Privacy & Data Policy
This Privacy & Data Policy explains what information ChronoCart LLC (“ChronoCart,” “we,” “us”) collects, how we use and protect it, who we share it with, and—importantly—how long we keep it. It applies to our website (chronocart.xyz), the member dashboard, our Discord bot and server, and our iOS and Android apps (together, the “Service”).
1. Information We Collect
We collect the following categories of information, and only as needed to provide the Service:
Account & identity
When you sign in with Discord, we receive your Discord user ID, username, and avatar, and (with your permission) add you to our Discord server. We use this to create and secure your member account. We do not receive your Discord password.
Payment information
Subscriptions are processed by Stripe. We do not collect or store your full card number, CVC, or bank details—those go directly to Stripe. We store your Stripe customer and subscription identifiers, your plan, and your billing email so we can manage your membership.
Checkout profile information
To check out on your behalf, you submit retailer “profiles” through our forms. These may include your name, shipping address, email address, phone number, and the retailer account(s) you want us to use. We store this so our automation can complete purchases you’ve asked us to attempt.
Retailer email inbox access (optional)
If you choose to connect a retailer email inbox for order tracking, we store your mailbox login encrypted at rest (AES-256-GCM) and use it solely to read order, shipping, and delivery-confirmation emails. See Section 4 for the full details.
Checkout & order activity
We record the activity our automation generates for you: products, retailers, quantities, prices, order numbers, success/decline outcomes (including decline reasons), tracking and delivery status, and timestamps. This powers your member dashboard.
Collection data
If you use the “My Collection” feature, we store the items you add and any values or notes you provide.
Device & app data
In our mobile apps we may store a push-notification token so we can alert you to checkouts and order updates. Biometric unlock (Face ID / Touch ID) is handled entirely by your device—we never receive your biometrics. We do not collect your precise location.
Technical & usage data
Like most online services, our servers log basic technical data such as IP address and request metadata for security, abuse prevention, and rate limiting.
2. How We Use Your Information
- To provide the core Service—run automated checkouts you request and show you the results.
- To process your subscription and billing through Stripe.
- To track your orders and shipments and keep your dashboard up to date.
- To send you notifications (checkout wins/declines, order updates, billing notices) via Discord DM, push, or email.
- To provide support and respond to your requests.
- To secure the Service, prevent fraud and abuse, and enforce our terms.
- To comply with legal, tax, and accounting obligations.
We do not use your data for third-party advertising, and we do not sell your personal information.
3. How We Share Your Information
We share data only with service providers that help us operate, and only as needed. Our key processors are:
- Discord — sign-in, membership, and notifications.
- Stripe — payment processing and subscription management.
- Google — our profile-submission forms and the spreadsheets/Apps Script that receive them.
- Vercel — hosting for our authenticated API layer.
- DigitalOcean — hosting for our automation server and database.
- Apple & Expo — app distribution (TestFlight/App Store) and push-notification delivery.
- Your email provider — only if you connect an inbox for order tracking (read access, on your behalf).
We may also disclose information if required by law, to protect our rights or users’ safety, or in connection with a business transfer. Aggregated or anonymized statistics that cannot identify you may be shared or published (for example, public checkout counts on our homepage).
4. Retailer Email Access
Connecting an email inbox is entirely optional and used only for order tracking. When you connect one:
- Your mailbox credentials are stored encrypted with AES-256-GCM and are never displayed back to you or shared.
- We use read-only access to scan for order, shipping, and delivery-confirmation emails and extract the relevant order details (order number, status, tracking, delivery date).
- We do not read, store, or use unrelated email content, and we never send email from your account.
- You can disconnect the inbox at any time from your dashboard, which permanently deletes the stored credentials.
We recommend using a dedicated shopping inbox and an app-specific password where your provider supports it.
5. Automated Checkouts
ChronoCart acts on your behalf, using the profile information you provide, to attempt purchases at retailers when eligible products go live. You are responsible for the accuracy of the information you submit and for complying with each retailer’s terms of service. We are not affiliated with, endorsed by, or sponsored by any retailer.
6. Data Security
We take reasonable technical and organizational measures to protect your information, including:
- Encryption at rest for connected email credentials (AES-256-GCM).
- Signed, verified sessions (HMAC-SHA256) between the app/dashboard and our API.
- No storage of full payment card data—handled by Stripe under PCI-DSS.
- Access controls and a secret that keeps our automation server private and not directly exposed to the public internet.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal data, we will notify you and any regulators as required by law.
7. Data Retention
We keep personal information only for as long as we need it to provide the Service, meet legal and tax obligations, resolve disputes, and enforce our agreements. When it is no longer needed, we delete it or irreversibly anonymize it. The table below is our standard retention schedule.
| Data type | Retention period |
|---|---|
| Account & identity (Discord ID, username) | While your account is active. Deleted or anonymized within 30 days of account closure (residual backups purge within 90 days). |
| Checkout profile information (name, address, email, phone) | While your account is active. Deleted within 30 days of account closure or on request. |
| Connected email credentials | Only while the inbox is connected. Permanently deleted immediately when you disconnect it or close your account. |
| Checkout & order activity, order tracking | While your account is active plus up to 90 days after closure for support and disputes, then deleted or anonymized. Anonymized, non-identifying statistics may be kept indefinitely. |
| Collection data | Until you delete the items or close your account. |
| Payment & billing records (invoices, subscription history) | Retained as required by law and tax/accounting rules—typically up to 7 years. Card data is held by Stripe under its own policy, not by us. |
| Support communications | Up to 24 months after your last contact. |
| Server & security logs (IP, request metadata) | Short-term only—typically 30–90 days—for security and abuse prevention. |
| Push-notification tokens | Until you sign out, disable notifications, or the token expires. |
Where a longer period is required by law (for example, financial records), we retain the minimum necessary for that purpose and restrict further use.
8. Your Rights & Choices
You can, at any time:
- Access a copy of the personal data we hold about you.
- Correct inaccurate information (you can also edit most profile data in your dashboard).
- Delete your data and close your account.
- Export your data in a portable format.
- Disconnect a connected email inbox, which deletes those credentials immediately.
- Opt out of non-essential notifications.
To exercise any of these, email admin@chronocart.io from the email associated with your account, or open a support ticket in our Discord. We will respond within the timeframe required by applicable law.
EEA/UK residents: You have rights under the GDPR/UK GDPR, including access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your local data-protection authority. Our legal bases for processing are performance of our contract with you, your consent (e.g., connecting an inbox), our legitimate interests in operating and securing the Service, and compliance with legal obligations.
California residents: Under the CCPA/CPRA you have the right to know, delete, and correct your personal information, and to not be discriminated against for exercising these rights. We do not sell your personal information and do not share it for cross-context behavioral advertising.
9. Children’s Privacy
The Service is intended for adults aged 18 and over and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact us and we will delete it.
10. International Users
We operate from the United States, and your information is processed and stored in the U.S. and by the service providers listed above. By using the Service, you understand your information may be transferred to and processed in the United States, which may have different data-protection laws than your country.
11. Changes to This Policy
We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you through the Service. Your continued use of the Service after changes take effect means you accept the updated policy.
12. Contact Us
ChronoCart LLC
Privacy & data requests: admin@chronocart.io
We aim to respond to privacy requests within 30 days.