1. About This Policy & Controller Identity
This Privacy Policy explains how Terzyapp UK Ltd ("TerzyApp", "we", "us", "our") collects, uses, shares, and protects personal data when you use our website, mobile applications, and related services (the "Platform"). Terzyapp UK Ltd is a company incorporated in England and Wales (Company No. 17234484, registered office: Suite 10861, 5 Brayford Square, London E1 0SG, United Kingdom) and is the data controller for the personal data described below. We are registered with the UK Information Commissioner's Office (ICO Reg. No. [TBC]). For the purposes of EU General Data Protection Regulation, our Article 27 Representative in the European Union is [EU Representative TBC]. This Policy is written and executed in English. We may publish translations into other languages for your information and convenience only. In the event of any conflict between the English version and any translation, the English version shall prevail and shall be the sole authoritative version for all legal, regulatory, and judicial purposes.
2. Personal Data We Collect
We collect personal data in the categories below. Where a category is optional, we mark it accordingly; the rest are required to operate the Platform or fulfil your Order.
- Identity & account data: name, date of birth, account email, password (hashed), profile photo (optional), preferred language and currency.
- Contact & address data: shipping and billing addresses, phone number, country of residence.
- Transactional data: Orders, items, tailoring details, prices, refunds, dispute records, communications with Sellers via in-app chat.
- Body Data (special category — see Section 4): camera or depth images submitted for measurement, processed transiently, and the 30 derived measurement values retained against your account.
- User-uploaded reference photos ("My Photos" surface): photographs you import from your device's photo library into your personal in-app gallery, used solely as input to the Virtual Try-On feature and to personalise garment recommendations. We do not run biometric identification against these images and we do not use them to train models that are made available outside the Platform. The general legal bases in Section 6 apply (primarily Art. 6(1)(b) performance of contract and Art. 6(1)(a) consent given by uploading); specific retention is in Section 10.
- Virtual try-on output: rendered images of your selected garments on a body model derived from your measurements or a generic avatar.
- Payment data: card brand and last 4 digits, billing country, payment status. Full card numbers are handled directly by Stripe and never reach our servers.
- Device & technical data: IP address, device model and OS, app version, language, crash reports, performance traces, push-notification token.
- Location data: approximate location derived from IP for currency, language, and tax calculation; precise location only if you grant device permission for delivery features.
- Usage & analytics data: pages visited, features used, search queries, A/B test allocations, click and scroll events (subject to your cookie consent — see Section 13).
- Support & feedback data: messages to our support team, reviews you submit, complaints, ID verification documents when required.
3. How We Collect Personal Data
We collect personal data (a) directly from you when you create an account, place an Order, complete a measurement scan, use chat, or contact support; (b) automatically through your device and our analytics tools when you use the Platform; (c) from third parties including Stripe (payment status and limited card metadata), our identity-verification providers (where KYC checks are required), and from Sellers when they update Order status. We do not buy personal data from data brokers. **Chat content is not end-to-end encrypted on TerzyApp**: messages between Customer and Seller are stored on our servers and may be scanned by automated abuse/fraud/IP-protection filters and read by trained moderators for the purposes set out in Sections 6 and 8 and in our Terms of Service Section 12. Each chat event also captures your IP address, device fingerprint, and approximate location at the time of sending for security and dispute evidence; this metadata is retained per Section 10.
4. Special Category Data — Biometric & Body Measurements
Body images and depth captures used to estimate body measurements are biometric data within the meaning of Article 9 UK GDPR (and Article 9 EU GDPR). We process this data only with your explicit consent given through the Biometric & Body Data Notice presented in-app before the first measurement session. Raw images and depth captures are processed transiently in our infrastructure and deleted immediately after the 30 derived measurement values have been generated; we do not retain raw biometric images. The 30 derived measurement values are retained against your account so you can reuse them across Orders and may be deleted by you at any time from the body-measurement settings. We do not use Body Data for advertising, model training outside the Platform, or sharing with parties other than the Seller you contract with.
5. Children's Data
The Platform is intended for users aged 18 and over. We do not knowingly collect personal data from anyone under 18, and we do not market the Platform to children. If we become aware that an account belongs to a person under 18, we will close the account and delete the associated personal data unless a longer retention period is required by law. If you are a parent or guardian and believe we hold a child's personal data, please contact us at the address in Section 17.
6. Purposes & Legal Bases for Processing
We process personal data only where we have a lawful basis under UK GDPR Article 6 (and Article 9 where special category data is involved). The purposes and legal bases are:
- Operating your account, fulfilling Orders, processing payments and refunds — performance of a contract (Art. 6(1)(b)).
- Body measurement and virtual try-on — explicit consent (Art. 6(1)(a) + Art. 9(2)(a)).
- Fraud prevention, dispute resolution, abuse moderation, securing the Platform — our legitimate interests in operating a safe marketplace (Art. 6(1)(f)).
- Sending transactional communications about your account and Orders — performance of contract (Art. 6(1)(b)).
