Privacy Policy
Last updated: 31 May 2026
FitSnap ("we", "us") respects your privacy. This policy explains what personal data we collect when you use FitSnap (the "Service"), why we collect it, how we use it, and what rights you have under the EU General Data Protection Regulation (GDPR).
1. Data controller
The data controller is FitSnap. For any data-protection question — including data access, correction, export or account deletion — you can reach our privacy team at privacy@fitsnap.io. For general questions, contact info@fitsnap.io.
2. Data we collect
Account data: email, display name, password hash, login timestamps. Content you upload: clothing photos and any metadata (brand, size, condition). Generated content: AI-cleaned photos, model photos and listing copy. Billing data: plan, billing interval, renewal date (no card numbers are stored on our servers — payments are handled by Stripe). Usage & analytics data: pages visited, device, browser, language, anonymised IP, referrer (only if you accept analytics cookies). Consent records: timestamp at which you accepted these Terms, the cookie banner and (optionally) marketing emails.
3. Legal bases
We process your data under: (a) contract performance — to provide the Service you signed up for; (b) legitimate interest — to keep the Service secure; (c) consent — for analytics cookies, marketing emails and non-essential cookies; (d) legal obligation — to comply with tax, accounting and law-enforcement requests.
4. AI processing
Uploaded photos are sent to our AI sub-processors (currently OpenAI and Google) to remove the background, isolate the garment and generate model photos. We do not allow these sub-processors to train their models on your photos. Photos and generated content are stored on our backend (Lovable Cloud / Supabase, EU region) for as long as your account exists.
5. Analytics — Google Analytics 4
If you accept analytics cookies, we use Google Analytics 4 (provided by Google Ireland Limited and Google LLC, USA) to understand how visitors use FitSnap. GA4 reads cookies named _ga and _ga_* (valid up to 13 months) and sends pseudonymous data — page URL, page title, device type, browser, language, approximate location derived from an anonymised IP — to Google. Data may be transferred to the USA under the EU-US Data Privacy Framework. The legal basis is your consent (Art. 6(1)(a) GDPR); you can withdraw it at any time by clearing the cookie 'fitsnap_cookies_accepted' or via the cookie banner. We do NOT use Google Signals, advertising features or cross-site tracking. IP anonymisation is enabled.
6. Sharing
We share data only with sub-processors strictly needed to run the Service: cloud hosting (Lovable Cloud / Supabase), AI generation (OpenAI, Google), payment processing (Stripe), analytics (Google Analytics, if consented), and email delivery. We never sell your data.
7. Retention
Account and listing data are kept as long as your account is active. After deletion, data is removed within 30 days, except for invoices and logs we are legally required to keep (up to 7 years). Google Analytics data is retained for 14 months. Free-trial enforcement: after account deletion we retain a one-way SHA-256 hash of your email address indefinitely. This hash cannot be reversed to recover your email; it is used only to enforce our one-free-trial-per-email rule and prevent abuse of the free tier.
8. Your rights
You can access, correct, export or delete your data at any time from your account, or by emailing privacy@fitsnap.io. You can withdraw analytics or marketing consent at any time. You have the right to lodge a complaint with your national data-protection authority (in Belgium: the APD/GBA; in France: the CNIL).
9. Cookies we use
Essential (always on): 'fitsnap_lang' — remembers your language (12 months); session cookies for authentication. Consent state: 'fitsnap_cookies_accepted' / 'fitsnap_cookie_consent' — records your choice (12 months). Analytics (only if accepted): '_ga' (13 months), '_ga_3VQT2D7TC2' (13 months) — set by Google Analytics. You can change or revoke your choice at any time by clearing these cookies in your browser.
10. Changes
We will notify you of material changes by email or in-app before they take effect.