Effective date: May 1, 2024
Last updated: May 20, 2026Garde-Robe ("Garde-Robe", "us", "we", or "our") operates the https://www.garde-robe.com website, the Garde-Robe mobile application, and the Garde-Robe Shopify checkout widget (collectively, the "Service").
This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use our Service and the choices you have associated with that data.
We use your data to provide and improve the Service in accordance with this Privacy Policy ("Policy"). By using the Service, you agree to the collection and use of information in accordance with this Policy. Unless otherwise defined in this Policy, terms used in this Policy have the same meanings as in our Terms and Conditions.
Service
Service means the https://www.garde-robe.com website, the Garde-Robe mobile application, and the Garde-Robe Shopify checkout widget, all operated by Garde-Robe.
Shopify Merchant
Shopify Merchant means any business that has installed the Garde-Robe Widget on their Shopify store.
Shopper
Shopper means any individual who interacts with the Garde-Robe Widget at the checkout of a Shopify Merchant's store.
Personal Data
Personal Data means data about a living individual who can be identified from that data (or from that and other information either in our possession or likely to come into our possession).
Usage Data
Usage Data is data collected automatically either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
Cookies
Cookies are small pieces of data stored on your device (computer or mobile device).
Data Controller
Data Controller means the natural or legal person who (either alone or jointly or in common with other persons) determines the purposes for which and the manner in which any Personal Data are, or are to be, processed. For the purpose of this Policy, we are a Data Controller of your Personal Data. We may use the services of various Service Providers in order to process your data more effectively.
Data Subject (or User) Data Subject or User is any living individual who is using our Service and is the subject of Personal Data.
We collect several different types of information for various purposes to provide and improve our Service to you.
Types of Data CollectedPersonal Data
While using our Service, we may ask you to provide us with certain personal information that may be used to contact or identify you ("Personal Data"). Personal Data may include, but is not limited to:
Registration and Profile
To register for the Service and create a Garde-Robe account ("Account"), we collect certain personal information that you provide to us, such as your first and last name, email address, gender, and birthday.
Login Credentials
When registering for our Service, you may use your email login credentials to link your email accounts with your Garde-Robe Account. You may also use your email login credentials to link your Account with certain online retailers, service providers, or other merchant accounts.When a user connects an email account, Garde-Robe may access receipt emails, order confirmations, merchant information, purchase metadata, and related information necessary to provide purchase synchronization functionality.Users may disconnect linked email accounts at any time through account settings or applicable third-party account permissions (such as Google Account permissions). Once disconnected, Garde-Robe will stop accessing new email data associated with that account.Previously imported purchases may remain in the user’s wardrobe until deleted by the user or removed pursuant to our retention policies.
User Content
When you use the Service, you may create, upload, publish, display, link to or otherwise make available content or other information on the Service, such as image collections of Purchases and comments regarding your Purchases (collectively, "User Content"). Your User Content becomes public information once you post it in a public area of the Service, may be accessed by us or other Users, and we may store such information.
Data Collected Through the Garde-Robe Shopify Widget
When a Shopify Merchant installs the Widget, we collect the following through Shopify's APIs:
- Shop domain (e.g. your-store.myshopify.com) — to identify and authenticate the merchant's store
- Shopify access token — to make authorised API calls on the merchant's behalf
- Store owner email — for account communications and support
- Order data (line items, prices, product IDs) — to save wardrobe entries when Shoppers opt in
- Customer email address (hashed using SHA-256 — never stored in raw form) — to link wardrobe entries to Shoppers without storing raw email addresses. Hashed identifiers may still be treated as personal data under applicable privacy laws and are protected accordingly.
- Product metadata (title, variant, image URL) — to display items in the Garde-Robe wardrobe
- Merchant brand colour settings — to style the Widget to match the merchant's storeWhen a Shopper interacts with the Widget at a merchant's checkout, we collect:
- Opt-in consent flag (whether the Shopper ticked the Garde-Robe checkbox at checkout)
- Purchased items (product title, variant, image URL, price, quantity)
- Opt-in timestamp
- Shopify order ID (to prevent duplicate saves)
- Hashed email address (SHA-256 one-way hash — we never store the raw email address of Shoppers who have not created a Garde-Robe account)We do not collect payment card details, billing addresses, or financial information from Shoppers. We do not drop cookies on merchant storefronts.
We do not use tracking pixels or log browsing behaviour on any merchant's store.
