Privacy Policy

Last updated: 17 August 2026

STYLORY LTD respects the privacy of every person who visits its website or subscribes to its service. The present Policy explains what personal data we collect, why we collect it, the legal basis on which we rely, with whom it is shared, how long it is kept, where it is sent, and what rights are available to the individuals concerned. Please read it together with the Cookie Policy, which addresses the technologies used on the website itself.

1. Who We Are and the Scope of the Policy

1.1 STYLORY LTD ("STYLORY", "we", "us", or "our") is a private limited company incorporated in England and Wales under company number 17152844, with its registered office at 67 Tradescant Road, London, Lambeth, England, SW8 1XJ. We are the controller of the personal data described below.

1.2 The Policy applies to the website at https://www.stylory.io, to the subscription service made available through it, to communications sent by us in connection with that service, and to enquiries received from prospective subscribers. It does not apply to any third-party website reached through a link from ours.

1.3 Processing carried out in the United Kingdom is governed by the UK General Data Protection Regulation and by the Data Protection Act 2018, in each case as amended by the Data (Use and Access) Act 2025. Processing relating to individuals in the European Economic Area is governed by Regulation (EU) 2016/679. Additional rights conferred by the privacy legislation of individual United States jurisdictions are addressed in section 17.

1.4 Our supervisory authority in the United Kingdom is the Information Commissioner's Office. Our registration reference with that authority is set out in section 19.

1.5 Questions about the Policy, and requests to exercise any right described in it, should be sent to dpo@stylory.io.

2. The Personal Data We Collect

2.1 The categories described in the present section are those we process. Not every category applies to every individual, since several of them depend on choices made by the subscriber.

2.2 Account data comprises the full name, the email address, a hashed form of the password, the country of residence, the date on which the account was created, and the language preference. All of it is supplied by the individual at registration.

2.3 Subscription data comprises the plan selected, the status of the subscription, the renewal date, the billing history, and the customer and subscription identifiers allocated by Stripe. Payment data comprises the card type, the final four digits, the expiry date, and the outcome of each authorisation. Complete card numbers are neither received nor stored by us, since the card itself is handled by Stripe and reported back to us only in truncated form.

2.4 Wardrobe content comprises photographs of garments and accessories owned by the subscriber, together with the attributes derived from those photographs, such as category, colour, pattern, and season. An optional profile photograph or avatar falls within the same category. Material of this kind is uploaded by the subscriber, or by a delegated staff user acting on the subscriber's behalf.

2.5 Optional information comprises body measurements, recorded to refine the fit of the suggestions produced, and free-text notes on taste, occasions, colours avoided, and comparable matters. Both are entered voluntarily and may be withheld entirely.

2.6 Correspondence comprises messages exchanged with a human stylist on the plans that include the service, support requests, other communications with us, and records of the transactional messages we have sent and their delivery status.

2.7 Usage and device data comprises the pages viewed, the features used, the approximate location derived from the IP address for the purpose of confirming territorial eligibility, the browser and device type, the operating system, and the associated timestamps. Collection of that kind is automatic and is governed in addition by the Cookie Policy.

2.8 Competition data comprises entries to the Creator Challenge, the referral records associated with them, and any prize awarded.

2.9 Provision of account data and of subscription data is necessary in order for the contract to be performed, and without it an account cannot be opened. Everything identified above as optional may be withheld without any loss of access to the service.

3. Wardrobe Photographs, Measurements, and the Question of Special Category Data

3.1 Photographs of garments are central to the service. A subscriber photographs items already owned, and the platform isolates each item from its background before adding it to the digital wardrobe.

3.2 We recognise that an image taken of a garment may incidentally include the subscriber or another person. Where that occurs, the image is treated with the same protection as every other item of wardrobe content, and it is used only for the purposes described in section 4.

3.3 We do not subject any image to facial recognition, to facial or bodily template extraction, or to any other technique intended to identify a natural person uniquely. Photographs are accordingly not processed as biometric data within the meaning of Article 4(14) and Article 9 of the UK GDPR and of the EU GDPR.

