Privacy Policy

Last updated: 1 May 2026

We are committed to protecting your privacy. This policy explains what personal data we collect, why we collect it, and how we keep it safe. Written in plain English, no legal jargon.

1

Who We Are

Dripscan is a UK-based online marketplace connecting independent fashion and beauty brands with customers across the United Kingdom and beyond. As the data controller, we are responsible for the personal data you share with us. For any privacy-related questions, email [email protected].

2

What Data We Collect

We collect the following categories of data when you use Dripscan:

  • Account data: your name, email address, and a secure password hash when you register.
  • Order data: delivery address, order history, and payment method. Card details are handled entirely by Stripe and are never stored on our servers.
  • Vendor data: business name, contact details, banking or PayPal details for payouts, and any brand imagery or biographical content you choose to publish. See “If You Are a Vendor on Dripscan” below.
  • Visual search data: photos you upload to our Scan That Drip feature at /scan. See “AI-Powered Features and Visual Search” below.
  • Usage data: pages visited, search queries, and clicks, collected via anonymised analytics.
  • Communications: emails and messages you send to our support team, plus messages you exchange with vendors via our order-scoped messaging system.
  • Cookie data: session identifiers, functional preferences, and (with your consent) analytics and marketing identifiers. See our Cookie Policy for full details.
3

Why We Use Your Data

We process your data under the following legal bases as defined by UK GDPR:

  • Contract: to process and fulfil your orders, manage your account, and handle returns.
  • Legitimate interests: to prevent fraud, improve our platform, and send transactional emails such as order confirmations and shipping updates.
  • Consent: to send marketing emails and newsletters. You can withdraw consent at any time by clicking Unsubscribe or emailing [email protected].
  • Legal obligation: to retain financial records for HMRC purposes for up to 7 years.
4

Who We Share Your Data With

We share only the data necessary with the following service providers, each acting as a data processor under UK GDPR. We have signed Data Processing Agreements with each one. Where data is transferred outside the UK we rely on Standard Contractual Clauses or adequacy decisions recognised under UK GDPR.

Named partners:

  • Stripe Payments UK Ltd (UK / Ireland) — payment processing for orders and vendor subscription billing, plus vendor payouts via Stripe Connect.
  • PayPal (Europe) S.à r.l. et Cie, S.C.A. (Luxembourg) — optional payment processing and vendor payouts via PayPal Payouts.
  • Klaviyo Inc. (United States, with SCCs) — marketing email automation, only for users who have opted in or who qualify under the soft-opt-in rule for previous customers (UK PECR Regulation 22).
  • OpenRouter (United States, with SCCs) — routing of vision-search requests to AI inference providers for our Scan That Drip feature. See “AI-Powered Features and Visual Search” below for full detail.
  • Google Analytics, operated by Google LLC (United States, with SCCs) — anonymised site analytics, only when you have given consent via our cookie banner.
  • Meta Platforms Ireland Limited (Ireland) — measurement of marketing campaign effectiveness via the Meta Pixel and Conversions API, only when you have given consent.
  • PostHog Inc. (United States, with SCCs) — product analytics to understand how our marketplace is used, only when you have given consent via our cookie banner. We use it in identified-only mode so anonymous traffic is not profiled.

Infrastructure providers:

We also rely on the following categories of infrastructure providers (specific named suppliers available on request via [email protected]):

  • A hosted database provider (United States, with SCCs) — secure storage of account, vendor, and order data.
  • A website hosting and edge-delivery provider (United States, with SCCs) — serving the dripscan.com website to your browser.
  • A transactional email provider (United States, with SCCs) — delivery of order confirmations, password resets, shipping updates, and account notifications.
  • An image storage provider (United States, with SCCs) — storage of product imagery and vendor brand imagery.
  • A content management system (United States, with SCCs) — for the editorial magazine and homepage content.
  • An error-tracking provider (United States, with SCCs) — for catching application errors so we can fix them. Personal data fields are masked before transmission.
  • A UK postcode lookup provider (United Kingdom) — for autocompleting your delivery address at checkout. Receives only the postcode you enter, not your name or other personal details.

We never sell your personal data to third parties. Vendors selling on Dripscan receive only the data needed to fulfil your order: your name, delivery address, and the items ordered.

6

If You Are a Vendor on Dripscan

Vendors selling on Dripscan provide additional categories of personal data beyond what we collect from buyers. Specifically:

  • Founder and contact name, email address, business name, and trading address.
  • Business registration details if you operate as a registered company.
  • Bank account or PayPal email for payouts.
  • Photos and brand imagery you upload (founder photo, brand banner, brand avatar).
  • Brand story, social links, and biographical content you choose to publish on your brand page.
  • Messages you send to customers via our order-scoped messaging system.

We use this data to verify your application, list your business and products on the marketplace, process customer orders, pay you out for sales, and communicate with you about your account and the platform.

The lawful basis for this processing is contract (UK GDPR Article 6(1)(b)) — the seller agreement you accept when joining Dripscan. For platform analytics and product improvement, we additionally rely on legitimate interests (Article 6(1)(f)).

Vendor data is shared with the same service providers listed above, with these specific routes:

  • Banking details for payouts go to Stripe Connect or PayPal Payouts only.
  • Brand imagery is held by our image storage provider and served via our website hosting.
  • Vendor account data lives in our hosted database alongside order data.

Vendors have the same data subject rights as buyers (access, erasure, rectification, restriction, portability, objection). To exercise any of these, email [email protected].

For vendors who close their account, we delete personal data within 30 days of closure, except where we are required to retain financial records (for HMRC tax purposes, up to 7 years).

7

How Long We Keep Your Data

  • Account data: retained while your account is active. Deleted within 30 days of an account deletion request.
  • Order records: retained for 7 years to comply with UK financial regulations.
  • Marketing preferences: retained until you withdraw consent.
  • Analytics and visual-search logs: identifying fields (customer ID, hashed IP, user agent) are automatically removed after 12 months by a scheduled job. The aggregate event remains, with no link to a specific person.
  • Audit logs: retained for security investigation purposes under our legitimate interest. Personal data fields are scrubbed when an account is deleted; the audit event itself stays.
8

Your Rights

Under UK GDPR, you have the following rights regarding your personal data:

  • Right of access: request a copy of the data we hold about you.
  • Right to rectification: ask us to correct inaccurate data.
  • Right to erasure: request deletion of your personal data, subject to legal obligations.
  • Right to restrict processing: ask us to pause processing while a dispute is resolved.
  • Right to data portability: receive your data in a machine-readable format.
  • Right to object: object to processing based on legitimate interests or direct marketing.

To exercise any of these rights, email [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

9

How We Keep Your Data Safe

We take data security seriously. All data is transmitted over HTTPS. Passwords are hashed and never stored in plain text. Payment data is handled exclusively by PCI-DSS compliant providers. Access to personal data is restricted to authorised personnel only.

In the unlikely event of a data breach that poses a risk to your rights, we will notify you and the ICO within 72 hours as required by UK GDPR.

10

Cookies

We use essential cookies to keep you logged in and maintain your shopping basket, and optional analytics cookies to understand how the site is used. You can manage your preferences at any time. For full details, see our Cookie Policy.

11

Changes to This Policy

We may update this policy from time to time. Significant changes will be communicated by email or via a notice on the platform. The “Last updated” date above always reflects the latest revision.

12

Contact Us

For any privacy-related queries or to exercise your rights, email us at [email protected]. Dripscan Ltd, United Kingdom.

Questions about this policy?

[email protected]

Share feedback