Skip to content
Policies and legal

Six short documents that say what Lantern does, what it refuses to do, and exactly how it is paid.

Set last reviewed
1 Aug 2026
Review cycle
Every six months
Authoritative language
English

Privacy policy

Lantern is a discovery platform, not an advertising business. That distinction decides almost everything below: we do not need to know who you are to show you good products, so we have built the product to avoid finding out.

Effective 21 Aug 2026Version 1.5No account needed to browse

The short version

You can browse, search and save on Lantern without creating an account, giving an email address or accepting a cookie banner. Submitting products, reviews or photos requires an account: an email address, a password we store only as a hash, and a session cookie plus the two functional helper cookies the sign-in flow needs to keep you signed in. A submission is public the moment you send it, and the photos you upload are hosted on our servers and published with it. Your saved products, likes, follows and boards are written to your own browser's local storage and stay there. No taste profile is built from what you look at unless you switch personalisation on, which is off by default: a visit where you only read pages writes nothing to your device at all. With it on, that profile is written to the same local storage, and when the personalised feed needs recommendations your browser posts it to us as the body of a single request; we compute an answer and return it, and we do not store the request. Switching personalisation off deletes the profile. We run no third-party analytics, no advertising pixels and no cross-site tracking. When you click through to a purchasing agent, the outbound link carries a referral parameter that identifies Lantern, not you.

Everything after this point is the same statement in the detail a regulator, a researcher or a cautious buyer would want.

Accounts: optional, and what one stores

Browsing, searching and saving need no account, and most visits never involve one. An account exists for one purpose: publishing. If you create one to submit products, reviews or photos, we store your email address, a hash of your password (never the password itself), the username you chose, and the content you submit. Where sign-in through an external provider (OAuth) is enabled, we store the account identifier and tokens that provider returns, plus the display name and avatar it supplies, instead of a password. Signing in sets the cookies described in Cookies and local storage. That record exists so your contributions have an author; it is not used for advertising, profiling or anything in the sections below. What you publish is covered in Reviews, photos and anything you publish.

Personalisation does not use the account either way: it is off until you ask for it, and device-local. If you open Lantern on your phone and then on your laptop, the two will not know about each other. That is a deliberate trade: cross-device continuity would mean moving your taste profile onto our servers, and we prefer not to hold it.

What lives on your device

Lantern writes at most two local storage keys in your browser, and each is written only once you do something that needs it. Reading pages is not one of those things: browse without saving, choosing or switching anything and you leave with neither key. Nothing else, and no cookie unless you sign in to an account, which sets the sign-in cookies covered in Cookies and local storage.

lantern.v1: your library and taste profile

  • Saved products and likes: the product identifiers you bookmarked.
  • Follows: creators, tags, categories and collections you follow.
  • Personalisation switch: off unless you turned it on. The control sits on your feed, under “Personalise my feed”, next to a plain description of what it collects. The next two entries exist only while it is on, and switching it off deletes them rather than only stopping the collection.
  • Recently viewed (personalisation on only): the last 60 product identifiers you opened, used to avoid showing you the same thing twice.
  • Taste profile (personalisation on only): weighted counts per category, subcategory, tag, style and colour, plus a rough price centre and a total event count. It is a scorecard of product attributes, not a log of your session: there are no timestamps, no URLs, no search strings and no device identifiers in it.
  • Local boards: any boards you created before an account system exists, with the titles you typed.
  • Preferences: your shipping region and display currency, and which one-off notices you have dismissed.

The key is readable by you at any time: open your browser's developer tools, go to local storage for this site, and you will see exactly the values described above, or an empty list if you have not given us anything to store. We think you should be able to audit a personalisation system rather than take its word for it.

What our servers receive

Beyond an account and anything you publish, each covered in its own section, there are three ways data reaches us, and all three are narrow.

1. Personalisation requests

This request is only made when you have switched personalisation on. With it off, your feed is ranked on our side with nothing about you in it, and you get the same page as any other first-time visitor.

When personalisation is on, your browser sends a request containing your taste profile, the product identifiers you have saved, and a short exclusion list of things you have already seen. We rank the catalogue against it and return products. The request body is used to compute the response and is then discarded: it is not written to a database, not attached to any identifier, and not used to build a server-side profile. The response is not cached.

2. Search suggestions

Type-ahead sends the characters you have typed so far in order to return matching categories, tags and products. Suggestion responses are cached publicly by search term for about a minute, which means the cache entry is shared by everyone who typed that term and contains nothing about who asked.

3. Ordinary server logs

Like any website, requests to Lantern are logged by our hosting provider: IP address, timestamp, requested path, response status, user agent and referrer. These logs exist to keep the site up and to stop abuse. We do not join them to personalisation requests and we do not use them for analytics or profiling. Retention is covered in Retention.

We do not ask for, and have no way to receive, your name, postal address, phone number, payment details or marketplace credentials. Lantern sells nothing, so there is no checkout to enter them into. Anyone asking you for those under Lantern's name is not us.

