GDPR · LOPDGDD
Privacy Policy
Last updated: August 27, 2026
Privacy Policy
Last updated: 2026-08-27
Runway Ready AI SL ("RunwayReady", "we", "us") is the data controller for personal data processed through our mobile application and website https://runwayready.ai (the "Services").
Legal texts are maintained in our systems and published as a durable snapshot (cloud storage + API); they are not loaded at runtime from an external legal-document vendor.
1. Controller identity
- Legal name: Runway Ready AI SL
- Tax ID (CIF/NIF): B27598499
- VAT: ESB27598499
- Address: Calle Faraday 7, Parque Científico de Madrid, 28049 Madrid, Comunidad de Madrid, Spain
- Contact: contact@runwayready.ai
- Data protection contact: contact@runwayready.ai (we have not appointed a formal Data Protection Officer; this is the privacy channel).
2. Data we collect
- Account: name, email, Firebase UID, profile photo, locale.
- Images & wardrobe content: clothing photos, outfits, profile and try-on images you upload, stored in Google Cloud Storage (EU region
europe-west1). - Body measurements: measurements you enter or we estimate for sizing (we do not use biometric data for identification).
- Usage data: app interactions, technical logs, device identifiers, push tokens.
- Diagnostic logs (
diagnosticLogs): crash/error logs and technical metadata (e.g. via Sentry) only if you opt in to diagnostic consent; default is off. - GeoIP / approximate location: country or region inferred from IP for security, compliance, and service localization (not precise GPS).
- Website leads (waitlist / contact / newsletter): name, email, and message you submit on marketing-site forms; waitlist covers transactional confirmation of your request; newsletter is separate explicit commercial consent.
- Light social features: minimum data for friends / wishlists you choose to share (identifiers and visible items per feature).
- Payments: processed by Stripe; we never store full card numbers.
- Marketplace: listings, orders, support messages for peer-to-peer sales.
- Legal consent records: document version, timestamp, bundle hash (GDPR audit trail).
3. Purposes & legal bases (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Provide the service (account, wardrobe, outfits, product AI) | Contract performance |
| AI image processing (detection, flat-lay, try-on) — under contract; US processors with SCCs | Contract performance |
| Marketplace & shipping | Contract performance |
| Security, fraud, GeoIP, legal compliance | Legitimate interest / legal obligation |
| Support and incident review (including wardrobe images) | Contract performance / legitimate interest |
| Waitlist / contact forms (respond to your request) | Pre-contractual steps / legitimate interest |
| Newsletter and commercial email | Consent (explicit opt-in) |
| Non-essential analytics (app / web) | Separate consent (cookies/SDKs); not inferred from legal-document acceptance |
| Marketing / ad pixels (e.g. Meta, TikTok when configured) | Marketing consent (separate from analytics) |
Diagnostic logs (diagnosticLogs / Sentry) | Consent (opt-in; default off) |
| Transactional push (FCM: orders, security, account) | Contract performance / legitimate interest |
| Promotional push / offers | Marketing consent |
4. Who may access your data
In addition to the processors listed below, authorized personnel of RunwayReady (administrators and support staff on a need-to-know basis) may access your account details and wardrobe images to provide customer support, debug incidents, prevent fraud or abuse, and meet legal obligations. Access is limited to what is necessary and protected by authentication and role controls.
5. AI & processors
Product AI features (detection, flat-lay, try-on, suggestions) are provided as part of the service contract. Your images and prompts may be sent to processors, including some in the US under Standard Contractual Clauses:
- Google Cloud / Vertex AI (Gemini) — vision, text, image generation; EU region where available.
- fal.ai — image generation and LLM failover; may involve transfer to the US under SCCs.
- OpenRouter — optional chat/suggestion model routing (may involve US transfer).
- Stripe — payments.
- Shippo — marketplace shipping labels, rates, and tracking (minimum delivery data).
- Google Firebase — authentication, FCM, and technical operation.
- Apple — StoreKit / App Store billing (iOS), ATT.
- Google Play — Android billing.
- Brevo — transactional email (not SendGrid).
- Sentry — error monitoring only when
diagnosticLogsis consented. - Meta — pixels / Custom Audiences off unless marketing consent and ATT.
Third-party SLAs and legal documents: see the Service Level Agreement (vendors section) and fal.ai/legal, Stripe SSA, GCP SLAs, Shippo Terms.
AI outputs (e.g. flat-lays, try-on renders) may be synthetic and not perfectly accurate. They are not professional advice.
