Privacy policy
Last updated on
We keep as little as possible. We only measure for advertising if you say yes in the cookie banner. Below is exactly what, why and for how long.
Version 3 · 3 October 2026. What changed since the previous version:
- Measurement for advertising has grown: after your yes, Meta also receives three steps in the shop and your purchase from our server, and we see which ad you came from (section 2).
- Every party is named, with what it actually receives: our print shop is Printful and also gets your email address, Google also screens your own photo, and Replicate has been added, which enlarges your own photo if it is too small (section 4).
- For each party it now says where it processes your data, and what applies when that data leaves the EU (section 4).
- For what the Meta pixel collects and sends on, we and Meta are jointly responsible. What that means for your rights is in section 4.
- Your right to object now has its own place (section 6).
- If you live in Luxembourg, your supervisory authority is now listed too (section 9).
- It said we only store a design when you go to checkout. That was wrong: we store every design as soon as you make it (sections 2 and 5).
- It said data about free designs stays at most twelve months, but nothing removed it. A daily clean-up now removes it after that period (section 5).
- Section 3 now also lists the reminder emails, the request for a review and the gift guide, with their legal basis. You can always object to those emails, without giving a reason (section 6).
1. Who is responsible
- Legal entity
- Align2Grow
- Company number
- 0833.016.006
- Contact
- hello@imaginewear.eu
2. What data we process
If you only create designs
- A random visitor number in a cookie. That is not a name and not a profile — just a string of characters by which the shop recognises your browser: to count your free designs, and to keep your designs, your credit, your basket and your orders tied to you.
- Your language choice in a cookie, so you don’t have to choose again on every visit.
- Your choice in the cookie banner in a cookie, so we don’t ask you again on every page.
- An encrypted version of your IP address. We don’t store your actual IP address; it is turned into an irreversible code. That lets us curb abuse without knowing who you are.
- The description you type and the outcome of the check (passed, refused, error), plus which AI model was used and what it cost.
- Every design you make: the image the generator draws, your own photo or a design made of text. We store it in a restricted folder as soon as it has been made and checked, even if you never order it. How long is set out in section 5.
- If your own photo is too small to print sharply, we first have Replicate enlarge it (see section 4).
If you leave your email address
- your email address;
- whether you consented to commercial messages;
- the moment you signed up.
If you place an order
- Your design stays stored with your order. That is necessary: without the file we cannot print anything.
- what you ordered (product, colour, size) and the amount paid;
- the language you ordered in, so your confirmation comes in that language;
- your name, email address and delivery address, collected via the payment page;
- Stripe’s payment references (no card numbers — we never see those).
If you allow measurement for advertising
If you choose “Allow” in the cookie banner, the Meta pixel and the Google Ads tag load. Meta and Google then receive:
- which pages you look at, and which site or ad you came from;
- Meta only: that you put something on a garment in the studio, add something to your basket and go to checkout, at checkout with the total and the number of items;
- data about your browser and your device, including your IP address, and the numbers their cookies give your browser;
- Google only: an email address you type into a form or that is shown on the thank-you page after your order: not the address itself, but a code derived from it (a “hash”);
- after an order: the amount, the currency and a number derived from your payment, so the same order is not counted twice;
- Meta only, and from our own server: the same purchase once more, with the type of browser and the numbers the Meta pixel set in your browser earlier (
_fbp,_fbc). That way an order counts even if you close the tab before the thank-you page. No IP address and no email address.
Without your yes those scripts do not load and Meta and Google receive nothing. The full list, including the cookies, is in our cookie policy.
Which ad you came from
We put a few labels in our own ad links: the name of the campaign and of the ad. They say nothing about you.
- Without consent we only count, on our own server, that a visit came in through such a link: the labels, the page and the day (not the time), without a number, without an IP address and without anything on your device. Nobody can be recognised in that count.
- With your consent we keep those labels with your browser’s number (
iw_visitor), with the time of the click and when you then first designed something, added something to your basket and went to checkout, and whether an order followed. That shows us which ad works. It stays with us; we share it with no one.