Cookies and local storage

Lantern sets no analytics, advertising, tracking or consent cookies. Browsing sets no cookie at all. Signing in to an account sets a session cookie, whose only job is keeping you signed in, plus two functional helper cookies the sign-in flow itself needs (a CSRF token and a redirect target). None of the three is used for tracking.

We also use local storage, which is functionally similar in that it is data stored on your device by a website. Under the EU and UK rules on terminal-equipment access, storage that is strictly necessary to provide a service the user has requested does not require consent. A session cookie for the sign-in you asked for, saving a product you clicked save on, and remembering the theme you selected all fall inside that: each one stores the thing you just did, because you did it.

A profile assembled from what you merely looked at does not fall inside that, and we are not going to pretend otherwise. So it is not written unless you turn it on. The switch is on your feed, under “Personalise my feed”, beside a plain description of what gets stored; it starts off; and turning it off again deletes what it collected. That is the consent, asked for where the feature is explained and before anything is written. It is not a banner because a banner is what a site needs when the storage happens first and the asking comes second. We use no cookies or local storage for measurement or advertising, so there is nothing else here we would need to ask consent for. If that ever changes, the control will appear before the storage is written, not after.

Third parties may set their own cookies once you leave Lantern. That is covered under Clicking through to a purchasing agent.

Analytics and advertising

There is currently no third-party analytics tooling, tag manager, session recorder, heatmap, A/B testing service, advertising pixel, social embed or fingerprinting script deployed on Lantern. Aggregate traffic figures we look at come from our hosting provider's own request logs, at the level of “this page was requested this many times”.

We are not going to promise this forever. If we introduce measurement, it will be a cookieless, page-level, self-hosted or EU-hosted product, this section will name it before it ships, and it will never include cross-site tracking or the sale of behavioural data. Lantern will not run behavioural advertising. There is no version of this business where your browsing history is the product.

Clicking through to a purchasing agent

Every outbound link to a purchasing agent passes through a redirect on our side. That redirect adds the marketplace URL of the listing, the marketplace it came from, and, for the agents that have a referral relationship with us, a referral identifier plus standard campaign parameters identifying Lantern as the source. The parameters describe us, not you: there is no visitor identifier, no profile fragment and no hashed anything in the outbound URL.

6 of the 8 agents we compare have such a relationship. Which ones, and what it does and does not buy them, is set out in the affiliate disclosure.

Once you land on an agent's site you are their visitor under their rules. They will typically set cookies, run their own analytics, and, if you place an order, collect your name, address, payment details and identity documents where customs requires it. Lantern never sees any of that. Read the privacy policy of the agent you actually use; we link to each one from its agent profile. The same applies to the marketplaces themselves, which are operated independently of Lantern.

Reviews, photos and anything you publish

Where Lantern offers a way to submit a product, a review, a photo or a report, the content you submit and any display name you choose become visible to other people, and remain visible after you stop using the site unless you ask for removal. Do not put anything in a submission that you would not want indexed by a search engine: order numbers, tracking numbers, addresses on parcel labels, or faces you do not have permission to publish. Photographs of a shipping label should have the label blurred before upload.

Photographs you upload are hosted on our servers and attached to the submission they came with. The submission publishes the moment you send it, so those photographs are on a public product page from that moment: there is no review step in front of them. Email privacy@lantern-finds.com to have one removed.

Submissions are published immediately and read by a moderator afterwards, as described in our content policy. If a page is removed at review or on a report, it stops being public straight away; what we keep after that is covered under retention below. Reports you send us are retained long enough to act on them and to recognise a repeat pattern from the same source.

For visitors in the EU, EEA, UK and Switzerland, the GDPR bases we rely on are:

  • Contract (Art. 6(1)(b)): serving the pages you request, operating an account you created, and answering a personalisation request you initiated.
  • Legitimate interests (Art. 6(1)(f)): keeping the service available, preventing abuse and fraud, and defending legal claims. Our assessment is that these are narrow, expected and low-impact, and we hold no special-category data.
  • Legal obligation (Art. 6(1)(c)): responding to valid takedown notices and lawful requests.
  • Consent (Art. 6(1)(a)): the taste profile and the recently-viewed list, written to your device only after you switch personalisation on, and deleted when you switch it off. Withdrawing is the same one control as giving it, and costs you nothing but a general feed. Any further non-essential storage or measurement would be asked for the same way, in advance.

Where you are in a jurisdiction with a different framework (for example a US state privacy law), the operative facts are the same: we do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not engage in profiling that produces legal effects.