3.4 Body measurements are personal data, but they are not processed for the purpose of revealing health, and they are not used to make any inference about a health condition. We do not treat them as data concerning health under Article 9. Given the sensitivity that individuals may nonetheless attach to such information, we collect it only where the subscriber has actively chosen to provide it, we rely on consent as the legal basis, and we delete it immediately upon withdrawal of that consent.

4. Why We Process Personal Data and on What Legal Basis

4.1 Every processing operation rests on one of the legal bases in Article 6 of the UK GDPR and of the EU GDPR, identified below by reference to the purpose it supports.

4.2 We rely on the performance of a contract, under Article 6(1)(b), in order to create and administer an account, to authenticate logins, to provide the wardrobe and styling functionality, to generate automated outfit suggestions, to supply the human stylist service on the plans that include it, to take subscription payments and manage renewals, to issue receipts and handle refunds, to send the service and transactional messages that the subscription requires, and to administer the Creator Challenge for those who enter it.

4.3 We rely on consent, under Article 6(1)(a), in order to record and use optional body measurements and style notes, in order to operate the analytics and other non-essential technologies described in the Cookie Policy, and in order to send marketing communications about our own service.

4.4 We rely on our legitimate interests, under Article 6(1)(f), in order to maintain the security of the platform, to prevent and investigate fraud and misuse, to handle support requests and complaints, to run promotions such as the Creator Challenge, and to establish, exercise, or defend legal claims.

4.5 We rely on compliance with a legal obligation, under Article 6(1)(c), in order to keep accounting and tax records, to issue the notices that consumer and subscription legislation requires, and to respond to a lawful request from a court, a regulator, or another competent authority.

4.6 Where we rely on legitimate interests, we have carried out a balancing assessment and have satisfied ourselves that our interest is not overridden by the interests, rights, and freedoms of the individuals concerned. A summary of any such assessment is available on request from dpo@stylory.io.

4.7 Where we rely on consent, that consent may be withdrawn at any time, without charge and without giving a reason. Withdrawal does not affect the lawfulness of processing carried out before it took effect.

4.8 We do not rely on the recognised legitimate interests basis introduced into the UK GDPR by the Data (Use and Access) Act 2025 for any of the purposes described above.

5. Automated Processing and Artificial Intelligence

5.1 Outfit suggestions, garment categorisation, and comparable outputs are produced by automated systems, including a large language model supplied by a third party and image-processing software operated on our own infrastructure.

5.2 Processing of that kind does not produce a legal effect concerning any individual and does not similarly significantly affect any individual. It therefore falls outside the restriction in Article 22 of the UK GDPR and of the EU GDPR on decisions based solely on automated processing.

5.3 Content submitted to our artificial-intelligence supplier through its application programming interface is not used by that supplier to train its models, and we do not use subscriber content to train any model of our own.

5.4 Automated processing is confined to the generation of styling output. No profiling is undertaken for the purpose of assessing creditworthiness, employment suitability, insurance risk, or any comparable matter, and no automated decision determines a subscriber's access to the service.

5.5 Background removal from garment photographs is performed by software hosted on infrastructure operated by or for STYLORY. Images are not transmitted to any third-party background-removal service.

6. Human Stylists and Delegated Staff Access

6.1 On the plans that include the service, a human stylist is granted access to the wardrobe content and optional information of the subscriber concerned, strictly for the purpose of preparing recommendations. Stylists are bound by confidentiality obligations and access only the accounts allocated to them.

6.2 A subscriber may grant a nominated individual delegated access to manage the wardrobe. Access of that kind is granted, controlled, and revoked entirely by the subscriber from within the account. While delegated access is active, the nominated individual can view and alter the wardrobe content held in the account.

6.3 STYLORY remains the controller of the personal data processed through the platform. A subscriber who grants delegated access should satisfy themselves that the nominated individual is trustworthy, since we cannot distinguish between actions taken by the subscriber and actions taken by an authorised delegate.

