DRAFT — pending legal review. Not yet binding.

Privacy Policy

Last updated August 9, 2026

What we collect

  • Account details — name, email address, the business and location names you enter, and the role each person has.
  • Business data — inventory counts, items, par levels, suppliers, purchase orders, prices, recipes and costs. This is the service; it is what you came here to store.
  • Technical data — IP address, browser or device type, and error reports. Used to keep the service running and to diagnose problems.

We do not collect payment card details. Checkout happens on Paddle, and card data never touches our systems.

Why we collect it

To run Larder for you, to bill you, to answer your support emails, and to fix things that break. We do not sell personal data, and we do not use your business data to advertise anything to anyone.

Who we share it with

  • Supabase — database and authentication hosting, United States (us-east-1).
  • Vercel — application hosting, United States.
  • Paddle — payments and merchant of record.
  • Resend — sends the emails you ask us to send, such as a purchase order to your supplier.

When you email a purchase order to a supplier, the contents of that order and your business name go to the supplier. That is the point of the feature, but it is worth saying out loud.

Where it lives

Data is stored in the United States. If we open an Australian region, the location will be stated here before anything moves.

How long we keep it

For as long as you have an account, and afterwards until you ask us to delete it. An expired subscription makes an account read-only; it does not erase anything. Ask and we will delete it — permanently, within 30 days.

Your rights

You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Email support@larder.day.

Reviewer note: the specific rights language differs between US state privacy laws (CCPA/CPRA and the state acts that follow it) and, for market 2, the Australian Privacy Principles. This section needs to be written per jurisdiction before launch, along with a named data controller and a “do not sell or share” mechanism if any analytics are added later.

Security

Every request is authenticated, and access to your data is enforced at the database level by row-level security policies rather than only in application code. Staff accounts cannot read prices or costs at all — not because a button is hidden, but because the database refuses the query.

Children

Larder is a business tool and is not intended for anyone under 18.

Contact

support@larder.day — we reply within 24 hours on business days.