- Sending marketing communications about TerzyApp and similar products to existing customers — our legitimate interests under PECR reg 22(3) ("soft opt-in"), subject to your right to unsubscribe at any time.
- Personalising recommendations, ranking listings, and improving the Platform — legitimate interests (Art. 6(1)(f)); statistical analysis only, no automated decision-making with legal effect.
- Complying with tax, accounting, anti-money-laundering, sanctions, and consumer-protection law — legal obligation (Art. 6(1)(c)).
- Establishing, exercising, or defending legal claims — legitimate interests and legal obligation.
7. Automated Decision-Making & AI Features
We do not make decisions producing legal or similarly significant effects on you solely by automated means within the meaning of UK GDPR Article 22. Our body-measurement and virtual try-on features apply machine-learning models to your inputs to produce estimates and visualisations, but the resulting Order decisions are taken by you and by the Seller you contract with. Our fraud-screening system may flag transactions for human review; no Order is permanently declined without human review. Listing ranking and recommendations use statistical scoring that does not single out individuals for adverse treatment.
8. Sharing & Disclosure of Personal Data
We share personal data only as described here. We do not sell personal data.
- Sellers (Tailor Stores and Fabric Managers): the data necessary to fulfil your Order — your name, shipping address, contact details, Order content, measurements relevant to the items ordered, and chat messages. Sellers act as independent controllers for the data they receive and are bound by their own seller agreement and applicable law.
- Stripe Payments Europe Ltd (and Stripe affiliates): payment processing via Stripe Connect. Stripe is an independent controller for payment data.
- Cloud and infrastructure providers (Amazon Web Services): hosting and storage. AWS acts as our data processor under contractual data-protection terms.
- Analytics providers (where you have consented via cookies): aggregated usage analytics. See Section 13.
- Identity-verification and anti-fraud providers, where required by law or to protect users.
- Professional advisers (lawyers, accountants, auditors) under duties of confidentiality.
- Regulators, law enforcement, and courts where we are legally required to disclose data, or where disclosure is necessary to establish or defend legal claims.
- Successors in interest in connection with a merger, acquisition, or sale of assets, subject to equivalent privacy protections.
9. International Data Transfers
Personal data may be transferred to and processed in countries outside the United Kingdom or European Economic Area, including the United States (in connection with AWS and Stripe operations) and any country where a Seller you contract with is based. Transfers from the UK rely on UK adequacy decisions where they exist, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses. Transfers from the EEA rely on the European Commission's Standard Contractual Clauses or applicable adequacy decisions. Where transfers occur to a country without an adequacy decision, we apply supplementary measures including encryption, access controls, and contractual safeguards. You may request a copy of the transfer mechanism used for a specific data flow by contacting us at the address in Section 17.
10. Retention
We retain personal data only for as long as necessary for the purposes set out in this Policy. Specific retention periods are:
- Account data: while your account is active, then 24 months from last login, after which it is deleted unless a longer period applies to specific data classes below.
- Order records, invoices, and tax documents: 7 years from the end of the relevant tax year (HMRC requirement under the VAT Act 1994 and Companies Act 2006).
- Chat and Order communications: 5 years from Order completion, to support dispute resolution and legal claims.
- Body Data — raw images and depth captures: deleted immediately after measurement values are derived (typically within seconds).
- Body Data — 30 derived measurement values: retained until you delete them or close your account.
- Virtual try-on output: 30 days from generation, then automatically deleted.
- User-uploaded reference photos ("My Photos"): retained until you delete the individual photo or close your account, subject to the per-owner cap published in the in-app gallery (currently 50). You can delete any single photo from the gallery at any time; closing your account triggers immediate deletion of all gallery contents.
- Marketing preferences and consent records: 3 years after withdrawal or last consent, to evidence compliance.
- Fraud and abuse evidence: up to 7 years where necessary to establish or defend legal claims.
- System audit logs (administrative and security access trails — user identifiers, action timestamps, IP addresses, request metadata): 7 years from generation. Retention period aligns with UK Companies Act 2006 §388 accounting-record requirements and SOC 2 / ISO 27001 audit-trail expectations, and is grounded in UK GDPR Art 6(1)(c) — compliance with legal obligation — and Art 6(1)(f) — legitimate interest in detecting unauthorised access. Access to these logs is restricted to platform administrators and security personnel under role-based controls.
- Analytics data (where consented): aggregated and anonymised after 26 months.
- Contact-form enquiries (name, email, subject, message): up to 12 months from the date the enquiry is closed, then deleted. Legal basis: pre-contract preparation and legitimate interest under UK GDPR Art 6(1)(b) and Art 6(1)(f). Where the enquiry leads to an active account or Order, the operational records of that account/Order follow the retention rules above instead.
- Tailor and partner applications (business name, contact name, email, phone, country, city, portfolio URLs, message): up to 24 months from the date of last contact, then deleted, where the application does not result in onboarding. Onboarded Sellers' records follow the Seller-Agreement retention rules. Legal basis: pre-contract preparation and legitimate interest under UK GDPR Art 6(1)(b) and Art 6(1)(f).
