| **Version 1.0 | Last Updated: February 6, 2026** |
LateMate (“we,” “us,” or “our”) is operated by Fantastic Online Stores Pty Ltd (ABN 39 655 964 784), an Australian company. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use the LateMate mobile application (the “App”) available on iOS and Android.
By using LateMate, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the App.
When you create a LateMate account, we collect:
When you use the App, we collect:
We calculate the following from your usage data:
These calculations are performed automatically based on your session data and pair settings.
We collect limited device information:
We use your information for the following purposes:
| Purpose | Data Used | Legal Basis (GDPR) |
|---|---|---|
| Provide and operate the App | Account data, usage data | Performance of contract (Art. 6(1)(b)) |
| Authenticate your account | Email, password | Performance of contract (Art. 6(1)(b)) |
| Display your profile to your pair partner | Display name, avatar | Performance of contract (Art. 6(1)(b)) – necessary for the pair-based service |
| Track and display wait sessions | Session records, notes | Performance of contract (Art. 6(1)(b)) |
| Calculate units owed and statistics | Session records, pair settings | Performance of contract (Art. 6(1)(b)) – core feature of the service |
| Send push notifications | Push tokens, session data | Consent (Art. 6(1)(a)) – you choose to enable notifications |
| Process subscriptions | User ID, subscription status | Performance of contract (Art. 6(1)(b)) |
| Diagnose crashes and fix bugs | Device info, error logs | Legitimate interest (Art. 6(1)(f)) – our legitimate interest is ensuring app stability and reliability by identifying and resolving crashes that affect user experience |
| Improve the App | Aggregated, anonymized usage patterns | Legitimate interest (Art. 6(1)(f)) – our legitimate interest is improving the App’s functionality and performance based on aggregated usage patterns; this does not override your rights as we use only anonymized data |
| Respond to support requests | Email, account data | Performance of contract (Art. 6(1)(b)) |
| Comply with legal obligations | As required | Legal obligation (Art. 6(1)(c)) |
We do not use your data for:
| Data | Required or Optional | Consequence of Not Providing |
|---|---|---|
| Email address | Required | You cannot create an account or use LateMate |
| Password | Required | You cannot create an account or use LateMate |
| Display name | Required | You cannot complete your profile; your pair partner needs to identify you |
| Avatar selection | Required | A default avatar will be assigned if you do not select one |
| Session notes | Optional | Sessions will be tracked without additional context |
| Push notification token | Optional | You will not receive push notifications; all other features remain available |
| Device info (crash reporting) | Automatically collected | Collected by the Sentry SDK when the App runs; necessary for maintaining App stability |
Your data is stored on servers operated by Supabase (our backend provider), which uses PostgreSQL databases with row-level security (RLS) policies ensuring users can only access their own data and their pair’s shared data.
We implement the following security measures:
We have data breach notification procedures in place to comply with applicable laws:
GDPR (EU/UK): In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to you, we will also notify you directly without undue delay via email and/or in-app notification.
Australian Notifiable Data Breaches (NDB) Scheme: If we experience a data breach that is likely to result in serious harm to any individual, we will conduct a reasonable and expeditious assessment within 30 days of becoming aware of the breach (or suspected breach). If the breach is an “eligible data breach,” we will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable. Notification will include the nature of the breach, the kinds of information involved, and recommended steps you can take.
US State Laws: We will comply with applicable US state breach notification requirements.
We use the following third-party services to operate the App:
| Service | Provider Location | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|---|
| Supabase | United States | Authentication and database | Email, profile data, session data, hashed passwords | supabase.com/privacy |
| RevenueCat | United States | Subscription management | Anonymous user ID, purchase receipts | revenuecat.com/privacy |
| Sentry | United States | Error tracking and crash reporting | Device info (model, OS version), error logs, anonymous user ID | sentry.io/privacy |
| Expo | United States | Push notifications and OTA updates | Push tokens, notification content | expo.dev/privacy |
These services process data on our behalf and are contractually obligated to protect your data in accordance with applicable privacy laws. We maintain Data Processing Agreements (DPAs) with these providers. We do not share your data with third parties for their own marketing or advertising purposes.
