Privacy Policy

Last updated 2026-07-31

l8r.shop lets shoppers save products they find in physical stores — by scanning a QR code or taking a photo — so they can come back to them later. This page explains what we collect, who we share it with, and how to delete your data. It applies to shoppers using l8r.shop ("consumers") and to the retailers who list their catalog on l8r.shop.

The short version: a retailer never learns who saved their product unless you explicitly say so, for that specific save. Anonymity is the default, not an opt-out.

What we collect

If you're a shopper:

  • Your email address (for sign-in — we use passwordless magic links, so we never store a password)
  • Products you save, and their status (saved / purchased / no longer interested)
  • Consent records — whether you agreed to share your contact info with a specific retailer for a specific save, and when
  • Optional profile attributes you choose to provide (age, gender, clothing/shoe size) — each has its own sharing toggle, off by default
  • A coarse, city-level location signal if you opt in to confirm an in-store scan — see "Location" below; we never store your exact coordinates
  • A random visitor identifier in a first-party cookie, so our own analytics can count anonymous shoppers as distinct people (e.g. how many people who scan in a store later save something). It's a randomly generated ID — not derived from your device, network, or location — it's never shared with retailers or anyone else, and it's deleted when you sign out or delete your account

If you're a retailer:

  • Your contact email and store information
  • Your product catalog (synced from Shopify, or entered manually)
  • OAuth access tokens for services you connect (Shopify, Instagram), encrypted at rest

If you connect Instagram (retailers only):

We read your Instagram Business account's recent post images and captions, solely to match them against your product catalog for visual search. We don't access or store anything about your followers or anyone else's Instagram activity.

How your identity works

When you save a product, we ask — every time, for that specific retailer — whether you want to share your contact info with them. If you decline, the item still saves to your own list and still gets a reminder; declining only affects what the retailer sees.

If you decline, the retailer never sees anything that identifies you for that save — not your email, name, account ID, or any other identifier. All they see is that their product's save count went up by one, the same as every other undisclosed save.

If you do share, that retailer sees your contact info for that one save, and only that retailer — a different retailer you've also interacted with never sees it unless you separately agree to share with them too. You can revoke a share at any time from your dashboard — the retailer's access to your contact info for that item is removed immediately.

We never sell or license what any individual person saved, scanned, or ignored. When we ever show retailers aggregate shopper patterns (e.g. demographics), we require a minimum group size before showing anything — never a breakdown small enough to identify one person — and operational counts (saves, clicks) carry no such limit, since a retailer already knows a shopper interacted with their own product.

Location

If you enable it, location is used to confirm a scan happened in-store. Your exact coordinates are used for a single moment on our server to compute that confirmation, and are then discarded — we don't log them, store them, or send them anywhere. There is no location history for any shopper. Retailers only ever see either a coarse confirmation ("verified in-store") or a city-level area, never anything more precise.

Enabling location is always optional — scanning and saving work identically without it.

Photos you scan

If you photograph a product to identify it, that photo is sent to our image-matching provider to find the product, and is discarded immediately after. We don't keep a copy.

Who we share data with

We use the following processors to run l8r.shop. None of them are permitted to use your data for anything beyond the service listed:

ProviderWhat they receiveWhy
SupabaseAuth identity, emailSign-in and database hosting
VercelRequest traffic (transient)Application hosting
ResendEmail address, saved-product namesDelivering reminder emails
PostHogInternal user IDs, random visitor IDs, event metadataProduct analytics (internal use only)
OpenAI / CohereScan photos (transient), catalog imagesMatching a photo to a product; not used to train their models per their API data policies
Shopify / InstagramRetailer catalog / post data (only if a retailer connects them)Catalog sync
OpenStreetMapStore addresses only — never consumer dataOne-time store geocoding

We use essential cookies to keep you signed in and to get you back to the right page after signing in, plus one first-party analytics cookie: the random visitor ID described above, which lets us count anonymous shoppers as distinct people in our own analytics. It expires after a year, and is deleted sooner when you sign out or delete your account. We don't use advertising or cross-site tracking cookies — PostHog, our analytics processor, runs entirely server-side and sets no cookie of its own in your browser.

Deleting your data

If you're a shopper:

Go to Profile Delete account. This immediately and permanently deletes your saved items, consent records, profile attributes, and sign-in identity — there's a confirmation step, and it cannot be undone. A small number of rows tied to your activity (like product-view records) are anonymized rather than deleted — the references back to you, including your account ID and the random visitor ID from your browser, are removed, not the row itself. The visitor cookie itself is cleared as part of deletion. Database backups age out on our hosting provider's own retention schedule.

Prefer email? Send a deletion request to hello@l8r.shop and we'll delete your account for you.

If you're a retailer:

Uninstalling l8r.shop from your Shopify admin removes our access to your store immediately. We don't yet have a self-serve disconnect for Instagram, or for removing a Shopify connection from within l8r.shop itself — email hello@l8r.shop and we'll remove your connected accounts and any associated data by hand.

If l8r.shop is ever acquired or sold

Your data would only transfer under these same commitments. We would notify you before any transfer and give you at least 30 days to delete your account first if you'd rather not carry over.

Questions

Email hello@l8r.shop with any privacy question or concern.

This policy describes what l8r.shop actually does today, not aspirational goals. If we ever change how we handle your data, we'll update this page and note the change.