Usage Data
We may also collect information that your browser sends whenever you visit our Service or when you access the Service by or through a mobile device ("Usage Data"). This Usage Data may include information such as your computer's Internet Protocol ("IP") address, browser type, browser version, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data. When you access the Service by or through a mobile device, this Usage Data may include information such as the type of mobile device you use, your mobile device unique ID, the IP address of your mobile device, your mobile operating system, the type of mobile Internet browser you use, unique device identifiers and other diagnostic data.
Tracking & Cookies Data
We use cookies and similar tracking technologies to track the activity on our Service and hold certain information. Cookies are files with a small amount of data which may include an anonymous unique identifier. Cookies are sent to your browser from a website and stored on your device. Tracking technologies also used are beacons, tags, and scripts to collect and track information and to improve and analyze our Service. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service. Where required by law, we obtain consent before placing non-essential cookies.
The Garde-Robe Shopify Widget does not use cookies on merchant storefronts. Cookies described above apply only to the Garde-Robe website and mobile application.
Examples of Cookies we use:
- Session Cookies — We use Session Cookies to operate our Service.
- Preference Cookies — We use Preference Cookies to remember your preferences and various settings.
- Security Cookies — We use Security Cookies for security purposes.
Garde-Robe uses your data for various purposes:
- To provide and maintain our Service, including making recommendations to you or other Users, or to provide you or other Users with customized content
- To save wardrobe entries for Shoppers who opt in at a merchant's checkout
- To provide Shopify Merchants with aggregated opt-in rate and wardrobe data through the merchant dashboard
- To notify you about changes to our Service
- To allow you to participate in interactive features of our Service when you choose to do so
- To provide customer support and other administrative purposes, such as addressing Account issues, investigating fraud or abuse on the Service, and enforcing or applying our Terms of Service and this Policy
- To gather analysis or valuable information so that we can improve our Service
- To monitor the usage of our Service
- To detect, prevent and address technical issues
- To provide you with news, special offers and general information about other goods, services and events which we offer that are similar to those that you have already purchased or enquired about unless you have opted not to receive such information
We do not use your data for targeted advertising or to build profiles for sale to third parties.
Notwithstanding anything else in this Policy, if you choose to connect your Gmail account or another supported email provider to Garde-Robe ("Google User Data" or "Gmail Data"), we may access information contained in purchase receipts, order confirmations, merchant names, item descriptions, prices, purchase dates, and related metadata solely for the purpose of identifying purchases, importing items into your wardrobe, and maintaining synchronization functionality.
We request access only to the Google API scopes necessary to provide receipt synchronization and purchase import functionality.
Access to Gmail-derived data is limited to the minimum information required to provide receipt extraction and wardrobe synchronization features.Google-derived data is used solely to provide purchase synchronization and wardrobe functionality and is not combined with merchant data for advertising, resale, or third-party profiling.
We do not:
- use Gmail Data for advertising or marketing personalization;
- sell Gmail-derived data;use Gmail Data to build profiles for sale to third parties;
- transfer Gmail-derived data to third parties except where necessary to operate the Service, comply with legal obligations, address security issues, or in connection with a merger, acquisition, or asset sale;
- use Google User Data, including Gmail content, to develop, improve, or train generalized artificial intelligence or machine learning models;
- permit humans to read Gmail content except where necessary for security purposes, fraud prevention, debugging, compliance review, or where explicitly authorized by the user.
Service providers that process Google User Data may do so only to support functionality necessary to operate Garde-Robe and are prohibited from using such data for independent purposes.
Garde-Robe’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
If you are from the European Economic Area (EEA), Garde-Robe's legal basis for collecting and using the Personal Data described in this Policy depends on the Personal Data we collect and the specific context in which we collect it.
Garde-Robe may process your Personal Data because:
- We need to perform a contract with you
- You have given us permission to do so — for example, when a Shopper ticks the opt-in checkbox at checkout
- The processing is in our legitimate interests and it's not overridden by your rights
- To comply with the law
Note: In EU, UK, and EEA markets, the Garde-Robe Widget opt-in checkbox is unchecked by default and requires active consent from the Shopper, in compliance with GDPR Article 7(2). Consent practices vary by jurisdiction and are implemented in accordance with applicable law.
Garde-Robe classifies collected data into the following protection levels:
Level 1 – Standard Personal Data
Includes registration and profile information (name, email address, gender, birthday) and basic usage data. This data is protected using industry-standard security controls.
