Privacy & Cookie Policy
Last updated: 19 June 2026
Time Merchant (“we”, “us”) respects your privacy. This policy explains what we collect, why, the cookies and analytics we use, and the choices and rights you have. If you have any questions, email us at hello@timemerchant.app.
What we collect
When you contact us: the name, email address, and message you submit through our contact form, so we can respond.
When you browse the site (only with your consent): analytics about how the site is used — pages viewed, links and buttons clicked, scroll depth, approximate location derived from your IP address, and device and browser type. With your consent we may also record anonymised session replays to understand and improve the experience.
Cookies and analytics
We use PostHog (hosted in the EU) for privacy-friendly product analytics. Analytics and any session recording run only after you accept via the cookie banner. If you decline, no analytics cookies are set and no usage data is collected. You can change your mind at any time by clearing this site’s cookies and local storage in your browser, which brings the banner back.
Legal basis
We rely on your consent for analytics and session recording (GDPR Art. 6(1)(a)). For replying to your contact-form message, we rely on our legitimate interest in responding to enquiries and on taking steps at your request.
Who processes your data
We use a small number of trusted providers, acting on our behalf:
- PostHog — product analytics (EU hosting)
- Resend — delivery of contact-form emails
- Vercel — website hosting
Retention
Contact-form emails are kept for as long as needed to handle your enquiry and our records. Analytics data is retained only for as long as it is useful for improving the site, in line with PostHog’s retention settings.
Your rights
You can ask us to access, correct, or delete your personal data, object to or restrict its processing, and withdraw consent for analytics at any time. To exercise any of these, email hello@timemerchant.app. You also have the right to complain to your local data protection authority.