Who we are
Stolen (stolenfits.com) is run by [company name], registered in [country] (company number [number]), [registered address]. We decide how your information is used (in legal terms, the “controller”).
Questions or requests about your data: hello@stolenfits.com.
[If the company is outside the UK and the EU: Our representative in the EU is [name, address], and in the UK [name, address]. You can contact them instead of us.]
What we collect
When you use Stolen as a member
- Your account: email address and password, or, if you sign in with Google, the name, email address and profile photo Google shares with us. Passwords are stored encrypted by our login provider; we can never see them.
- Your answers when you join: first and last name, how you’ll use Stolen, age range, gender, country (optional), styles, what you’re looking for, budget and where you shop. If you’re a creator, also your experience and goals.
- Your fit (optional): height, size and shape, so you can find looks on people like you. Only you see these.
- Your wardrobe (optional): pieces you add, with names, brands, links and photos. Private to you.
- Saved looks, saved creators and ratings: what you save is private to you. Your star ratings are private too; creators and other members only see the average.
- Your taste: we learn which styles, moods and occasions you like from the looks you open, save, rate and filter for, and keep a simple tally on your account. We use it only to put the looks you’re most likely to love first.
- Your country and currency: worked out from where you’re connecting (our host tells us the country, not your exact location), or the one you choose, so prices are shown in your currency.
- Activity, only if you say yes to trend insights: which looks you view and save, which products you click to shop, and what you search and filter for.
- Visit counts, only if you accept analytics cookies: a random number in a cookie, so we count each person once across stolenfits.com and the site itself, with the pages you open, the link or site that brought you, your country and your type of device. It isn’t linked to your account or used for anything else. If you don’t, we only count that a page was opened.
- Messages to us: what you write when you contact us.
When you pay for something (Stolen Pro, a boost, or a styling session)
- Your card details go straight to our payment provider, Stripe. We never see or store them. We keep what you bought, the amount, the currency, the date and its status.
When you book a session with a creator
- Your name, the session, its time and anything you write in the booking notes. These are shared with the creator you book, so they can prepare.
- If you leave a review, it’s shown on the creator’s page with your first name and the initial of your last name.
If you’re a creator
- Your creator page: name, city, bio, photos, links and looks. These are public.
- Payouts: to pay you, Stripe verifies your identity and bank details. Stripe keeps those; we only see whether payouts are switched on, and what you’ve earned.
- Applications: if you apply to be a founding creator or to a paid campaign, what you send us (for example your Instagram or TikTok, audience size, links and pitch).
- Your stats: how often your looks and links are viewed, saved and clicked, counted in total, not per visitor.
On the waitlist (before launch): your email address, whether you’re a shopper, creator or brand, and which link brought you (for example an Instagram post).
Why we use it
- To provide Stolen (needed to give you the service you signed up for): to sign you in, show your saved looks and wardrobe, publish creators’ pages, take payments, run bookings and pay creators.
- To show you looks you’ll like (our legitimate interest in a useful site): ordering looks by their ratings, your taste and how new they are.
- To keep Stolen safe and fair (legitimate interest): to stop spam, fake ratings and fraud, and to fix problems.
- To improve Stolen (legitimate interest): we look at members’ answers in total (for example “most members want ideas for clothes they already own”) to decide what to build.
- Trend insights, only with your consent: we combine activity from many members to spot trends, and may share or sell anonymous trend reports to brands and retailers. A report only includes a group of at least 10 people, and never includes names, emails or anything that identifies you.
- Emails: account and booking emails (sign-in links, password resets, booking confirmations) are always sent. News about creators, looks and features only with your consent.
- To meet legal duties: for example keeping payment records for tax.
What we never do
- We never sell your personal information: your name, email, answers linked to you, or your individual activity.
- No advertising trackers or third-party ad cookies.
Who helps us
These providers handle data for us under contract, only to run Stolen:
- Supabase: login, database and photo storage. Your data is stored in the United States (Oregon).
- Cloudflare: hosts the website, protects it from attacks, and tells us which country a visitor is in. Cloudflare Web Analytics also counts visits for us (which pages, which site or link people came from, their country and type of device), without cookies and without identifying you.
- Stripe: payments, subscriptions and creator payouts.
- Resend: sends our emails.
- Google: “Continue with Google” sign-in, only if you use it. (Our fonts are served from our own site, so Google isn’t contacted when you browse.)
- Frankfurter: provides the day’s exchange rates; your browser asks for them, so it sees your IP address and nothing else.
- [FASHN: only if a creator uses an AI model; receives product photos, not your personal details.]
- [Affiliate network, e.g. Skimlinks or Sovrn, once switched on: when you click to shop, the link passes through them so the shop knows the sale came from Stolen. They may set a cookie for that.]
Photos of products are sometimes loaded from the shop’s own website, which then sees your IP address, as with any link on the web.
Others who see some of your information: creators you book (see above); brands running a campaign you take part in (your creator page and the campaign look); and everyone, for what’s public on a creator’s page.
Data outside your country
Our main database is in the United States, and some providers work from other countries. When data leaves the UK or the European Union, we rely on the safeguards the law requires: the European Commission’s standard contract clauses, the UK’s addendum to them, and the UK–US data bridge where it applies. You can ask us for a copy.
How long we keep it
- Your account: until you delete it. Your creator page, looks and wardrobe go with it.
- Activity (trend insights): [24 months], then deleted. If you withdraw consent, it’s deleted straight away.
- Payments, bookings and payouts: as long as tax law requires ([usually 5 to 7 years]), even after you close your account. Booking records you were part of stay with the other person’s account, without your contact details.
- Visit counts: 13 months, then deleted.
- Waitlist: until we launch and invite you, or until you ask us to remove you.
- Applications (founding creators, campaigns): [12 months] after our decision.
Your rights and choices
In Your account you can, at any time:
- see and change your answers and your fit;
- turn trend insights or emails on or off;
- download a copy of all your data;
- delete your account (Close your account).
Depending on where you live, you may also have the right to ask us what we hold about you, to correct it, to object to how we use it, or to restrict it. Write to hello@stolenfits.com and we’ll reply within a month.
You can complain to a data protection authority: in the UK the Information Commissioner’s Office (ico.org.uk), in the EU the authority in your country, in the UAE the UAE Data Office. We’d appreciate the chance to fix things first.
If you live in the US: we don’t sell your personal information or use it for targeted advertising. You can ask to know, correct or delete what we hold, and we won’t treat you differently for asking.
Age
Stolen is for people aged 18 and over. If we learn that someone under 18 has an account, we delete it.
Storage on your device
We store a small amount of information in your browser: to keep you signed in, and to remember your country and currency, the day’s exchange rates, your display choices and your taste tally. This is needed for the site to work the way you set it; we don’t use it for tracking. Cloudflare may set a security cookie to tell people from bots.
Cookies. Our cookie banner asks whether you accept analytics cookies, and shows again until you choose. Your choice is kept in a strictly necessary cookie (stolen_ok) so we don’t ask again. Until you choose, nothing is counted. If you accept, an analytics cookie (stolen_vid) holds a random number so we count you once. Both last 13 months and work on stolenfits.com and its sub-sites. We use no advertising cookies. Change your choice any time with Cookies, at the bottom of every page.
Security
Everything travels encrypted (https). Each member can only reach their own private data: our database checks who is asking on every request. Only a small number of people at Stolen can see account data, and only when needed (for example to help you with a booking).
Changes
If we change this policy in a meaningful way, we’ll tell you by email or on the site before it takes effect.
See also our Terms of service.