6.4 Our own personnel access account content only where necessary for support, security, billing, or legal compliance. Access is governed by role-based permissions and is logged.

7. Recipients and Service Providers

7.1 Personal data is disclosed to the service providers described below. Each of them acts as our processor under a written contract meeting the requirements of Article 28 of the UK GDPR and of the EU GDPR, save where a different role is indicated.

7.2 Supabase provides authentication, the database, and the storage of wardrobe images and account records. The project is hosted in the Central EU region, at Frankfurt, Germany (eu-central-1), so that the account records and wardrobe images concerned reside within the European Economic Area. No transfer to a third country therefore arises in respect of subscribers in the European Economic Area. For subscribers in the United Kingdom, personal data is transferred to an EEA state, and paragraphs 4 and 5 of Schedule 21 to the Data Protection Act 2018 treat a transfer of that kind as approved by regulations made under Article 45A of the UK GDPR, with the result that neither the standard contractual clauses nor the United Kingdom Addendum is relied upon for it. Where the provider requires remote access to the hosted environment from outside the European Economic Area for support or maintenance, that access is governed by the written contract referred to in section 7.1, which incorporates the standard contractual clauses together with the United Kingdom Addendum.

7.3 Stripe provides subscription billing, payment processing, and the customer portal through which a subscription is cancelled. Processing takes place in Ireland and in the United States, and transfers are made under the standard contractual clauses, the United Kingdom Addendum, and the EU-US Data Privacy Framework.

7.4 OpenAI provides the automated generation of outfit suggestions and the analysis of wardrobe items. Processing takes place in the United States, and transfers are made under the standard contractual clauses together with the United Kingdom Addendum.

7.5 Resend delivers our transactional and notification messages. Processing takes place in the United States, and transfers are made under the standard contractual clauses together with the United Kingdom Addendum.

7.6 Vercel hosts the website and delivers its content. Processing takes place in the United States and at edge locations worldwide, and transfers are made under the standard contractual clauses together with the United Kingdom Addendum, and under the EU-US Data Privacy Framework.

7.7 Stripe acts as our processor when it takes payment on our instructions, and as an independent controller when it determines the purposes and means of processing for its own compliance, fraud-prevention, and regulatory obligations. Its own privacy notice governs that second role.

7.8 Background removal from garment images is carried out by software self-hosted by STYLORY and involves no third-party recipient. On our public blog we display advertising supplied by Google LLC through Google AdSense; Google acts as an independent controller for the delivery, measurement and, where consented, personalisation of that advertising, processing data such as an IP address, the page viewed and interactions with an advertisement in the United States under the standard contractual clauses and the EU-US Data Privacy Framework, and its own privacy notice governs that processing. Advertising cookies are set only on the blog and only where the visitor has accepted the advertising category; no advertising is shown, and no advertising cookie is set, within the signed-in application. Aside from this advertising we do not use Google Analytics, advertising pixels or third-party marketing platforms, and our own site analytics are first-party and gated behind consent.

7.9 Beyond the providers described above, personal data may be disclosed to our professional advisers, including lawyers and accountants, where necessary and under a duty of confidence; to a public authority, court, or regulator where disclosure is required by law or by an order of a competent body; and to a purchaser or prospective purchaser in connection with a sale, merger, or reorganisation of our business, in which case the recipient is bound to handle the data in accordance with the Policy.

7.10 We do not sell personal data. Where personalised advertising is shown on the blog through Google AdSense, that activity may constitute a sale or a sharing for cross-context behavioural advertising under certain United States state laws; a means of opting out is described in section 18, and we honour the Global Privacy Control signal. We do not otherwise share personal data for cross-context behavioural advertising.

8. International Transfers

8.1 Several of the providers identified in section 7 are established in the United States. Transfers of personal data outside the United Kingdom and outside the European Economic Area are therefore made in the course of operating the service. Account records and wardrobe images stored with Supabase are an exception, since they reside within the European Economic Area, as section 7.2 explains.

