Policy 02
Privacy notice
We hold as little as the service can work with, we say plainly what each piece is for, and we never use anything you upload to train a model.

- Last updated
- 5 September 2026
- Applies under
- UK GDPR, DPA 2018, EU GDPR, CCPA
- Supervisory authority
- Information Commissioner’s Office
Something here unclear? Write to us and a person will answer. Support.
1. Who is responsible
The company that operates Betweenshoes is the controller of the personal data described here. Its registered details and the ways to contact it are on the legal information page. For anything about your data, write to support@primehosiery.shop.
2. What we collect
- Account data. Your email address, a hashed password, the plan you are on, and the date you joined.
- Photographs you upload. Three flat photographs per reading — trousers, socks, shoes — together with the colour, lightness and surface values read from them.
- What you type. The sentence describing where you are going, and any follow-up question you ask about a reading.
- Readings. The result produced for each set of three, so you can look at it again.
- Billing data. Your plan, the billing period, the amount, and a reference held by our payment processor. We never see or store your card number.
- Technical data. IP address, browser type and the pages requested, kept in server logs for security and for diagnosing faults.
- Analytics data. Aggregated page-view counts, and only if you accepted analytics cookies.
We do not ask for your name, your address, your age beyond confirming a minimum, or anything about your body. We have no use for any of it.
3. Why, and on what legal basis
- To provide the service you subscribed to — performance of a contract. This covers your account, your photographs, your readings and your billing record.
- To keep the service secure and working — our legitimate interests in running a service that is not abused and does not fall over. This covers server logs and rate limiting.
- To send service messages — performance of a contract. Renewal reminders, order confirmations, and notice of changes that affect you. These are separate emails and carry no marketing.
- To meet legal obligations — retaining billing records for the period tax law requires.
- Analytics — your consent, given through the cookie notice, and withdrawable at any time on the cookies page.
We do not send marketing email unless you ask us to, and if you ever do, one click stops it.
4. Your photographs
A photograph is uploaded, its dominant colour, lightness and surface are read, and those values are what the reading is built from. The reading itself is calculated in your browser.
The service is built for photographs of items laid flat on a surface. It does not accept photographs of anyone wearing clothing, and it produces no image of a person, a leg or a foot. If you upload something that appears to show a person wearing the item, the upload is refused and nothing is stored.
You can delete any reading from your account. Deleting a reading deletes its photographs at the same time, from live storage immediately and from backups within 30 days.
5. Model training
Nothing you upload, type or produce on this service is used to train, fine-tune or evaluate any machine learning model. Not by us, and not by anybody we work with. Our agreements with the providers who process images on our behalf prohibit it, and we do not grant, sell or licence your content to anyone for that purpose.
6. How long we keep things
- Photographs and readings — until you delete them, or until 30 days after you close your account, whichever comes first.
- Account data — for as long as your account is open, then deleted within 30 days of closure.
- Billing records — six years from the end of the relevant financial year, which is what UK tax law requires.
- Server logs — 90 days.
- Analytics data — 14 months, in aggregated form.
7. Who else processes it
We use a small number of suppliers, each under a written contract that restricts them to acting on our instructions:
- a cloud hosting and application platform provider;
- a database, authentication and file storage provider;
- an image recognition provider, which reads colour values from photographs;
- a payment processor, which handles card details so that we never receive them;
- an email delivery provider, for service messages.
We do not sell personal data, and we do not share it with anybody for their own marketing.
8. Transfers outside the UK
Some of those suppliers are outside the United Kingdom. Where personal data is transferred to a country that is not covered by UK adequacy regulations, we rely on the UK International Data Transfer Agreement (IDTA), or on the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, and we carry out a transfer risk assessment before the transfer begins.
You can ask us for a copy of the safeguards that apply to a particular transfer by writing to support@primehosiery.shop.
9. Your rights
Under the UK GDPR and the Data Protection Act 2018 you have the right to:
- be told what we hold about you, and get a copy of it;
- have inaccurate data corrected;
- have data erased, where there is no overriding reason for us to keep it;
- restrict how we process it while a question about it is resolved;
- receive the data you gave us in a portable, machine-readable form;
- object to processing carried out on the basis of legitimate interests;
- withdraw consent at any time, where consent is what we relied on.
Write to support@primehosiery.shop and we will respond within one month. There is no charge. We do not make any decision about you by automated means that produces a legal or similarly significant effect.
10. If you are in California
Under the California Consumer Privacy Act, as amended, you may ask what categories of personal information we have collected, request a copy, ask us to delete it, and ask us to correct it. You have the right not to be discriminated against for exercising any of those rights, and we do not treat anyone differently for doing so.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. There is therefore nothing for you to opt out of, but the request routes above are open to you all the same.
11. Security
The site is served over HTTPS throughout. Passwords are stored hashed, never in a readable form. Access to production data is restricted to the people who need it, and is logged. Uploaded files are stored in access-controlled storage and are not publicly addressable.
Card details are handled entirely by a PCI DSS compliant payment processor. They are entered on the processor’s own hosted form, they never reach our servers, and we never store them.
If a breach ever occurs that is likely to risk your rights and freedoms, we will tell the Information Commissioner’s Office within 72 hours and tell you without undue delay.
12. Cookies
We set strictly necessary cookies to keep you signed in and to remember your cookie choice. Analytics cookies are set only if you accept them. Everything we set, and how to change your mind, is on the cookies page.
13. Complaining to the ICO
If you are unhappy with how we have handled your personal data, please tell us first so that we can put it right. You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data protection, at any time and without going through us.
- Online: ico.org.uk/make-a-complaint
- By telephone: 0303 123 1113
- By post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
If you are in the EEA, you may instead complain to the supervisory authority in the country where you live.