Privacy policy
Your taste is personal. Your data should be too.
Last updated: 26 July 2026. This is an implementation-focused privacy notice, not legal advice. The highlighted founder-review items must be completed before relying on it as the final legal notice.
Who is responsible?
The storefront currently presents itself as MyStyleCollage. The legal controller details are not yet confirmed in the source code.
Founder review required before launch
Replace this box with the controller's full legal name, registered address, privacy contact email, and any required company or VAT registration details. Until then, visitors do not have a verified direct privacy-contact route in this notice.
What we process and why
| Situation | Data used | Purpose and legal basis |
|---|---|---|
| Using the site | Technical request data processed by the site, hosting and security services, such as IP-related connection data, browser/device information and requested pages. | Deliver, secure and troubleshoot the site. The intended basis is legitimate interests and, where needed, steps to provide the requested service. Confirm the final hosting/security setup with the founder. |
| Cookie choice | Your analytics choice and the date it was saved, stored in this browser as essential local storage. | Remember and honour your choice. Necessary for the consent interface and compliance record on this device. |
| MyStyleCollage visual quiz | The visual choices you make during the quiz; the resulting style mix and optional blend; and your email address if you ask for the result by email. | Calculate and show the result, or send the requested result link. The intended basis is taking steps at your request / providing the requested service. The optional Club sign-up uses separate consent. |
| MyStyleCollage updates | Email address and the fact that you chose the optional Club checkbox. | Record your request to receive Club updates. Consent only; the checkbox is unticked by default. Confirm the final marketing email workflow and unsubscribe controls before launch. |
| Purchases and downloads | Order, payment-status, product, delivery and customer-contact data handled through the MadeThis checkout and fulfilment flow. | Process the purchase, deliver the download, support customers and meet applicable record-keeping duties. Founder must confirm the payment processor, retention periods and controller/processor roles. |
| Optional analytics | A temporary analytics identifier in browser memory, product metadata, purchase amount/currency after a completed order resolves, and limited browser/network event context supplied by the analytics provider. | Understand which products and purchase steps are useful. Consent only. It does not start unless you choose Analytics. |
How storefront analytics work
This storefront has one optional analytics integration: PostHog. It is not loaded or initialised until you choose Accept analytics or save Analytics as on. If you reject it, the storefront does not load PostHog, capture analytics events, add analytics identifiers to checkout links, or store analytics state in browser cookies or local storage.
If you consent, the code records only these explicit storefront events: a product view (product ID, title, price, currency and slug); the buy action and checkout start (the same product details); and a completed checkout after the order resolves (amount and currency). Automatic page-view capture and automatic click/form capture are disabled. The current configuration uses memory-only browser persistence, so it is designed not to create a new PostHog cookie or local-storage record.
Quiz answers, entered email addresses, account details, checkout-session IDs and payment details are deliberately excluded from the analytics event payloads. The storefront no longer appends PostHog identifiers or UTM campaign values to checkout URLs. A purchase completion event can still be associated with the temporary, consented analytics session during that page visit; it is not sent with the customer's email address or order identifier from this code.
The source code does not configure a PostHog retention period. Retention is therefore a founder/legal confirmation item and must be checked in the live PostHog project before this notice is finalised. You can withdraw analytics consent at any time; future events stop, the in-memory client is reset, and legacy PostHog-looking browser storage is removed where the browser allows it.
Recipients and international transfers
The code routes site and order-related functions through MadeThis platform services, uses Convex for the storefront's application data, and is deployed on Vercel. If you opt into analytics, it also sends the described analytics events to PostHog using the configured analytics host. These companies may act as service providers/processors, but the final contractual roles and data-processing agreements need founder confirmation.
The default PostHog ingestion host in the code is a US host unless the deployment configuration replaces it. We do not state a transfer mechanism here because it is not verified in the repository. Founder/legal review must confirm where each processor handles data and which transfer safeguards apply before this policy is treated as final.
Retention, security and children
We keep data only for as long as needed for the purpose, legal obligations, disputes or accounting, but the exact retention schedule is not configured in this repository. The consent choice remains in your browser until you change it or clear browser storage. Quiz answers are kept only in the current browser session by the quiz component. The analytics integration uses browser memory only in the current configuration; the provider-side event retention is not yet confirmed.
The site uses technical and organisational safeguards intended to protect personal data, but no online service can promise absolute security. MyStyleCollage is not designed for children. Founder review must confirm the intended minimum age and any child-data process for the markets served.
Your choices and rights
Depending on the law that applies to you, you may ask for access, correction, deletion, restriction, portability, or object to certain processing. You can withdraw analytics consent without affecting the lawfulness of processing before withdrawal. You can also withdraw optional marketing consent through the unsubscribe route in the relevant email once that programme is active.
Use the cookie controls below to change analytics consent. For a privacy request, contact the controller at the verified contact details that must be added above. If you are in Austria or another EU/EEA country, you may also complain to your local supervisory authority; in Austria this is the Austrian Data Protection Authority (Österreichische Datenschutzbehörde).
Changes to this notice
We will update this notice when the site's processing changes, including before adding advertising pixels, affiliate tracking, embeds or a new analytics provider. Significant changes should be communicated in an appropriate way. Read the practical Cookie Policy for the current browser-storage inventory.
Founder/legal sign-off checklist
- Insert verified controller identity, contact details, registration details and a privacy-request process.
- Confirm each processor's role, DPA, processing location, international-transfer safeguard and retention schedule.
- Confirm the live checkout, email, account, support and fulfilment data flows against this notice.
- Confirm the live PostHog project's retention and ensure no additional plugins, recordings, autocapture, advertising pixels or embeds are enabled without a new consent category and disclosure.
