Privacy Policy
Last updated: April 16, 2026
1. Who we are
This Privacy Policy explains how NARCYA collects, uses, and protects personal data across the shopper experience, the store-owner dashboard, and related support operations.
NARCYA is currently operated by an independent controller. If you use NARCYA inside a participating physical store, that store may also act as a separate controller for some parts of the in-store experience.
For privacy questions or requests, contact narcya.contact@gmail.com.
2. What data we process
Depending on how the service is used, we may process the following categories of data:
- Shopper session data such as store, timestamp, browser language, and optional feedback about whether an item was purchased.
- Analysis outputs such as style category, score, detected garments, colors, and related explanation text.
- Estimated age-range and gender signals used only for aggregated store reporting.
- Store-owner account, business, billing, and authentication data.
- Technical and security logs needed to operate, monitor, and protect the service.
3. Shopper photos
In the standard shopper flow, NARCYA does not store the uploaded shopper photo on its own servers.
The photo may be held temporarily on the shopper's own device during the active browser session, and it is sent to OpenAI only to generate the requested style analysis.
Based on OpenAI's current API data-handling policy for this use, OpenAI does not store the photo to train its models. Even so, sending the image for analysis is still a form of personal-data processing.
4. How we use personal data
We use personal data to:
- Generate the shopper's style analysis and result screen.
- Operate the store-owner dashboard, QR flows, and aggregated reporting.
- Manage authentication, support, service security, and abuse prevention.
- Maintain and improve the reliability and quality of the service using aggregated or de-identified information where possible.
5. Estimated analytics
Some dashboard metrics, including estimated age-range and gender breakdowns, are inferred analytics only.
They are intended for aggregated trend reporting and should not be treated as exact facts about any particular individual.
6. Legal bases
Where applicable, we rely on one or more of the following legal bases:
- Performance of a contract or steps requested by the user.
- Legitimate interests in operating, securing, and improving NARCYA.
- Compliance with legal obligations.
- Consent, where consent is required by applicable law.
7. Service providers and transfers
We use service providers to operate NARCYA, including infrastructure, database, authentication, storage, analytics, and AI-processing providers such as Supabase and OpenAI.
Some of these providers may process data outside your country. Where required, we use contractual, technical, and organizational safeguards intended to protect personal data.
8. Retention
We keep personal data only for as long as necessary for the purposes described in this Policy, including operational, legal, accounting, and security needs.
In the current product setup, shopper photos are not retained on NARCYA servers in the standard flow. Session data and aggregated analytics may be retained for limited periods to support store reporting, fraud prevention, and service operations.
9. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data, and to lodge a complaint with a supervisory authority.
If your request relates to a specific in-store experience, we may need to coordinate with the participating store where that store acts as a separate controller.
10. Updates
We may update this Privacy Policy from time to time. When we do, we will update the 'Last updated' date on this page.