Privacy Policy
Last updated: 2026-08-27
Runway Ready AI SL ("RunwayReady", "we", "us") is the data controller for personal data processed through our mobile application and website https://runwayready.ai (the "Services").
Legal texts are maintained in our systems and published as a durable snapshot (cloud storage + API); they are not loaded at runtime from an external legal-document vendor.
1. Controller identity
- Legal name: Runway Ready AI SL
- Tax ID (CIF/NIF): B27598499
- VAT: ESB27598499
- Address: Calle Faraday 7, Parque Científico de Madrid, 28049 Madrid, Comunidad de Madrid, Spain
- Contact: contact@runwayready.ai
- Data protection contact: contact@runwayready.ai (we have not appointed a formal Data Protection Officer; this is the privacy channel).
2. Data we collect
- Account: name, email, Firebase UID, profile photo, locale.
- Images & wardrobe content: clothing photos, outfits, profile and try-on images you upload, stored in Google Cloud Storage (EU region
europe-west1). - Body measurements: measurements you enter or we estimate for sizing (we do not use biometric data for identification).
- Usage data: app interactions, technical logs, device identifiers, push tokens.
- Diagnostic logs (
diagnosticLogs): crash/error logs and technical metadata (e.g. via Sentry) only if you opt in to diagnostic consent; default is off. - GeoIP / approximate location: country or region inferred from IP for security, compliance, and service localization (not precise GPS).
- Website leads (waitlist / contact / newsletter): name, email, and message you submit on marketing-site forms; waitlist covers transactional confirmation of your request; newsletter is separate explicit commercial consent.
- Light social features: minimum data for friends / wishlists you choose to share (identifiers and visible items per feature).
- Payments: processed by Stripe; we never store full card numbers.
- Marketplace: listings, orders, support messages for peer-to-peer sales.
- Legal consent records: document version, timestamp, bundle hash (GDPR audit trail).
3. Purposes & legal bases (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Provide the service (account, wardrobe, outfits, product AI) | Contract performance |
| AI image processing (detection, flat-lay, try-on) — under contract; US processors with SCCs | Contract performance |
| Marketplace & shipping | Contract performance |
| Security, fraud, GeoIP, legal compliance | Legitimate interest / legal obligation |
| Support and incident review (including wardrobe images) | Contract performance / legitimate interest |
| Waitlist / contact forms (respond to your request) | Pre-contractual steps / legitimate interest |
| Newsletter and commercial email | Consent (explicit opt-in) |
| Non-essential analytics (app / web) | Separate consent (cookies/SDKs); not inferred from legal-document acceptance |
| Marketing / ad pixels (e.g. Meta, TikTok when configured) | Marketing consent (separate from analytics) |
Diagnostic logs (diagnosticLogs / Sentry) | Consent (opt-in; default off) |
| Transactional push (FCM: orders, security, account) | Contract performance / legitimate interest |
| Promotional push / offers | Marketing consent |
4. Who may access your data
In addition to the processors listed below, authorized personnel of RunwayReady (administrators and support staff on a need-to-know basis) may access your account details and wardrobe images to provide customer support, debug incidents, prevent fraud or abuse, and meet legal obligations. Access is limited to what is necessary and protected by authentication and role controls.
5. AI & processors
Product AI features (detection, flat-lay, try-on, suggestions) are provided as part of the service contract. Your images and prompts may be sent to processors, including some in the US under Standard Contractual Clauses:
- Google Cloud / Vertex AI (Gemini) — vision, text, image generation; EU region where available.
- fal.ai — image generation and LLM failover; may involve transfer to the US under SCCs.
- OpenRouter — optional chat/suggestion model routing (may involve US transfer).
- Stripe — payments.
- Shippo — marketplace shipping labels, rates, and tracking (minimum delivery data).
- Google Firebase — authentication, FCM, and technical operation.
- Apple — StoreKit / App Store billing (iOS), ATT.
- Google Play — Android billing.
- Brevo — transactional email (not SendGrid).
- Sentry — error monitoring only when
diagnosticLogsis consented. - Meta — pixels / Custom Audiences off unless marketing consent and ATT.
Third-party SLAs and legal documents: see the Service Level Agreement (vendors section) and fal.ai/legal, Stripe SSA, GCP SLAs, Shippo Terms.
AI outputs (e.g. flat-lays, try-on renders) may be synthetic and not perfectly accurate. They are not professional advice.
