UK GDPR Compliant

Privacy Policy

How Closetary Ltd collects, uses, stores, and protects your personal information.

Last Updated: March 2026

1. Introduction

Closetary Ltd ("we", "us", "our") is committed to protecting your personal data. This privacy policy explains how we collect, use, store, and protect your personal information when you use the Closetary mobile application and related services.

We are the data controller for your personal data and are registered with the Information Commissioner's Office (ICO) as required under UK data protection law.

2. Data We Collect

2.1 Information You Provide

Data TypePurposeLegal Basis
Name and email addressAccount creation and communicationContract performance
Password (hashed)Account securityContract performance
Body type and style preferencesPersonalised outfit recommendationsConsent
Wardrobe item details (photos, descriptions, brands)Core wardrobe management serviceContract performance
Purchase informationValue tracking, cost-per-wear analyticsConsent

2.2 Information Collected Automatically

Data TypePurposeLegal Basis
Device information (OS, model)App compatibility and debuggingLegitimate interest
Usage analytics (screens viewed, features used)Service improvementLegitimate interest
Location data (approximate, if permitted)Weather-based outfit suggestionsConsent
Crash reportsTechnical issue resolutionLegitimate interest

2.3 Information from Third Parties

SourceData TypePurpose
Google OAuthName, email, profile photoSocial login
Apple Sign InName, emailSocial login
Barcode databasesProduct informationItem auto-population

3. How We Use Your Data

  1. Provide the core service — Manage your digital wardrobe, generate outfit suggestions, and track sustainability impact
  2. Personalise recommendations — Use your style preferences, body type, and feedback to improve outfit suggestions
  3. AI model improvement — Anonymised, aggregated usage data to improve our recommendation algorithms
  4. Communication — Send service-related notifications and, with your consent, promotional content
  5. Legal compliance — Meet our legal and regulatory obligations

4. Legal Basis for Processing

Under UK GDPR (UK General Data Protection Regulation), we process your data based on:

  • Contract performance (Article 6(1)(b)) — Data necessary to provide our service
  • Consent (Article 6(1)(a)) — Optional data you choose to provide (location, body type, marketing)
  • Legitimate interests (Article 6(1)(f)) — Service improvement, fraud prevention, analytics

You can withdraw consent at any time through the app settings.

5. Data Storage and Security

5.1 Storage Location

All personal data is stored within the United Kingdom using AWS eu-west-2 (London) data centres, ensuring compliance with UK data residency requirements.

5.2 Security Measures

  • Passwords are hashed using bcrypt (never stored in plain text)
  • All API communication is encrypted via TLS 1.3
  • Access tokens expire after 30 minutes; refresh tokens after 7 days
  • Database encryption at rest (AES-256)
  • Regular security audits and penetration testing

5.3 Retention Period

Data TypeRetention Period
Account dataUntil account deletion + 30 days
Wardrobe itemsUntil item or account deletion
AI feedback dataAnonymised after 2 years
Usage analytics12 months (aggregated)
Financial records7 years (legal requirement)

6. Data Sharing

We do not sell your personal data.

We share data only with:

Third PartyPurposeSafeguards
AWS (Amazon Web Services)Cloud hostingUK data centres, Data Processing Agreement
Google Cloud AIAI outfit recommendationsAnonymised data only, DPA in place
StripePayment processing (marketplace)PCI DSS Level 1 certified
Charity partnersDonation logisticsMinimal data (item type, quantity)

7. Your Rights (UK GDPR)

Under UK data protection law, you have the right to:

RightDescriptionHow to Exercise
AccessRequest a copy of your personal dataIn-app or email
RectificationCorrect inaccurate dataEdit in app or email
ErasureRequest deletion of your dataIn-app "Delete Account" or email
RestrictionLimit how we process your dataEmail request
PortabilityReceive your data in a structured formatEmail request (JSON export)
ObjectionObject to processing based on legitimate interestsEmail request
Withdraw consentRemove consent for optional data processingIn-app settings

Contact: privacy@closetary.co.uk

8. Children's Privacy

Closetary is not intended for children under 13 years of age. We do not knowingly collect personal data from children under 13. If we become aware that we have collected such data, we will delete it promptly.

9. International Transfers

All data is processed within the UK. If we need to transfer data internationally in the future, we will ensure appropriate safeguards are in place, such as:

  • UK Standard Contractual Clauses
  • UK Adequacy Regulations

10. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of significant changes via the app or email. The "Last Updated" date at the top reflects the latest revision.

11. Contact Us

Data Controller: Closetary Ltd

Email: privacy@closetary.co.uk

Address: Registered UK address

ICO Complaints: If you are unhappy with how we handle your data, you can complain to the Information Commissioner's Office (ICO) at ico.org.uk or call 0303 123 1113.