latemate-legal

Privacy Policy

**Version 1.0 Last Updated: February 6, 2026**

LateMate (“we,” “us,” or “our”) is operated by Fantastic Online Stores Pty Ltd (ABN 39 655 964 784), an Australian company. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use the LateMate mobile application (the “App”) available on iOS and Android.

By using LateMate, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the App.


Table of Contents

  1. Information We Collect
  2. How We Use Your Information
  3. Whether Providing Data is Required
  4. How We Store and Protect Your Data
  5. Third-Party Services
  6. Data Sharing and Disclosure
  7. Data Retention
  8. Your Rights and Choices
  9. Your Privacy Rights Under GDPR (EEA/UK Users)
  10. Your Privacy Rights Under CCPA/CPRA (California Residents)
  11. Your Privacy Rights Under Other US State Laws
  12. Your Privacy Rights Under CalOPPA
  13. Your Privacy Rights Under Australian Privacy Law
  14. Push Notifications and Direct Marketing
  15. Cookies and Tracking Technologies
  16. Offline Mode and Data Sync
  17. Automated Decision-Making and Profiling
  18. International Data Transfers
  19. Children’s Privacy
  20. Changes to This Privacy Policy
  21. Contact Us

1. Information We Collect

1.1 Account Data

When you create a LateMate account, we collect:

1.2 Usage Data

When you use the App, we collect:

1.3 Derived Data

We calculate the following from your usage data:

These calculations are performed automatically based on your session data and pair settings.

1.4 Device Data

We collect limited device information:

1.5 Payment Data

1.6 Information We Do NOT Collect


2. How We Use Your Information

We use your information for the following purposes:

Purpose Data Used Legal Basis (GDPR)
Provide and operate the App Account data, usage data Performance of contract (Art. 6(1)(b))
Authenticate your account Email, password Performance of contract (Art. 6(1)(b))
Display your profile to your pair partner Display name, avatar Performance of contract (Art. 6(1)(b)) – necessary for the pair-based service
Track and display wait sessions Session records, notes Performance of contract (Art. 6(1)(b))
Calculate units owed and statistics Session records, pair settings Performance of contract (Art. 6(1)(b)) – core feature of the service
Send push notifications Push tokens, session data Consent (Art. 6(1)(a)) – you choose to enable notifications
Process subscriptions User ID, subscription status Performance of contract (Art. 6(1)(b))
Diagnose crashes and fix bugs Device info, error logs Legitimate interest (Art. 6(1)(f)) – our legitimate interest is ensuring app stability and reliability by identifying and resolving crashes that affect user experience
Improve the App Aggregated, anonymized usage patterns Legitimate interest (Art. 6(1)(f)) – our legitimate interest is improving the App’s functionality and performance based on aggregated usage patterns; this does not override your rights as we use only anonymized data
Respond to support requests Email, account data Performance of contract (Art. 6(1)(b))
Comply with legal obligations As required Legal obligation (Art. 6(1)(c))

We do not use your data for:


3. Whether Providing Data is Required

Data Required or Optional Consequence of Not Providing
Email address Required You cannot create an account or use LateMate
Password Required You cannot create an account or use LateMate
Display name Required You cannot complete your profile; your pair partner needs to identify you
Avatar selection Required A default avatar will be assigned if you do not select one
Session notes Optional Sessions will be tracked without additional context
Push notification token Optional You will not receive push notifications; all other features remain available
Device info (crash reporting) Automatically collected Collected by the Sentry SDK when the App runs; necessary for maintaining App stability

4. How We Store and Protect Your Data

4.1 Storage

Your data is stored on servers operated by Supabase (our backend provider), which uses PostgreSQL databases with row-level security (RLS) policies ensuring users can only access their own data and their pair’s shared data.

4.2 Security Measures

We implement the following security measures:

4.3 Breach Notification

We have data breach notification procedures in place to comply with applicable laws:


5. Third-Party Services

We use the following third-party services to operate the App:

Service Provider Location Purpose Data Shared Privacy Policy
Supabase United States Authentication and database Email, profile data, session data, hashed passwords supabase.com/privacy
RevenueCat United States Subscription management Anonymous user ID, purchase receipts revenuecat.com/privacy
Sentry United States Error tracking and crash reporting Device info (model, OS version), error logs, anonymous user ID sentry.io/privacy
Expo United States Push notifications and OTA updates Push tokens, notification content expo.dev/privacy

These services process data on our behalf and are contractually obligated to protect your data in accordance with applicable privacy laws. We maintain Data Processing Agreements (DPAs) with these providers. We do not share your data with third parties for their own marketing or advertising purposes.


6. Data Sharing and Disclosure

6.1 With Your Pair Partner

When you pair with another user, the following information is shared with them:

6.2 With Service Providers

We share data with the third-party services listed in Section 5, strictly for the purposes of operating the App. All providers are located in the United States (see Section 18 for international transfer safeguards).

