styleprofile. — home

Legal

Privacy policy

Last updated: 9 August 2026

This policy explains what StyleProfile does with personal data: what retailers give us when they open an account, and the photographs shoppers upload when they use try-on. Section 4 covers photographs, which is what most people came here for.

1. Who we are

StyleProfile is a virtual try-on product operated by Bridzia Sdn Bhd, incorporated in Malaysia in 2012 under registration number 201201018441 (1003954V), with its head office in Kuala Lumpur. “We” and “Style Profile” mean Bridzia Sdn Bhd.

We handle personal data in two roles:

  • As controller for the data we hold in our own right: retailer account and contact details, billing records, support correspondence and service analytics. We decide why and how it is processed.
  • As processor for shopper personal data, including photographs, processed on behalf of the retailer whose store the shopper is using. That retailer is the controller; we act on its documented instructions under a data processing agreement, and its own privacy notice governs its relationship with the shopper.

2. What this policy covers

This policy applies to styleprofile.io, the StyleProfile dashboard, and the try-on widget wherever it is embedded in a retailer’s store. It does not cover the rest of that retailer’s website, checkout or marketing, which their own policies govern.

3. The data we collect

  • Account and contact data. Name, work email, company, store URL, ecommerce platform and role, given when a retailer signs up, requests a demo, applies to the founding retailer program or writes to us.
  • Billing data. Plan, invoices and payment status. We do not hold payment card numbers. Cards are captured and stored by our payment provider; we receive a token, the brand and the last four digits.
  • Shopper photographs. Images uploaded to generate a try-on. Section 4 sets out how they are handled.
  • Catalogue data. Product images, descriptions, sizes and prices connected from a retailer’s store, processed to produce that store’s renders.
  • Usage and technical data. Pages viewed, features used, render counts, device and browser type, approximate location from IP address, and error logs.
  • Communications. Emails, support messages and notes from calls.

4. Shopper photographs

This is the most sensitive data the product touches, so it is set out plainly rather than folded into a general clause.

Purpose limitation: rendering only

A shopper photograph is used for exactly one purpose: generating the try-on render the shopper asked for. It is not used to profile them, not analysed for advertising signals, not enriched against other data sets, and not disclosed for anyone else’s marketing.

No model training without explicit consent

We do not use shopper photographs to train, fine-tune or evaluate our models. Any such use would require separate, specific, opt-in consent, recorded when given and withdrawable at any time. Continuing to use the widget is not consent, and a pre-ticked box is not consent.

Retention: transient, then deleted

Uploaded photographs are processed transiently: an image is held only as long as the render session needs it, then deleted. If a shopper or retailer asks us to delete one sooner we do, and confirm in writing.

Biometric-adjacent sensitivity

A photograph of a person’s body sits close to biometric data, even where it is not legally classified as such. We treat it with the care that category deserves: restricted access on a need-to-operate basis, encryption in transit and at rest, access logging, and no secondary use. We do not generate or store a biometric template or face signature from shopper photographs.

Opt-in by construction

There is no try-on without an upload. A shopper who never opens the widget never gives us an image, and the rest of the store works exactly as it would without StyleProfile installed.

6. Malaysia: Personal Data Protection Act 2010

Bridzia Sdn Bhd is established in Malaysia, so the Personal Data Protection Act 2010, as amended in 2024, applies to us as data controller for the personal data we hold in our own right. In practice: we process it only for the purposes described here; we keep it accurate, secure and no longer than necessary; we disclose it only as described in section 9 or where the law requires; and we honour access and correction requests within the statutory period.

The 2024 amendments added a breach notification duty and a data protection officer requirement. Where a breach meets the threshold we notify the Commissioner, and the affected individuals where significant harm is likely. PDPA requests go to privacy@styleprofile.io.

7. Your rights under the GDPR

If you are in the UK or the EU you have the right to access your personal data, correct it, erase it, restrict or object to processing, receive it in a portable format, and withdraw consent where processing relies on it. You may also complain to your supervisory authority.

Where we act as processor for a retailer, send your request to that retailer first; if you send it to us, we forward it and help them answer. Where we act as controller, write to privacy@styleprofile.io. We respond within one month, free of charge, and will say so if we need longer.

8. Your rights under the CCPA

If you are a California resident you have the right to know what personal information we hold and why, to request deletion or correction, to opt out of the sale or sharing of personal information, and not to be discriminated against for exercising any of them.

We do not sell or share personal information as those terms are defined by the CCPA, and we have not done so in the preceding twelve months. We do not use shopper photographs for cross-context behavioural advertising. To exercise a right, write to privacy@styleprofile.io. We verify identity in proportion to the sensitivity of the request before acting.

9. Who we share data with

We share personal data with a small set of service providers, each engaged under a written data processing agreement that limits them to our instructions and requires appropriate security: cloud hosting and storage, model inference infrastructure, payment processing, transactional email, error monitoring and product analytics.

The current sub-processor list, with locations, is in our security documentation and available on request. We may also disclose data where the law requires it or to defend a legal claim, telling the affected party where we are permitted to. If the business is ever sold or restructured, personal data may transfer with it, subject to this policy.

We never sell personal data, and we do not use one retailer’s catalogue or renders to serve another retailer.

10. International transfers

We are based in Malaysia and our retailers and their shoppers may be anywhere, so personal data crosses borders. Where data leaves the UK or the EEA we rely on the UK International Data Transfer Addendum or the European Commission’s Standard Contractual Clauses, with supplementary technical measures: encryption in transit and at rest, strict access control, and minimising what is transferred at all. Where data leaves Malaysia we take reasonable steps to satisfy ourselves it will receive a comparable standard of protection.

11. How long we keep things

We keep personal data only as long as the purpose or the law requires. In summary:

Retention at a glance

Shopper photographs
The render session only, then deleted. Sooner on request from the shopper or retailer.
Generated renders
Life of the retailer’s account, then deleted when the account closes.
Account and contact data
Life of the contract, then up to 24 months, unless the law or a dispute requires longer.
Billing records
Seven years, per Malaysian accounting and tax record-keeping requirements.
Usage analytics
Identifiable events for 14 months. Aggregated, de-identified counts may be kept.
Support messages
24 months from the last message in the thread.

12. Security

Data is encrypted in transit using TLS and at rest on our infrastructure. Internal access follows least privilege, is limited to people who need it to run the service, and is logged. We review providers, patch regularly and separate production from development.

No system is perfectly secure, and we will not pretend otherwise. If a breach affects your personal data and is likely to put your rights at risk, we notify you and the relevant authority within the periods the law sets.

13. Children

StyleProfile is a business tool sold to retailers, and the try-on widget is not directed at children. We do not knowingly collect a photograph or other personal data from anyone below the applicable digital-consent age in their jurisdiction, typically 13 to 16 across the UK and EU and higher where local law sets a higher bar for imagery of this kind. If we learn we hold such data we delete it. If you believe a child has uploaded a photograph, write to privacy@styleprofile.io.

14. Changes to this policy

We update this policy when the product or the law changes, and post the revised version here with a new “last updated” date. Where a change materially affects how we handle personal data we notify account holders by email before it takes effect, and where it requires consent we ask rather than assume.

15. Contact us

For privacy questions, requests and complaints: privacy@styleprofile.io. For anything else: hello@styleprofile.io.

Bridzia Sdn Bhd, registration 201201018441 (1003954V), Kuala Lumpur, Malaysia.