Skip to content

Privacy

Privacy Policy

Effective date:

Fits is a men's outfit-discovery service. You can browse curated outfits, inspect the products in each outfit, compare current retailer offers and follow links to retailer websites. You can optionally sign in with Google to save outfits, and you can contact Fits through the Contact form. Public browsing does not require an account.

Information Fits processes

Google sign-in and account information

If you choose to sign in, Google provides the identity information needed for authentication to Supabase Auth, including your email address and provider identity. Supabase creates account and session identifiers needed to keep you signed in and operate Saved. The Fits application requests no custom Google API scopes and does not use Google sign-in to access Gmail, Drive, Calendar, Contacts or other unrelated Google services. Fits has no public user profiles.

Saved outfits

When you are signed in, Fits stores the relationship between your Supabase account and each outfit you save, together with the time it was saved. Unsave removes that relationship. An archived outfit may be hidden from Saved while its relationship is retained, so it can reappear if the outfit is published again.

Contact messages

If you use Contact, Fits stores the name, email address, subject and message you submit in its Supabase database, together with operational information such as a message identifier, status and timestamps. Authorized Fits administrators use this information to review and respond to messages.

Technical and session information

Supabase authentication uses first-party session and authentication-flow cookies to sign you in and refresh your session. When an anonymous visitor starts Google sign-in from a Save action, Fits uses a short-lived, first-party pending-Save cookie to remember the selected outfit and a safe return path. It expires after no more than 30 minutes and is cleared when the flow completes, is dismissed or you log out. Fits and its service providers also process standard request information, such as an IP address, browser information and timestamps, as needed to deliver and secure the service. For Contact abuse prevention, Fits may temporarily derive a transformed, process-local value from a request IP; the application does not store that raw IP in the Contact message.

Optional analytics

Production analytics may remain disabled. If PostHog is enabled, Fits sends only deliberately allowlisted event names and validated public page paths, together with pseudonymous browser, device and session identifiers needed by the analytics SDK. Fits does not intentionally send Contact content, Google profile data, Supabase user IDs, authentication tokens, retailer URLs, query strings or arbitrary form contents. Fits does not identify signed-in users in PostHog or create person profiles. Autocapture, automatic form capture and session replay are disabled. When enabled, the PostHog SDK uses browser local storage for pseudonymous analytics state.

How Fits uses information

Fits uses this information to provide and secure the service: to authenticate users, maintain sessions, save or unsave outfits, display Saved, receive and respond to Contact messages, prevent abuse and, only when enabled, understand limited use of public product features. Retailer offers are editorial information; Fits does not operate a cart or checkout.

Service providers

  • Supabase provides the database, authentication and private editorial image storage.
  • Vercel hosts and runs the application.
  • Google is used solely as the V1 authentication provider.
  • If Contact email notifications are enabled, Fits sends the submitted name, email address, subject and message to Resend so the Fits administrator can be notified. The Supabase database remains the source of truth for the message. The email is an operational notification, and a notification failure does not remove the stored submission.
  • If analytics is enabled, PostHog processes only the restricted analytics information described above.

Retailer websites

Fits links to third-party retailer websites. When you follow one of those links, your browser connects directly to that retailer. The retailer's own privacy policy and practices apply once you leave Fits.

Retention and choices

Fits retains account, Saved and Contact information as needed to operate, secure and administer the service and handle messages. No fixed retention period is promised here. You can remove an outfit from Saved by using Unsave. Fits V1 does not provide an in-app account-deletion control.

To ask about, correct or request deletion of personal information associated with you, use the Contact page. Fits may need to verify a request before acting on it. Do not include passwords or authentication tokens in your message.

Security

Fits uses measures such as server-side validation, authenticated sessions, database row-level access controls and private storage authorization. No service can guarantee absolute security, so avoid sending information through Contact that is not needed for your request.

Changes to this policy

Fits may update this notice as the service or its providers change. A revised policy will be published here with an updated effective date.

Privacy requests

For privacy questions or requests, use the Contact page. This notice is an operational draft based on the current Fits V1 implementation and should be reviewed by the service owner and qualified legal counsel before production launch.

Save outfits with Fits

Continue with Google to save outfits and find them again later.