Stolen.

Last updated [date]

Privacy policy

In plain words: what we collect, why, who sees it, and how to change your mind.

Draft, to be reviewed before launch.

Who we are

Stolen (stolenfits.com) is run by [company name], registered in [country] (company number [number]), [registered address]. We decide how your information is used (in legal terms, the “controller”).

Questions or requests about your data: hello@stolenfits.com.

[If the company is outside the UK and the EU: Our representative in the EU is [name, address], and in the UK [name, address]. You can contact them instead of us.]

What we collect

When you use Stolen as a member

When you pay for something (Stolen Pro, a boost, or a styling session)

When you book a session with a creator

If you’re a creator

On the waitlist (before launch): your email address, whether you’re a shopper, creator or brand, and which link brought you (for example an Instagram post).

Why we use it

What we never do

Who helps us

These providers handle data for us under contract, only to run Stolen:

Photos of products are sometimes loaded from the shop’s own website, which then sees your IP address, as with any link on the web.

Others who see some of your information: creators you book (see above); brands running a campaign you take part in (your creator page and the campaign look); and everyone, for what’s public on a creator’s page.

Data outside your country

Our main database is in the United States, and some providers work from other countries. When data leaves the UK or the European Union, we rely on the safeguards the law requires: the European Commission’s standard contract clauses, the UK’s addendum to them, and the UK–US data bridge where it applies. You can ask us for a copy.

How long we keep it

Your rights and choices

In Your account you can, at any time:

Depending on where you live, you may also have the right to ask us what we hold about you, to correct it, to object to how we use it, or to restrict it. Write to hello@stolenfits.com and we’ll reply within a month.

You can complain to a data protection authority: in the UK the Information Commissioner’s Office (ico.org.uk), in the EU the authority in your country, in the UAE the UAE Data Office. We’d appreciate the chance to fix things first.

If you live in the US: we don’t sell your personal information or use it for targeted advertising. You can ask to know, correct or delete what we hold, and we won’t treat you differently for asking.

Age

Stolen is for people aged 18 and over. If we learn that someone under 18 has an account, we delete it.

Storage on your device

We store a small amount of information in your browser: to keep you signed in, and to remember your country and currency, the day’s exchange rates, your display choices and your taste tally. This is needed for the site to work the way you set it; we don’t use it for tracking. Cloudflare may set a security cookie to tell people from bots.

Cookies. Our cookie banner asks whether you accept analytics cookies, and shows again until you choose. Your choice is kept in a strictly necessary cookie (stolen_ok) so we don’t ask again. Until you choose, nothing is counted. If you accept, an analytics cookie (stolen_vid) holds a random number so we count you once. Both last 13 months and work on stolenfits.com and its sub-sites. We use no advertising cookies. Change your choice any time with Cookies, at the bottom of every page.

Security

Everything travels encrypted (https). Each member can only reach their own private data: our database checks who is asking on every request. Only a small number of people at Stolen can see account data, and only when needed (for example to help you with a booking).

Changes

If we change this policy in a meaningful way, we’ll tell you by email or on the site before it takes effect.

See also our Terms of service.