Last updated: September 12, 2025
SIZEBAY provides technology solutions for fashion e-commerce, offered under a software as a service (SaaS) model. The purpose of these solutions is to enhance the shopping experience of end consumers, increase sales for CLIENTS, and reduce return rates.
This Privacy Policy applies exclusively to SIZEBAY SOLUTIONS integrated into CLIENTS’ online stores, including, but not limited to, Virtual Fitting Room, Size Chart, Fashion Hint, Fashion Looks, Fashion Image Search, Intelligence, My.Sizebay, Order Tracker, and any new products that may be made available.
For information about cookies and data collected directly on the SIZEBAY institutional website (www.sizebay.com), the specific policy made available by the consent management platform adopted by SIZEBAY applies and does not form part of this document.
OVERVIEW
This PRIVACY POLICY explains how SIZEBAY processes data during the use and access of its applications and website. It also explains data subjects’ rights and how they can exercise them with SIZEBAY.
PLEASE READ THIS POLICY CAREFULLY. By using the solutions developed by SIZEBAY, you consent to this PRIVACY POLICY and fully acknowledge and agree to how we will use information and data collected during the use of the website and the services developed by SIZEBAY.
1. HOW DOES SIZEBAY COLLECT DATA?

1.1 Data collection occurs when the USER uses the SIZEBAY SOLUTIONS integrated into the CLIENT’s ONLINE STORE. For size recommendations, product suggestions, and statistical reports to function properly, the USER may provide minimum information such as height, weight, age, gender, and, where applicable, body measurements.
1.2 In addition to data provided directly by the USER, technical records may be collected during the use of the SIZEBAY SOLUTIONS through technologies such as cookies, SDKs, APIs, tags, or browsing events. This information is essential to ensure the proper functioning of the SOLUTIONS, optimize performance, ensure operational security, generate statistical analyses, and support continuous improvements to the features provided.
1.3 Within the Fashion Image Search feature, the USER may upload images to perform visual searches. These images are processed solely to identify similar products available in the ONLINE STORE’s catalog and are not stored by SIZEBAY after the search is processed.
1.4 SIZEBAY may also receive from the CLIENT information necessary for the operation of the SOLUTIONS, such as catalog data (descriptions, images, measurements, size charts), orders placed, and return data (via Order Tracker), used exclusively to enable the contracted features and to generate statistical reports for the CLIENT.
2. WHAT DATA ARE COLLECTED BY SIZEBAY?
2.1 SIZEBAY may collect the following information:
Category | Examples | Purpose of processing | Source |
Profile data | Nickname (optional); Age; Gender; Height; Weight; Body profile; Body measurements | (i) Performance of contract: information necessary to provide personalized size recommendations; avatar/look composition; and personalization of the experience in the SIZEBAY SOLUTIONS. | Provided by the USER |
Order and behavioral data | Order number; Product code/SKU; Product permalink; Product price; Size purchased; Size recommended; Add/remove items in cart; Product returns | (i) Performance of contract: to ensure the functioning of the SOLUTIONS (size recommendations, suggestions, and looks) as well as the preparation of dashboards and reports for the ONLINE STORE. (ii) Legitimate interest: preparation of statistical reports without identifying the user, to enable continuous improvement of the solutions and user experience. | Provided by the CLIENT |
Device technical data and access logs | User ID (random number); user clicks on Virtual Fitting Room and Size Chart buttons; views and interactions with SIZEBAY Solutions; suggested products; most-clicked, viewed, and most-purchased products | (i) Performance of contract: size recommendation, proper functioning of the solutions, and optimization of performance/experience. (ii) Legitimate interest: statistical reporting without user identification, enabling continuous improvement of the solutions. | Obtained by SIZEBAY via cookies and other technologies linked to the SOLUTIONS |
Image data uploaded by the user (where applicable) | Images voluntarily uploaded by the USER in the visual search (Fashion Image Search) or other features that allow uploads | (i) Performance of contract: to enable the image search requested within the ONLINE STORE environment, identifying similar or complementary products. (ii) Legitimate interest: continuous improvement of AI models and output accuracy. | Provided by the USER |
Catalog data | Descriptions; Images; Measurements; Size Chart; Price; Stock quantity | (i) Performance of contract: to ensure the functioning of the SOLUTIONS (recommendations, suggestions, and looks) and the preparation of dashboards/reports for the ONLINE STORE. | Provided by the CLIENT |
2.2 SIZEBAY may also receive operational data provided directly by the online store, such as public product images (including with models or visual renderings), size charts, descriptions, SKUs and catalog information, order data, and return data (without identification and without customer contact data).
Such data are the exclusive responsibility and property of the online store and are used solely to enable proper operation of the SIZEBAY SOLUTIONS, allowing for size suggestions, look composition, statistical reports, and visual searches, in accordance with the contract executed between SIZEBAY and the ONLINE STORE. For the purposes of data protection laws (LGPD, GDPR, and CCPA), this data is not considered personal data and is treated as operational and commercial business data.
2.3 When using the SIZEBAY SOLUTIONS within the online store, our systems may automatically generate processed results. This data is referred to as derived data or outputs and is created from the operation of SIZEBAY’s tools and the use of technologies such as artificial intelligence, statistical models, and machine learning algorithms. Outputs may include, for example, recommendations of similar products, outfit suggestions (looks), comparative size visualizations, or graphical renderings (such as dynamically generated avatars using store products). This data is generated to enable the functionalities of the SIZEBAY SOLUTIONS and to provide a more personalized experience in the ONLINE STORE, without involving information that allows user identification.
2.4 No information will be used outside the purpose for which it was provided or captured. Data will be processed for the period necessary to perform the contracted SOLUTIONS, to comply with legal/regulatory/contractual obligations and/or to preserve rights in administrative, arbitral, or judicial proceedings, while applying anonymization or pseudonymization whenever possible.
2.5 Images sent by the USER within the image search feature (Fashion Image Search) are used solely to process the search and are not stored by SIZEBAY.
2.6 The USER may delete cookies stored in their browser at any time. Doing so causes SIZEBAY to lose the reference between that browser/device and previously recorded events; thus, any data collected up to that point will persist only in statistical and aggregated form, without an individualizable association with the USER. From deletion onward, a new cycle of technical identification begins with no link to prior records.

