Skip to content

Privacy Policy

How LaterCart handles your data

A plain-language explanation of the data LaterCart uses to run your purchase Dashboard, browser extension, and reminder emails.

Effective date: August 17, 2026

This policy explains how LaterCart handles personal data. It is written with the Swiss Federal Act on Data Protection (FADP) and the GDPR in mind.

Overview

LaterCart is a purchase-decision web app and browser extension for Products you almost bought. You save a product reference instead of buying it, let it wait, and decide later. LaterCart is not a shop. It does not sell products, place orders, or process store payments.

This policy describes what personal data LaterCart collects, why, and what rights you have. We try to collect only what the product needs to work.

Who is responsible

LaterCart is operated by Jon Kevin Wong Gutierrez as an individual in Switzerland. For the first stage of the project, LaterCart does not operate through a separate company.

For privacy questions and requests, contact hello@getlatercart.com.

Data we collect

Account data. Your email address and authentication identifiers. If you sign in with Google, we also receive the name and profile picture connected to your Google account.

Saved product data. The items you choose to save: product title, product URL, shop or domain name, image URL, price and currency, category label, Collection name, personal notes, want level, saved date, waiting time and decision date, status, and notification settings.

Price tracking data. If you turn on price tracking for an item, we store the prices we observe on that item's public product page over time.

Email data. Whether decision reminders and price-drop emails are enabled, and delivery information such as whether an alert was claimed, retried, or sent. For a price alert, a restricted delivery record freezes the recipient and exact email content before sending so a technical retry cannot change or duplicate the message.

Technical data. IP address, browser and device information, request logs, error information, and similar data generated when you use the website, app, or extension. We use this to keep the service running and secure.

Payment data. If you buy a paid plan, our payment provider processes your payment details directly. See the Payments section below.

Browser extension

By default, the extension does not run on every website. When you open the LaterCart toolbar popup, it uses temporary access to the active tab to detect product details or selected basket items for the save form. It may process the product title, link, image, displayed price, currency, shop name, and basket line-item title, quantity, and selected state. You can review and edit detected details before saving.

Smart Save prompts are optional and off by default. If you choose to enable them, the browser asks you to grant access separately for the exact shop site you chose. Product-page detection happens locally in your browser only on approved shops. The Smart Save page in your LaterCart account reflects the installed extension's settings for that browser; these permissions may differ on another device. You can remove one shop or all Smart Save access at any time.

LaterCart does not inspect protected browser pages or identifiable checkout, payment, login, account, email, admin, banking, or health pages. It does not read payment-card details, passwords, address fields, or unrelated form input. It does not retain or send your browsing history. Product and basket details are sent to LaterCart only after you explicitly confirm a save.

The extension stores its connection session, recent save status, configured Smart Save shop origins and states, and per-site disabled-prompt hostnames in Chrome extension storage. It does not upload general browsing history to power Smart Save settings. Authentication tokens are never placed in a shopping page or page storage. Access tokens are sent only to LaterCart’s API; refresh tokens are sent only to LaterCart’s dedicated Supabase authentication project. LaterCart does not sell extension data or use it for advertising.

Why we use data

  • To create your account and let you sign in.
  • To provide the service: saving, showing, organizing, updating, and recording Decisions for Products.
  • To calculate waiting times and decision dates.
  • To send decision reminder and price-drop emails when each preference is enabled.
  • To check prices for items you track, where the shop page allows it.
  • To handle billing for paid plans.
  • To keep the service secure, prevent abuse, and debug errors.
  • To respond to support requests.
  • To comply with legal obligations that apply to us.

If we add product analytics or error monitoring tools in the future, we will name them in this policy before they are used. We are preparing to use Google AdSense to fund the free version of LaterCart; the advertising disclosures below apply once ads are enabled.

Product emails

LaterCart may email you when a saved item is ready to revisit. If you explicitly enable price-drop emails and keep Price Watch active for an item, LaterCart may also email you after a meaningful confirmed price decrease. These emails relate only to items you saved. You can control decision reminders and price-drop emails separately in account settings. Transactional account emails may still be sent where necessary, for example about billing or security.

