Montinz Privacy Policy
Last updated: September 8, 2026
1. Introduction
This policy explains what personal data Montinz collects, why we collect it, who else handles it, how long we keep it, and the rights you have over it. It covers both the Montinz mobile app and this website.
Most of what we do with your data is necessary to provide the service you signed up for — we don't rely on your consent for that, and we say exactly which legal basis applies to each purpose in section 5. Where we do rely on consent, you can withdraw it at any time without losing access to anything else.
2. Who We Are
The data controller responsible for your personal data is Montinz.
Email: team@montinz.co
We are not required to appoint a Data Protection Officer, so data-protection questions go to the address above.
3. Information We Collect
3.1 Information you provide directly
- Account information: email address, name, password (hashed, never stored in plaintext)
- Authentication data: Apple ID or Google account identifier if you use social sign-in
- Clothing photographs and wardrobe data you upload to the App
- Optional profile details you choose to give us, such as date of birth and gender, used to tailor suggestions
3.2 Information collected automatically
- Device information: device type, operating system version, app version
- Usage data: features used, outfit suggestions viewed, accepted, or rejected, session duration
- General location at country level, and local weather for weather-based outfit features
- Crash reports and error logs
We do not store your IP address against your analytics events.
3.3 Information from third parties
- Sign in with Apple: Apple ID, name, email as shared by Apple (subject to Apple's privacy policies)
- Sign in with Google: Google account name and email (subject to Google's privacy policies)
- Subscription status from Apple, Google Play and RevenueCat. We never receive your card details.
- Weather data from third-party APIs (no personal data shared with weather providers)
4. How We Use Your Information
We use your information to:
- Create and manage your account
- Process clothing images and generate outfit suggestions
- Improve the accuracy of the suggestions we make to you
- Send service emails (verification, password reset, service notices)
- Take payment and keep subscription records
- Monitor App performance and fix bugs
- Prevent abuse of the service
- Comply with legal obligations
We do NOT:
- Sell your personal data to third parties
- Use your clothing photographs to train AI models for other users
- Send marketing emails without your explicit consent
- Share identifiable data with advertising networks
- Use any advertising or cross-app tracking SDKs
5. Our Legal Bases
GDPR requires a specific lawful basis for each purpose. Ours are set out below. Where the basis is legitimate interests, you can object under section 10 and we will stop unless we have compelling grounds not to.
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and run your account | Name, email, sign-in identifier, timezone | Performance of a contract — Art. 6(1)(b) |
| Identify each garment you add | The photograph you upload | Performance of a contract — Art. 6(1)(b) |
| Generate outfit suggestions | Garment attributes, occasion, weather for your area | Performance of a contract — Art. 6(1)(b) |
| Make your suggestions better over time | Which outfits you accept, reject, save or wear | Performance of a contract — Art. 6(1)(b) |
| Service emails — verification, password reset, service notices | Email address | Performance of a contract — Art. 6(1)(b) |
| Take payment and keep subscription records | Subscription status, plan, transaction identifiers | Contract — Art. 6(1)(b); tax records: legal obligation — Art. 6(1)(c) |
| Keep the service working — crash reports and error logs | Device type, OS and app version, error details | Legitimate interests — Art. 6(1)(f) |
| Understand which features are used, in the app | Screens viewed and features used, linked to your account | Legitimate interests — Art. 6(1)(f) |
| Prevent abuse — rate limits and access blocks | Request patterns, account status | Legitimate interests — Art. 6(1)(f) |
| Website analytics and live chat | A random website identifier, pages viewed, referring site | Consent — Art. 6(1)(a) |
| Push notifications | Device push token, notification preferences | Consent — Art. 6(1)(a), given via your device and in-app settings |
| Respond to legal requests and defend legal claims | Whatever the request concerns | Legal obligation — Art. 6(1)(c); legitimate interests — Art. 6(1)(f) |
6. How Long We Keep Your Data
We keep personal data only as long as we need it for the purposes above, or as long as the law requires.
| Data | Kept for |
|---|---|
| Account, wardrobe, garment photographs, outfits, worn history | While your account is active, then deleted within 30 days of account deletion |
| Subscription and billing records | 7 years from the end of the subscription, to meet tax record-keeping rules |
| Product analytics events | 24 months from the event |
| Crash reports and error logs | 90 days |
| Support conversations — email and live chat | 24 months from the last message |
| Push notification device tokens | Until you log out on that device, or your account is deleted |
| Database backups | 14 daily backups on a rolling basis, so deletions clear backups within 14 days |
| Website analytics identifier in your browser | 12 months, or until you clear it or withdraw consent |
When you delete your account, your data is removed within 30 days, and clears our rolling backups within 14 days after that. Records we are legally required to keep — principally billing records for tax purposes — are retained for the period in the table and nothing else.