When you pair with another user, the following information is shared with them:
We share data with the third-party services listed in Section 5, strictly for the purposes of operating the App. All providers are located in the United States (see Section 18 for international transfer safeguards).
We may disclose your information if required to do so by law or if we believe in good faith that such action is necessary to:
If Fantastic Online Stores Pty Ltd is involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you before your data is subject to a different privacy policy.
We do not sell, rent, or trade your personal information to any third party. This applies to all users, including California residents (see Section 10). We do not share your personal information for cross-context behavioral advertising.
| Data Type | Retention Period |
|---|---|
| Account data (email, display name, avatar) | Retained while your account is active; deleted or anonymized upon account deletion |
| Hashed password | Retained while your account is active; deleted upon account deletion |
| Wait session records | Retained while your account is active; anonymized upon account deletion |
| Session notes | Retained while your account is active; cleared upon account deletion |
| Pair relationships and settings | Retained while your account is active; anonymized upon account deletion |
| Push notification tokens | Retained while your account is active; deleted upon account deletion or token expiry |
| Error logs (Sentry) | Automatically purged after 90 days |
| Device information (Sentry) | Automatically purged after 90 days with error logs |
| Subscription data (RevenueCat) | Retained per RevenueCat’s data retention policy |
You may delete your account at any time through the App settings. When you delete your account:
Regardless of where you live, you have the following rights:
To exercise any of these rights, contact us at latemateapp@gmail.com.
If you are located in the European Economic Area (EEA) or the United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR), effective since May 25, 2018.
We process your personal data under the legal bases described in Section 2. In summary:
In addition to the rights listed in Section 8, you have the right to:
For GDPR-related inquiries, contact us at latemateapp@gmail.com with “GDPR Request” in the subject line.
Your data is transferred to the United States where our service providers (Supabase, RevenueCat, Sentry, Expo) are located. We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission. See Section 18 for details.
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), effective January 1, 2023.
In the preceding 12 months, we have collected the following categories of personal information:
| Category | Examples | Collected | Source |
|---|---|---|---|
| Identifiers | Email address, display name, user ID | Yes | Directly from you |
| Personal information under Cal. Civ. Code 1798.80(e) | Name, email | Yes | Directly from you |
| Internet or electronic network activity | App usage data, session records, error logs | Yes | Directly from you (sessions); automatically from your device (crash data) |
| Commercial information | Subscription status, purchase history | Yes | From RevenueCat (third-party service provider) |
| Inferences | Units owed calculations, wait statistics, net wait time difference | Yes | Derived from your session data and pair settings |
| Sensitive personal information | Account login credentials (email + password combination) | Yes | Directly from you |
| Geolocation data | None | No | N/A |
| Audio, visual, or similar information | None | No | N/A |
| Professional or employment information | None | No | N/A |
| Education information | None | No | N/A |
| Biometric information | None | No | N/A |
We use personal information for the business purposes described in Section 2 of this Privacy Policy. We use sensitive personal information (account login credentials) only for the purpose of authenticating your account and providing the service – we do not use it for any secondary purpose beyond what is necessary to provide the App.
As a California resident, you have the right to:
You may submit a verifiable consumer request by contacting us at latemateapp@gmail.com. We will verify your identity before fulfilling any request. You may also authorize an agent to submit a request on your behalf.
We will respond to verifiable requests within 45 days. If we need more time (up to an additional 45 days), we will notify you of the reason and extension period.
We do not offer financial incentives related to the collection, sale, or deletion of personal information.
In addition to California, several other US states have enacted privacy laws that may apply to you. These include, but are not limited to:
If you are a resident of a state with a comprehensive privacy law, you generally have the right to:
For states that require it (including Colorado and Connecticut), we honor Global Privacy Control (GPC) signals as valid opt-out requests on the web version of the App.
To exercise any of these rights, contact us at latemateapp@gmail.com. We will verify your identity and respond within the timeframe required by your state’s law.
In accordance with the California Online Privacy Protection Act (CalOPPA), effective since January 1, 2014, we make the following disclosures:
This Privacy Policy is accessible from the App settings and on our website at https://fantasticonlinestores.github.io/latemate-legal.
We describe the categories of personal information we collect in Section 1 and how that information is used in Section 2 of this policy.
