quantities, plus a tag naming Order-Bot as the source. We never see, store or handle your retailer login, verification codes, cookies or payment details, and we never place an order.
If you connect an AI assistant, the results of the requests you make through it go to that assistant’s provider (see above). We don’t share your personal data with any other third parties. Aggregated, de-identified price data may be shared or licensed as described above.
Your rights
You can:
- Request a copy of all data we hold about you
- Correct or update your data
- Delete your account and all associated data
Email contact@lukedurrant.comto make any of these requests. We’ll respond within 30 days.
Cookies and similar technologies
The Order-Bot website uses a single first-party authentication cookie set by Supabase when you sign in. The extension reads that cookie (and only that cookie) when sending API requests on your behalf. We also keep a first-party cookie recording which link first brought you here, so a later sign-up can be credited to it. The only third-party cookie is Google’s conversion cookie, set only on visits that arrive from one of our Google ads (see Telemetry above).
Changes to this policy
We may update this policy from time to time. Material changes will be announced on the Order-Bot website. The “last updated” date at the top of this page reflects the most recent change.
Contact
Privacy questions or data requests: contact@lukedurrant.com