Third-party providers (SLA / official documents)
Third-party uptime commitments are as published by each vendor; may be plan- or enterprise-gated. Counsel-pending.
| Provider | Published SLA (summary) | Online documents |
|---|---|---|
| fal.ai (Features & Labels, Inc.) Generative image APIs + LLM failover (`fal-ai/any-llm`) | Enterprise / Serverless marketed uptime ~99.99%; public ToS has no end-user consumer SLA. DPA/SCC countersignature pending (ENG-05 / CF-04). | Legal center · Terms of Service · Privacy Policy · Acceptable Use Policy · Trust center · Status · Enterprise · Status |
| Shippo Marketplace shipping labels, rates, tracking, optional insurance | Shippo publishes ~99.9% uptime SLA (plan-dependent; Premier/API plans advertise 99.9%). Carrier transit times are outside Shippo API SLA. | Terms of Use · Privacy Policy · Insurance Terms of Service · Privacy hub · API docs · Status · Status |
| Stripe Subscriptions, marketplace payments, Stripe Connect payouts | Availability and remedies under Stripe Services Agreement; no separate public uptime % for all products. Refunds/chargebacks per network + SSA. | Services Agreement (SSA) · SSA overview · Data Processing Agreement · Privacy Center · Status · Status |
| Google Cloud / Vertex AI Primary LLM / vision (Gemini); GCS storage | Vertex AI Platform SLA (Monthly Uptime % / financial credits per Google Cloud SLA pages). Generative features may have separate Gemini SLA docs. | GCP SLA index · Vertex AI Platform SLA · Gemini generative AI SLA · Cloud Data Processing Addendum · Status · Status |
| Google Firebase Authentication, app config, hosting (marketing), messaging | Firebase services under GCP Terms / Firebase ToS; Cloud Storage for Firebase and related products inherit applicable GCP SLAs where listed. | Firebase Terms of Service · Privacy & Security · Cloud Data Processing Addendum · Status · Status |
| OpenRouter Optional chat/suggestion model routing | No public uptime SLA found; monitor status.openrouter.ai. Provider-specific data retention / training policies apply per route. | Terms of Service · Privacy Policy · Provider logging / retention · Status · Status |
| Sentry Error monitoring (when DSN configured; production) | SaaS availability per Sentry subscription plan / MSA; not a consumer-facing product SLA. | Terms of Service · Privacy Policy · DPA · Status · Status |
| Apple App Store / StoreKit billing (iOS), ATT, privacy nutrition labels | App Store / StoreKit availability per Apple Developer / media services terms. ATT governs tracking; NSPrivacyTracking=false holds only while app emails are not synced to Meta Custom Audiences. | Privacy Policy · App Store Review Guidelines · User Privacy and Data Use (ATT) · Licensed Application End User License Agreement |
| Google Play Play billing (Android), Data Safety form | Play distribution and billing under Google Play Developer / Payments terms. Data Safety disclosures must match in-app privacy text. | Google Play Terms of Service · Developer Distribution Agreement · Payments / billing |
| Brevo Transactional email (verification, password reset, welcome). Live ESP — not SendGrid. | Transactional email under Brevo terms / DPA; no consumer-facing uptime SLA. Deliverability depends on domain authentication (SPF/DKIM/DMARC). | Terms of Use · Privacy Policy · Data Processing Agreement · Status · Status |
| Meta Custom Audiences / marketing pixels — gated on ATT + marketing consent; not enabled for tracking while NSPrivacyTracking=false | Marketing measurement only when configured and marketing consent (and iOS ATT, if tracking) is granted. Sync of app emails to Custom Audiences must stay gated or Apple tracking answers flip to Yes. | Privacy Policy · Business Tools Terms · Custom Audiences terms |
6. Retention
We retain data while your account is active. After a deletion request, we erase or anonymize per the schedule below (proposed / counsel-pending periods):
| Category | Retention (draft) |
|---|---|
| Account & identity | While account active; erasure is immediate on deletion request (only minimal tombstones and legal-hold records persist per this schedule) |
| Wardrobe / try-on images | While account active; erased immediately with the account (except applicable legal holds) |
| Legal consent records | Up to 6 years (accountability / audit) |
| Payment data (Stripe) | Per Stripe + tax rules (typically up to 6–10 years for invoicing) |
| Support / moderation records | Up to 3 years after incident close, unless litigation |
| Analytics (if consented) | Per provider policy; collection stops within ≤24h of consent withdrawal |
7. International transfers
Where processors operate outside the EEA (e.g. fal.ai in the US), we use appropriate safeguards including EU Standard Contractual Clauses.
8. Your rights
You may access, rectify, erase, restrict, port, or object to processing, and withdraw consent via contact@runwayready.ai or in-app data export and account deletion (Privacy settings).
Rights SLA (draft, counsel-pending): we acknowledge within 5 business days and complete within 30 days (GDPR Art. 12). Analytics/cookies/marketing/diagnosticLogs consent withdrawal takes effect ASAP / within 24 hours of API success. Personal-data breach notify AEPD when required: 72 hours of awareness.
You may request human review where automated decisions have significant legal effects.
9. Children
Services are not directed at children under 14 (minimum age aligned with Spanish LOPDGDD / in-app signup gate). We do not knowingly collect data from children below that age.
10. Supervisory authority
You may lodge a complaint with the Spanish Data Protection Agency (AEPD): https://www.aepd.es.