Payments

Paid plans are processed by Stripe. Your card details go directly to the payment provider; LaterCart does not receive or store full card numbers. We receive information needed to manage your plan, such as your subscription status and billing tier.

Third-party processors

We use a small number of service providers to run LaterCart. They process data on our behalf and only as needed to provide their service:

  • Vercel: website and app hosting, serverless functions, and scheduled jobs.
  • Supabase: authentication and database.
  • Google: sign-in with Google, if you choose that login method, and Google AdSense advertising once ads are enabled.
  • Resend: sending reminder, price-drop, and transactional emails.
  • Stripe: payment processing for paid plans.
  • No standalone analytics provider is currently used. This policy will be updated before one is added.

When AdSense is enabled, Google may process device and browser information, IP address, page and ad interactions, cookie or similar identifiers, and consent signals to select, deliver, limit, secure, and measure advertising. Depending on your region and choices, ads may be personalized, non-personalized, or limited. LaterCart does not give Google your private Product notes or account credentials for advertising.

A current list of processors and their documentation can be requested via the contact email below.

Cookies and local storage

LaterCart separates cookies and similar storage into three categories:

Essential. Always on, because they are needed for login, security, and core app features such as your saved products. This includes authentication cookies and the local storage the app and browser extension need to work. Your consent choice itself is stored locally so we do not ask again.

Analytics (optional). Off unless you turn it on. Used to understand how LaterCart is used, in aggregated form, so we can improve the product. No analytics vendor is connected today; if one is added, it will only run with your consent and will be named in this policy.

Marketing and advertising (optional). Used for optional attribution and, once enabled, advertising. Where consent is required, Google advertising choices are collected through a Google-certified consent platform. You may be offered personalized, non-personalized, or limited ads depending on your location and choice. The LaterCart marketing toggle remains off by default and controls LaterCart's own optional marketing storage; Google's advertising choices are shown separately when applicable.

LaterCart may use aggregated, non-identifying shopping insights, such as overall trends across many users, to understand usage and improve the service. We do not sell your personal Dashboard data by default, and we do not build individual shopping profiles for sale. Any change to this would require an update to this policy and, where required, your consent.

You can change your choices at any time via the Cookie settings link in the footer of every page.

International transfers

Our service providers may process data outside Switzerland and the EU/EEA, including in the United States. Where that happens, we rely on recognized safeguards such as adequacy decisions or standard contractual clauses offered by the provider.

Data sharing

We do not sell your personal data, and we do not sell your saved product lists, Collection names, notes, or category labels. We share data only with the processors listed above, or where required by law, legal process, or to protect the security of the service and its users.

Retention and deletion

Account and Dashboard data are kept while your account exists. We aim to retain routine technical and security logs for no longer than 30 days, unless a longer period is needed to investigate an incident or comply with law.

Account deletion is currently handled by request at the contact email below. We aim to delete or anonymize account and saved product data within 30 days of verifying the request. Encrypted backups may retain the data for up to 90 days, and we may retain billing records where required by law.

Your rights

Depending on where you live, you have rights under the Swiss FADP, the GDPR, or similar laws, including the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Delete your data.
  • Receive a copy of your data in a portable format.
  • Object to or restrict certain processing.
  • Withdraw consent where processing is based on consent.
  • Complain to a supervisory authority, such as the Swiss FDPIC or your local data protection authority.

To exercise any of these rights, or to request account deletion, email hello@getlatercart.com from the address connected to your account. We may need to verify your identity before acting on a request.

Security

We use account-based access controls, encrypted connections, server-side secrets, and database row-level access rules to keep each user's saved items private. Access to production data is limited to what is needed to operate the service.

No online service can guarantee perfect security. Please use a strong password and do not send passwords or payment details through support messages.

Children

LaterCart is not directed at children. You must be at least 16 years old to use LaterCart, or older where your local law requires it. If you believe a child has created an account, contact us and we will delete it.

Changes

We may update this policy as LaterCart changes. If a change is significant, we will make it visible in the app or by email. The effective date at the top shows the latest version.

Contact

Jon Kevin Wong Gutierrez operates LaterCart as an individual in Switzerland. For privacy questions and requests, contact hello@getlatercart.com.