Account
Data and privacy
What LatchPay stores about you and your buyers, what it never stores (card numbers, IP addresses), who else sees it, and how long it is kept.
Updated
What LatchPay stores about you
Your Whop user id, name and email; the ids of the Whop businesses you administer and the sign-in tokens that keep you signed in; the connected business id and the webhook id; the shop domain, the custom-app credentials you paste and the shop settings read back (name, currencies); your membership status; and the usage-fee payments LatchPay creates. Secrets are encrypted at rest and never sent to the browser. The full text is the privacy notice.
What it stores about your buyers
- Per checkout: the cart, the email and addresses the buyer typed, Shopify's live quote and the Whop payment id; after payment, the Shopify order and its status.
- Storefront events under random first-party ids: page path, product and variant, cart token and value, and which checkout steps were reached.
- The fraud rules' score, outcome and reasons per checkout, and the buyer's two-letter country at the moment of paying.
- Disputes and alerts as Whop reports them, including the buyer email on a dispute.
For buyer data LatchPay acts on your instructions: you are the controller for your store, LatchPay your processor.
What it never stores
Card numbers and bank details: they are entered in Whop's secure fields, or with the buyer's bank or provider, and charged by Whop; LatchPay never sees them. LatchPay only stores the method's display name Whop sends, such as "Visa •••• 4242".
IP addresses and user agents: not in events, not on checkouts; only the two-letter country for the fraud rules.
Query strings, and any account page path beyond "/account".
Anything from a browser that sends Global Privacy Control or Do Not Track: no events, no pixels.
Who else sees data
Whop (sign-in, buyer charges on your business, the membership and fee payments), Shopify (quotes and orders in your store), and the hosting and database provider that runs the app. Your own ad pixels, only when you set them up and only on the checkout pages. Nobody else; no data is sold or used for advertising. Some providers process data outside the EU under the EU standard contractual clauses or an adequacy decision.
How long, and how to delete
- Account data for as long as the account exists; Shopify credentials and the Whop webhook secret are deleted when you disconnect.
- Storefront events are deleted after 13 months, every night.
- Checkout sessions that never paid are marked expired; with the abandoned-checkout export on, those with an email are sent to your Shopify customers within 30 days and then left alone.
- Orders, payments and fee records for as long as invoicing and tax rules require, seven years in the Netherlands.
Under the GDPR you can ask for a copy of your data, a correction, deletion or a portable export; contact us through the support form and we answer within a month. Buyers should contact the store they bought from first; LatchPay helps you answer.