8.2 For transfers from the United Kingdom, we rely on the International Data Transfer Addendum to the European Commission standard contractual clauses issued by the Information Commissioner under section 119A of the Data Protection Act 2018, and where the recipient holds a current certification, on the United Kingdom Extension to the EU-US Data Privacy Framework. Since 5 February 2026, the assessment required before such a transfer is the data protection test introduced by the Data (Use and Access) Act 2025, under which the standard of protection in the destination must not be materially lower than the standard under United Kingdom law.

8.3 For transfers from the European Economic Area, we rely on the standard contractual clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 and, where the recipient holds a current certification, on the adequacy decision for the EU-US Data Privacy Framework adopted in Implementing Decision (EU) 2023/1795.

8.4 We monitor the status of the Data Privacy Framework. An action seeking its annulment was dismissed by the General Court of the European Union on 3 September 2025, and an appeal against that judgment is pending before the Court of Justice. The adequacy decision remains in force pending the outcome, and the standard contractual clauses referred to above operate as an independent safeguard in any event.

8.5 Where required, we carry out a transfer risk assessment and apply supplementary measures, including encryption in transit and at rest, access restriction, and the minimisation of the data sent to each recipient.

8.6 A copy of the safeguards applicable to a particular transfer may be requested from dpo@stylory.io.

9. How Long We Keep Personal Data

9.1 Personal data is kept only for as long as is necessary for the purpose for which it was collected, or for as long as the law requires. The periods currently applied are those set out below.

9.2 Account data and wardrobe content are held for the life of the account and are deleted within 30 days of its closure. Body measurements and style preferences are held until consent is withdrawn or the account is closed, and are deleted immediately at that point. Residual copies within encrypted backups are overwritten within 90 days of deletion, and are not accessible for operational use in the meantime.

9.3 Subscription, billing, and tax records are held for six years from the end of the accounting period to which they relate, in order to meet statutory record-keeping obligations in the United Kingdom. Records evidencing consent to the automatic-renewal terms are held for three years from the date of consent, or for one year after termination of the subscription, whichever period expires later.

9.4 Support and stylist correspondence is held for 24 months from the last message in the exchange, so that follow-up enquiries and complaints can be handled. Records of marketing consent are held until consent is withdrawn, and for 24 months thereafter as evidence of the withdrawal. Security, access, and audit logs are held for 12 months.

9.5 Records relating to a live or anticipated legal claim are held until the claim and any period for appeal have concluded.

9.6 At the end of the applicable period, personal data is deleted or irreversibly anonymised. Anonymised information, which no longer identifies any individual, may be retained indefinitely for statistical purposes.

10. Security

10.1 We apply technical and organisational measures appropriate to the risk, taking account of the nature of the data we hold and the harm that its compromise could cause.

10.2 Measures currently in place include encryption of data in transit using transport layer security, encryption of stored data at rest, hashing of passwords using a one-way algorithm, role-based access control with the principle of least privilege, logging of administrative access, network and application-level access restrictions, and regular application of security updates to the components we operate.

10.3 Card details are handled by Stripe within its own certified payment environment. We neither receive nor store full card numbers, and we do not store card security codes.

10.4 No method of transmission or storage is entirely secure. While we take the protection of personal data seriously, we cannot guarantee absolute security, and information is transmitted to the platform at the sender's own risk.

10.5 Where a personal data breach occurs that is likely to result in a risk to the rights and freedoms of individuals, we notify the Information Commissioner's Office, and the competent supervisory authority in the European Union where relevant, within 72 hours of becoming aware of it. Where the risk is high, we notify the affected individuals directly and without undue delay.

11. Your Rights Under United Kingdom and European Union Law

11.1 Individuals in the United Kingdom and the European Economic Area have the right of access, which entitles them to a copy of the personal data held about them together with the supplementary information required by Article 15.

