Working legal draft. This document is being reviewed by a qualified lawyer. Contact us if anything looks incomplete or unclear.
Effective date: 17 August 2026
Last reviewed: 17 August 2026
Data controller: Planbase Limited (“FitMatch”, “we”, “us”, or “our”)
Contact: hello@fitmatch.org.uk
Registered address: Flat 6, Chales Street, Newport, United Kingdom
1. About this policy
This Privacy Policy explains how FitMatch collects, uses, stores, shares, and protects personal information when you use the FitMatch mobile app, website, and related services.
FitMatch provides a private digital wardrobe and outfit-planning service. We aim to collect only the information needed to provide and improve that service.
2. Information we collect
Information you provide
- Account details, such as your name, email address, profile image, and sign-in method.
- Style preferences, including preferred styles, colours, occasions, climate, and other choices you add.
- Wardrobe content, including clothing photos, categories, colours, tags, favourites, and notes.
- Outfit information, including generated combinations, saved looks, feedback, and preferences.
- Messages or information you send when requesting support or exercising your rights.
Information collected automatically
- Basic device and app information, such as operating system, app version, device type, language, and diagnostic information.
- Security and authentication records, such as session identifiers, sign-in events, and fraud-prevention signals.
- Usage information needed to understand whether features work correctly. FitMatch does not currently use advertising trackers. If product analytics are introduced, this policy will identify the provider and the events collected before they are enabled.
Information from connected sign-in providers
If you choose Google or Apple sign-in, the provider may give us information you authorise it to share, such as your name, email address, and profile image. The provider handles your password and its own authentication process.
3. How we use your information
We use personal information to:
- Create, authenticate, secure, and maintain your account.
- Store and organise your private wardrobe.
- Generate and improve outfit suggestions based on your wardrobe and preferences.
- Save your preferences and provide a personalised experience.
- Operate, troubleshoot, secure, and improve FitMatch.
- Respond to support requests and account enquiries.
- Prevent abuse, fraud, unauthorised access, and security incidents.
- Meet legal, regulatory, accounting, and enforcement obligations.
We do not use your wardrobe photos to train general-purpose artificial intelligence models unless we first provide clear information and obtain any permission required by law.
4. Our lawful bases
Depending on the purpose, we rely on:
- Contract: processing needed to provide FitMatch after you create an account.
- Legitimate interests: operating, securing, debugging, and improving the service, where those interests are not overridden by your rights.
- Consent: where we ask for an optional permission, such as device photo-library access or optional communications. You can withdraw consent at any time.
- Legal obligation: processing required to comply with applicable law.
5. Wardrobe photos and AI processing
Wardrobe photos are stored in private, user-scoped storage. FitMatch uses short-lived access links when it needs to display a photo to you.
FitMatch may analyse a clothing image to identify details such as category, colour, pattern, season, or formality. It may also create mathematical representations, commonly called embeddings, to help retrieve relevant wardrobe items. These outputs can be inaccurate, and you should be able to review or correct important details.
FitMatch does not intentionally use outfit suggestions to make legal or similarly significant decisions about you.
6. Who processes information for us
Current or planned providers include:
- Clerk: authentication, account management, and session security.
- Supabase: database, private file storage, and backend services.
- Pinecone: vector search and retrieval for wardrobe and styling features.
- Apple and Google: optional sign-in services.
- Expo and app-store infrastructure: app distribution, updates, and technical delivery.
- Additional hosting, monitoring, support, or AI-processing providers: we will add any new provider to this policy before it handles personal information.
We may also disclose information if required by law, to protect users or the service, or as part of a merger, financing, acquisition, or sale. We do not sell personal information.
7. International transfers
Some providers may process information outside the United Kingdom. Where required, we use a lawful transfer mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to approved standard contractual clauses, together with appropriate safeguards.
8. How long we keep information
- Active account, wardrobe, and outfit data: while the account remains open.
- Account deletion requests: deletion from active systems within 30 days after verification.
- Deleted wardrobe photos and records: removed from active systems promptly and from rolling backups within 90 days.
- Security and diagnostic logs: up to 12 months, unless a longer period is needed to investigate an incident.
- Support records: up to 24 months after the request is resolved.
- Legal, tax, fraud-prevention, and dispute records: only for the period required by applicable law or a documented legal claim.
9. Security
We use measures designed to protect personal information, including authenticated access, user-scoped database rules, private storage, encrypted connections, short-lived image links, and restricted server-side credentials.
No service can guarantee absolute security. Keep your device and sign-in credentials secure, and contact us promptly if you suspect unauthorised account access.
10. Your data-protection rights
Depending on the circumstances, you may have the right to:
- Access a copy of your personal information.
- Correct inaccurate or incomplete information.
- Ask us to delete your information.
- Restrict or object to certain processing.
- Receive certain information in a portable format.
- Withdraw consent where processing relies on consent.
- Complain to a data-protection regulator.
To exercise a right, contact hello@fitmatch.org.uk. We may need to verify your identity. If you are in the UK, you may complain to the Information Commissioner's Office.
11. Account and photo deletion
You may edit wardrobe details and remove individual pieces in the app. To request account deletion, use the account controls in FitMatch where available or email hello@fitmatch.org.uk from the email address connected to your account. After identity verification, we aim to delete account data from active systems within 30 days and from rolling backups within 90 days.
Deleting the app from your device does not by itself delete your account.
12. Children
FitMatch is currently intended for users aged 16 or older. Users under 18 should have permission from a parent or guardian where required.
13. Device permissions
FitMatch may request access to your photo library so you can choose a wardrobe image. We request access only when needed for that feature. You can manage permissions in your device settings, though disabling access may prevent photo uploads.
14. Changes to this policy
We may update this policy as FitMatch changes or legal requirements develop. We will update the date above and provide additional notice where a change materially affects your rights or how we use your information.
15. Contact
Planbase Limited
hello@fitmatch.org.uk
Flat 6, Chales Street, Newport, United Kingdom