Privacy Policy
Last updated: 08 August 2025
1. Introduction
Fiwera Ltd (“we”, “our”, “us”) is committed to protecting your privacy and respecting your personal data.
We operate the website fiwera.com and related services (the “Service”).
Fiwera Ltd is a company registered in England & Wales.
Company number: 16636767
Registered office: 28 Chieftan Drive, Purfleet-On-Thames, England, RM19 1PN
Contact email: support@fiwera.com
This Privacy Policy explains how we collect, use, and safeguard your information when you use our Service, and what rights you have under applicable data protection laws, including the UK GDPR.
2. Data we collect
We collect the following categories of information:
A. Information you provide to us
- Account details: username, email address, full name (optional), password (stored securely via Supabase).
- Saved content: items, outfits, or game results you save to your account.
- Communications: feedback, support requests, bug reports, feature suggestions, and any other messages you send via our contact forms.
- Google account data (if you sign in with Google): name, email address, and Google account ID (we do not receive your Google password).
B. Information collected automatically
When you use our Service, certain information is collected automatically through cookies and similar technologies:
- Analytics data:
- PostHog (EU endpoint) — usage analytics and product improvement.
- Vercel Analytics — aggregated performance and traffic insights.
- Device and browser information: browser type, operating system, device type, screen resolution, and similar technical details.
- IP address: collected by our analytics and hosting providers for security and fraud prevention. Where possible, we anonymise or store only aggregated IP data.
- Cookies:
- Essential cookies — required for site functionality.
- Non-essential cookies — analytics, only set with your consent (via our cookie banner).
- Affiliate link tracking — clicking an affiliate product link may allow the destination site or network to set tracking cookies or collect information (e.g., that you came from Fiwera) to attribute purchases. These parties operate under their own privacy policies.
C. Information from third-party services
- Google Authentication: if you sign in with Google, we receive your Google profile name, email address, and Google account ID to create/manage your account.
- Email delivery provider (Resend): when we send transactional emails (e.g., password reset), your email and related metadata are processed to deliver the message.
3. How we use your data
We use the information described in Section 2 for the following purposes:
- To provide and operate the Service
- Create and manage your account.
- Enable features such as saving outfits, participating in games, and viewing your saved content.
- Send transactional messages (via Resend) such as password resets, confirmations, or service notifications.
- To improve and develop the Service
- Diagnose technical issues, fix bugs, and ensure cross-device/browser performance.
- Understand interactions using aggregated analytics (PostHog EU, Vercel Analytics).
- To personalise your experience
- Remember preferences (e.g., cookie consent, session).
- Recommend content/features where consented to analytics.
- For analytics and measurement
- Collect anonymised/aggregated usage patterns.
- Measure feature/design effectiveness.
- Track affiliate clicks to attribute commissions; we don’t receive personal purchase details.
- For security and fraud prevention
- Monitor suspicious activity, protect accounts, and prevent unauthorised access.
- Maintain server/app logs (via Supabase and hosting) to investigate incidents.
- To comply with legal obligations
- Maintain required business records.
- Respond to lawful requests from public authorities.
5. Legal bases for processing (UK/EU users)
- Consent — for non-essential cookies/analytics (PostHog, Vercel). Withdraw anytime via cookie preferences.
- Contract — to provide requested features when you create/use an account.
- Legitimate interests — essential analytics, security, and fraud prevention, balanced against your rights.
- Legal obligation — to comply with applicable laws (e.g., tax, corporate, law enforcement).
7. International transfers
Some providers process data outside the UK/EEA. Where we transfer data internationally, we rely on:
- Adequacy decisions by the UK/EU, or
- Standard Contractual Clauses (SCCs) ensuring equivalent protection.
Examples:
- Data sent to Resend or Google may be processed in the US under SCCs.
- Vercel may process data globally with SCCs where applicable.
We transfer only the minimum necessary data to provide the Service.
8. Data retention
We keep data only as long as needed for the Service and purposes in this policy, unless longer retention is required by law.
- Account data: kept until deletion or inactivity for 24 months.
- Communications: up to 24 months after resolution.
- Analytics:
- PostHog — events up to 12 months before aggregation/deletion.
- Vercel Analytics — aggregated data up to 13 months.
- Cookies: up to 6 months for non-essential analytics (unless you withdraw consent earlier).
- Legal/transactional records: typically 6 years (UK tax law).
When no longer needed, we delete or anonymise your data.
9. Your rights
If you are in the UK or EEA, you have the right to:
- Access — request a copy of your personal data.
- Rectification — correct inaccurate/incomplete data.
- Erasure — request deletion (“right to be forgotten”).
- Restriction — limit processing in certain cases.
- Data portability — obtain data in a machine-readable format.
- Object — to processing based on legitimate interests, including direct marketing.
- Withdraw consent — for consent-based processing (e.g., analytics cookies) at any time via cookie settings.
To exercise these rights, email support@fiwera.com. We’ll respond within one month.
10. Contact details
We operate fiwera.com and related services (the “Service”).
Fiwera Ltd — registered in England & Wales.
- Company number: 16636767
- Registered office: 28 Chieftan Drive, Purfleet-On-Thames, England, RM19 1PN
- Contact email: support@fiwera.com
11. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will update the “Last updated” date at the top of this page.
If changes are material, we will provide additional notice (e.g., a prominent notice on our website or an email). We encourage you to review this page periodically.