// Legal

Privacy Policy

Last updated June 2026

SizeFit AI Technologies ("SizeFit AI", "we", "us") operates a software-as-a-service sizing recommendation platform used by online clothing retailers. This Privacy Policy explains how we process personal data when (a) a merchant uses our dashboard and (b) an end shopper uses the SizeFit widget embedded on a merchant's website.

1. Who is the data controller

For shopper data (body measurements, fit preferences, recommendations) entered into the widget on a merchant's website, the merchant is the controller and SizeFit AI is the processor. Our processing is governed by the Data Processing Agreement available at /dpa.

For merchant data (account, billing, dashboard usage) SizeFit AI is the controller.

2. What we collect

From shoppers (via the widget)

  • Body measurements: height, weight, chest, waist (only what the shopper enters)
  • Fit preference: tight / regular / oversized
  • A random, browser-local pseudonymous token (no name, no email, no IP stored alongside it)
  • Product viewed and recommended size, for analytics

We do not collect shopper name, email, address, phone number, or government IDs through the widget.

From merchants

  • Account: email, name, password hash (via our auth provider)
  • Billing: customer ID and last 4 digits of card (held by Stripe, not by us)
  • Dashboard usage and audit log entries

3. Why we process it (legal basis)

  • Shopper measurements — explicit consent given in the widget before the Recommend button is enabled (GDPR Art. 9(2)(a) for health-adjacent data).
  • Merchant account & billing — performance of contract (GDPR Art. 6(1)(b)).
  • Security, fraud prevention, audit logs — legitimate interest (GDPR Art. 6(1)(f)).

4. How long we keep it

  • Shopper measurements & recommendations: 180 days, then automatically deleted.
  • Aggregated, non-identifying analytics: indefinitely.
  • Merchant account: for the life of the subscription + 90 days after cancellation.
  • Billing records: 7 years (tax law).

5. Sub-processors

We use the following sub-processors. Current list and locations: /dpa#subprocessors.

  • Supabase (database & auth) — EU region
  • Cloudflare (edge hosting & DDoS) — global
  • Stripe (payments) — Ireland & US
  • Resend (transactional email) — US

6. International transfers

Where data leaves the EEA (e.g. Stripe US), transfers rely on the EU Standard Contractual Clauses (2021/914) and the supplementary measures described in our DPA.

7. Your rights (shoppers)

Under GDPR you may request access, rectification, erasure, restriction, portability, or object to processing. Because shopper data is pseudonymous, the easiest path is via the merchant whose store you used the widget on. You can also email us at privacy@sizefit.ai with the random token shown in your browser's local storage and we will action it within 30 days.

8. Security

Transport encryption (TLS 1.2+), encryption at rest, row-level security per tenant, least-privilege service roles, audit logging on the admin panel, and quarterly access reviews. We have not (yet) completed a SOC 2 audit; we will publish status updates on this page when we do.

9. Children

The widget is not intended for shoppers under 16. We do not knowingly collect data from children.

10. Changes

Material changes are announced via merchant dashboard 30 days before they take effect.

Questions? Email privacy@sizefit.ai — we reply within 5 business days.