- Feedback submissions (rating, message, submitter identifier if signed in): up to 12 months from submission, then either deleted or aggregated into anonymous quality metrics that no longer identify the submitter. Legal basis: legitimate interest under UK GDPR Art 6(1)(f) in improving the Platform.
- Blog comments (commenter name, optional email, comment body, and server-side moderation metadata): up to 12 months from posting, then deleted. Where you choose to display your name publicly on a comment, that public-facing name and comment body remain visible on the post until the retention period elapses or you request earlier deletion. Legal basis: legitimate interest under UK GDPR Art 6(1)(f) in enabling discussion of our published content.
11. Your Rights
Where we process your personal data you have the following rights under UK GDPR (and equivalent rights under EU GDPR where applicable):
- Right of access — to a copy of the personal data we hold about you.
- Right of rectification — to correct inaccurate or incomplete data.
- Right of erasure — to delete personal data, subject to legal retention requirements (for example, tax records).
- Right to restrict processing — to limit how we use your data while a dispute is resolved.
- Right to data portability — to receive your data in a machine-readable format and have it transmitted to another controller where technically feasible.
- Right to object — to processing based on legitimate interests, including direct marketing (which you can stop at any time).
- Right to withdraw consent — where processing is based on consent (including biometric Body Data), at any time and without affecting the lawfulness of past processing.
- Right not to be subject to a decision based solely on automated processing producing legal or similarly significant effects (see Section 7).
- Right to lodge a complaint with the UK Information Commissioner's Office (ico.org.uk) or your local EU/EEA data protection authority.
12. How to Exercise Your Rights
You can exercise most rights directly from your account settings (download data, delete account, delete measurements, manage marketing preferences). For requests not available in-app, contact us at info@terzyapp.com. We will acknowledge receipt within 5 business days and respond substantively within 1 month, extendable by 2 further months for complex requests with notice to you. We may ask you to verify your identity before acting on a request. We do not charge a fee unless a request is manifestly unfounded or excessive.
13. Cookies & Similar Technologies
We use cookies and similar technologies (local storage, device identifiers, SDKs) to operate the Platform, remember your preferences, secure your session, measure performance, and — where you consent — analyse usage and personalise content. Strictly necessary cookies are set without consent. All other cookies are set only where you give consent through our cookie banner, which you can change at any time. On terzyapp.com, the Analytics category may be shown as enabled by default in the Cookie preferences panel, but analytics scripts load only after you click "Accept all" or save preferences with Analytics enabled. You may turn Analytics off before saving or use "Reject all" to keep non-essential cookies off. If your browser sends Global Privacy Control, we suppress analytics and marketing cookies regardless of the banner state. Our Cookie Policy describes each cookie category, retention, and partners. Where required by PECR and ePrivacy, we obtain prior consent for non-essential cookies.
14. Marketing Communications
We send transactional messages about your account and Orders without requiring marketing consent. For marketing emails and push notifications, we rely on (a) your explicit opt-in where required, or (b) the "soft opt-in" exception under PECR reg 22(3) where you have previously purchased from us and we are promoting our own similar products and services. Every marketing message includes a one-click unsubscribe link and the ability to manage granular preferences in your account. Unsubscribing from marketing does not affect transactional messages essential to your Orders.
15. Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include encryption in transit (TLS) and at rest, role-based access controls, audit logging, secrets stored in AWS Secrets Manager, isolated production environments, security monitoring, and supplier due diligence. No system is completely secure; we cannot guarantee absolute security but we treat any incident seriously and will notify you and the ICO where required by law (Article 33 and 34 UK GDPR — within 72 hours where a notification threshold is met).
16. Jurisdiction-Specific Provisions
Depending on where you live, additional rights or specific notices may apply:
- European Economic Area & Switzerland: you may contact our Article 27 Representative and lodge complaints with your local supervisory authority.
- California (CCPA/CPRA): if you are a California resident you have the right to know, delete, correct, and opt out of "sale" or "sharing" of personal data; we do not sell personal data and limit sharing to the purposes described in Section 8.
- United Kingdom: complaints can be lodged with the Information Commissioner's Office at ico.org.uk or 0303 123 1113.
17. Contact & Data Protection Lead
For any privacy enquiry, request, or complaint, contact our Data Protection Lead at info@terzyapp.com or write to: Terzyapp UK Ltd — Data Protection, Suite 10861, 5 Brayford Square, London E1 0SG, United Kingdom. We will acknowledge your message within 5 business days. If we are unable to resolve your concern, you may refer the matter to the Information Commissioner's Office (or your local EU/EEA data protection authority) as described in Section 11.
18. Changes to This Policy
We may update this Privacy Policy from time to time. Where a change is material (for example, a new processing purpose, a new category of recipient, or a change in legal basis), we will notify you by email or in-app message at least 30 days before the change takes effect. Non-material changes (clarifications, corrections, formatting) take effect when published. The "Last updated" date at the top of this Policy always reflects the current version. Previous versions are available on request.