Privacy Policy
Last updated: 1 May 2026
We are committed to protecting your privacy. This policy explains what personal data we collect, why we collect it, and how we keep it safe. Written in plain English, no legal jargon.
Who We Are
Dripscan is a UK-based online marketplace connecting independent fashion and beauty brands with customers across the United Kingdom and beyond. As the data controller, we are responsible for the personal data you share with us. For any privacy-related questions, email [email protected].
What Data We Collect
We collect the following categories of data when you use Dripscan:
- Account data: your name, email address, and a secure password hash when you register.
- Order data: delivery address, order history, and payment method. Card details are handled entirely by Stripe and are never stored on our servers.
- Vendor data: business name, contact details, banking or PayPal details for payouts, and any brand imagery or biographical content you choose to publish. See “If You Are a Vendor on Dripscan” below.
- Visual search data: photos you upload to our Scan That Drip feature at /scan. See “AI-Powered Features and Visual Search” below.
- Usage data: pages visited, search queries, and clicks, collected via anonymised analytics.
- Communications: emails and messages you send to our support team, plus messages you exchange with vendors via our order-scoped messaging system.
- Cookie data: session identifiers, functional preferences, and (with your consent) analytics and marketing identifiers. See our Cookie Policy for full details.
Why We Use Your Data
We process your data under the following legal bases as defined by UK GDPR:
- Contract: to process and fulfil your orders, manage your account, and handle returns.
- Legitimate interests: to prevent fraud, improve our platform, and send transactional emails such as order confirmations and shipping updates.
- Consent: to send marketing emails and newsletters. You can withdraw consent at any time by clicking Unsubscribe or emailing [email protected].
- Legal obligation: to retain financial records for HMRC purposes for up to 7 years.
AI-Powered Features and Visual Search
Dripscan offers an AI-powered visual search feature called Scan That Drip, available at /scan. When you upload a photo to find similar products, the data flow is:
- The photo is processed in-memory on our server and is never written to disk on Dripscan infrastructure.
- The photo is sent to a vision-language AI model via OpenRouter (United States, with SCCs), where the model extracts product-level visual attributes (item type, colour, fabric, style descriptors).
- The extracted attributes are matched against our UK marketplace product catalogue, and matching products are returned to you.
- We retain a SHA-256 hash of the photo (not the photo itself) for up to 12 months to deduplicate repeat scans and investigate service-quality issues. The hash cannot be reversed into the original image. After 12 months any link to your customer account is removed automatically.
- Your original photo is not used to train the AI model.
The lawful basis for this processing is our legitimate interest in providing the visual-search feature you actively requested by uploading a photo (UK GDPR Article 6(1)(f)). You can request deletion of any photos you have uploaded by emailing [email protected].
We do not use facial recognition, biometric matching, or any feature that identifies individuals from uploaded photos. The visual-search model extracts product-level descriptors only.
If you do not wish to use this feature, simply do not upload a photo. The rest of Dripscan works without it.
If You Are a Vendor on Dripscan
Vendors selling on Dripscan provide additional categories of personal data beyond what we collect from buyers. Specifically:
- Founder and contact name, email address, business name, and trading address.
- Business registration details if you operate as a registered company.
- Bank account or PayPal email for payouts.
- Photos and brand imagery you upload (founder photo, brand banner, brand avatar).
- Brand story, social links, and biographical content you choose to publish on your brand page.
- Messages you send to customers via our order-scoped messaging system.
We use this data to verify your application, list your business and products on the marketplace, process customer orders, pay you out for sales, and communicate with you about your account and the platform.
The lawful basis for this processing is contract (UK GDPR Article 6(1)(b)) — the seller agreement you accept when joining Dripscan. For platform analytics and product improvement, we additionally rely on legitimate interests (Article 6(1)(f)).
Vendor data is shared with the same service providers listed above, with these specific routes:
- Banking details for payouts go to Stripe Connect or PayPal Payouts only.
- Brand imagery is held by our image storage provider and served via our website hosting.
- Vendor account data lives in our hosted database alongside order data.
Vendors have the same data subject rights as buyers (access, erasure, rectification, restriction, portability, objection). To exercise any of these, email [email protected].
For vendors who close their account, we delete personal data within 30 days of closure, except where we are required to retain financial records (for HMRC tax purposes, up to 7 years).
How Long We Keep Your Data
- Account data: retained while your account is active. Deleted within 30 days of an account deletion request.
- Order records: retained for 7 years to comply with UK financial regulations.
- Marketing preferences: retained until you withdraw consent.
- Analytics and visual-search logs: identifying fields (customer ID, hashed IP, user agent) are automatically removed after 12 months by a scheduled job. The aggregate event remains, with no link to a specific person.
- Audit logs: retained for security investigation purposes under our legitimate interest. Personal data fields are scrubbed when an account is deleted; the audit event itself stays.
Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
- Right of access: request a copy of the data we hold about you.
- Right to rectification: ask us to correct inaccurate data.
- Right to erasure: request deletion of your personal data, subject to legal obligations.
- Right to restrict processing: ask us to pause processing while a dispute is resolved.
- Right to data portability: receive your data in a machine-readable format.
- Right to object: object to processing based on legitimate interests or direct marketing.
To exercise any of these rights, email [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
How We Keep Your Data Safe
We take data security seriously. All data is transmitted over HTTPS. Passwords are hashed and never stored in plain text. Payment data is handled exclusively by PCI-DSS compliant providers. Access to personal data is restricted to authorised personnel only.
In the unlikely event of a data breach that poses a risk to your rights, we will notify you and the ICO within 72 hours as required by UK GDPR.
Changes to This Policy
We may update this policy from time to time. Significant changes will be communicated by email or via a notice on the platform. The “Last updated” date above always reflects the latest revision.
Contact Us
For any privacy-related queries or to exercise your rights, email us at [email protected]. Dripscan Ltd, United Kingdom.
Questions about this policy?
[email protected]