Privacy
Privacy Policy
Protecting your personal data matters to us. Below we explain which data we process, for what purpose and on what legal basis under the GDPR.
1. Controller
Tobias HerbProzessionsweg 17
69226 Nußloch, Deutschland
Email: info@shinealyse.com
Phone: +49 176 61370317
2. Visiting the website (server logs)
When you visit the site, technically necessary data is processed (including IP address, date and time, requested resource, browser type) to deliver and secure the website. The legal basis is our legitimate interest in stable, secure operation (Art. 6(1)(f) GDPR). Hosting is provided by a processor with servers in Germany (netcup GmbH).
3. Photo upload and AI analysis
The core of the service is analysing a selfie you upload. For this we process your photo and your email address. A facial image may contain special categories of personal data (Art. 9 GDPR). We process the photo solely to produce the colour, make-up and style analysis you requested, and not to uniquely identify or recognise individuals.
The legal basis is your explicit consent (Art. 6(1)(a) in conjunction with Art. 9(2)(a) GDPR), which you give by actively ticking a box before uploading and which you may withdraw at any time with effect for the future.
Storage and deletion: the uploaded photo is only cached transiently (with a lifetime of at most 30 minutes) and is automatically and irreversibly deleted once processing is complete. Image variants generated during the analysis are likewise deleted after delivery. We retain the analysis result (e.g. colour season, undertones, contrast, palette and recommendations — without your photo) for quality assurance for at most 30 days, after which it is deleted automatically. That record contains neither your name nor your email address, only an internal job reference — so this storage is pseudonymous, not anonymous.
Transfer to an AI provider: to create the analysis, the photo is transferred to our AI provider OpenRouter, Inc. (USA), which forwards the request to the respective AI model. This involves a transfer to a third country (USA) — see section 8.
4. Email verification and email delivery
Before you upload a photo, you confirm your email address: we send you a verification link that is valid for 15 minutes. After the upload, the analysis starts immediately — there is no second confirmation email. Email delivery is handled by the provider Resend. The legal basis is the performance of our relationship with you and/or your consent (Art. 6(1)(a) and (b) GDPR).
5. Paid report and payment processing
Payment for the paid full report is handled by the payment provider Stripe. You enter payment data (e.g. card details) directly with Stripe; we do not receive or store full payment data. For processing and record-keeping we store a pseudonymous identifier of your email address, the amount, the country and the payment status. The legal basis is performance of the contract (Art. 6(1)(b) GDPR) and compliance with tax and commercial retention obligations (Art. 6(1)(c) GDPR).
6. Abuse prevention
To prevent abuse (e.g. automated bulk requests) we limit the number of requests per IP address and per email address. For this we briefly process the IP address and a hashed form of the email address. The legal basis is our legitimate interest in protecting the service (Art. 6(1)(f) GDPR).
7. Analytics (Umami)
We use the self-hosted, cookie-free analytics software Umami. No cookies are set and no cross-site profiles are built; measurement is aggregated and without storing the full IP address. The legal basis is our legitimate interest in privacy-friendly analytics (Art. 6(1)(f) GDPR). No consent banner is required for this.
8. Recipients and transfers to third countries
We use the following processors / recipients:
- netcup GmbH – hosting (Germany/EU)
- OpenRouter, Inc. – AI processing of the photo (USA)
- Stripe – payment processing (EU/USA)
- Resend – email delivery (EU/USA)
Where data is transferred to the USA, we rely on the EU Standard Contractual Clauses and — in the case of the photo — additionally on your explicit consent (Art. 49(1)(a) GDPR). The USA does not provide a level of data protection comparable to the EU; in particular, authorities may be able to access data.
9. Retention periods
- Uploaded photo: at most 30 minutes, then automatic deletion.
- Email verification link: valid for 15 minutes, then invalid.
- Analysis result (without photo, pseudonymous): at most 30 days for quality assurance, then deleted automatically.
- Purchase and invoice data: until statutory retention periods expire (up to 10 years under German law).
- Consent records: for as long as proof is required.
10. Your rights
Subject to the statutory conditions, you have the right to:
- access (Art. 15 GDPR)
- rectification (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- object to processing based on legitimate interests (Art. 21 GDPR)
- withdraw consent with effect for the future (Art. 7(3) GDPR)
To exercise your rights, a message to info@shinealyse.com is sufficient. You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg.
11. Necessity of provision
Providing your photo and email address is voluntary. However, without this data we cannot create or deliver the analysis.
12. Automated processing
The analysis is produced by automated (AI-based) means. There is no automated decision within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you; the analysis serves purely informational and creative purposes.
13. Updates
We update this privacy policy when our data processing changes. The version published on this page applies.