PRIVACY

Privacy at WaitToSave.

This policy explains what information WaitToSave may process, why we use it, and the choices available to you.

Effective September 11, 2026

Who operates WaitToSave

WaitToSave is operated by Nora Knows LLC. This policy applies to the WaitToSave mobile app, Chrome extension, and WaitToSave.com.

Information we may process

How we use information

We use information to provide product checks and shopping recommendations, show already-cached shopping intelligence on supported Amazon pages, maintain watches, deliver notifications you request, manage app access, prevent abuse, diagnose problems, improve reliability, and operate the website, mobile app, and Chrome extension.

If you join the launch list, we use that email address to send WaitToSave launch or availability updates. Launch-list attribution is used to understand which launch channels are bringing interested shoppers to WaitToSave; it is not used to create a general browsing profile.

When analytics is enabled, we use analytics events to understand how people discover WaitToSave, whether the public website and app flows are understandable, which product-loop steps are being reached, and where reliability or usability should be improved. We do not use WaitToSave analytics to build personalized advertising profiles.

Chrome extension data is used only for the extension's disclosed shopping purpose and related security, reliability, account, and service-operation needs. We do not sell extension browsing data, use it for personalized advertising, or use Amazon page activity to create an unrelated browsing profile.

WaitToSave's use of user data collected or processed by the Chrome extension complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.

Service providers and third parties

WaitToSave relies on service providers for functions such as hosting, databases, product and pricing data, email verification, push notifications, app distribution, purchase or entitlement processing, and, when enabled, product and acquisition analytics. Google may process limited analytics information through Google Analytics or Google Analytics for Firebase when those services are enabled. Those providers may process information only as needed to perform those services or as otherwise permitted by their own terms and privacy policies.

When you leave WaitToSave for Amazon or another third-party service, that service's privacy policy applies to your activity there.

Data retention

Account-linked watches, Wait History, notification state, and access information may remain while your account or watch lifecycle is active because that information is needed to preserve watch continuity, avoid duplicate alerts, and provide the service you requested. Deleting your account removes that account-linked service data as described below.

Launch-list information is retained while it is needed for WaitToSave launch communications. You can remove a launch-list email yourself from the launch-list form on the download page. When launch-list information is no longer needed for that purpose, we may delete it.

The Chrome extension keeps its installation credential locally until sign-out, credential rotation, extension-data removal, or uninstall according to Chrome's storage behavior. Current Amazon page context is kept in Chrome session storage for the active browser session and is not intended to become canonical WaitToSave price history.

Short-lived authentication challenges, sessions, usage-limit buckets, and worker leases are configured to expire automatically. Disabled push registrations and backend worker-run diagnostics are configured to expire automatically after approximately 30 days. MongoDB performs TTL cleanup asynchronously, so deletion can occur shortly after the nominal expiration time rather than at an exact second.

Some operational purchase or billing-event records may be retained when reasonably necessary for webhook integrity, security, fraud prevention, refunds, disputes, legal obligations, or accounting. When an account is deleted, WaitToSave removes the direct account identifier from matching billing-event audit records where practical.

Analytics data, when analytics is enabled, is retained according to the configured analytics-service retention settings and the applicable provider policies. WaitToSave's analytics event design intentionally avoids the account, product-watch, and precise-location fields described above.

Your choices

What account deletion removes

Account deletion removes the WaitToSave user account and account-linked data used to provide the service, including watches, device and push registrations, watch-slot and access records, notification events, and account-linked shopping-state and Wait History records.

To keep an old deleted installation credential from silently recreating the deleted identity, WaitToSave may retain a minimal security-revocation marker consisting of a one-way hash of that installation credential and a non-account installation identifier. The deleted account's email and account user ID are not retained in that revocation marker.

A separate launch-list email is not automatically an app account record. If you joined the launch list and also later created an account, use the launch-list removal control described above if you want the launch-list record removed too.

Children

WaitToSave is a shopping utility and is not directed to children under 13. We do not knowingly design the service to collect personal information from children under 13.

Security

We use reasonable technical and organizational measures intended to protect information, including isolated extension storage for the Chrome installation credential, hashed installation credentials on the server, HTTPS service endpoints, and fresh email verification for destructive account deletion. No online service can guarantee absolute security.

Changes to this policy

We may update this policy as WaitToSave changes. When we make a material update, we will revise the effective date and make the current version available at this URL.