Level 2 – User-Generated Content
Includes images, comments, and purchase collections uploaded by users. Access to this data is restricted to authorized systems and users, and content visibility is controlled by user settings.
Level 3 – Sensitive / Restricted OAuth Data
Includes OAuth access tokens, connected email permissions, receipt metadata, order confirmations, and purchase information obtained through supported email providers including Gmail and other connected email services. This data is classified as sensitive and subject to enhanced protections, including:
- Strict access controls (no general human access)
- Encryption in transit and at restUse limited solely to purchase extraction and synchronization
- No use for advertising or marketing
- No sale or disclosure beyond service operation requirements
- No use for generalized AI or machine learning model training
- Compliance with Google API Services User Data Policy and Limited Use requirements
Level 4 – Shopify Merchant and Shopper Data
Includes Shopify access tokens, shop domains, order data received via Shopify webhooks, and hashed Shopper email addresses. This data is subject to the strictest access controls:Shopify access tokens are stored encrypted and never loggedAccess is restricted to the minimum required to operate the WidgetDeleted within 30 days of merchant uninstall
Garde-Robe implements the following mandatory Shopify compliance webhooks:
- customers/data_request — when a customer requests their data, we compile all wardrobe entries associated with their hashed email and make this available within 30 days.
- customers/redact — when a customer requests deletion of their data, we permanently delete all wardrobe entries associated with their hashed email within 30 days.
- shop/redact — when a merchant uninstalls the Widget, Shopify sends this webhook within 48 hours. We permanently delete all wardrobe entries, opt-in events, and merchant records associated with that store within 30 days.
Garde-Robe retains your Personal Data only for as long as is necessary for the purposes set out in this Policy. We retain and use your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies. Garde-Robe also retains Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period of time, except when this data is used to strengthen the security or to improve the functionality of our Service, or we are legally obligated to retain this data for longer time periods.
Specific retention periods:
- Wardrobe entries: until the customer requests deletion or the merchant uninstalls the Widget
- Shopify merchant access tokens: until the merchant uninstalls the Widget or requests deletion
- Opt-in event logs: 24 months from collection, then deleted
- Operational/error logs: 30 days, then automatically deleted
- Support communications: 3 years from last contact, then deleted
- Gmail-derived receipt metadata and imported purchase records: retained only as long as necessary to provide wardrobe synchronization functionality or until the user disconnects their linked account, deletes their account, or requests deletion.
- OAuth access tokens: deleted upon account disconnection, revocation of permissions, or account deletion, subject to backup retention requirements
Your information, including Personal Data, may be transferred to — and maintained on — computers located outside of your state, province, country or other governmental jurisdiction where the data protection laws may differ than those from your jurisdiction. If you are located outside United States and choose to provide information to us, please note that we transfer the data, including Personal Data, to United States and process it there. Your consent to this Policy followed by your submission of such information represents your agreement to that transfer. We take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Policy. We do not transfer your Personal Data to outside organizations or countries unless there are adequate controls in place including the security of your data and other Personal Data.
Where we transfer personal data of EEA or UK residents to the United States, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission in our agreements with infrastructure providers including Railway and Supabase.
Business Transaction
If Garde-Robe is involved in a merger, acquisition or asset sale, your Personal Data may be transferred. We provide notice before your Personal Data is transferred and becomes subject to a different Privacy Policy.
Disclosure for Law Enforcement
Under certain circumstances, Garde-Robe may be required to disclose your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).
Legal Requirements
Garde-Robe may disclose your Personal Data in the good faith belief that such action is necessary to:
- To comply with a legal obligation
- To protect and defend our rights or property
- To prevent or investigate possible wrongdoing in connection with the Service
- To protect the personal safety of Users of the Service or the public
- To protect against legal liability
Third-Party Service Providers
We share data only with the following service providers, solely to operate the Garde-Robe Service:
- Railway (railway.app) — cloud hosting for our API backend
- Supabase — managed PostgreSQL database for wardrobe and merchant data
- Shopify — the platform through which the Widget operates
- Google Analytics — website and app analytics
All service providers are contractually required to process data only on our behalf and are not authorized to use your data for their own purposes. Service providers receiving Google-derived or OAuth-protected data may process such information only to support functionality necessary to operate Garde-Robe and may not use such information independently, including for advertising, profiling, or model training.