3. Why, and on what basis
| Purpose | Legal basis |
|---|---|
| Fulfilling and delivering your order | Performance of the contract |
| Counting free designs and curbing abuse | Legitimate interest (keeping the service affordable) |
| Screening designs for inappropriate content | Legitimate interest and legal obligation |
| Newsletter and offers | Your consent (withdrawable at any time) |
| Measuring whether ads lead to an order (Meta pixel and Google Ads tag) | Your consent in the cookie banner (withdrawable at any time) |
| Keeping track of which ad you came from and what you did next, with your browser’s number | Your consent in the cookie banner (withdrawable at any time) |
| Counting how many visits come in through each ad | No personal data: a count without a number, IP address or time of day |
| One reminder about a basket you left or a payment you did not finish, and after your order one request for a review | Legitimate interest (not letting an order or a review get lost). You can unsubscribe with one click at the bottom of every email. |
| Sending the gift guide you asked for | Carrying out your request |
| Keeping accounts and invoices | Legal obligation |
4. Who we share data with
We do not sell your data. To run the shop we rely on a number of service providers, and only if you gave consent in the cookie banner do Meta and Google also receive data about your visit:
| Party | Purpose | What they receive |
|---|---|---|
| Supabase | Database and design storage | Everything in section 2 (servers in Frankfurt, EU) |
| Generating and screening designs | Your description, the generated image and your own photo | |
| Replicate | Enlarging your own photo if it is too small to print sharply | That photo |
| Stripe | Processing payment | Name, email, address and payment details |
| Resend | Sending order confirmations | Your email address, name, order and delivery address |
| Printful | Printing and shipping | Your design, name, email address and delivery address |
| Vercel | Hosting and counting visitors | Every request to the site, and per page view or step in the shop the path, referring site, country and device type — not tied to a person |
| Meta | Measuring whether ads on Facebook and Instagram lead to an order — only after your consent | What is listed in section 2 under “If you allow measurement for advertising” |
| Google Ads | Measuring whether ads on Google lead to an order — only after your consent | What is listed in section 2 under “If you allow measurement for advertising” |
Meta and Google also process what they receive through those scripts for their own purposes, under their own privacy policies.
Meta and us: jointly responsible
For collecting your data with the Meta pixel and sending it on to Meta — from your browser, and for a purchase also from our server — we and Meta Platforms Ireland Ltd. are jointly responsible. This follows from the Fashion ID judgment of the Court of Justice of the EU, and it is set out in the arrangement Meta makes with advertisers for this, the Controller Addendum. That arrangement comes down to this:
- We ask for your consent before anything goes to Meta, tell you here what is collected and why, and make sure the pixel and the report from our server are set up correctly.
- Meta is responsible for what it does with the data afterwards, and decides on that itself: among other things, to target and show ads. Under its terms Meta may keep the data for at most two years. How and on what basis Meta uses it, and how you exercise your rights with Meta, is set out in Meta’s privacy policy.
- Your rights can be exercised with us and with Meta. If your request is about the collecting and sending, we do what we can ourselves and pass it on to Meta within seven days. What Meta stores itself afterwards — access, correction, erasure, restriction, portability — is handled by Meta.
For the measurement itself, the reports on how our ads perform, Meta works on our instructions.
We let third parties such as Meta and Google collect data on this site with cookies and pixels, only if you chose “Allow”. They also collect data this way on other sites and elsewhere on the internet, and use it to measure ads and to target and show ads. You say no to that in our cookie question, or withdraw your yes with “Change cookie choice” at the bottom of every page or in the menu on your phone. In addition, you can opt out of targeted ads via youronlinechoices.eu and aboutads.info/choices.
Where they do this, and on what basis
All of these parties process at least part of your data outside the European Union, mostly in the United States. For the US there is an adequacy decision of the European Commission, the EU-US Data Privacy Framework (decision 2023/1795): American companies that sign up to it may receive data from the EU. The standard contractual clauses are terms drawn up by the European Commission in which the recipient commits to protecting your data as in the EU. For each party, with a link to its own explanation:
- Supabase stores your data in Frankfurt (EU) and processes it mainly there. The company itself is based in Singapore; for access from outside the EU, the standard contractual clauses in Supabase’s data processing agreement apply.
- Vercel: the part of our site that runs on a server is in the US (Washington, D.C. region). Everything you enter on the site passes through it. Vercel has signed up to the Data Privacy Framework and also uses the standard contractual clauses (Vercel’s privacy notice).
- Google (making and screening designs): our contracting party is Google Cloud EMEA Limited in Dublin. Google processes your description and the images in any country where Google or its subprocessors have facilities, including outside the EU. If they go to Google in the US, the Data Privacy Framework applies; otherwise the standard contractual clauses (Google’s explanation).
- Replicate is an American company. Your own photo goes there to be enlarged if it is too small to print sharply. According to Replicate, the photo and the result are deleted automatically after one hour (Replicate’s explanation). A larger photo first goes to Replicate as a separate file; we have that deleted as soon as the enlarging has finished or failed.
- Stripe: our contracting party is Stripe Payments Europe in Ireland. Stripe also has data processed by subprocessors in the US, and relies for that on the Data Privacy Framework (Stripe, LLC has signed up) and on the standard contractual clauses (Stripe’s privacy policy).
- Resend sends our emails from Ireland (EU), but keeps data about each email, and its logs, in the US. Resend has signed up to the Data Privacy Framework and also uses the standard contractual clauses (Resend’s data processing agreement).
- Printful prints and ships your order from the EU. Our contracting party, Printful, Inc., is based in the US, and data can also go to affiliated companies in, among other places, Latvia, Poland, Spain and the United Kingdom. Printful uses the standard contractual clauses for this (Printful’s privacy policy).
