Fit Analytics Innovation GmbH
Last Significant Update: 13 Aug 2026
Fit Analytics Innovation GmbH ("we", "us", "our") is committed to protecting your privacy. This privacy policy explains how we collect, use, and safeguard the user’s (“you”, “your”) personal data when interacting with our Products, including Fit Finder, Fit Cues, the Shopping Assistant, and any future additions (collectively, the "Products"), as integrated via Widget (SDK) or API into the websites of our commercial partners ("Stores").
Stores may license any individual Product or combination of Products, and we may expand our offerings over time. Because feature availability varies by Store, certain data processing activities described below may not apply to your visit. Where a section applies exclusively to a single Product, it is explicitly noted.
For more on how we use AI within our Products and how we meet the transparency requirements of the EU AI Act, please refer to our AI Transparency Statement.
We collect the following types of personal data depending on which Product you interact with:
Technical Data: Information collected automatically when you visit a Store with our Products integrated, such as IP address, browser/device characteristics, User Agent, and session/account identifiers provided by the Store. We combine some of these into an identifier to recognise you as a returning visitor within that specific Store only, never across different Stores.
Usage Data: Information about how you interact with our Products and the Store's website, including pages viewed, items added to your cart (with selected sizes), the pages where our Products are loaded, session timestamps/duration, and feature variants shown during performance testing.
User Inputs: The measurements, preferences, and reference items you provide so we can recommend a size. This may include height, weight, age, bra size, body shape, fit preference, and existing reference brands/sizes. Providing this data is optional, but necessary to receive personalised size recommendations.
Conversation Data (Shopping Assistant Only): Text and query inputs you send when chatting with the Shopping Assistant (e.g., questions regarding sizing, fit, or styling preferences). We process this data solely to respond to your questions and refine Assistant recommendations.
Transaction Data: Purchase and return information shared with us by the Store (such as order IDs, items purchased, and returned items). We use this to evaluate and improve the accuracy of our size and fit algorithms over time.
Note: We only process pseudonymised data, meaning the data cannot be directly linked to your actual identity without additional information. We do not ask for or collect direct identifiers such as your name, email address, phone number, or shipping address, and we do not attempt to link the data we hold to your real identity. Indirect identifiers such as Store Session IDs, Store User IDs, Order IDs, and IP addresses are strictly pseudonymised.
This is subject to one exception. Conversations with the Shopping Assistant are free text, so any information you choose to include in a message is stored as part of that conversation. We recommend you do not share any unnecessary personal information with the Shopping Assistant.
All collected data is managed with strict security measures to ensure your privacy and data protection.
The collected data is used to:
Provide personalised size recommendations and conversational shopping assistance.
Identify items and the sizes available from Store pages.
Enhance the accuracy, quality, and user experience of our Products, including testing feature updates.
Provide Stores with performance metrics and insights regarding our Products.
Facilitate billing for our services to the Store.
We store all collected data exclusively in multi-region data centres within the European Union, hosted on Google Cloud Platform (GCP). This ensures that our data handling practices comply fully with the General Data Protection Regulation (GDPR). Our data protection measures include encryption, access controls, and regular security audits to safeguard data against unauthorised access and breaches. Where any of our service providers process data outside the European Union, we apply the safeguards described under International Data Transfers.
Data is retained according to our Data Retention section below. Access to personal data is restricted to authorised personnel only and is subject to strict confidentiality obligations.
This policy describes how we process personal data on behalf of the Stores that use our Products.
As a data processor, we do not own the collected data; full ownership and control remain with the respective Stores.
All data processing is carried out strictly in accordance with the Store’s instructions and under contractual obligations. We execute Data Processing Agreements (DPAs) with each Store, which define our scope of processing, outline technical security measures, and enforce strict compliance with applicable data protection laws, including GDPR. Stores serve as the data controller of processed data, and are responsible for maintaining their own privacy notices accordingly.
Our processing activities are conducted in accordance with GDPR. We rely on the following lawful bases for processing personal data:
Explicit User Consent: We obtain explicit consent from users for processing activities such as analytics and personalised size recommendations. As a user, you can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
Contractual Necessity: We process personal data that is necessary to fulfil our contractual obligations under data processing agreements with partner Stores and to provide services to users under our agreed terms and conditions.
