Consent & cookies
Cookie Policy
Last updated: August 27, 2026
Cookie Policy
Last updated: 2026-08-27
Runway Ready AI SL uses cookies, localStorage, and similar technologies on https://runwayready.ai. Strictly necessary cookies do not require consent. Analytics and marketing (including Meta/TikTok pixels when configured) load only after your choice in the banner (Accept / Reject / Manage).
Cookie & SDK inventory
| Cookie / SDK | Provider | Purpose | Type | Duration |
|---|---|---|---|---|
| rrai-cookie-consent-v1 (localStorage) | RunwayReady | Stores Accept / Reject / Manage cookie preferences in browser localStorage | Strictly necessary | 12 months |
| Firebase Auth session | Authentication | Strictly necessary | Session / persistent | |
| Firebase Analytics | App analytics | Analytics (consent) | Per Google policy | |
| Google Analytics 4 | Web analytics | Analytics (consent) | Per Google policy | |
| Meta Pixel | Meta | Marketing measurement (only when configured and marketing consent + ATT granted) | Marketing (consent) | Per Meta policy |
| TikTok Pixel | TikTok | Marketing measurement (only when configured and marketing consent granted) | Marketing (consent) | Per TikTok policy |
| Stripe | Stripe | Payment fraud prevention | Functional / necessary | Per Stripe |
| Firebase Cloud Messaging | Push delivery token — transactional by default; promotional push requires marketing consent | Functional / marketing (split) | Until token refresh / logout | |
| Sentry (SDK) | Sentry | Crash / error diagnostics tied to diagnosticLogs opt-in (default off) | Performance (consent) | Per Sentry / session |
Manage and withdraw consent
You can reopen preferences anytime via the cookie-preferences link in the site footer or Settings → Privacy in the app. Withdrawal takes effect ASAP / within 24 hours.
Transactional email uses Brevo (server-side; not a cookie). Meta Pixel is gated on marketing consent and ATT.
Controller: Runway Ready AI SL, CIF B27598499, Calle Faraday 7, Parque Científico de Madrid, 28049 Madrid, Comunidad de Madrid, Spain
Contact: contact@runwayready.ai
United Kingdom addendum (UK GDPR / PECR / DPA 2018)
Sources read 2026-08-27. Not legal advice. The in-app language pack is en for en-GB as well as en-US.
If UK GDPR applies, the Information Commissioner’s Office (ICO) is the UK supervisory authority: ico.org.uk. PECR governs cookies, electronic marketing, and similar technologies in the UK (consent for non-essential storage/access, separate from document-acceptance).
Restricted transfers from the UK (e.g. to the US — fal.ai, Stripe, OpenRouter) require adequacy, an exception, or appropriate safeguards such as the ICO International Data Transfer Agreement (IDTA) or the UK Addendum to EU SCCs, plus a transfer risk assessment / data-protection test so protection is not materially lower than in the UK.
Counsel-open: countersigned IDTA/UK Addendum with fal.ai and other US processors is not complete (CF-04 / ENG-05).
California / US addendum (CCPA / CPRA)
Sources read 2026-08-27. Not legal advice. Other US state privacy laws (CPA, CTDPA, etc.) may also apply — counsel-open patchwork.
We act as a business under the CCPA (Cal. Civ. Code 1798.100 et seq., as amended by the CPRA) when we meet applicable thresholds and process personal information of California residents.
Categories we may collect: identifiers (name, email, Firebase UID); commercial information (purchases, credits); internet / app activity; approximate geolocation (IP); inferences (style preferences); photos you upload (wardrobe / try-on). We do not use biometric identifiers for identity recognition. Payments: Stripe processes card data; we do not store full PANs.
Sale / share. We do not sell personal information for money. We do not share personal information for cross-context behavioural advertising unless you grant separate marketing consent (and, on iOS, ATT if tracking is ever enabled). Meta Custom Audiences sync of app emails is gated off while NSPrivacyTracking=false.
To opt out of any sale or share, email contact@runwayready.ai with subject “Do Not Sell or Share My Personal Information”, or use in-app Privacy settings. We honour browser opt-out preference signals (e.g. Global Privacy Control) on web surfaces we control when implemented.
California rights: know / access, delete, correct, opt out of sale/share, limit use of sensitive personal information (we do not use SPI for inferring characteristics beyond what you provide for sizing), and non-discrimination. We verify requests reasonably. We do not “sell” children’s data; services are not directed at under-16s (app gate is 14 aligned with Spanish LOPDGDD — US age gates remain counsel-open where state law differs).
Primary sources (accessed 2026-08-27): ICO — international transfers / IDTA · PECR · DPA 2018 · Cal. Civ. Code 1798.120 opt-out of sale/share · Cal. Civ. Code 1798.135 methods · CPPA FAQs · OPC — PIPEDA · Quebec Law 25 / CAI · OAIC — Australian Privacy Principles · Privacy Act 1988 (Cth) · DPDP Act 2023 · DPDP Rules 2025 (notice / grievance)