User Journeys¶
Each journey traces one persona through a complete flow and realizes a set of the user stories. Journeys 1–4 follow the thin end-to-end slice (anonymous scan -> optional account -> personal verdict -> fridge); Journeys 5 and 6 cover privacy and the brand side; Journeys 7 and 8 cover the shopping list and the revisit/compare experience specified on top of the slice. These are requirement narratives, not an implementation-status report. Journey 5's whole-account path and Journey 6's product onboarding path are not yet implemented.
The personas (Anonymous Shopper, Sara, Marco) are defined in Stories Section 1.
Journey 1, First scan, no account (Anonymous Shopper)¶
Context: the shopper is at a supermarket shelf with no installed app and no Account.
Goal: know what this product is, what's in it, and whether to trust it, in seconds.
- For a GS1 Digital Link URL, the shopper uses the phone's native camera and the browser opens without an app download. A plain EAN/UPC barcode requires the in-app scanner because it is not itself a URL.
- The GS1 resolver preserves supported application identifiers encoded in the Digital Link, such as GTIN, lot, serial and expiry. The current in-app linear-barcode path extracts GTIN only; it must not claim qualifiers that were not encoded or decoded.
- The Product Passport opens in the browser and is subject to the complete-flow target in QAS-1.
- The shopper checks the digital label: ingredients, highlighted allergens, nutrition table.
- Optionally they expand the journey and the eco score.
- A single dismissible line notes that a personal verdict exists for account holders. It never blocks the product information.
Exit points:
- Finished, closes the browser after reading the Product Passport.
- Curious, taps "Create a profile", entering Journey 2.
- Comparing, scans another candidate and opens Compare / History (Journey 8).
Failure paths:
- Unknown product: a clear "We don't know this product yet" screen with a one-tap report option, never a raw error.
- Partial data: a failed data source (e.g. eco score) shows a "temporarily unavailable" note on that section only; the rest of the passport renders normally.
Journey 2, From anonymous to Sara (sign-up and health profile)¶
Context: the shopper has scanned a few products and wants the personal verdict. Sign-up is invited, never forced.
Goal: create an optional Account and record informed consent before collecting a Health Profile.
- From a scan result (or a landing page), the shopper taps "Create a profile".
- Sign-up asks only email + password; authentication is handled by the platform's identity provider.
- The pseudonymous Visitor ID from earlier scans is linked to the new account, so no pre-account activity is lost.
- A one-screen privacy summary explains in plain language that brands only ever see anonymous aggregates.
- The app asks whether to enable health personalization. This step is explicitly optional:
- Decline -> onboarding ends. Nothing is saved; the account works fine without personalization.
- Accept -> explicit opt-in is recorded (checkbox + timestamp + policy version).
- Sara selects her allergies and conditions from the standard EU list, for her: milk, lactose intolerance.
- She sets her diet (high-protein) and one primary goal (build muscle).
- Onboarding ends back where she started, ready to scan.
Exit point: a complete or minimal profile, editable at any time.
Journey 3, "Does this fit me?" (Sara's personalized scan)¶
Context: Sara, logged in with her health profile, picks up a yogurt at the shelf. This is the core moment of the product.
Goal: receive a personal Verdict within the scan response budget.
- Sara follows the scan steps in Journey 1.
- The scan result opens with the verdict at the top, before any other detail:
- Avoid, the yogurt contains milk: a prominent red allergen warning (color + icon + text).
- Be careful, e.g. a condition or diet conflict, shown as a medium-severity warning with a one-line reason.
- Good for you, plus one or two plain-language lines tying the product to her goal: "high in protein, fits your muscle-building goal".
- Unknown, when the label is incomplete the product cannot be assessed; it is shown as Unknown, never silently Good.
- Tapping the verdict reveals the reasons; scrolling past it shows the same full passport any anonymous shopper sees.
- Sara decides at the shelf: put it back, or buy it.
Exit points:
- Bought it, one tap adds it to her Fridge, entering Journey 4.
- Want it later, adds it to her Shopping List instead, entering Journey 7.
- Put it back, scans the next candidate; the loop repeats.
Journey 4, My Fridge¶
Context: Sara is home with her shopping. Days pass between the steps of this journey, it is the only flow that spans weeks.
Goal: use items before expiry and review monthly consumed and discarded counts.
