Curaits

Privacy Policy

This policy explains what personal data Curaits processes, why we process it, who processes it with us, and the rights you have over it.

Who we are

Curaits is operated by Szobota Zsuzsanna e.v., Anilin utca 2/C, 1165 Budapest, Hungary.

The operator is the data controller and is also the contact point for privacy matters: contact@curaits.com

Sole proprietor registration number (vállalkozói nyilvántartási szám): 54875472

Hungarian tax number: 56240357-2-42

EU VAT number: HU56240357

Data we process

  • Account and profile data — email address, authentication identifiers (including Google sign-in identifiers if you use it), plan and subscription status.
  • Uploaded images and generated visualisations — photos you upload to ask a question, and AI-generated preview images created from them.
  • Decisions and follow-up history — your questions, the decisions and explanations returned to you, follow-ups, feedback and saved decisions.
  • Taste Memory and taste signals — durable aesthetic preferences derived from your explicit feedback and decisions.
  • First-party analytics and session identifiers — product events (for example decision created, product clicked, share link created) and session identifiers used to keep your session working.
  • Merchant / shop attribution — which participating store a decision or visualisation was made in, used for merchant usage metering and aggregate reporting.
  • AI and provider telemetry — technical metadata about AI calls such as model name, token counts, latency, status and computed cost. Used for reliability and cost control.
  • Shopify shop and catalogue data — for merchants: shop domain, installation tokens and product catalogue data synced from the store. Curaits does not request, ingest or store Shopify customer records or Shopify customer personal data through the Shopify customer APIs; the mandatory Shopify customer data-request and erasure webhooks therefore find no Shopify customer data held by Curaits. Curaits does still process its own Curaits account holders and the other data described in this policy.
  • Guest visualisation identity and abuse-control data — a server-issued, signed identifier stored in a cookie, plus a hashed bucket derived from IP address and user agent. Used only to enforce free visualisation allowances and prevent abuse.

Why we process it, and on what legal basis

  • To provide the service (decisions, visualisations, product matching, saved history) — performance of a contract with you.
  • To personalise recommendations via Taste Memory — performance of a contract; you can delete your taste data at any time.
  • To keep the service secure and prevent abuse (guest identity, hashed IP/user-agent bucket, rate limits) — legitimate interests.
  • To meter merchant usage and bill merchants — performance of a contract with the merchant and legitimate interests.
  • To monitor reliability, quality and AI cost — legitimate interests.
  • To take payments — performance of a contract, carried out by Stripe.
  • To meet legal obligations (for example accounting) — legal obligation.

What merchants can and cannot see

Participating stores do not receive your personal Curaits history. Merchants see aggregate activity for their own store and usage metering, not your visual history, decisions made in other stores, or your Taste Memory.

Retention and deletion

We keep personal data only for as long as it is needed for the purposes above. When you delete your account, we delete or irreversibly anonymise your account data, uploaded images, visualisations, decisions, taste signals and personal analytics identifiers. Aggregate and anonymised counts that cannot identify you may be retained.

  • Account and profile data — retained while the account is active; deleted on account deletion, except where retention is legally required.
  • Decisions, follow-ups, Taste Memory and uploaded or generated decision imagery — retained while the account exists; deleted when you delete your account, subject to technical backup expiry and legal obligations.
  • Guest visualisation identity and abuse-control identifiers — maximum 30 days.
  • First-party analytics events — 12 months.
  • AI and provider telemetry and operational logs — 12 months, unless needed longer for security, dispute, billing or legal compliance.
  • Merchant and shop configuration and catalogue-derived data — while the merchant relationship is active; deleted or anonymised after termination, subject to required accounting and legal retention.
  • Billing, invoice and transaction records — retained for the period required by applicable Hungarian accounting and tax law.
  • Security and fraud records — only as long as reasonably necessary for abuse prevention and legal claims.

These periods may be extended only where required by law, or where necessary for dispute resolution, security, fraud prevention, or the establishment, exercise or defence of legal claims.

Your rights

Under the GDPR you have the right of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent where processing is based on consent. You can also lodge a complaint with the Hungarian supervisory authority (NAIH) or the authority in your country of residence.

You can exercise access, portability and erasure yourself: your Account page includes Export my data and Delete account. For any other request, contact contact@curaits.com.

Processors we use

  • Supabase — database, authentication and file storage.
  • Lovable — application hosting and error reporting.
  • Lovable AI Gateway — routing of AI requests.
  • Google Gemini models, accessed through the Lovable AI Gateway — generation of decisions, suggestions and visualisations.
  • Stripe — payment processing and subscription billing. Card details are handled by Stripe and never stored by Curaits.
  • Shopify — where you use Curaits inside a Shopify store, for installation, catalogue access and the storefront surface.

International transfers

Some of these providers process data outside the European Economic Area. Where that happens, transfers rely on the safeguards offered by those providers, such as the European Commission's Standard Contractual Clauses or an adequacy decision.

Cookies, local storage and session storage

Curaits does not use advertising cookies, third-party ad trackers, Google Analytics or social pixels. We use only what is necessary to run the service:

  • Authentication storage — your sign-in session is stored by the authentication client in browser local storage.
  • Session storage — short-lived values such as an embed session token when Curaits runs inside a store.
  • Guest visualisation cookie — a signed, HttpOnly cookie used solely to apply free visualisation allowances and prevent abuse.
  • First-party product analytics — stored in our own database, not shared with advertising networks.

Because all of the above is strictly necessary or first-party and non-advertising, Curaits does not display a cookie-consent banner. If we later add non-essential tracking, we will ask for consent first.

Children

Curaits is not intended for children under 16.

Changes to this policy

We may update this policy as the service changes. Material changes will be reflected on this page.