Privacy
Privacy statement
This statement explains what personal data Looqa.ai processes, why we do so, and what your rights are. We comply with the General Data Protection Regulation (GDPR).
Last updated: 10 July 2026 · Version 1.1
Table of contents
Data controller
Looqa Technology B.V. (trading under the name Looqa.ai) is the data controller for the personal data processed through this website and the associated applications.
- Legal name
- Looqa Technology B.V.
- Trade name
- Looqa.ai
- KvK
- 42110646
- Establishment no.
- 000066141419
- Registered office
- Damcoogh 93, 1132 EB Volendam, the Netherlands
- Contact
- hello@looqa.ai
- Privacy contact
- privacy@looqa.ai
What data we collect
Depending on how you use Looqa, we process the following categories of personal data:
- Account data: email address, name (optional), hashed password, language preference and any style preferences.
- Wardrobe content: photos you upload or add via URL, metadata (category, colour, brand, size), wear log and saved outfits.
- Biometric data (special category, GDPR Art. 9): body scan photos for the virtual fitting room. These are only processed with your explicit consent and are stored encrypted.
- Characteristics derived from photos: AI image analysis derives characteristics from your photos: from clothing photos, for example, category, colour and material, and — only if you use the virtual fitting room with consent — appearance traits such as body type and skin-tone category to make the try-on result realistic. We use these characteristics solely for the feature you provide them for and do not infer ethnicity, health or other special categories from them for any other purpose.
- Payment data: subscription status and invoice information via Stripe. Looqa.ai does not itself store credit card numbers or IBANs.
- Technical data: IP address, browser type, time zone, session tokens and basic usage statistics for security and troubleshooting.
- Reports about AI results: if you report an AI result, we keep your report (reason and any explanation) in order to follow up on it.
Purposes and legal basis
We process personal data exclusively for clearly defined purposes, and always on the basis of a GDPR legal basis:
- Performance of a contract (Art. 6.1.b): we use account data and wardrobe content to provide the Looqa service to you — storing, searching, suggesting, virtual try-on.
- Legal obligation (Art. 6.1.c): for invoicing and tax administration we are required to retain certain data.
- Legitimate interest (Art. 6.1.f): for security (fraud prevention, DDoS mitigation), handling reports about AI results and product improvement at an aggregated level.
- Consent (Art. 6.1.a, and Art. 9.2.a for biometric data): for body scans, marketing communications and optional analytics. You can withdraw consent at any time.
- AI processing after explicit consent: your photos and garment data are only shared with the AI services Google Gemini and Replicate after you have given explicit permission in the app. You can withdraw that permission per category in your settings; new AI processing then stops immediately.
Retention periods
We do not keep your data longer than necessary. Specifically:
- Account: for as long as your account is active. After deletion, another 30 days in backups, then permanently erased.
- Body scans: until you delete your photo, withdraw your consent or delete your account. Removal from active storage happens immediately; copies in encrypted backups expire automatically within 30 days.
- Virtual try-on results: kept until you delete them yourself or delete your account; there is no automatic expiry period.
- Invoices and tax records: 7 years (statutory retention period of the Dutch Tax Administration).
- Log files (technical): 90 days at most.
Sub-processors
We work with carefully selected sub-processors that make our service possible. A data processing agreement has been concluded with each party:
| Party | Purpose | Location |
|---|---|---|
| Supabase | Database & file storage | EU (Frankfurt) |
| Vercel | Hosting | EU / US |
| Stripe | Payments (web) | EU / US (adequacy decision) |
| Google Cloud | AI image analysis (Gemini) | EU / US |
| Replicate | AI virtual fitting room | US (SCCs) |
| Sentry | Error monitoring (after consent) | EU / US |
| Upstash | Rate limiting (technical) | EU / US |
| Apple App Store | In-app purchases (iOS) | EU / US |
| Google Play | In-app purchases (Android) | EU / US |
| RevenueCat | Subscription management (mobile) | US (SCCs) |
We do not process payment data ourselves. For a purchase via the website, Stripe receives your payment and invoice details; for a purchase via the mobile app, payment and data go through Apple or Google under their own privacy policies. Looqa receives from these parties only the status of your subscription (active/expired) and a pseudonymous customer or transaction ID — never your full card details.
International transfers
For some AI services, processing takes place outside the EEA. For this we use appropriate safeguards: Standard Contractual Clauses (SCCs) of the European Commission, or applicable adequacy decisions (such as for Stripe). For the virtual fitting room, your body scan is processed temporarily and via a short-lived secure link by our AI processor Replicate in the US (under SCCs); storage remains in the EU.
Your rights
Under the GDPR you have the following rights:
- Access: request what data we hold about you.
- Rectification: have inaccurate data corrected.
- Erasure: have your account and all data deleted ("right to be forgotten").
- Restriction: have processing suspended during an investigation.
- Objection: object to processing based on legitimate interest.
- Data portability: a copy of your data in machine-readable form (JSON).
- Withdrawal of consent: for processing based on consent.
You can exercise these rights via your settings (signed in), via the public page looqa.ai/account/delete (account deletion, also without the app) or by sending an email to privacy@looqa.ai. You also have the right to lodge a complaint with the Autoriteit Persoonsgegevens (the Dutch Data Protection Authority).
Security
We take appropriate technical and organisational measures:
- Transport encryption (TLS 1.3) for all connections.
- Encryption at rest (AES-256) for sensitive data including body scans.
- Row-Level Security at database level — every user can only access their own data.
- Temporary signed URLs for access to stored files.
- Rate limiting and DDoS protection on all endpoints.
- Regular backups, automatic patching and access logging.
Minors
Looqa.ai is not intended for use by persons under the age of 16. We do not knowingly process data of minors without the consent of a parent or legal representative. If you discover that a child under 16 has left personal data with us, let us know via privacy@looqa.ai and we will delete the data.
Changes
This privacy statement may be amended in the future when our service or legislation changes. We announce material changes at least 30 days in advance by email to all registered users. The date at the top of this page indicates the latest update.
Contact
Questions about privacy or your rights? We answer everything personally within 30 days.