Privacy Policy
Last updated: June 17, 2026
PhantomCart ("we," "our," or "us") is committed to being transparent about how we handle your information. This Privacy Policy explains what limited data we collect, how we use it, and your rights regarding that data when you use our parody food-delivery simulator (the "Service").
Important context: PhantomCart is a parody simulator — a gamified fake delivery app designed as a behavioral financial wellness tool. No real orders, no real food, no real payments. This policy reflects the minimal data practices of a service that, by design, doesn't need much from you.
1. Information We Collect
We collect the absolute minimum data required to make the Service function:
- Local App State: Your preferences, order history, game progress (XP, level, coins, mascot collection, achievements), and cart contents are stored exclusively in your browser's LocalStorage. This data never leaves your device and is never transmitted to our servers.
- Anonymous Usage Analytics: We use a privacy-focused, cookieless analytics provider to collect anonymous, aggregated metrics such as page views, feature usage, and approximate session duration. This data does not identify you personally and cannot be used to track you across sites.
- Voluntary Contact Information: If you choose to email us directly (for support, feedback, or inquiries), we will have access to your email address and whatever information you include in your message. We use this solely to respond to your inquiry.
- Push Notification Subscriptions: If you enable push notifications, your browser generates a subscription endpoint. This endpoint is stored on our server solely to deliver phantom delivery countdown notifications. It contains no personal information beyond what your browser provides to the Web Push API.
2. How We Use Your Information
The limited data we collect is used exclusively for:
- Delivering core Service functionality (game state, delivery timers, push notifications)
- Understanding aggregate usage patterns to improve the Service
- Responding to your direct inquiries
We do not sell, rent, or share your data with third parties for marketing purposes. We do not build advertising profiles. We do not track you across the internet.
3. Cookies and LocalStorage
PhantomCart uses your browser's LocalStorage API to persist your game state, preferences, and order history entirely on your device. This is not a tracking mechanism — it is the functional equivalent of a save file for a video game. We do not use traditional HTTP cookies for tracking, advertising, or cross-site profiling.
The only server-side identifier we store is a randomly generated UUID created by your browser on first visit. This ID is used to associate your game progress with your device and is not linked to any personally identifiable information.
4. Third-Party Analytics
We use a privacy-respecting analytics service (such as Plausible or a self-hosted equivalent) that does not use cookies, does not collect personal data, and does not track users across sites. All analytics data is aggregated and anonymized. We see general trends — not individual browsing histories.
5. Data Retention
- LocalStorage: Data stored in your browser remains there until you clear it manually through your browser settings, or until you use the in-app "Delete Profile" feature.
- Push subscriptions: Retained until you disable notifications in your browser, or until the endpoint is reported as invalid by the push service (at which point it is automatically removed).
- Contact emails: Retained for up to 12 months after your inquiry is resolved, then deleted.
- Analytics data: Aggregated data is retained indefinitely in anonymized form. Raw server logs, if any, are rotated within 30 days.
6. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your data:
- Right to Access: You can request a copy of any personal data we hold about you. Since most of your data lives in your own browser's LocalStorage, you already have direct access to it. For any server-side data, contact us at the email below.
- Right to Deletion: You can delete all locally stored data at any time by clearing your browser's LocalStorage for our domain, or by using the "Delete Profile" button within the app. To request deletion of any server-side data (push subscriptions, contact history), email us and we will comply within 30 days.
- Right to Correction: If any server-side data we hold about you is inaccurate, contact us and we will correct it promptly.
- Right to Object: You may object to the processing of your data. Since we process almost nothing server-side, this right is largely self-executing — stop using the Service, clear your LocalStorage, and no further processing occurs.
- Right to Data Portability: Your LocalStorage data can be exported via your browser's developer tools. Contact us if you need assistance.
7. EU / GDPR Compliance
PhantomCart is designed to comply with the EU General Data Protection Regulation (GDPR). Our lawful bases for the limited processing we perform are:
- Legitimate interest: Delivering the core Service you requested (game state, delivery timers, push notifications), and understanding aggregate usage to improve the Service.
- Consent: Push notifications are only enabled with your explicit opt-in through your browser's native permission dialog.
You may exercise any of the rights described in Section 6 by contacting us at the email below. We will respond within 30 days. If you believe we have not addressed your concern, you have the right to lodge a complaint with your local supervisory authority.
8. Children's Privacy
PhantomCart is not directed at children under the age of 13, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us so we can delete it.
9. Data Security
We implement reasonable technical and organizational measures to protect the limited server-side data we hold. However, because the vast majority of your data resides in your own browser, the security of that data is primarily determined by your device and browser security practices.
10. International Data Transfers
Our servers may be located in various jurisdictions. If you are accessing the Service from outside the server's country of residence, your limited server-side data may be transferred across borders. We ensure that any such transfers comply with applicable data protection laws.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. We encourage you to review this policy periodically. For material changes, we will make reasonable efforts to notify you through the Service or via a prominent notice on our website.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your data, please contact us at:
Email: privacy@phantomcart.app
We take privacy seriously — even for a parody app that barely has any data to protect.