Legitimate Interests: Apart from legal obligations or contractual necessity, we also process data based on legitimate interests to ensure the security and functionality of our Products, as long as it does not conflict with users' rights.
Compliance with Legal Obligations: Personal data is processed if necessary to comply with legal obligations, including regulatory requirements and lawful requests from public authorities.
Loading our Products on a Store's website requires your consent. There are two ways consent can be given:
Store’s Cookie Consent: by accepting analytics cookies through the Store’s cookie consent banner, where analytics covers our product usage.
Fit Analytics Consent: by consenting to the use of our products directly through our Fit Finder widget or the Shopping Assistant.
This consent allows us to collect and analyse the usage data needed to provide personalised size recommendations and shopping assistance, improve our Products over time, and report on their effectiveness to the Store. Without your consent, our Products will not load and you will not be able to use them.
We do not use the data for any purpose other than those described in this policy.
You can manage and withdraw your consent in the following ways:
The Store’s Cookie Consent Settings: Change your analytics consent settings using the cookie management option on the Store’s website. This applies to all analytics on the Store’s website, including ours;
Our Privacy Settings: Withdraw your consent through the privacy settings in the Fit Finder widget or in the Shopping Assistant. This withdrawal applies only to our Products.
You can also delete your size profile at any time through the privacy settings in our widget, or clear everything we have stored on your device by deleting all cookies and storage whose name begins with "fitanalytics" through your browser settings.
For assistance with managing your consent preferences, contact us at privacy@fitanalytics.com.
Our Products are intended for use by adults. Where consent is required from a child, or from a parent or guardian on a child's behalf, the Store is responsible for obtaining it.
To provide a personalised experience, we store a small amount of information on your device using cookies and your browser's local and session storage. Every item we store has a name beginning with "fitanalytics", so that you can find and remove it through your browser settings.
fitanalytics.consent: A cookie recording whether you have given consent, so that we do not ask again on every visit. This cookie is retained for 13 months.
fitanalytics.identity.token: A cookie holding a short-lived token that identifies your session while you use our Products. This cookie is retained for up to 30 days.
fitanalytics.state.*: Local and session storage holding your display preferences, such as which prompts you have dismissed, together with short-lived technical data. Retained until you clear it through your browser settings, or until you close the tab for session storage.
fitanalytics.profile.*: Session storage holding your profile data temporarily so it carries across our different features to enhance your experience. The session is cleared when you close the tab.
None of these items are used to track you across websites. They are set within the context of the Store’s domain and cannot be accessed or read by any other website. For some integrations, such as API, we store no data on your device, and session management is handled directly by the Store.
You can clear this information at any time through your browser settings. See Managing Consent above for how to withdraw your consent entirely.
You have comprehensive rights regarding your personal data, as granted by GDPR and other relevant data protection laws. These rights include:
Access, Correction, and Deletion: You have the right to request access to your personal data, correct inaccuracies, or request the deletion of their data.
Restriction and Objection: You can request the restriction of processing your personal data or object to processing based on legitimate interests or for direct marketing purposes.
Data Portability: You have the right to request the transfer of your personal data to another controller.
Withdrawal of Consent: You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
Right to Complain: You have the right to lodge a complaint with a data protection supervisory authority in the country where you live or work. Our lead authority is the Berlin Commissioner for Data Protection and Freedom of Information.
We facilitate the exercise of these rights via email to ensure secure and verifiable communication. Please direct all such requests to our dedicated email at privacy@fitanalytics.com.
We will respond to all requests within one month of receipt. Where a request is particularly complex, we may extend this by up to two further months, and will tell you within the first month if we need to. For requests under the California Consumer Privacy Act, we will acknowledge your request within 10 business days and respond within 45 calendar days.
We implement advanced technical and organisational measures to protect the security of all personal data, ensuring data integrity and protection against unauthorised access. Leveraging the robust security infrastructure provided by Google Cloud Platform (GCP), our security measures include:
Encryption: Personal data is protected during transmission and storage using the industry-standard encryption protocols Transport Layer Security (TLS >=1.2) for data in transit and Advanced Encryption Standard (AES-256) for data at rest.