7. Data Storage and Security
Your account, wardrobe and outfit data are stored on servers in Germany. We implement technical and organisational measures including:
- Passwords stored using industry-standard hashing (bcrypt)
- JWT tokens with short expiry windows and refresh token rotation
- HTTPS encryption for all data in transit
- Encrypted, access-controlled backups
- Regular security reviews
No method of transmission or storage is 100% secure. We cannot guarantee absolute security. If a breach affects your data and presents a risk to you, we will notify you and the relevant supervisory authority as required by Articles 33 and 34.
9. International Data Transfers
Your account, wardrobe and outfit data are held in Germany. Some of the providers in section 8 are based in the United States, so data reaching them is transferred outside the EEA and the UK.
For each of those transfers we rely on the European Commission's Standard Contractual Clauses, together with the UK Addendum where UK data is involved, as the Chapter V safeguard. You can ask us for details of the safeguards for any specific provider at team@montinz.co.
10. Your Rights
If you are in the EEA or the UK you have the rights below. They are free to use, and using them never costs you access to the service.
- Access (Art. 15): get a copy of the personal data we hold about you
- Rectification (Art. 16): have inaccurate data corrected
- Erasure (Art. 17): have your account and associated data deleted
- Restriction (Art. 18): ask us to pause processing while a dispute is resolved
- Portability (Art. 20): receive your data in a portable, machine-readable format
- Objection (Art. 21): object to processing based on legitimate interests
- Withdraw consent (Art. 7(3)): withdraw consent at any time, as easily as you gave it
The quickest way to use any of them is the data request form, or email team@montinz.co. We respond within one month, as Article 12(3) requires. You can also delete your account yourself at any time from Profile in the app.
Before sending personal data we may ask you to confirm you control the email address on the account. That check exists to stop someone else obtaining your data by asking for it in your name.
11. Complaints
If you think we have handled your personal data unlawfully, please tell us first at team@montinz.co so we can put it right.
You also have the right under Article 77 to lodge a complaint with a data protection supervisory authority — in the EEA, the authority in the country where you live or work, and in the UK, the Information Commissioner's Office. A list of EEA authorities is published by the European Data Protection Board. You do not need our permission, and you can complain to them without contacting us first.
12. Children's Privacy
Montinz is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13.
If we become aware that we have collected data from a child under 13 without parental consent, we will delete it promptly. If you believe a child has created an account, email team@montinz.co and we will act on it.
13. Apple and Google Sign-In
When you use Sign in with Apple or Sign in with Google, those services share limited information with us. Their handling of your data is governed by Apple's Privacy Policy and Google's Privacy Policy respectively. We use only what they share to create and manage your Montinz account.
14. Cookies, Analytics and Tracking
We use no advertising cookies and no third-party ad or tracking networks. What the website stores on your device falls into three groups:
- Strictly necessary: your light/dark theme choice, and a country lookup used to decide whether to show you the consent notice. These carry no identifier and are never shared.
- Analytics (consent required): our own first-party measurement of which pages and features get used. It stores a random identifier in your browser and records page views, clicks, and the site or campaign that linked you here. It is processed on our own servers, is never sold, and is never shared with advertisers.
- Live chat (consent required): we use tawk.to to provide live chat support. When it loads, tawk.to sets its own cookies and processes what you share in the conversation (such as your name, email, and messages) to operate the support service on our behalf. See the tawk.to privacy policy for details.
If you are in the EEA, the UK, or Switzerland, neither analytics nor live chat runs until you agree to it, and refusing costs you nothing but those two features. You can change or withdraw your choice at any time via Cookie settings in the site footer. Elsewhere, both are active by default and the same link lets you turn them off.
The mobile app records the same kind of usage analytics against your account to understand how features are used. It contains no advertising SDKs and does not track you across other apps or websites.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via in-app notification or email. The “Last updated” date at the top reflects the most recent revision.
16. Contact Us
For privacy-related questions, or to use any of the rights above:
Email: team@montinz.co
Data requests: montinz.co/data-request