- Meta: Meta Platforms Ireland in Dublin receives the data and passes it on to Meta Platforms, Inc. in the US. For the measurement Meta does for us, Meta relies on the Data Privacy Framework, with the standard contractual clauses as a fallback (Meta’s transfer terms). What Meta does for itself is described in its own privacy policy.
- Google Ads: Google processes the data in any country where it has facilities, including outside the EU. For the US, Google relies on the Data Privacy Framework, and otherwise on the standard contractual clauses (Google’s explanation).
5. How long we keep it
- Data about free designs (your visitor number, the code of your IP address and, if a design was refused or failed, your description): at most 12 months. We use it to enforce limits and to fine-tune our checks. A daily clean-up removes it after that; what remains only says when a design was made, with what result and what it cost.
- Your email address for the newsletter: until you unsubscribe.
- Your choice in the cookie banner: six months, in a cookie on your own device. After that we ask again.
- Which ad you came from (after your consent): twelve months, and gone at once if you withdraw your consent. A daily clean-up enforces that period.
- What Meta and Google receive after your consent: they keep that themselves, under their own policies; under its terms Meta may keep it for at most two years. We keep no copy of it, apart from what we keep briefly to report a purchase from our server (see the next point). The cookies their scripts set on your device stay for 90 days.
- What we keep to report a purchase to Meta from our server (
_fbp,_fbc, the type of browser): until that report has gone or your payment failed, and never longer than seven days; gone at once if you withdraw. With your order we do keep when, and under which version of the question, you gave consent: that is our proof. - Orders, invoices and the associated design: seven years, because accounting law requires it.
- Designs you don’t order: we store every design as soon as you make it. Designs older than thirty days that have not been ordered, not saved to your account and not shared with the community are deleted in a clean-up round. We start that round by hand, not automatically and not on a fixed day, so such a design can also stay longer. If you want a design gone sooner, ask us (see section 6).
6. Your rights
You can ask at any time for:
- access to what we hold about you;
- correction of inaccurate data;
- erasure, insofar as we are not legally required to keep it;
- restriction of processing, or objection to it;
- transfer of your data in a readable file;
- withdrawal of your consent: for the newsletter, or for measurement for advertising.
Send your request to hello@imaginewear.eu. We respond within one month. You can unsubscribe from the newsletter with one click at the bottom of every email. You withdraw your consent for measurement with the “Change cookie choice” link at the bottom of every page or in the menu on your phone.
Right to object
Where we process your data on the basis of our legitimate interest, you can object to that on grounds relating to your particular situation. This applies, among other things, to counting your free designs and curbing abuse, and to screening designs for inappropriate content (see section 3). Email your objection to hello@imaginewear.eu. We then stop that processing, unless we can demonstrate compelling reasons that outweigh your interests, rights and freedoms, or we need the data for legal claims.
On request we send you how we weigh our interest against yours.
You can always object to the reminder emails and the request for a review, without a reason and without any weighing: the unsubscribe link at the bottom of every email is enough, or an email to hello@imaginewear.eu.
7. Security
All connections are encrypted. The database is configured so that data is only reachable through our server, never directly from your browser. Designs sit in a restricted folder and cannot be retrieved publicly. Your IP address is stored in encrypted form and payment details never reach our servers.
8. Children
Our shop is not aimed at children under 16. If we notice that we hold data about a child without a parent’s consent, we delete it.
9. Lodging a complaint
If you are unhappy with how we handle your data, tell us first — we usually sort it out quickly. You can also always lodge a complaint with the Belgian Data Protection Authority (Drukpersstraat 35, 1000 Brussels). If you live in the Netherlands, you can go to the Autoriteit Persoonsgegevens. If you live in Luxembourg, you can go to the Commission nationale pour la protection des données (CNPD, 15, Boulevard du Jazz, L-4370 Belvaux).
10. Cookies
Which cookies we use, what only loads after your consent and how to withdraw it is set out in our cookie policy.
11. Designs you share
By default your design stays yours alone. If you choose to share it with the community, you give us permission to show it in our gallery and to let other customers order it. That is your choice, not a condition for ordering.
- What we show: the image, and the description you typed if it contains no personal data. Your name is not shown unless you choose a username.
- Legal basis: your consent (art. 6.1.a GDPR), given through a checkbox that is off by default.
- Withdrawing: at any time, from your account. We then take the design out of the gallery and nobody can order it any more. Orders already placed remain — we cannot undo those, and printed garments least of all.
- Username: it belongs to your account, can be changed at any time, and disappears when your account does.
This text is a translation of the Dutch version. Where the language versions differ in interpretation, the Dutch text prevails.
Questions about this text? Get in touch via our contact page or hello@imaginewear.eu.