11.2 The right to rectification entitles an individual to have inaccurate personal data corrected and incomplete data completed. Much of the information we hold may be corrected directly within the account.

11.3 The right to erasure entitles an individual to have personal data deleted where it is no longer necessary for the purpose for which it was collected, where consent has been withdrawn and no other basis applies, where the individual objects and no overriding ground exists, or where the data has been processed unlawfully.

11.4 The right to restriction entitles an individual to have processing limited while accuracy is contested, while an objection is considered, or in place of erasure where the data is needed for a legal claim.

11.5 The right to data portability entitles an individual to receive the personal data they have provided, in a structured, commonly used, and machine-readable format, and to have it transmitted to another controller where technically feasible. The right applies to data processed by automated means on the basis of consent or of a contract.

11.6 The right to object entitles an individual to object at any time to processing carried out on the basis of legitimate interests, and to object at any time and without qualification to processing for direct marketing.

11.7 Where processing is based on consent, that consent may be withdrawn at any time by the means described in section 4.7.

11.8 Exercising a right is free of charge. Where a request is manifestly unfounded or excessive, in particular because it is repetitive, we may charge a reasonable fee or refuse to act, and we will explain our reasons and the routes of challenge available.

12. How to Exercise a Right

12.1 Requests should be sent to dpo@stylory.io. In order to protect the account, we may ask for information sufficient to confirm the identity of the person making the request, and the period for response begins once that confirmation has been received.

12.2 We respond within one month. Where a request is complex, or where several requests have been received from the same person, the period may be extended by up to two further months, and we will explain the reason for the extension within the first month.

12.3 A request may be made through an authorised agent, in which case written evidence of the agent's authority is required.

13. Complaining About How We Handle Personal Data

13.1 A complaint may be made directly to us at dpo@stylory.io, and we encourage that route first, since most concerns can be resolved quickly.

13.2 Since 19 June 2026, data subjects in the United Kingdom have a statutory right under section 164A of the Data Protection Act 2018 to complain to the controller about processing that they consider infringes the UK GDPR. On receipt of such a complaint, we acknowledge it within 30 days and take appropriate steps to respond without undue delay, informing the complainant of the outcome.

13.3 A complaint may also be made to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom, by telephone on 0303 123 1113, or through https://ico.org.uk/make-a-complaint. The Information Commissioner ordinarily expects the controller to have been given the opportunity to respond first.

13.4 Individuals in the European Economic Area may complain to the supervisory authority of the Member State of their habitual residence, place of work, or the place of the alleged infringement.

14. Cookies and Similar Technologies

14.1 The website uses cookies and comparable technologies. Their categories, purposes, durations, and the means of granting and withdrawing consent are described in the Cookie Policy, which forms part of the present Policy.

14.2 Consent given or refused through the cookie banner is recorded, and the record is kept so that we can demonstrate the choice made.

15. Marketing Communications

15.1 Marketing messages about our own service are sent only where the recipient has consented, or where the soft opt-in in regulation 22 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 applies to an existing customer in respect of similar services.

15.2 Every marketing message contains a means of unsubscribing without charge, and consent may equally be withdrawn from the account or by writing to dpo@stylory.io.

15.3 Service and transactional messages, including renewal reminders, payment notifications, security alerts, and notices of changes to our terms, are not marketing. They form part of the service and cannot be opted out of while a subscription remains active.

16. Children

16.1 The service is intended for adults. Individuals must be at least 18 years of age in order to register, and we do not knowingly collect personal data from anyone below that age.

16.2 Where we become aware that an account has been opened by a person below the minimum age, the account is closed and the associated personal data is deleted without undue delay.

16.3 A parent or guardian who believes that a child has provided personal data to us should contact dpo@stylory.io so that the matter can be addressed.

17. Your United States State Privacy Rights

17.1 Residents of United States jurisdictions with comprehensive privacy legislation in force may have rights in addition to those described above. The jurisdictions concerned currently include California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island.