We describe third parties with whom we share information in Sections 5 and 6 of this policy.
LateMate does not track users across third-party websites. We do not respond to Do Not Track (DNT) signals because our App does not track users for advertising purposes. No third-party tracking occurs within the App.
We will notify users of material changes to this Privacy Policy by updating the “Last Updated” date and, where appropriate, through an in-app notification. See Section 20 for details.
This Privacy Policy is effective as of the “Last Updated” date shown at the top of this document.
As an Australian company, Fantastic Online Stores Pty Ltd complies with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
LateMate requires account identification because the service involves pairing with another specific user to track shared wait sessions. Anonymous usage is not practicable for the core functionality of the App. However, you may choose any display name you wish – it does not need to be your real name.
You have the right to:
We will respond to access and correction requests within 30 calendar days. If we refuse a request, we will provide written reasons and information about how to complain.
To make a request, contact us at latemateapp@gmail.com.
If you believe we have breached the Australian Privacy Principles, you may:
We disclose personal information to overseas recipients in the United States (see Section 5 for specific providers). We take reasonable steps to ensure these recipients comply with the Australian Privacy Principles, including maintaining Data Processing Agreements. We remain accountable for any breach by these overseas recipients.
We may use push notifications to inform you about new features or premium offerings. Under Australian law, this constitutes direct marketing. You can opt out of promotional notifications at any time by:
We will not send you promotional notifications unless you have opted in. Session-related notifications (e.g., “Your partner started waiting”) are service notifications, not marketing.
Any promotional push notifications about premium features or weekly recaps constitute direct marketing. We will:
LateMate does not use cookies. The App does not use cookies, web beacons, pixel tags, or similar tracking technologies.
We do not engage in cross-app or cross-site tracking. We do not use advertising identifiers or participate in ad networks.
The only local storage we use is:
This local storage is strictly necessary for the App to function and does not require separate consent.
LateMate supports offline usage. When you use the App without an internet connection:
LateMate automatically calculates “units owed” based on your wait session durations and pair-specific rules (e.g., minutes per unit). The App also generates statistics such as total wait time, net difference between pair members, and session counts.
These calculations are straightforward arithmetic performed for entertainment purposes. We do not engage in automated decision-making that produces legal or similarly significant effects on you as described in GDPR Article 22. Specifically:
Your data is transferred to and processed in the United States, where all of our service providers are located:
| Provider | Country | Data Transferred |
|---|---|---|
| Supabase (Supabase Inc.) | United States | Email, profile data, session data, hashed passwords |
| RevenueCat (RevenueCat Inc.) | United States | Anonymous user ID, purchase receipts, subscription status |
| Sentry (Functional Software Inc.) | United States | Device info (model, OS version), crash logs, anonymous user ID |
| Expo (650 Industries Inc.) | United States | Push notification tokens, notification content |
Where data is transferred outside your jurisdiction, we ensure appropriate safeguards are in place:
Under Australian Privacy Principle 8, we take reasonable steps to ensure overseas recipients handle your data in accordance with the APPs. We remain accountable for any breach by these overseas recipients as if we had committed it ourselves.
LateMate is not intended for children. We enforce the following age requirements:
We do not knowingly collect personal information from children below the applicable minimum age. If we become aware that we have collected personal information from a child below the applicable age, we will take steps to delete that information promptly.
If you believe a child has provided us with personal information, please contact us at latemateapp@gmail.com.
We may update this Privacy Policy from time to time. When we make changes:
We encourage you to review this Privacy Policy periodically.
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, contact us at:
Fantastic Online Stores Pty Ltd ABN: 39 655 964 784 Address: 16 Etheridge Ln, Craigieburn VIC 3064, Australia Support Email: latemateapp@gmail.com Company Email: fantasticonlinestores@gmail.com Phone (Australia): +61 434 690 302 Phone (Morocco): +212 667 78 24 64 Website: https://fantasticonlinestores.github.io/latemate-legal
For specific inquiries:
We aim to respond to all privacy-related inquiries within 30 days.
Australian Privacy Complaints Escalation: If you are not satisfied with our response to your privacy complaint, you may contact the Office of the Australian Information Commissioner (OAIC):