- After scanning (or right after Journey 3), Sara taps "Add to Fridge". An expiry date present in the resolved Digital Link is stored with the physical item; the same item cannot be added twice, while multiple items may share a GTIN.
- Whenever she opens the Fridge, items are sorted by what expires first, with fresh / expiring (≤5 days) / expired states visually distinct.
- When an item crosses the expiring threshold, the service creates one in-app alert for that item and freshness level. The alert appears when she opens the Fridge; no push-notification channel is implemented.
- As she cooks and shops, she removes items, marking "used" vs "thrown away" so the waste count remains accurate. On removal she may be offered "add to shopping list?" to re-buy a staple (Journey 7).
- At the end of the month she sees plain counts, without points or badges: "you used 14 items and discarded 2". Expiry alone is not counted as waste.
Exit point: a Fridge projection that matches current items and a monthly outcome summary.
Journey 5, Walking away (consent revocation and erasure)¶
Context: Sara decides she no longer wants her health data on the platform, or wants to leave entirely. This journey must be as short as sign-up.
Goal: exercise her right to erasure with one clear action.
- From settings, Sara chooses between deleting the health profile only or the whole account.
- The flow requires one action and one confirmation and does not add a retention prompt.
- Health-profile deletion is implemented. Whole-account deletion is an accepted contract but is not yet implemented; it must not be presented to users as complete until its publisher, idempotent erasure consumers and completion reporting exist.
- If she deleted only the Health Profile, the app remains usable and returns to the anonymous-style experience of Journey 1, with an account. Her Shopping List, which is not health data, is unaffected.
Exit point: the selected data scope is erased and the result is reported to the Consumer.
Journey 6, Proof of engagement (Marco at the brand dashboard)¶
Context: Marco needs to justify the QR investment internally. He logs in from his desk, not from a shelf.
Goal: review privacy-thresholded engagement evidence for an internal report.
- Marco logs into the B2B interface and sees the list of his brand's products on the platform.
- For each product he reads total scans and a trend over time in a table and trend line.
- For depth of interest, he checks aggregate engagement signals: % of scans saved to a Fridge, % of scanners with accounts. Every number is an aggregate with a minimum group size; nothing is traceable to a person.
- In the planned onboarding flow, he submits label, origin and sustainability data through a validated manual producer process. The current producer snapshot is operated outside the dashboard.
Exit point: a dashboard suitable for an internal meeting, with no access to any individual consumer.
Journey 7, My Shopping List¶
Context: Sara manages products she intends to buy separately from products currently in her Fridge. The client coordinates transfers only after explicit confirmation.
Goal: keep a reliable list of catalog products and close the loop between buying and owning.
- Sara adds a product to her list, by searching the catalog by name, from a scan result (Journey 3), or via the "re-buy?" prompt when a Fridge item leaves (Journey 4). Every entry references a GTIN with a trusted product snapshot; there are no free-text notes.
- Adding something already on the list bumps its quantity rather than duplicating the line.
- She opens the list, adjusts quantities, and marks each item as bought or removed while she shops.
- On marking an item bought, she is offered "add to fridge?", one confirmation re-stocks the Fridge by GTIN, no re-scan needed.
Exit points:
- Re-stocked, a purchased item flows into the Fridge (Journey 4).
- Done shopping, a clean list reflecting what she still needs.
The fridge ↔ list loops are client-orchestrated prompts, each crossing is an explicit user confirmation, never a silent background sync.
Journey 8, Revisiting and comparing (Anonymous Shopper)¶
Context: the shopper scanned several products and wants to find one again, or choose between two, without standing in the aisle re-scanning.
Goal: get back to a product, or decide between candidates, in a couple of taps.
- From the History tab, the shopper searches the device-local recent-scan cache by product name or brand and reopens a product. The cache retains at most 100 product entries, deduplicated by product, and is available without an account. It is not a complete server history.
- From the home screen's recent scans, they pick two or three products and open Compare, which highlights field-level differences such as eco score and sugar.
- Throughout, the interface is in the shopper's language (English, Italian, Spanish or French). The existing Italian, Spanish, and French strings still require native review before production-quality localization can be claimed.
Exit point: the shopper finds or chooses a product and continues into a normal passport view (Journey 1), or, if signed in, a personal verdict (Journey 3).