We may disclose your information if required to do so by law or if we believe in good faith that such action is necessary to:

6.4 Business Transfers

If Fantastic Online Stores Pty Ltd is involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you before your data is subject to a different privacy policy.

6.5 We Do NOT Sell Your Data

We do not sell, rent, or trade your personal information to any third party. This applies to all users, including California residents (see Section 10). We do not share your personal information for cross-context behavioral advertising.


7. Data Retention

Data Type Retention Period
Account data (email, display name, avatar) Retained while your account is active; deleted or anonymized upon account deletion
Hashed password Retained while your account is active; deleted upon account deletion
Wait session records Retained while your account is active; anonymized upon account deletion
Session notes Retained while your account is active; cleared upon account deletion
Pair relationships and settings Retained while your account is active; anonymized upon account deletion
Push notification tokens Retained while your account is active; deleted upon account deletion or token expiry
Error logs (Sentry) Automatically purged after 90 days
Device information (Sentry) Automatically purged after 90 days with error logs
Subscription data (RevenueCat) Retained per RevenueCat’s data retention policy

Account Deletion

You may delete your account at any time through the App settings. When you delete your account:


8. Your Rights and Choices

Regardless of where you live, you have the following rights:

To exercise any of these rights, contact us at latemateapp@gmail.com.


9. Your Privacy Rights Under GDPR (EEA/UK Users)

If you are located in the European Economic Area (EEA) or the United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR), effective since May 25, 2018.

We process your personal data under the legal bases described in Section 2. In summary:

9.2 Your GDPR Rights

In addition to the rights listed in Section 8, you have the right to:

9.3 Data Protection Officer

For GDPR-related inquiries, contact us at latemateapp@gmail.com with “GDPR Request” in the subject line.

9.4 Data Transfers

Your data is transferred to the United States where our service providers (Supabase, RevenueCat, Sentry, Expo) are located. We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission. See Section 18 for details.


10. Your Privacy Rights Under CCPA/CPRA (California Residents)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), effective January 1, 2023.

10.1 Categories of Personal Information Collected

In the preceding 12 months, we have collected the following categories of personal information:

Category Examples Collected Source
Identifiers Email address, display name, user ID Yes Directly from you
Personal information under Cal. Civ. Code 1798.80(e) Name, email Yes Directly from you
Internet or electronic network activity App usage data, session records, error logs Yes Directly from you (sessions); automatically from your device (crash data)
Commercial information Subscription status, purchase history Yes From RevenueCat (third-party service provider)
Inferences Units owed calculations, wait statistics, net wait time difference Yes Derived from your session data and pair settings
Sensitive personal information Account login credentials (email + password combination) Yes Directly from you
Geolocation data None No N/A
Audio, visual, or similar information None No N/A
Professional or employment information None No N/A
Education information None No N/A
Biometric information None No N/A

10.2 How We Use Personal Information

We use personal information for the business purposes described in Section 2 of this Privacy Policy. We use sensitive personal information (account login credentials) only for the purpose of authenticating your account and providing the service – we do not use it for any secondary purpose beyond what is necessary to provide the App.

10.3 Sale and Sharing of Personal Information

10.4 Your CCPA/CPRA Rights

As a California resident, you have the right to:

10.5 How to Exercise Your Rights

You may submit a verifiable consumer request by contacting us at latemateapp@gmail.com. We will verify your identity before fulfilling any request. You may also authorize an agent to submit a request on your behalf.

We will respond to verifiable requests within 45 days. If we need more time (up to an additional 45 days), we will notify you of the reason and extension period.

10.6 Financial Incentives

We do not offer financial incentives related to the collection, sale, or deletion of personal information.


11. Your Privacy Rights Under Other US State Laws

In addition to California, several other US states have enacted privacy laws that may apply to you. These include, but are not limited to:

Your Rights Under These Laws

If you are a resident of a state with a comprehensive privacy law, you generally have the right to:

Universal Opt-Out Signals

For states that require it (including Colorado and Connecticut), we honor Global Privacy Control (GPC) signals as valid opt-out requests on the web version of the App.

How to Exercise Your Rights

To exercise any of these rights, contact us at latemateapp@gmail.com. We will verify your identity and respond within the timeframe required by your state’s law.


12. Your Privacy Rights Under CalOPPA

In accordance with the California Online Privacy Protection Act (CalOPPA), effective since January 1, 2014, we make the following disclosures:

12.1 Conspicuous Posting

This Privacy Policy is accessible from the App settings and on our website at https://fantasticonlinestores.github.io/latemate-legal.

12.2 Information About Data Collected

We describe the categories of personal information we collect in Section 1 and how that information is used in Section 2 of this policy.

12.3 Third Parties

We describe third parties with whom we share information in Sections 5 and 6 of this policy.

12.4 Do Not Track Signals

LateMate does not track users across third-party websites. We do not respond to Do Not Track (DNT) signals because our App does not track users for advertising purposes. No third-party tracking occurs within the App.