2.7 SIZEBAY may process anonymized and aggregated data resulting from users’ use of the solutions and interactions in online stores for statistical analysis, business intelligence, new product development, improvement of predictive models and algorithms, and the generation of dashboards, reports, and operational insights for online stores. Anonymized data, whether alone or in combination with other data, does not allow the identification, direct or indirect, of a natural person, nor can it be reversed for reidentification purposes.
3. WITH WHOM DOES SIZEBAY SHARE DATA?
3.1 To provide the best possible experience with our services, SIZEBAY may rely on third-party companies, and will do so only with entities that ensure security standards that are adequate and consistent with market practice.
3.2 SIZEBAY uses specialized providers for data hosting, processing, information security, and statistical analysis. To clarify how data sharing occurs:
With whom? | Data category | Purpose |
Amazon Web Services | Profile data; Purchase data | (i) Data storage; (ii) Data querying and processing |
ClickHouse | Anonymized and aggregated usage data from the SOLUTIONS; Purchase data | Large-scale data storage and analysis; generation of insights and reports |
3.3. Regarding data storage, SIZEBAY uses cloud infrastructure providers including Amazon Web Services (AWS), located in regions such as Ireland and the United States, and ClickHouse Cloud, a managed service by ClickHouse Inc. operating on AWS infrastructure, ensuring the same security and compliance standards. Currently, data may be stored in the following data centers:
- Amazon AWS South Dublin Data Center, Greenhills Road, Tymon North, Dublin, Ireland; and/or
- Amazon AWS Ashburn Data Center, 21155 Smith Switch Road, Ashburn, VA, USA.
3.3.1. When used, ClickHouse Cloud is provisioned in the same AWS data centers, so the physical infrastructure remains the same, with additional management performed by ClickHouse Inc.
3.4 Data processed in the context of SIZEBAY solutions is shared with the ONLINE STORE that has contracted SIZEBAY and makes SIZEBAY solutions available in its digital environment.

3.5 SIZEBAY clarifies that only the data and information strictly necessary for the provision of services by partner companies and suppliers will be shared.
3.6 SIZEBAY does not share personal data with unauthorized third parties, does not sell data, and does not share data for its own direct marketing or that of third parties. Sharing occurs solely and exclusively under the terms described in this Policy and always for the purposes set out herein.
3.7 SIZEBAY may also share personal data where there is a legal obligation, order from a competent authority, or court order, always within the limits established by applicable law.
4. INTERNATIONAL DATA TRANSFERS

4.1 As mentioned above, SIZEBAY uses AWS cloud services located in Virginia (United States) and Dublin (Ireland), and Google analytics services (California, United States). Accordingly, data collected may be shared with these companies for the specific purposes described, and—depending on the user’s or visitor’s location—may be transferred internationally due to the location of these providers.
4.2 By accepting this Privacy Policy, the data subject declares that they have been duly informed about the conditions and risks involved in the international transfer of their personal data, including the possibility of transfer to servers located outside the country of origin of the data, and expressly consents to such transfers as set out in this Policy and in accordance with applicable data protection laws.
5. CHILDREN AND ADOLESCENTS

