styleprofile. — home

Security & trust

Built for enterprise-grade trust

Try-on runs on shopper photos, and that is a serious responsibility. This page is the plain-English version of how we handle them: what happens to an image, what never happens to it, and what you can ask us to put in writing before you sign anything.

No certification badges on this page. We publish practices we can evidence, and nothing else.

An archive room: a wall of pale wood flat-file drawers, one slightly open showing neatly stacked cream folders, with a small brass key in the lock.
Kept, catalogued, and handed back on request.

Shopper images

How shopper images are handled

A photo of someone’s body is close to the most sensitive thing a retail tool can hold. These four commitments are product behaviour, not aspiration.

  • 01

    Processed to render, nothing else

    Not scanned for advertising signals, not enriched against other datasets, not handed to anyone outside the render pipeline.

  • 02

    Never training data without explicit consent

    Not by default, ever. Silence is not consent, and a pre-ticked box buried in a checkout flow is not consent either.

  • 03

    Deletion on request and on offboarding

    A shopper asks, we delete. When a retailer leaves, their shoppers’ images go with the account. Nothing is quietly retained.

  • 04

    Encrypted in transit and at rest

    TLS on the way in, encrypted at rest on our infrastructure. Access is limited to the people who run the service, and logged.

Retailer data

Your side of the account

What happens to the catalogue you connect and the numbers the widget produces.

  • Your catalogue stays yours

    We render from it for your store. We do not resell it, republish it, or use one retailer’s catalogue to serve another.

  • Render analytics are aggregated

    You see your own store’s numbers. Anything we look at across the platform is aggregated and stripped of identifiers first.

  • We do not sell data, full stop

    No brokerage, no advertising partnerships, no side business in “anonymised insights”. Our revenue is the published subscription fees.

Plainly stated

No badges we haven’t earned

This page describes practices we can evidence today. When something changes, the ledger below changes with it.

Compliance posture

Where we stand today

Written as it is, not as it will be. When something changes, this ledger changes with it.

GDPR
GDPR-aligned processing for EU shoppers. Retailers are the controller for their shoppers’ data and we act as processor under a data processing agreement, with sub-processors held to the same terms.
PDPA (Malaysia)
The Personal Data Protection Act 2010, as amended in 2024, applies to us directly. Bridzia Sdn Bhd is the data controller for the data we hold in our own right, including retailer account and contact data.
CCPA
CCPA-aware for California shoppers: the right to know, the right to delete, and the right to opt out of the sale of personal information. There is nothing to opt out of, because we do not sell data.
Documentation
Security documentation available on request. We answer vendor security questionnaires, and we will tell you what is in place today rather than what is on a roadmap.

We do not claim a certification we have not completed. If a certificate matters to your procurement process, ask us and you will get a straight answer about status.

Questions we expect

The four we get asked first

Usually by a security reviewer, occasionally by a shopper who read the widget copy carefully.

On secure cloud infrastructure, encrypted at rest, in a limited set of regions. The specific providers, regions and retention windows are set out in our security documentation rather than on a marketing page, because those details change and a stale page would be worse than no page at all.

Vendor review

Request our security documentation

Data flows, sub-processors, retention windows, encryption, incident handling and the DPA. Sent as a document you can forward to your security team.

We will also complete your own questionnaire rather than insisting on our format. If the honest answer to a line is “not yet”, that is what the answer will say.

Data residency, sub-processor list, a questionnaire in your own template, a DPA to review. Say so and we will answer it directly.

Sent within one business day. No sales sequence attached to this request.

Next step

Bring your security questions to the walkthrough

Thirty minutes with the people who built the pipeline. Bring the questionnaire, the data-residency question, or the awkward one about model training.

Cancel anytime · No long-term contract