Privacy Policy
Last updated: March 31, 2026
1. Who We Are
Clothset(“we,” “us,” “our”) operates a multi-brand fashion marketplace at clothset.com. We connect buyers with brands and independent sellers, process payments through Stripe, and provide AI-powered virtual try-on features. This policy explains how we collect, use, and protect your personal information.
2. Information We Collect
We collect the following categories of information:
- Account information: Name, email address, and password when you create an account. Authentication is handled by Supabase Auth.
- Profile information: Shipping addresses, saved payment methods, and profile preferences.
- Body measurements (opt-in only): Height, weight, chest, waist, hip measurements, and shoe size — only if you choose to use our virtual try-on feature. This data is collected only after explicit consent.
- Purchase data: Order history, items in your cart, wishlist, and closet. Payment card details are processed directly by Stripe and are never stored on our servers.
- Usage data: Pages viewed, search queries, device type, browser, IP address, and interaction patterns. Collected via cookies and server logs.
3. How We Use Your Information
- Process and fulfill orders across multiple sellers
- Operate our virtual try-on and outfit layering features
- Provide size recommendations based on your body profile
- Send order confirmations, shipping updates, and account notifications
- Personalize product recommendations and search results
- Detect and prevent fraud, abuse, and unauthorized access
- Improve our platform, fix bugs, and develop new features
- Send marketing emails (only with your opt-in consent)
4. Body Data & Virtual Try-On
We take your body data seriously. Here's exactly how it works:
- Body measurements are collected only with your explicit consent. You can use Clothset without ever providing body data.
- Your consent is recorded with a timestamp. You can view and manage your consent status in your account settings at any time.
- Body data is encrypted at rest in our database (Supabase with row-level security) and encrypted in transit via TLS/HTTPS.
- Body data is used solely for generating virtual try-on results and size recommendations. It is never shared with sellers, advertisers, or any third party.
- You can revoke consent and delete all body data at any time through your profile settings. Deletion is permanent and immediate.
5. Data Sharing
We share your information only in these cases:
- Sellers: When you place an order, we share your name and shipping address with the seller(s) who need to fulfill it. We do not share your email, payment details, or body data with sellers.
- Stripe: Payment processing is handled entirely by Stripe. Your card details go directly to Stripe and never touch our servers. See Stripe's Privacy Policy.
- Supabase: Our database and authentication provider. Data is stored in their US-based data centers with encryption at rest.
- Vercel: Our hosting provider. Handles request routing and serves our website.
- Legal requirements: We may disclose information if required by law, court order, or government request.
We do not sell your personal information. We do not share it with advertisers. We do not allow third parties to track you across our site for their own advertising purposes.
6. Data Security
- All connections to clothset.com are encrypted via HTTPS with HSTS enforcement
- Database access is restricted by row-level security policies — users can only access their own data
- Admin accounts require multi-factor authentication
- API endpoints are rate-limited to prevent brute-force attacks
- Payment data is handled by PCI DSS-compliant Stripe infrastructure
- Secrets and API keys are stored in environment variables, never in code
- Database backups are automated
7. Cookies
We use cookies for authentication (keeping you logged in), storing your cart contents, and remembering your preferences. We use basic analytics to understand how our site is used. We do not use third-party advertising cookies or cross-site tracking pixels. You can disable cookies in your browser settings, but some features (like staying logged in) will not work without them.
8. Your Rights
You have the right to:
- Access all personal data we hold about you
- Correct inaccurate information in your account
- Delete your account and all associated data
- Export your data in a portable format
- Opt out of marketing emails at any time
- Revoke consent for body data processing
- Lodge a complaint with a data protection authority
To exercise any of these rights, email privacy@clothset.com or use the controls in your account settings.
9. Data Retention
We retain your account data for as long as your account is active. Order history is retained for 7 years for tax and legal compliance. If you delete your account, we remove all personal data within 30 days, except where retention is required by law. Body measurement data is deleted immediately upon consent revocation.
10. Children's Privacy
Clothset is not intended for users under 16 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
11. Changes to This Policy
We may update this policy as our practices or the law change. If we make material changes, we will notify you by email or through a prominent notice on the site at least 14 days before the changes take effect. Your continued use of Clothset after the effective date constitutes acceptance of the updated policy.
12. Contact Us
For questions about this privacy policy or how we handle your data:
- Email: privacy@clothset.com
- Website: clothset.com