Retention

  • On-device data: kept until you delete it, indefinitely. It is yours; we cannot see it and cannot delete it for you.
  • Personalisation request bodies: not retained. They exist for the duration of the request.
  • Search suggestion queries: not retained beyond the shared per-term cache entry, which expires within minutes.
  • Hosting request logs: retained by our provider for a rolling window of no more than 30 days, then deleted, except where a specific entry is needed to investigate abuse or a security incident.
  • Account data: email address, password hash, username and, for OAuth sign-in, the provider identifier, tokens, display name and avatar are kept while the account exists, and deleted when you ask us to delete the account, except records we are legally required to keep.
  • Published community content, including uploaded photos: retained while published, and in backups for a short period after removal.
  • Correspondence and legal notices: retained for as long as needed to handle the matter and to meet limitation periods that apply to it.

International transfers

Lantern is a small international operation and the products it indexes are in China, so data crosses borders by design. Concretely: the site is served from a content delivery network with points of presence worldwide, so a request from Berlin is normally handled in Europe and a request from Toronto in North America. Our own operations do not require us to send personal data to China.

Where a transfer outside the EEA or UK does occur (for example because a support email reaches us through a provider hosted elsewhere), it is covered by an adequacy decision where one exists, and otherwise by the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum. Because the categories of data are so limited, the practical exposure of any single transfer is a request log line or an email thread.

When you click through to a purchasing agent, you are initiating a relationship with a company that is typically established in mainland China or Hong Kong, and any order you place with them involves sending your delivery and identity details there. That transfer is between you and them; we simply want you to know it is happening before you commit.

Your rights

Depending on where you live, you have some or all of the following rights. We honour them for everyone, regardless of jurisdiction.

  • Access: ask what we hold about you. For a visitor with no submissions, the honest answer is normally “request logs that may contain your IP address, if they have not yet aged out”. We will tell you that plainly rather than dress it up.
  • Deletion: ask us to delete your account, content you submitted, and any correspondence. On-device data you delete yourself, in seconds, using the steps below.
  • Portability: receive your data in a structured, machine-readable format. Your on-device library is already JSON: copy the lantern.v1 value out of local storage and you have a complete, portable export with no request to anyone.
  • Objection and restriction: object to processing based on legitimate interests, or ask us to restrict it while a dispute is resolved.
  • Rectification: have inaccurate information about you corrected, including in a review or photo caption that names you.
  • No automated decisions: nothing on Lantern makes a decision about you with legal or similarly significant effects. Ranking products is not that.
  • No retaliation: exercising any of these rights will never degrade the service you get.

Write to privacy@lantern-finds.com. We answer within 30 days, usually far sooner, and we will not ask you to identify yourself more than is necessary. For someone with no account, that is usually not at all.

How to erase everything, in under a minute

Because your profile is local, deletion is genuinely instant and genuinely complete. There is no request to file and no waiting period.

  1. Clear the taste profile only. Use the reset control under “Personalise my feed” on your feed. This empties the affinity scores and the recently-viewed list while leaving your saved products, likes and follows intact, which is useful when the feed has latched onto something you were only briefly curious about. Switching personalisation off does the same clearing and stops anything more being collected.
  2. Clear everything Lantern stores. In your browser's settings, open the privacy or site-data section, find lantern-finds.com, and choose to delete the site's data. In Chrome and Edge this is under Privacy and security → Third-party cookies → See all site data and permissions; in Safari under Settings → Privacy → Manage website data; in Firefox under Settings → Privacy & Security → Cookies and Site Data → Manage Data. Both keys disappear together, and Lantern reverts to the state a first-time visitor sees.
  3. Remove something you published, or the account itself. On-device deletion does not remove a review, photo or submission that is publicly visible, and it does not delete an account. Email privacy@lantern-finds.com with a link, or ask for the account to be deleted, and we will do it.

Using private or incognito browsing gives you the same outcome automatically: local storage is discarded when you close the window, and Lantern works normally without it: you simply get the general feed instead of a personalised one.

Children

Lantern is not directed at children. The service is intended for people aged 16 or over, which also matches the minimum age in our terms of service. We do not knowingly collect personal data from children, and accounts are not offered to anyone under 16. If you believe a child has registered or published content here, write to privacy@lantern-finds.com and we will remove it.

Purchasing agents and marketplaces set their own age requirements, and importing goods across a border generally requires an adult.

Changes to this policy

The effective date and version number at the top of this page change whenever the text does. For a change that materially reduces your privacy (new categories of data, a new recipient, a new purpose), we will publish the revision at least 30 days before it takes effect and note it here, so that a reader can see what changed rather than only that something did. Superseded versions are kept on file and available on request.

Contact and complaints

Data protection enquiries: privacy@lantern-finds.com. Legal notices: legal@lantern-finds.com. Content and safety: trust@lantern-finds.com. The controller's registered details and postal address are in the imprint.

If you are in the EEA, the UK or Switzerland and you are not satisfied with how we have handled a request, you may complain to your national data protection authority. You are welcome to come to us first, but nothing in this policy requires you to.

Plain-language summary: no account to browse, no tracking cookies, no analytics, no advertising. An account is optional and holds only what publishing requires. Your taste profile is a JSON object in your own browser that you can read, export and delete without asking us.