"Do Not Track" Signals Under California Online Privacy Protection Act (CalOPPA)
We do not support Do Not Track ("DNT"). DNT is a preference you can set in your web browser to inform websites that you do not want to be tracked. You can enable or disable Do Not Track by visiting the Preferences or Settings page of your web browser.
Deletion of Connected Account Data
Users may request deletion of Gmail-derived purchase information, disconnect linked email accounts, or request deletion of imported purchase records by contacting hi@garde-robe.com or through available account settings.Upon verified request, Garde-Robe will stop processing newly accessible email data and delete associated information in accordance with applicable legal obligations and retention requirements.
Your Data Protection Rights Under General Data Protection Regulation (GDPR) If you are a resident of the European Economic Area (EEA), you have certain data protection rights. Garde-Robe aims to take reasonable steps to allow you to correct, amend, delete, or limit the use of your Personal Data. If you wish to be informed what Personal Data we hold about you and if you want it to be removed from our systems, please contact us. In certain circumstances, you have the following data protection rights:
- The right to access, update or to delete the information we have on you. Whenever made possible, you can access, update or request deletion of your Personal Data directly within your account settings section. If you are unable to perform these actions yourself, please contact us to assist you.
- The right of rectification — You have the right to have your information rectified if that information is inaccurate or incomplete.
- The right to object — You have the right to object to our processing of your Personal Data.
- The right of restriction — You have the right to request that we restrict the processing of your Personal Data.
- The right to data portability — You have the right to be provided with a copy of the information we have on you in a structured, machine-readable and commonly used format.
- The right to withdraw consent — You also have the right to withdraw your consent at any time where Garde-Robe relied on your consent to process your Personal Data.
Please note that we may ask you to verify your identity before responding to such requests. You have the right to complain to a Data Protection Authority about our collection and use of your Personal Data. For more information, please contact your local data protection authority in the European Economic Area (EEA).
California Privacy Rights (CPRA/CCPA)
If you are a California resident, you have the following additional rights:Right to know what personal information we collect, use, share, or sell in the past 12 monthsRight to delete personal information we have collectedRight to correct inaccurate personal informationRight to opt out of the sale or sharing of personal information — we do not sell personal informationRight to non-discrimination for exercising any of these rightsTo exercise these rights, contact us at hi@garde-robe.com. We will respond within 45 days.
The security of your data is important to us. We implement the following measures to protect your Personal Data:
- All data in transit is encrypted using TLS 1.2 or higher
- Sensitive production data is encrypted at rest using industry-standard measures
- Shopper email addresses are never stored in raw form — we apply a one-way SHA-256 hash
- Shopify access tokens are stored encrypted and never logged
- Access to production data is restricted to authorised personnel onlyWe do not store payment card data under any circumstances
- Google-derived data and OAuth tokens are subject to enhanced access restrictions and monitored access controls designed to minimize exposure.
No method of transmission over the Internet, or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.
We may employ third party companies and individuals to facilitate our Service ("Service Providers"), to provide the Service on our behalf, to perform Service-related services or to assist us in analyzing how our Service is used. These third parties have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.
Analytics
We may use third-party Service Providers to monitor and analyze the use of our Service.
Google Analytics
Google Analytics is a web analytics service offered by Google that tracks and reports website traffic. Google uses the data collected to track and monitor the use of our Service. This data is shared with other Google services. Google may use the collected data to contextualize and personalize the ads of its own advertising network. For more information on the privacy practices of Google, please visit the Google Privacy & Terms web page: https://policies.google.com/privacy?hl=en
Our Service may contain links to other sites that are not operated by us. If you click on a third party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.
The Service is not intended for use by anyone under 12 years of age (or under 16 in the EEA/UK). If you are a parent or guardian of a child from whom you believe we have collected personal information in a manner prohibited by law, please contact us. If we learn that we have collected personal information through the Service from a child without the consent of the child's parent or guardian as required by law, we will comply with applicable legal requirements to delete the information.
We may update our Policy from time to time. We will notify you of any changes by posting the new Policy on this page. We will let you know via email and/or a prominent notice on our Service, prior to the change becoming effective and update the "effective date" at the top of this Policy. For Shopify Merchants, we will provide at least 14 days' notice before material changes take effect. You are advised to review this Policy periodically for any changes. Changes to this Policy are effective when they are posted on this page.
If you have any questions about this Policy, please contact us:
By email: hi@garde-robe.com