This policy explains what personal data the FashClick mobile app collects, how we use it, and the rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. FashClick is published by VrittIQ ("we", "us", "our").
This policy covers the FashClick app only. Use of the VrittIQ website is covered by our main Privacy Policy.
1. Who We Are
FashClick is a product of VrittIQ, a software company based in London, United Kingdom. We are the data controller for the personal data described in this policy. For any privacy-related query you can reach us at:
- Email:contact@vrittiq.co.uk
- Phone:+44 20 4549 9338
- Address: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, UK
2. Photos & Facial Images
When you use FashClick's virtual try-on features, you upload photos of yourself and of garments. These photos may include your face. FashClick does not perform facial recognition or face matching, and does not create any biometric identifier or template. Your face is processed only as ordinary image content, so that the generated image preserves your appearance.
What we collect
The images you upload (standard JPEG, PNG, or WEBP files up to 10 MB), which may contain your face, for the sole purpose of generating the virtual try-on image you request. We do not extract facial geometry, facial landmarks, or embeddings.
How we use them
Only to create the try-on image you request. We do not use your photos or your face for advertising, analytics, profiling, or tracking, and we do not use them to train AI models.
Who processes or receives them
To generate the image, your photo is processed by our AI image-generation provider, Google (Gemini / Generative Language API), strictly to produce the result. No other third party receives it. We never sell your images and never share them with advertisers or data brokers.
Where they are stored
In private, access-controlled Microsoft Azure Blob Storage with no public access, hosted in the UK/EU region and reachable only through secure, time-limited signed links.
Retention & deletion
Uploaded photos and generated try-on images are automatically deleted 30 days after creation. You can also request account deletion at any time from within the app: your account is then scheduled for permanent deletion after a 30-day grace period, during which you may cancel the request. On day 30 your profile details, uploaded images, generated images, and history are permanently removed. To request earlier deletion, email contact@vrittiq.co.uk.
Legal basis (UK GDPR)
Performance of the service you request (Article 6(1)(b)), and your consent where required (Article 6(1)(a)).
3. Account Data
Your name, email address, and optional phone number. If you sign in with Google or Apple, we receive the basic profile information those providers return (typically your name, email address, and a provider account identifier) — we never receive your password for those accounts. Authentication is handled on our behalf by Google Firebase Authentication. If you choose Apple's "Hide My Email" option, we only ever hold the relayed address.
4. Face ID and Biometric Sign-In
If you enable biometric sign-in, your fingerprint or face is checked entirely on your device by Apple's or Android's own operating-system security features. We never receive, transmit, or store any biometric data, and we cannot access it. This is separate from, and unrelated to, the try-on images described in section 2.
5. Device and Notification Data
If you allow notifications, Google Firebase Cloud Messaging issues a device token that lets us send you service messages about your account, credits, and try-on results. We also use Firebase App Check to verify that requests come from a genuine copy of our app and to block abuse. Notifications are optional and can be turned off at any time in your device settings.
6. Subscription and Payment Data
We keep a record of your plan, credit balance, transaction history, and subscription status. We never see or store your card details. Payments are processed entirely by the relevant provider:
- iOS — Apple In-App Purchase. Apple handles the payment, and manages billing, cancellation, and refunds.
- Android — Stripe. Card details are collected and held by Stripe under their own privacy policy.
We retain transaction records for 6 years to meet UK tax and accounting obligations. This retention continues after account deletion, because the law requires it — but the records are limited to what is needed for accounting and are not linked to your uploaded images.
7. Lawful Basis for Processing
- Contract — account creation, sign-in, delivering try-ons, and processing your subscription
- Consent — push notifications, and image processing where consent is required
- Legitimate interest — securing the service against fraud and abuse
- Legal obligation — retaining financial records
8. Sharing Your Information
We share data only with trusted third parties that help us operate FashClick. These currently include:
- Google Gemini / Generative Language API (Google LLC) — AI image generation; receives the photos you upload solely to produce the requested try-on image
- Google Firebase (Google LLC) — authentication, push notifications, and app-integrity checks
- Microsoft Azure — private Blob Storage for your images
- Apple — In-App Purchase processing and subscription management on iOS
- Stripe — payment processing on Android
All third parties are contractually required to safeguard your data and use it only for the purpose for which it is shared. We do not sell your data or share it with advertisers or data brokers.
9. International Transfers
Some of our processors — including Google Firebase and the Google Gemini image-generation API — may transfer data outside the UK or EEA, principally to the United States. Where this happens we rely on UK adequacy regulations (including the UK Extension to the EU–US Data Privacy Framework) or Standard Contractual Clauses to ensure equivalent protection. Your images are stored at rest in the UK/EU region as described in section 2.
10. Data Retention
- Photos and generated try-on images — automatically deleted 30 days after creation; on account deletion, all remaining content is permanently removed at the end of a 30-day grace period
- Account data — kept while your account is active, then permanently removed at the end of the 30-day grace period following a deletion request
- Transaction records — 6 years from the transaction, as required by UK tax law, retained after account deletion
11. Your Rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data ("right to be forgotten")
- Object to or restrict our processing
- Request data portability
- Withdraw consent at any time (without affecting prior lawful processing)
- Lodge a complaint with the Information Commissioner's Office (ICO)
You can delete your account and content directly in the app at any time. To exercise any other right, email us at contact@vrittiq.co.uk. We respond within 30 days.
12. Security
We use TLS encryption for data in transit, restrict access to personal data to authorised personnel, and review our processors' security practices. Your images are held in private storage with no public access and are reachable only through short-lived signed links. No system is 100% secure, but we take reasonable steps to protect your information.
13. Children's Privacy
FashClick is intended for users aged 13 and over. We do not knowingly collect data from children under 13. If you believe a child has created an account or uploaded images, please contact us and we will delete it.
14. Changes to This Policy
We may update this policy from time to time. The "Last updated" date at the top reflects the most recent revision. Material changes will be highlighted on this page and, where appropriate, notified in the app.
15. Contact
Questions, requests, or concerns? Email contact@vrittiq.co.uk or write to the address above. For the terms governing use of the app, see the FashClick Terms and Conditions.