5.1 Minors may not use SIZEBAY solutions unless represented and/or assisted by their parents or legal guardians. Accordingly, we do not knowingly collect or process minors’ data.
5.2 Using features such as the Virtual Fitting Room, look generation, or other tools on behalf of a minor presumes such use occurs under the responsibility of an adult, who assumes full civil, administrative, and criminal responsibility for any act performed, information provided, or data entered in the use of the solutions.
6. WHAT ARE DATA SUBJECTS’ RIGHTS?
6.1 Data subjects may choose not to disclose their data to SIZEBAY, but some of this data may be necessary for users to access the services provided. Regardless, rights relating to privacy and the protection of personal data will be ensured.
6.2 Below are the rights of data subjects under data protection legislation:

Right to rectification: You may request correction and/or rectification of inaccurate personal data at any time. To implement rectification, it may be necessary to verify the validity of the data provided. Requests can be sent to privacy@sizebay.com.

Right of access: You may request confirmation of processing and access to your personal data, as well as information about its origin, criteria, and purposes. Requests can be sent to privacy@sizebay.com.

Right to erasure: You may request deletion of personal data. To request deletion from SIZEBAY’s database, email privacy@sizebay.com.

Right to request anonymization, blocking, or deletion: You may request suspension of processing in the following scenarios: (a) verification of data accuracy; (b) retention of data necessary to establish, exercise, or defend legal claims; (c) objection to the use of data, in which case the existence of legitimate grounds for use will be assessed.

Right to withdraw consent: You may withdraw the consent given to this Privacy Policy. Withdrawal does not affect the lawfulness of processing carried out previously, but it may prevent SIZEBAY from offering certain products/services.

Right to review automated decisions: You may request a review of decisions made solely on the basis of automated processing of personal data that affect your interests, including decisions aimed at defining personal, professional, consumer, and credit profiles and/or aspects of your personality.
6.3 Heirs or authorized representatives of data subjects have the right to access, correct, or delete the data subject’s data after their death, ensuring ongoing protection of personal data rights under applicable laws.
6.4 SIZEBAY may need to request specific information to confirm the identity of the data subject in order to ensure rights of access to personal data or the exercise of other rights inherent to the data subject. This is a security measure to prevent personal data from being disclosed to anyone not entitled to receive it.
6.4.1 Responses will be provided within 5 (five) business days. Occasionally, it may take longer than 5 (five) business days if the request is particularly complex or if the user/data subject has made multiple requests. In such cases, SIZEBAY will contact you to provide an updated status.
6.5 If you have questions about these matters or how to exercise your rights, contact SIZEBAY’s Data Protection Officer (DPO):

Marcelo Motta Bastos
União Europeia
privacy@sizebay.com

Janderson Roberto Araujo
Demais localidades
privacy@sizebay.com
7. HOW DOES SIZEBAY PROTECT YOUR DATA?
7.1 SIZEBAY considers the confidentiality and security of its customers’, users’, and visitors’ information to be extremely important. It uses encryption and firewall technologies and will do everything reasonably possible to protect your data and information. All data is confidential and only duly authorized persons will have access to it.
7.2 SIZEBAY applies high security standards; however, it is not possible to guarantee that all data and information in SIZEBAY’s database will be free from unauthorized access. We recommend adopting practical security measures for your account and devices.

Cookie cleaning: We recommend periodically clearing cookies stored in your browser to remove local browsing data and reset identifiers associated with the application’s use.

Protection software: We recommend using up-to-date antivirus and anti-malware programs and keeping systems and applications updated to reduce the risk of unauthorized access to devices.
7.3 In the event of a personal data breach processed by SIZEBAY, the company will promptly notify the data controller, providing relevant information about the incident and the measures taken to mitigate potential impacts. Responsibility for notifying data subjects and competent authorities will be assessed together with the controller, as required by applicable law.
7.4 In accordance with applicable laws, SIZEBAY undertakes to retain personal data for as long as necessary to fulfill the purposes for which it was collected. Once those purposes have been achieved or when the data is no longer needed, SIZEBAY will take the necessary steps to ensure deletion or anonymization of the data, considering legal, contractual, and business criteria.
8. UPDATES TO THIS PRIVACY POLICY
8.1 SIZEBAY reserves the right to amend this Policy whenever necessary in order to provide greater security and convenience and to continually improve the customer experience.
8.2 The date of the last update will always appear at the beginning of this Policy.
9. DISPUTE RESOLUTION
9.1 To resolve disputes arising from this Policy that cannot be settled amicably, the following will apply:
Location | Governing law | Forum |
United States | Laws of the State of Delaware | Delaware, United States |
European Union | Laws of Portugal | Coimbra, Portugal |
Other locations | Laws of the Federative Republic of Brazil | Joinville, Santa Catarina, Brazil |
10. HOW TO CONTACT SIZEBAY

10.1 For questions, suggestions, or requests related to this Policy, please contact the SIZEBAY team at privacy@sizebay.com.