Secure Storage and Processing: We use Google Cloud Platform (GCP) services, including but not limited to BigQuery, Google Cloud Storage (GCS), Pub/Sub, and Dataflow, to store, process, and transfer data securely. These services are compliant with GDPR and other relevant regulations.
API Security: Data received through API calls is secured using JSON Web Tokens (JWT) to ensure that only authorised users and applications can access the data.
Access Controls: Access to personal data is restricted to authorised personnel only and is subject to strict confidentiality obligations. Data access is audited twice a year to ensure compliance.
Regular Security Reviews: We conduct regular reviews of our security practices to ensure ongoing protection of personal data.
Incident Response: We have an incident response plan in place to address any data breaches or security incidents promptly and effectively, including notifying affected users and relevant authorities as required by law.
By implementing these measures, we ensure that your personal data is handled securely and in compliance with GDPR as well as other relevant data protection regulations, such as the California Consumer Privacy Act (CCPA) or Data Protection Act 2018.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements.
Shopper data, including your size profile and your usage and technical data, is retained for no longer than two years.
Conversation history from the Shopping Assistant is retained for no longer than 90 days.
Anonymised and aggregated data is retained indefinitely for reporting, statistical, financial, and other lawful purposes. This data no longer identifies you and cannot be linked back to you.
Business records such as invoicing and accounting data are retained for the periods required by law.
We regularly review our retention practices. For more detailed information, contact us at privacy@fitanalytics.com.
As part of our services, we act as a data processor on behalf of our partner Stores, who act as the data controllers. In this role, we may transfer processed data back to the relevant Store, including Stores located outside the European Union. We are committed to ensuring that these data transfers are conducted securely and in compliance with applicable data protection laws.
When a Store requests data, we share it as they are the rightful data owners. We adhere to strict protocols to ensure that all international data transfers are secure and comply with relevant regulations.
We use a small number of service providers to operate our Products. These are listed in our sub-processor list, which is available on request. For any service providers that process personal data outside the European Union, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum. To request a copy of these safeguards, contact us at privacy@fitanalytics.com.
We do not sell personal data, and we do not share it with third parties for their own purposes.
To operate our Products, we rely on a limited number of trusted service providers who process data strictly on our behalf and under binding contractual obligations. These providers support our operations through cloud hosting, secure data storage, and powering the AI models behind the Shopping Assistant. They may not use the data for any purpose of their own. Our current sub-processor list is available on request.
We do not use advertising networks, marketing platforms, session recording tools, or third-party analytics services.
Automated decision-making refers to making decisions or generating recommendations using automated algorithms without human involvement, based on data you provide.
Fit Finder can use automated decision-making to preselect sizes for you. This is done by analysing the measurements and fit preferences you voluntarily provide, alongside pseudonymised purchase and return data shared by the Store. The sole purpose of these automated suggestions is to enhance your shopping experience by helping you find the right fit quickly. The automated size preselection can be changed by you at any time during your shopping session.
We comply with GDPR and US privacy laws by ensuring transparency and obtaining user consent for these automated processes. These automated decisions do not impact your rights or freedoms, and are intended to improve your shopping experience.
Do Not Track ("DNT") is a privacy preference that can be set in certain web browsers. There is no common standard for how DNT signals should be interpreted, and we do not currently respond to them. You can control our processing of your data through the consent mechanism described under the Manage Consent section above.
This Privacy Policy is updated to reflect changes in our practices or legal requirements. It is reviewed at least annually or more frequently as required by regulatory shifts, organisational needs, or emerging requirements. When updates occur, we will notify the Stores that use our Products before publishing the revised version. If an update affects how we collect or use your data, we will notify you directly through our Products.
You are encouraged to review this Privacy Policy periodically to stay informed about how we are protecting your personal data.
For questions or concerns about our data privacy practices, or to exercise your data rights, please contact our Data Protection Officer at:
Data Protection Officer
Fit Analytics Innovation GmbH
Schwedter Straße 263
10119 Berlin, Germany