Privacy notice
Your shopping goals are your data.
This notice explains the information HoldTheCart processes, why we need it, which service providers help us operate, and the controls available to you.
Effective July 24, 2026
Information you provide
- Account and sign-in information managed by Clerk, including email addresses and authentication methods.
- Buying goals, answers, budgets, notes, product links, saved products, target prices, and preferences.
- Messages you send to our public contact addresses.
Buying goals can reveal sensitive circumstances. Do not include information that is unnecessary for the product decision.
Information created when you use the service
- Research plans, cited evidence, candidate evaluations, comparisons, and recommendation history.
- Saved price observations, watch events, alert preferences, and delivery audit records.
- Budget and provider-request records needed to enforce external API limits.
- Privacy-scoped page and feature analytics, error reports, and hashed authenticated-session activity.
How we use information
We use information to authenticate users, answer product-research requests, save and compare projects, run product lookups, provide transactional alerts, enforce provider budgets, secure and debug the service, and understand whether product features are useful.
Product goals and requirements may be processed by OpenAI and Exa to generate structured questions, research, and comparisons. We are designed not to send names, email addresses, passwords, or precise addresses with those requests.
Analytics, cookies, and diagnostics
Clerk uses necessary browser storage and cookies for sign-in. Google Analytics 4 may use first-party cookies to distinguish browsers and sessions. HoldTheCart sends page views and a small allowlist of product events to Google Analytics without names, email addresses, prompts, free-text requirements, or account identifiers.
Sentry receives scrubbed error reports with cookies, headers, query strings, request bodies, and environment details removed. Langfuse tracing is sampled and masks model input, output, and metadata by default.
Service providers and disclosures
We use vendors that provide hosting, databases, identity, AI and search processing, product-data lookup, job execution, email delivery, analytics, tracing, and error monitoring. Current providers include Vercel, Neon, Clerk, OpenAI, Exa, Canopy, Trigger.dev, Resend, Google Analytics, Langfuse, and Sentry.
We do not sell purchasing-intent profiles. When you follow a retailer link, that retailer receives the normal information associated with visiting its site and handles it under its own privacy policy. Eligible purchases may result in an affiliate commission to HoldTheCart.
Retention and deletion
Projects and their research history remain until you delete them or your account. Verified product lookup records expire after 30 minutes. Raw retailer responses are not stored. Operational budget records may remain after account deletion with the user reference removed. Shared, immutable product observations may also remain for audit integrity.
Signed-in users can export their application data and delete their account in Settings. Account deletion removes user-owned projects, watches, research, preferences, activity sessions, and alert history, then requests deletion of the Clerk identity.
Children
HoldTheCart is a general-audience service and is not intended for children under 13. Do not create an account or provide personal information if you are under 13.
Contact and changes
Privacy questions and requests can be sent to privacy@holdthecart.com. We may update this notice as the product or its providers change. Material updates will receive a new effective date on this page.