LatchPay

Legal

Privacy

What LatchPay stores, why, who else sees it, and how to get it removed. LatchPay is operated from the Netherlands and this notice follows the GDPR. Last updated 26 September 2026.

This is a draft. It describes what LatchPay actually stores today, but it has not yet been reviewed by a lawyer. It will be before LatchPay opens to merchants outside the pilot.

Who is responsible

LatchPay is the controller for the merchant account data described below. For buyer data handled during a checkout, LatchPay acts on the merchant's instructions: the merchant is the controller for their store and LatchPay is their processor. Contact us through the contact form.

What we store about merchants

When you sign in with Whop we store your Whop user id, name and email, and the ids of the Whop businesses you administer, together with the Whop OAuth tokens that keep you signed in. When you connect a business we store its id and the id of the payment webhook we register on it. When you connect Shopify we store the shop domain, the custom-app client id and client secret (or legacy access token) you paste, and the shop settings we read back: name, store currency and presentment currencies. Secrets are encrypted at rest and never sent to the browser.

We also store your LatchPay membership status so we know whether the checkout may run, and the ids and amounts of the usage-fee payments we create.

What we store about buyers

For each checkout we store the cart, the email and shipping address the buyer enters, the live quote from Shopify, and the Whop payment id. Once the payment succeeds we store the order we created in Shopify and its status. This is what we need to create the paid order, to handle refunds and disputes, and to show orders in the merchant's dashboard.

We never see or store card numbers. Cards are entered in Whop's payment element and charged by Whop on the merchant's own business. Whop is the merchant of record on that charge.

On a store that has the theme line, we also store storefront events: the page path (account pages are stored as just "/account", never a query string), the product handle and variant viewed or added, the cart token, the cart value and currency, and which checkout steps were reached, each under a random visitor id and session id that live in the buyer's browser for that store. No IP address, no user agent, no name and no email is part of an event. These make the sessions, funnel and abandoned-checkout numbers in the merchant's dashboard.

When the merchant switches on the abandoned-checkout export, a checkout that was quiet for 30 minutes with an email entered is sent to the merchant's own Shopify customer list: the email, name, address and phone the buyer typed, the cart lines and total, and a link to resume the checkout. The buyer is marked as subscribed to the store's emails only when they ticked the "Email me with news and offers" box, stamped with the moment they ticked it; an existing subscription is never changed. This is the merchant's data in the merchant's store, under the merchant's own privacy notice.

Why we use it

To run the service you asked for (the contract with you as a merchant), to create paid orders and answer refunds and disputes on the merchant's behalf, to bill the membership and the usage fee, to keep the dashboard secure, and to meet invoicing and tax rules. We do not sell data, use it for advertising, or profile buyers.

Cookies

The dashboard uses one session cookie so you stay signed in, and a short-lived cookie during the Whop sign-in flow. The marketing pages set no tracking cookies and load no analytics.

On the merchant's storefront, the theme line and the hosted checkout report first-party storefront events to LatchPay (page view, product view, add to cart, checkout steps) under random ids kept in the browser per store, without IP address or user agent, and not at all when the browser sends Global Privacy Control or Do Not Track. The merchant's own ad pixels (Meta, TikTok, Google Analytics), when the merchant has set them up, may run on the checkout and thank-you page; those are the merchant's, under the merchant's own privacy notice. Meta and TikTok receive the page address with each event, which on the checkout contains the checkout link (it stops working once the checkout expires); Google Analytics receives the address without that link. No email, address or cart line is sent to a pixel.

Who else sees data (subprocessors)

Whop, to sign merchants in, charge buyers on the merchant's business, and bill the membership and the usage fee. Shopify, to quote carts and create orders in the merchant's store. Our hosting and database provider, to run the app. Nobody else. Some of these providers process data outside the EU under the EU standard contractual clauses or an adequacy decision.

How long we keep it

Merchant account data for as long as the account exists. Shopify credentials and the Whop webhook secret are deleted when you disconnect that connection in Settings; the Whop sign-in tokens are kept while your account exists, because they are what signs you in. Checkout sessions that never turned into a payment are marked expired and no longer used, except that, when the merchant switched the abandoned-checkout export on, a session with an email is sent to the merchant's Shopify customer list within 30 days of its creation and then left alone. Storefront events are deleted after 13 months, every night. Orders, payments and fee records for as long as invoicing and tax rules require, which in the Netherlands is seven years.

Your rights

Under the GDPR you can ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, and to receive it in a portable format. Send the request through the contact form and we answer by email within a month. You can also complain to the Dutch data protection authority (Autoriteit Persoonsgegevens). Buyers should contact the store they bought from first; we help the merchant answer.

Deleting your data

Disconnecting Shopify in Settings deletes the stored Shopify credentials; disconnecting Whop deletes the webhook secret. To delete your account, including the Whop sign-in tokens and the order history, cancel the LatchPay membership on Whop and ask us to remove the rest; we keep only what invoicing rules require.

Changes

We update this notice when what we store changes. Material changes are announced in the dashboard or by email.