Cold Cart logoCold Cart Back to site
Legal

Privacy Policy

Last updated 24 July 2026

Cold Cart is built to help you shop more calmly — not to harvest your data. This policy explains exactly what we collect, why, who we share it with, and how you stay in control.

On this page

  1. Data we collect
  2. How we use it
  3. Service providers
  4. Affiliate links
  5. Retention & deletion
  6. Your GDPR rights
  7. Children
  8. Contact

01Data we collect

We only collect what the app needs to do its job. That falls into a few categories:

What
Details
Account
Your email address and an encrypted password (or the identifier from your chosen sign-in provider), so you can log in and sync across devices.
Saved links
The product URLs you add, plus the title, price, and image we automatically extract from each page so your cart is readable.
Uploaded photos
Any images you attach to an item yourself. Stored only to display them back to you.
Push token
A device token used solely to send the reminder when an item's 48-hour cool-down ends. No token, no notifications.
Currency preference
The currency you pick, so prices and savings totals display correctly.
Analytics events
Aggregated, non-identifying usage events via Firebase Analytics (e.g. "item added", "screen opened") to understand what to improve.

We do not collect payment card details — Cold Cart never processes purchases — and we do not sell your personal data to anyone, ever.

02How we use it

We never use your data for third-party advertising, and we don't build advertising profiles about you.

Under the GDPR, our legal bases for processing are: performance of a contract — running your account and the core features; legitimate interest — aggregated analytics and keeping the service secure; and consent where required, such as push notifications, which you can withdraw at any time in your device settings.

03Service providers

To operate Cold Cart we rely on a small set of trusted infrastructure providers. Each processes only the data needed for its function, under its own privacy terms:

HetznerServer hosting (EU) — stores your account and saved items.
CloudflareCDN, security, and image delivery.
Google / GeminiFirebase Analytics, and AI processing of product pages to extract title & price.
Scrape.doFetches product pages so we can read their public details.
ResendSends transactional email (verification, account notices).
ExpoDelivers push notifications for cool-down reminders.

Some of the providers above (Cloudflare, Google, Resend, Expo) are based in the United States, so limited data may be transferred outside the EEA. Such transfers rely on recognised safeguards — the EU–US Data Privacy Framework and/or Standard Contractual Clauses.

04Affiliate links

Some outbound product links in Cold Cart may be affiliate links. If you buy through one, we may earn a small commission at no extra cost to you.

This never changes the price you pay, never affects which items you can save, and never influences the cool-down process. It simply helps support the app.

05Retention & deletion

We keep your data only for as long as your account exists. You can delete everything yourself, at any time:

Once deleted, data cannot be recovered. Some minimal records may persist briefly in encrypted backups before being overwritten on their normal cycle.

06Your GDPR rights

If you're in the EEA or UK, you have the right to:

To exercise any of these, email us and we'll respond within 30 days.

07Children

Cold Cart is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has provided us data, contact us and we'll delete it promptly.

08Contact

Questions about this policy or your data? Reach the developer directly at [email protected]. Cold Cart is operated by an individual developer, who is the data controller for the purposes of GDPR.