12.5 How We Notify Users of Changes

We will notify users of material changes to this Privacy Policy by updating the “Last Updated” date and, where appropriate, through an in-app notification. See Section 20 for details.

12.6 Effective Date

This Privacy Policy is effective as of the “Last Updated” date shown at the top of this document.


13. Your Privacy Rights Under Australian Privacy Law

As an Australian company, Fantastic Online Stores Pty Ltd complies with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

13.1 Anonymity and Pseudonymity (APP 2)

LateMate requires account identification because the service involves pairing with another specific user to track shared wait sessions. Anonymous usage is not practicable for the core functionality of the App. However, you may choose any display name you wish – it does not need to be your real name.

13.2 Access and Correction (APPs 12 & 13)

You have the right to:

We will respond to access and correction requests within 30 calendar days. If we refuse a request, we will provide written reasons and information about how to complain.

To make a request, contact us at latemateapp@gmail.com.

13.3 Complaints (APP 1)

If you believe we have breached the Australian Privacy Principles, you may:

  1. Contact us first at latemateapp@gmail.com with “Privacy Complaint” in the subject line. We will acknowledge your complaint within 7 days and aim to resolve it within 30 days.
  2. Escalate to the OAIC if you are not satisfied with our response. You can lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
    • Website: oaic.gov.au
    • Phone: 1300 363 992
    • Post: GPO Box 5218, Sydney NSW 2001

13.4 Cross-Border Disclosure (APP 8)

We disclose personal information to overseas recipients in the United States (see Section 5 for specific providers). We take reasonable steps to ensure these recipients comply with the Australian Privacy Principles, including maintaining Data Processing Agreements. We remain accountable for any breach by these overseas recipients.

13.5 Direct Marketing (APP 7)

We may use push notifications to inform you about new features or premium offerings. Under Australian law, this constitutes direct marketing. You can opt out of promotional notifications at any time by:

We will not send you promotional notifications unless you have opted in. Session-related notifications (e.g., “Your partner started waiting”) are service notifications, not marketing.


14. Push Notifications and Direct Marketing

14.1 Push Notifications

14.2 Direct Marketing

Any promotional push notifications about premium features or weekly recaps constitute direct marketing. We will:


15. Cookies and Tracking Technologies

LateMate does not use cookies. The App does not use cookies, web beacons, pixel tags, or similar tracking technologies.

We do not engage in cross-app or cross-site tracking. We do not use advertising identifiers or participate in ad networks.

The only local storage we use is:

This local storage is strictly necessary for the App to function and does not require separate consent.


16. Offline Mode and Data Sync

LateMate supports offline usage. When you use the App without an internet connection:


17. Automated Decision-Making and Profiling

17.1 Automated Calculations

LateMate automatically calculates “units owed” based on your wait session durations and pair-specific rules (e.g., minutes per unit). The App also generates statistics such as total wait time, net difference between pair members, and session counts.

17.2 No Significant Automated Decisions

These calculations are straightforward arithmetic performed for entertainment purposes. We do not engage in automated decision-making that produces legal or similarly significant effects on you as described in GDPR Article 22. Specifically:


18. International Data Transfers

Your data is transferred to and processed in the United States, where all of our service providers are located:

Provider Country Data Transferred
Supabase (Supabase Inc.) United States Email, profile data, session data, hashed passwords
RevenueCat (RevenueCat Inc.) United States Anonymous user ID, purchase receipts, subscription status
Sentry (Functional Software Inc.) United States Device info (model, OS version), crash logs, anonymous user ID
Expo (650 Industries Inc.) United States Push notification tokens, notification content

Transfer Safeguards

Where data is transferred outside your jurisdiction, we ensure appropriate safeguards are in place:

Australian Users

Under Australian Privacy Principle 8, we take reasonable steps to ensure overseas recipients handle your data in accordance with the APPs. We remain accountable for any breach by these overseas recipients as if we had committed it ourselves.


19. Children’s Privacy

LateMate is not intended for children. We enforce the following age requirements:

We do not knowingly collect personal information from children below the applicable minimum age. If we become aware that we have collected personal information from a child below the applicable age, we will take steps to delete that information promptly.

If you believe a child has provided us with personal information, please contact us at latemateapp@gmail.com.


20. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make changes:

We encourage you to review this Privacy Policy periodically.


21. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, contact us at:

Fantastic Online Stores Pty Ltd ABN: 39 655 964 784 Address: 16 Etheridge Ln, Craigieburn VIC 3064, Australia Support Email: latemateapp@gmail.com Company Email: fantasticonlinestores@gmail.com Phone (Australia): +61 434 690 302 Phone (Morocco): +212 667 78 24 64 Website: https://fantasticonlinestores.github.io/latemate-legal

For specific inquiries:

We aim to respond to all privacy-related inquiries within 30 days.

Australian Privacy Complaints Escalation: If you are not satisfied with our response to your privacy complaint, you may contact the Office of the Australian Information Commissioner (OAIC):