United Kingdom addendum (UK GDPR / PECR / DPA 2018)
Sources read 2026-08-27. Not legal advice. The in-app language pack is en for en-GB as well as en-US.
If UK GDPR applies, the Information Commissioner’s Office (ICO) is the UK supervisory authority: ico.org.uk. PECR governs cookies, electronic marketing, and similar technologies in the UK (consent for non-essential storage/access, separate from document-acceptance).
Restricted transfers from the UK (e.g. to the US — fal.ai, Stripe, OpenRouter) require adequacy, an exception, or appropriate safeguards such as the ICO International Data Transfer Agreement (IDTA) or the UK Addendum to EU SCCs, plus a transfer risk assessment / data-protection test so protection is not materially lower than in the UK.
Counsel-open: countersigned IDTA/UK Addendum with fal.ai and other US processors is not complete (CF-04 / ENG-05).
California / US addendum (CCPA / CPRA)
Sources read 2026-08-27. Not legal advice. Other US state privacy laws (CPA, CTDPA, etc.) may also apply — counsel-open patchwork.
We act as a business under the CCPA (Cal. Civ. Code 1798.100 et seq., as amended by the CPRA) when we meet applicable thresholds and process personal information of California residents.
Categories we may collect: identifiers (name, email, Firebase UID); commercial information (purchases, credits); internet / app activity; approximate geolocation (IP); inferences (style preferences); photos you upload (wardrobe / try-on). We do not use biometric identifiers for identity recognition. Payments: Stripe processes card data; we do not store full PANs.
Sale / share. We do not sell personal information for money. We do not share personal information for cross-context behavioural advertising unless you grant separate marketing consent (and, on iOS, ATT if tracking is ever enabled). Meta Custom Audiences sync of app emails is gated off while NSPrivacyTracking=false.
To opt out of any sale or share, email contact@runwayready.ai with subject “Do Not Sell or Share My Personal Information”, or use in-app Privacy settings. We honour browser opt-out preference signals (e.g. Global Privacy Control) on web surfaces we control when implemented.
California rights: know / access, delete, correct, opt out of sale/share, limit use of sensitive personal information (we do not use SPI for inferring characteristics beyond what you provide for sizing), and non-discrimination. We verify requests reasonably. We do not “sell” children’s data; services are not directed at under-16s (app gate is 14 aligned with Spanish LOPDGDD — US age gates remain counsel-open where state law differs).
Canada addendum (PIPEDA / Quebec Law 25)
Sources read 2026-08-27.
PIPEDA. For commercial activity with Canadians we follow the 10 fair-information principles. Complaints: Office of the Privacy Commissioner of Canada.
Quebec Law 25 (Law 25 / Bill 64). If we process personal information of Quebec residents, additional rules may apply (privacy officer, impact assessment before certain transfers outside Quebec, portability, automated-decision transparency). French-language consumer notices must be available (Charter of the French Language / Bill 96) — use the in-app Français legal documents.
Counsel-open: formal Quebec privacy-officer appointment and transfer PIA are not completed.
Australia addendum (Privacy Act 1988 / APPs / ACL)
Sources read 2026-08-27.
We handle personal information in line with the Australian Privacy Principles when the Privacy Act 1988 (Cth) applies: collect only what is reasonably necessary, notify of collection (APP 5), use/disclose for the primary purpose or with consent (APP 6), take reasonable security steps (APP 11), and give access/correction (APPs 12–13). Complaints: OAIC.
ACL consumer guarantees (Competition and Consumer Act 2010 Sch 2) for services — due care and skill, fitness for purpose — cannot be excluded against a consumer. Digital subscription withdrawal still follows the EU 14-day baseline we apply globally for distance contracts; ACL remedies are additional where they apply.
Counsel-open: whether we meet the APP-entity turnover threshold and NDB scheme on-boarding.
India addendum (DPDP Act 2023)
Sources read 2026-08-27.
When we act as a Data Fiduciary for digital personal data of Data Principals in India, processing is based on consent or a legitimate use under the Act. The consent notice must be understandable independently of other text, describe personal data and purposes item-wise, and explain how to withdraw consent as easily as it was given (DPDP Rules 2025 r. 3).
Grievance Officer channel: contact@runwayready.ai. We aim to respond to grievances within the statutory window (Rules: up to 90 days). You may also complain to the Data Protection Board of India when operational.
Counsel-open: a named Grievance Officer distinct from the public mailbox is not designated.
Primary sources (accessed 2026-08-27): ICO — international transfers / IDTA · PECR · DPA 2018 · Cal. Civ. Code 1798.120 opt-out of sale/share · Cal. Civ. Code 1798.135 methods · CPPA FAQs · OPC — PIPEDA · Quebec Law 25 / CAI · OAIC — Australian Privacy Principles · Privacy Act 1988 (Cth) · DPDP Act 2023 · DPDP Rules 2025 (notice / grievance)