GDPR · LOPDGDD
Privacy Policy
Last updated: 12 August 2026
Privacy Policy
Last updated: 2026-08-02
Runway Ready AI SL ("RunwayReady", "we", "us") is the data controller for personal data processed through our mobile application and website https://runwayready.ai (the "Services").
Legal texts are maintained in our systems and published as a durable snapshot (cloud storage + API); they are not loaded at runtime from an external legal-document vendor.
1. Controller identity
- Legal name: Runway Ready AI SL
- Tax ID (CIF/NIF): B27598499
- VAT: ESB27598499
- Address: Calle Faraday 7, Parque Científico de Madrid, 28049 Madrid, Comunidad de Madrid, Spain
- Contact: contact@runwayready.ai
- Data protection contact: contact@runwayready.ai (we have not appointed a formal Data Protection Officer; this is the privacy channel).
2. Data we collect
- Account: name, email, Firebase UID, profile photo, locale.
- Images & wardrobe content: clothing photos, outfits, profile and try-on images you upload, stored in Google Cloud Storage (EU region
europe-west1). - Body measurements: measurements you enter or we estimate for sizing (we do not use biometric data for identification).
- Usage data: app interactions, technical logs, device identifiers, push tokens.
- Diagnostic logs (
diagnosticLogs): crash/error logs and technical metadata (e.g. via Sentry) only if you opt in to diagnostic consent; default is off. - GeoIP / approximate location: country or region inferred from IP for security, compliance, and service localization (not precise GPS).
- Website leads (waitlist / contact / newsletter): name, email, and message you submit on marketing-site forms; waitlist covers transactional confirmation of your request; newsletter is separate explicit commercial consent.
- Light social features: minimum data for friends / wishlists you choose to share (identifiers and visible items per feature).
- Payments: processed by Stripe; we never store full card numbers.
- Marketplace: listings, orders, support messages for peer-to-peer sales.
- Legal consent records: document version, timestamp, bundle hash (GDPR audit trail).
3. Purposes & legal bases (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Provide the service (account, wardrobe, outfits, product AI) | Contract performance |
| AI image processing (detection, flat-lay, try-on) — under contract; US processors with SCCs | Contract performance |
| Marketplace & shipping | Contract performance |
| Security, fraud, GeoIP, legal compliance | Legitimate interest / legal obligation |
| Support and incident review (including wardrobe images) | Contract performance / legitimate interest |
| Waitlist / contact forms (respond to your request) | Pre-contractual steps / legitimate interest |
| Newsletter and commercial email | Consent (explicit opt-in) |
| Non-essential analytics (app / web) | Separate consent (cookies/SDKs); not inferred from legal-document acceptance |
| Marketing / ad pixels (e.g. Meta, TikTok when configured) | Marketing consent (separate from analytics) |
Diagnostic logs (diagnosticLogs / Sentry) | Consent (opt-in; default off) |
| Transactional push (FCM: orders, security, account) | Contract performance / legitimate interest |
| Promotional push / offers | Marketing consent |
4. Who may access your data
In addition to the processors listed below, authorized personnel of RunwayReady (administrators and support staff on a need-to-know basis) may access your account details and wardrobe images to provide customer support, debug incidents, prevent fraud or abuse, and meet legal obligations. Access is limited to what is necessary and protected by authentication and role controls.
5. AI & processors
Product AI features (detection, flat-lay, try-on, suggestions) are provided as part of the service contract. Your images and prompts may be sent to processors, including some in the US under Standard Contractual Clauses:
- Google Cloud / Vertex AI (Gemini) — vision, text, image generation; EU region where available.
- fal.ai — image generation and LLM failover; may involve transfer to the US under SCCs.
- OpenRouter — optional chat/suggestion model routing (may involve US transfer).
- Stripe — payments.
- Shippo — marketplace shipping labels, rates, and tracking (minimum delivery data).
- Google Firebase — authentication, FCM, and technical operation.
- Sentry — error monitoring only when
diagnosticLogsis consented.
Third-party SLAs and legal documents: see the Service Level Agreement (vendors section) and fal.ai/legal, Stripe SSA, GCP SLAs, Shippo Terms.
AI outputs (e.g. flat-lays, try-on renders) may be synthetic and not perfectly accurate. They are not professional advice.
6. Retention
We retain data while your account is active. After a deletion request, we erase or anonymize per the schedule below (proposed / counsel-pending periods):
| Category | Retention (draft) |
|---|---|
| Account & identity | While account active; erasure is immediate on deletion request (only minimal tombstones and legal-hold records persist per this schedule) |
| Wardrobe / try-on images | While account active; erased immediately with the account (except applicable legal holds) |
| Legal consent records | Up to 6 years (accountability / audit) |
| Payment data (Stripe) | Per Stripe + tax rules (typically up to 6–10 years for invoicing) |
| Support / moderation records | Up to 3 years after incident close, unless litigation |
| Analytics (if consented) | Per provider policy; collection stops within ≤24h of consent withdrawal |
7. International transfers
Where processors operate outside the EEA (e.g. fal.ai in the US), we use appropriate safeguards including EU Standard Contractual Clauses.
8. Your rights
You may access, rectify, erase, restrict, port, or object to processing, and withdraw consent via contact@runwayready.ai or in-app data export and account deletion (Privacy settings).
Rights SLA (draft, counsel-pending): we acknowledge within 5 business days and complete within 30 days (GDPR Art. 12). Analytics/cookies/marketing/diagnosticLogs consent withdrawal takes effect ASAP / within 24 hours of API success. Personal-data breach notify AEPD when required: 72 hours of awareness.
You may request human review where automated decisions have significant legal effects.
9. Children
Services are not directed at children under 14 (minimum age aligned with Spanish LOPDGDD / in-app signup gate). We do not knowingly collect data from children below that age.
10. Supervisory authority
You may lodge a complaint with the Spanish Data Protection Agency (AEPD): https://www.aepd.es.