Privacy Policy

Last updated: July 2026

This Privacy Policy explains how Mathias Rading (“we”, “us”, “the operator”), the operator of MyStyle (mystyleweb.com) (“the Service”), collects, uses, stores, and protects your personal data, and describes your rights under the EU General Data Protection Regulation (GDPR).

Data controller: Mathias Rading (operator of MyStyle), Denmark. Contact: [email protected].


1. Information We Collect

  • Account information: When you create an account, we collect and store a username, a display name, and your email address. If you register with an email and password, your password is stored only in hashed form.
  • Google sign-in information: If you choose to sign in with Google, we receive your email address and basic profile information (such as your name and profile picture) from Google. We do not receive your Google password.
  • Uploaded content: Images and related information you add (such as wardrobe items and saved outfits) are stored under your personal user folder. These images are held in object storage located in the European Union.
  • Session data: If you use the Service without an account, your preferences and any items you create are stored temporarily in your browser session and are not linked to an identified person.
  • Technical data and logs: Our servers automatically record technical information needed to operate and secure the Service, including your IP address, access times, security-related events (such as sign-in attempts and rate-limiting events), and error events. We also keep a limited record of privacy-related account actions (such as account creation, consent changes, authentication changes, data export, and deletion) for accountability purposes.
  • Cookies: See Section 9.

2. How We Use Your Information

  • Account and service delivery: To create, maintain, and provide your account and the features of the Service, including sign-in, storing your wardrobe and outfits, and account deletion.
  • Communication: To send you account-related messages, such as email verification and password-reset emails.
  • Security and abuse prevention: To keep the Service secure and to prevent, detect, and address fraud, abuse, or technical problems (including rate limiting and monitoring of sign-in attempts).
  • Service improvement: To operate, maintain, and improve the Service.
  • Optional features: With your consent, for optional purposes such as analytics.

We do not sell or rent your personal data. We do not use automated decision-making that produces legal or similarly significant effects concerning you.


3. Legal Basis for Processing

Under the GDPR, we process personal data on the following legal bases:

  • Performance of a contract (Art. 6(1)(b)) – to create and maintain your account and provide the Service you request.
  • Legitimate interests (Art. 6(1)(f)) – to keep the Service secure, prevent abuse, and maintain and improve the Service. Where we rely on legitimate interests, we balance them against your rights and freedoms.
  • Consent (Art. 6(1)(a)) – for optional cookies and any optional features that require it. You may withdraw consent at any time.
  • Legal obligation (Art. 6(1)(c)) – where we are required to process, retain, or disclose information under applicable law.

4. Data Retention

  • Account information and uploaded content are retained for as long as your account exists.
  • When you delete your account, we take steps to permanently remove your account information and uploaded files. Residual copies may remain in secure backups for a limited period before they are overwritten or deleted.
  • Security and privacy-related log data is retained for up to 270 days.
  • Session data for logged-out users expires automatically and is not retained long-term.

5. Third-Party Service Providers

We use a limited number of trusted providers to operate the Service. These providers process personal data only on our behalf and in accordance with their own privacy terms:

  • Hetzner (Germany) – hosting of the application and database. Data is stored in the EU.
  • Cloudflare – storage of uploaded images and content delivery. Uploaded images are stored in the European Union.
  • Brevo (France) – sending transactional emails such as verification and password-reset messages.
  • Zoho (EU data region) – operating our contact email inbox.
  • Google – providing the optional “Sign in with Google” feature.
  • PayPal – processing voluntary donations. Payment is handled entirely by PayPal; we do not receive or store your payment card details.

We do not share your personal data with third parties for their own marketing purposes. Please review these providers’ privacy policies when relevant.


6. International Data Transfers

Our hosting, database, and image storage are located in the European Union. Some providers (such as Google and Cloudflare) are established outside the European Economic Area (EEA) or are part of international groups. Where personal data is transferred outside the EEA, we rely on appropriate safeguards (such as the EU–U.S. Data Privacy Framework and/or Standard Contractual Clauses approved by the European Commission) to ensure your data remains protected.


7. Data Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or loss. Passwords are hashed, connections are encrypted in transit, and access to data is restricted. However, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security. In the event of a personal data breach affecting your rights, we will notify the competent supervisory authority and, where required by law, affected users, without undue delay and within the timeframes required by applicable law.


8. Your Rights

Under the GDPR, you have the right to:

  • Access the personal data we hold about you and request a copy, including in a structured, commonly used, machine-readable format (data portability).
  • Request correction of inaccurate data or completion of incomplete data.
  • Request deletion of your data (“right to be forgotten”). You can delete your account and its associated data at any time from your settings.
  • Restrict or object to certain processing, including processing based on our legitimate interests.
  • Withdraw consent at any time where processing is based on consent (for example, optional cookies).
  • Lodge a complaint with a data protection supervisory authority. In Denmark, this is Datatilsynet (the Danish Data Protection Agency).

To exercise your rights, contact us at [email protected].


9. Cookies

  • Necessary cookies: required for the Service to function, such as authentication and session management. These are always active.
  • Optional cookies: with your explicit consent, we may use optional cookies, for example for analytics. Optional cookies are only set after you consent via our cookie banner or settings.

You can manage or withdraw your cookie preferences at any time in your settings. Any advertising features we may introduce in the future would likewise only set cookies with your consent.


10. Children

The Service is not directed at children. You must be at least 16 years old to create an account or use account-based features. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will take appropriate steps to delete it.


11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.


12. Contact

  • Data controller: Mathias Rading (operator of MyStyle)
  • Email: [email protected]
  • Country: Denmark

Welcome to MyStyle!

To personalize your experience, please choose what kind of clothing you'd like to see:

You can change this preference later in your settings.