ThriftAI Privacy Policy

Last updated: June 30, 2025

GDPR Compliance Notice

This privacy policy complies with the General Data Protection Regulation (GDPR) as we are based in Denmark, European Union.

This Privacy Policy describes how ThriftAI ("we", "our", or "us") collects, uses, and protects your personal information when you use our AI-powered thrift shopping application and related services (the "Service"). We are committed to protecting your privacy and ensuring transparent data practices in accordance with Danish and European Union data protection laws.

1. Data Controller Information

Data Controller

ThriftAI

Location

Denmark, European Union

Contact

simon@thriftai.io

2. Interpretation and Definitions

Definitions

For the purposes of this Privacy Policy:

Account means a unique account created for you to access our Service.
Application refers to ThriftAI, the software program provided by the Company.
Company (referred to as "the Company", "we", "us" or "our") refers to ThriftAI, located in Denmark.
Country refers to Denmark.
Device means any device that can access the Service such as a computer, smartphone, or tablet.
GDPR refers to the General Data Protection Regulation (EU) 2016/679.
Personal Data is any information that relates to an identified or identifiable natural person.
Service refers to the ThriftAI Application.
You refers to the individual accessing or using the Service.

3. Types of Data We Collect

Personal Data

While using our Service, we may ask you to provide certain personally identifiable information, including but not limited to:

Email address
First name and last name
Profile picture (optional)
Location data
Shopping preferences
Purchase history

Usage Data & Analytics

We collect extensive usage data automatically, including:

IP address and device information
App usage patterns and interactions
Feature usage and preferences
Session duration and frequency
Crash reports and error logs
Search queries and results interaction

Image Data

Important: Images you upload or take through our app are:

  • Only saved for display purposes - to show you the results of your ThriftAI scan
  • Not used for AI training or any other data processing
  • Not shared with third parties except as required for the scan functionality
  • Can be deleted by you at any time through your account settings

Third-Party Analytics & Advertising Data

We use extensive tracking through the following services:

RevenueCat

For subscription and purchase analytics:

• Purchase behavior and patterns• Subscription status and renewals• Revenue attribution• Cohort analysis• Churn prediction• Lifetime value calculations

Meta (Facebook/Instagram) Ads

For advertising optimization and targeting:

• Ad performance tracking• Conversion tracking• Custom audience creation• Lookalike audience generation• Retargeting campaigns• Attribution modeling

TikTok Ads

For TikTok advertising and analytics:

• Campaign performance tracking• User behavior analysis• Conversion optimization• Audience insights• Attribution tracking• Custom event tracking

4. Legal Basis for Processing (GDPR)

We process your personal data based on the following legal grounds:

Consent

When you provide explicit consent for advertising tracking, analytics, and marketing communications

Contract

To perform our contract with you and provide the ThriftAI Service

Legitimate Interest

For improving our Service, security, business operations, and fraud prevention

Legal Obligation

To comply with applicable laws and regulations

5. How We Use Your Personal Data

Service Provision

  • • Provide AI-powered thrift recommendations
  • • Manage your account and preferences
  • • Process subscriptions and purchases
  • • Provide customer support

Analytics & Optimization

  • • Analyze app usage and performance
  • • Improve AI algorithms and features
  • • Optimize user experience
  • • Measure subscription performance

Marketing & Advertising

  • • Deliver personalized advertisements
  • • Measure ad effectiveness
  • • Create custom audiences
  • • Send promotional communications

Security & Compliance

  • • Ensure platform security
  • • Prevent fraud and abuse
  • • Comply with legal obligations
  • • Resolve disputes

6. Data Sharing and Disclosure

⚠️ Important: We do not sell your personal data to third parties.

We may share your personal information in the following situations:

Third-Party Analytics Providers

RevenueCat, Meta, TikTok for analytics and advertising purposes (with your consent)

Service Providers

Cloud hosting, payment processing, customer support, and other operational services

Legal Compliance

When required by law, court order, or legal process

Business Transfers

In case of merger, acquisition, or sale of assets (with prior notice)

7. Data Retention

Account Data

Until account deletion + 30 days

Usage & Analytics Data

2-3 years for business analytics

Images

Until you delete them or close your account

Legal Compliance Data

As required by Danish/EU law

8. Your Rights Under GDPR

As a data subject under GDPR, you have the following rights:

Access & Portability

  • • Request access to your data
  • • Receive data in structured format
  • • Transfer data to another service

Control & Correction

  • • Correct inaccurate data
  • • Restrict processing
  • • Object to processing

Deletion & Consent

  • • Request data deletion
  • • Withdraw consent anytime
  • • Opt-out of tracking

Legal Recourse

  • • File complaints with authorities
  • • Seek legal remedies
  • • Contact our DPO

9. Cookies and Tracking

We use extensive tracking technologies including:

Essential Cookies

Session management, authentication, preferences

Analytics Cookies

Usage patterns, performance metrics, A/B testing

Advertising Cookies

Ad targeting, conversion tracking, retargeting

You can control cookies through your browser settings, but some functionality may be limited.

10. International Data Transfers

Your data may be transferred outside the EEA to:

United States: Meta, RevenueCat, TikTok (with adequate safeguards)
Safeguards: Standard Contractual Clauses, adequacy decisions, certification schemes

11. Children's Privacy

Age Requirement: 16+

Our Service is not intended for anyone under the age of 16. We do not knowingly collect personal data from children under 16.

If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately and we will take steps to remove such information.

12. Data Security

We implement comprehensive security measures to protect your personal data:

Technical Safeguards

  • • Encryption in transit and at rest
  • • Secure API communications
  • • Regular security audits
  • • Access logging and monitoring

Organizational Measures

  • • Staff training on data protection
  • • Access controls and authentication
  • • Incident response procedures
  • • Regular policy updates

Note: While we implement industry-standard security measures, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by:

Posting the new Privacy Policy in the app
Sending you an email notification
Push notification (if enabled)
Updating the "Last updated" date

Important: For significant changes affecting your rights, we will obtain your consent where required by law.

15. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us:

General Inquiries

Email: simon@thriftai.io

GDPR Requests

Email: simon@thriftai.io

For data access, deletion, or portability requests

Response Time

We will respond to your inquiry within 30 days as required by GDPR

Danish Data Protection Agency

If you wish to file a complaint about our data processing, you can contact the Danish Data Protection Agency (Datatilsynet):

Website: www.datatilsynet.dk

Email: dt@datatilsynet.dk

Thank you for trusting ThriftAI with your data

We're committed to protecting your privacy while delivering the best thrift shopping experience