Third-party providers (SLA / official documents)
Third-party uptime commitments are as published by each vendor; may be plan- or enterprise-gated. Counsel-pending.
| Provider | Published SLA (summary) | Online documents |
|---|---|---|
| fal.ai (Features & Labels, Inc.) Generative image APIs + LLM failover (`fal-ai/any-llm`) | Enterprise / Serverless marketed uptime ~99.99%; public ToS has no end-user consumer SLA. DPA/SCC countersignature pending (ENG-05 / CF-04). | Legal center · Terms of Service · Privacy Policy · Acceptable Use Policy · Trust center · Status · Enterprise · Status |
| Shippo Marketplace shipping labels, rates, tracking, optional insurance | Shippo publishes ~99.9% uptime SLA (plan-dependent; Premier/API plans advertise 99.9%). Carrier transit times are outside Shippo API SLA. | Terms of Use · Privacy Policy · Insurance Terms of Service · Privacy hub · API docs · Status · Status |
| Stripe Subscriptions, marketplace payments, Stripe Connect payouts | Availability and remedies under Stripe Services Agreement; no separate public uptime % for all products. Refunds/chargebacks per network + SSA. | Services Agreement (SSA) · SSA overview · Data Processing Agreement · Privacy Center · Status · Status |
| Google Cloud / Vertex AI Primary LLM / vision (Gemini); GCS storage | Vertex AI Platform SLA (Monthly Uptime % / financial credits per Google Cloud SLA pages). Generative features may have separate Gemini SLA docs. | GCP SLA index · Vertex AI Platform SLA · Gemini generative AI SLA · Cloud Data Processing Addendum · Status · Status |
| Google Firebase Authentication, app config, hosting (marketing), messaging | Firebase services under GCP Terms / Firebase ToS; Cloud Storage for Firebase and related products inherit applicable GCP SLAs where listed. | Firebase Terms of Service · Privacy & Security · Cloud Data Processing Addendum · Status · Status |
| OpenRouter Optional chat/suggestion model routing | No public uptime SLA found; monitor status.openrouter.ai. Provider-specific data retention / training policies apply per route. | Terms of Service · Privacy Policy · Provider logging / retention · Status · Status |
| Sentry Error monitoring (when DSN configured; production) | SaaS availability per Sentry subscription plan / MSA; not a consumer-facing product SLA. | Terms of Service · Privacy Policy · DPA · Status · Status |
| Apple App Store / StoreKit billing (iOS), ATT, privacy nutrition labels | App Store / StoreKit availability per Apple Developer / media services terms. ATT governs tracking; NSPrivacyTracking=false holds only while app emails are not synced to Meta Custom Audiences. | Privacy Policy · App Store Review Guidelines · User Privacy and Data Use (ATT) · Licensed Application End User License Agreement |
| Google Play Play billing (Android), Data Safety form | Play distribution and billing under Google Play Developer / Payments terms. Data Safety disclosures must match in-app privacy text. | Google Play Terms of Service · Developer Distribution Agreement · Payments / billing |
| Brevo Transactional email (verification, password reset, welcome). Live ESP — not SendGrid. | Transactional email under Brevo terms / DPA; no consumer-facing uptime SLA. Deliverability depends on domain authentication (SPF/DKIM/DMARC). | Terms of Use · Privacy Policy · Data Processing Agreement · Status · Status |
| Meta Custom Audiences / marketing pixels — gated on ATT + marketing consent; not enabled for tracking while NSPrivacyTracking=false | Marketing measurement only when configured and marketing consent (and iOS ATT, if tracking) is granted. Sync of app emails to Custom Audiences must stay gated or Apple tracking answers flip to Yes. | Privacy Policy · Business Tools Terms · Custom Audiences terms |
6. Retention
We retain data while your account is active. After a deletion request, we erase or anonymize per the schedule below (proposed / counsel-pending periods):
| Category | Retention (draft) |
|---|---|
| Account & identity | While account active; erasure is immediate on deletion request (only minimal tombstones and legal-hold records persist per this schedule) |
| Wardrobe / try-on images | While account active; erased immediately with the account (except applicable legal holds) |
| Legal consent records | Up to 6 years (accountability / audit) |
| Payment data (Stripe) | Per Stripe + tax rules (typically up to 6–10 years for invoicing) |
| Support / moderation records | Up to 3 years after incident close, unless litigation |
| Analytics (if consented) | Per provider policy; collection stops within ≤24h of consent withdrawal |
7. International transfers
Where processors operate outside the EEA (e.g. fal.ai in the US), we use appropriate safeguards including EU Standard Contractual Clauses.
8. Your rights
You may access, rectify, erase, restrict, port, or object to processing, and withdraw consent via contact@runwayready.ai or in-app data export and account deletion (Privacy settings).
Rights SLA (draft, counsel-pending): we acknowledge within 5 business days and complete within 30 days (GDPR Art. 12). Analytics/cookies/marketing/diagnosticLogs consent withdrawal takes effect ASAP / within 24 hours of API success. Personal-data breach notify AEPD when required: 72 hours of awareness.
You may request human review where automated decisions have significant legal effects.
9. Children
Services are not directed at children under 14 (minimum age aligned with Spanish LOPDGDD / in-app signup gate). We do not knowingly collect data from children below that age.
10. Supervisory authority
You may lodge a complaint with the Spanish Data Protection Agency (AEPD): https://www.aepd.es.