Privacy
Privacy Policy
Protecting your personal data matters to us. Below we explain which data we process, for what purpose and on what legal basis under the GDPR.
1. Controller
Tobias HerbProzessionsweg 17
69226 Nußloch, Deutschland
Email: info@shinealyse.com
Phone: +49 176 61370317
2. Visiting the website (server logs)
When you visit the site, technically necessary data is processed (including IP address, date and time, requested resource, browser type) to deliver and secure the website. The legal basis is our legitimate interest in stable, secure operation (Art. 6(1)(f) GDPR). Hosting is provided by a processor with servers in Germany (netcup GmbH).
3. Photo upload and AI analysis
The core of the service is analysing a selfie you upload. For this we process your photo and your email address. A facial image may contain special categories of personal data (Art. 9 GDPR). We process the photo solely to produce the colour, make-up and style analysis you requested, and not to uniquely identify or recognise individuals.
The legal basis is your explicit consent (Art. 6(1)(a) in conjunction with Art. 9(2)(a) GDPR), which you give by actively ticking a box before uploading and which you may withdraw at any time with effect for the future.
Storage and deletion: the uploaded photo is only cached transiently (with a lifetime of at most 30 minutes) and is automatically and irreversibly deleted once processing is complete. Image variants generated during the analysis are likewise deleted after delivery. We retain the analysis result (e.g. colour season, undertones, contrast, palette and recommendations — without your photo) for quality assurance for at most 30 days, after which it is deleted automatically. That record contains neither your name nor your email address, only an internal job reference — so this storage is pseudonymous, not anonymous.
Transfer to an AI provider: to create the analysis, the photo is transferred to our AI provider OpenRouter, Inc. (USA), which forwards the request to the respective AI model. This involves a transfer to a third country (USA) — see section 8.
4. Email verification and email delivery
For the free analysis you enter your email address and upload your photo straight afterwards — we do not ask you to confirm the address. For the paid report you confirm it beforehand via a verification link that is valid for 15 minutes. After the upload, the analysis starts immediately — there is no further confirmation email.
The email containing your free report includes a link that takes you straight to the paid report without entering your address again. That link carries your email address in signed form and is valid for 30 days, after which it expires. Nothing extra is stored for it — the address sits inside the link itself. Please do not share the link: whoever holds it reaches the checkout with your address. The email for the paid report contains no such link.
Email delivery is handled by the provider Resend. The legal basis is the performance of our relationship with you and/or your consent (Art. 6(1)(a) and (b) GDPR).
5. Paid report and payment processing
Payment for the paid full report is handled by the payment provider Stripe. You enter payment data (e.g. card details) directly with Stripe; we do not receive or store full payment data. For processing and record-keeping we store a pseudonymous identifier of your email address, the amount, the country and the payment status. The legal basis is performance of the contract (Art. 6(1)(b) GDPR) and compliance with tax and commercial retention obligations (Art. 6(1)(c) GDPR).
6. Abuse prevention
To prevent abuse (e.g. automated bulk requests) we limit the number of requests per IP address and per email address. For this we briefly process the IP address and a hashed form of the email address. The legal basis is our legitimate interest in protecting the service (Art. 6(1)(f) GDPR).
7. Analytics (Umami)
We use the self-hosted, cookie-free analytics software Umami. Umami sets no cookies and builds no cross-site profiles; measurement is aggregated and without storing the full IP address. The legal basis is our legitimate interest in privacy-friendly analytics (Art. 6(1)(f) GDPR). No consent banner is required for this.
We additionally record how far someone got on the site: home page seen, form opened, email submitted. For this we store only the name of the step, whether it was the free or the paid route, and which of the two design variants of the home page was shown. No email address, not even hashed, no order reference, no IP address. Without this count we would only know how many people open the site, not where they get stuck.
You can switch analytics off permanently for this device: visit shinealyse.com/en?notrack=1 once. We then store a switch in your browser's local storage and no measurement happens on any later visit. Clearing your browser data also clears that switch.
Separately, we set a small number of strictly necessary cookies required to operate the site. They serve no analytics purpose, carry no advertising identifiers and are not shared with third parties. Under § 25(2) TDDDG they require no consent. They are:
- sr_v – records which of two design variants of the home page you are shown, so it stays the same on every visit. Its content is a single letter with no personal reference. Lifetime 90 days.
- sr_verified – after you enter your email address, proves that the upload and payment belong to your request. Lifetime 1 hour.
- intake_bypass – only for our own testing of the form via the admin area; it is not set during a normal visit. Lifetime 15 minutes.
8. Recipients and transfers to third countries
We use the following processors / recipients:
- netcup GmbH – hosting (Germany/EU)
- OpenRouter, Inc. – AI processing of the photo (USA)
- Stripe – payment processing (EU/USA)
- Resend – email delivery (EU/USA)
Where data is transferred to the USA, we rely on the EU Standard Contractual Clauses and — in the case of the photo — additionally on your explicit consent (Art. 49(1)(a) GDPR). The USA does not provide a level of data protection comparable to the EU; in particular, authorities may be able to access data.
9. Retention periods
- Uploaded photo: at most 30 minutes, then automatic deletion.
- Email verification link (paid report only): valid for 15 minutes, then invalid.
- Upgrade link in the free report email: valid for 30 days, then invalid. Nothing is stored for it — the address is signed into the link itself.
- Analysis result (without photo, pseudonymous): at most 30 days for quality assurance, then deleted automatically.
- Purchase and invoice data: until statutory retention periods expire (up to 10 years under German law).
- Consent records: for as long as proof is required.
10. Your rights
Subject to the statutory conditions, you have the right to:
- access (Art. 15 GDPR)
- rectification (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- object to processing based on legitimate interests (Art. 21 GDPR)
- withdraw consent with effect for the future (Art. 7(3) GDPR)
To exercise your rights, a message to info@shinealyse.com is sufficient. You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg.
11. Necessity of provision
Providing your photo and email address is voluntary. However, without this data we cannot create or deliver the analysis.
12. Automated processing
The analysis is produced by automated (AI-based) means. There is no automated decision within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you; the analysis serves purely informational and creative purposes.
13. Updates
We update this privacy policy when our data processing changes. The version published on this page applies.