17.2 Subject to the conditions and exceptions of the applicable statute, those rights comprise the right to know and to access the categories and specific items of personal information collected, the sources from which it was collected, the purposes of collection, and the categories of recipients; the right to obtain a copy in a portable form; the right to correct inaccurate personal information; the right to delete personal information; the right to opt out of the sale of personal information, of the sharing of personal information for cross-context behavioural advertising, and of profiling in furtherance of decisions producing legal or similarly significant effects; the right to limit the use and disclosure of sensitive personal information; and the right not to receive discriminatory treatment for exercising any of them.

17.3 Several of those statutes apply only to a business meeting revenue or volume thresholds, and a number of them do not presently apply to STYLORY. Where a right described above is not owed to a resident as a matter of law, we nonetheless offer it as a matter of policy, so that the treatment of subscribers is consistent across the territories we serve.

17.4 A request may be made by writing to dpo@stylory.io with the subject line "US privacy request", stating the jurisdiction of residence and the right being exercised. We verify identity by reference to information already associated with the account and respond within the period allowed by the applicable statute, being 45 days in most jurisdictions, extendable once where reasonably necessary.

17.5 A request may be submitted by an authorised agent on production of written permission signed by the consumer, and we may require the consumer to verify their own identity directly.

17.6 Where a request is refused, the reason is given, together with details of the internal appeal mechanism required by the statutes of Virginia, Colorado, Connecticut, and comparable jurisdictions, and of the right to complain to the state attorney general.

18. Do Not Sell or Share My Personal Information

18.1 Except in connection with the personalised advertising shown on our blog through Google AdSense, STYLORY does not sell personal information and does not share personal information for cross-context behavioural advertising, as those expressions are defined in the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020. Where such advertising is shown, the resulting activity may fall within those definitions, and the opt-out described below is available.

18.2 We do not sell or share the personal information of any individual under 16 years of age, and no individual under 18 may hold an account in any event.

18.3 A visitor may opt out of any sale or sharing arising from advertising by refusing or withdrawing consent to the advertising category through the cookie preferences control, and we honour an opt-out preference signal such as Global Privacy Control as a valid opt-out for the jurisdictions whose law so requires. Because personal information is not otherwise sold or shared, these mechanisms relate to the blog advertising described in section 7.8.

18.4 We do not use or disclose sensitive personal information for any purpose other than those permitted without a right to limit under the California regulations.

19. Regulatory Registrations and Representatives

19.1 STYLORY LTD pays the data protection fee to the Information Commissioner's Office and appears on its register of fee payers. Our registration reference is ZC226794.

19.2 STYLORY does not offer the service to individuals in the European Union or the European Economic Area, and does not monitor their behaviour. Article 3(2) of the EU GDPR therefore does not apply to STYLORY, and no representative in the Union under Article 27 of the EU GDPR is required. Should STYLORY begin to offer the service to individuals in the European Union, a representative will be appointed under Article 27 and its details published here before that processing begins.

19.3 Because the service is not offered to recipients in the European Union, no representative under Article 13 of Regulation (EU) 2022/2065, the Digital Services Act, is required. Should the service be offered to recipients in the European Union in future, such a representative will be appointed and its details published in the Copyright and DMCA Policy before that time.

20. Changes to the Policy

20.1 The Policy is kept under review and may be updated to reflect a change in our processing, in the service, or in applicable law.

20.2 The date of the most recent revision appears at the head of the document. Where a change is material, we notify registered subscribers by email before it takes effect, and where the change requires consent, we obtain that consent before the new processing begins.

20.3 Earlier versions are retained and may be requested from dpo@stylory.io.

21. How to Contact Us

21.1 Data protection enquiries, requests to exercise rights, and complaints: dpo@stylory.io.

21.2 General enquiries: contact@stylory.io.

21.3 Postal address: STYLORY LTD, 67 Tradescant Road, London, Lambeth, England, SW8 1XJ, United Kingdom. Registered in England and Wales under company number 17152844.