Privacy
What we know about you — and what we don't.
Vinté+ is a directory of vintage and second-hand clothing shops. It doesn't live off advertising or off selling data, so this page is short on purpose: the less we collect, the less there is to explain.
This English version is provided for convenience. The Spanish version is the legally binding text.
The essentials
- Your location never leaves your phone. Not when sorting shops by distance, and not when alerting you that you're walking past one that's open.
- We don't sell data, we don't build advertising profiles, and no shop can pay to rank higher.
- The virtual try-on photo is used and discarded. It isn't stored.
- Every notification is optional, switched on one by one, and switched off from inside the app.
What data we handle
Your account. Email address and password — stored encrypted, never in the clear — the name you choose to display and, if you upload one, your profile photo. It's the minimum needed for your saves and holds to follow you from one phone to another.
What you save and put on hold. The shops you bookmark, the pieces you like and the ones you reserve, with the time each hold expires.
Your location. It's used to sort the directory by distance and to centre the map. If you switch on nearby-shop alerts, your phone additionally watches a few circles around the shops closest to you. In neither case does your position or your route leave the device: we don't receive them, we don't store them, and there is no way to reconstruct them from our servers.
Your photo, only in the virtual try-on. If you try a piece on, the image you choose is sent to the service that generates the try-on and discarded when it's done. It never passes through our storage.
Notification identifier. If you enable notifications, we store the identifier your operating system assigns to your device. It exists so we can deliver a notification and for nothing else; when you switch them off, it's deleted.
If you run a shop. The business's name, address, opening hours, logo and the photographs of the stock you publish. That's commercial information meant to be public.
What for, and on what legal basis
To provide the service (performance of a contract, art. 6.1.b GDPR): keeping your account, storing what you save, managing holds and letting you know when one is about to expire.
For the features you switch on yourself (consent, art. 6.1.a): flea-market alerts, new-city alerts, nearby-open-shop alerts and the virtual try-on. All of them start switched off, are enabled one by one, and can be withdrawn at any time without losing the rest of the service.
To keep the app working and safe (legitimate interest, art. 6.1.f): the minimal technical logs needed to detect errors and abuse.
We do no advertising profiling, we sell no data, and there is no automated decision-making with legal effects on anyone.
Who it's shared with
Only with the providers needed for the app to work, each acting as a data processor:
Supabase: accounts, database and storage for shop photographs.
Expo: notification delivery. It receives the device identifier and the text of the alert, nothing more.
Anthropic: framing of the garment photographs shops publish. It receives the photo of the stock; never data about users.
FASHN: generation of the virtual try-on image. It receives your photo only at the moment you ask to try something on.
Our own servers: garment photo processing runs on our own infrastructure.
Maps use OpenStreetMap cartography. No shop or third party can pay to appear, to appear higher, or to have you notified of its existence.
For how long
Your account and whatever you've saved, for as long as you keep it open. Expired holds and their trail, one year, so a disagreement with a shop can be resolved. The notification identifier, until you switch notifications off. The try-on photo isn't kept at all.
Deleting your account from the app removes everything of yours. If you run a shop, it must be transferred or closed first: a published business can't be left without someone responsible for it.
Your rights (GDPR)
Access, rectification, erasure, objection, restriction and portability. You exercise them by writing to the address below, and we reply within the month the regulation sets.
You can withdraw any consent without giving reasons and without losing the rest of the service, from Profile, Settings, Notifications inside the app, or from your phone's settings.
If you think we've got it wrong, you can lodge a complaint with the Spanish data-protection authority (AEPD, aepd.es).
Children
Vinté+ is not aimed at children under fourteen and we do not knowingly collect their information.
Data controller
Roberto Jiménez Manzano, a natural person registered as self-employed. Vinté+ and Vector Studio are his trading names, not companies.
Tax ID (NIF) Z2058723K. Carrer de Cadis 15, puerta 3, piso 2, 46004 València (Comunitat Valenciana, Spain).
For anything to do with your data, including exercising your rights: privacidad@vinte.plus. We reply within the month the regulation sets.
There is no data protection officer, and that's not an oversight. Article 37 of the regulation requires one where people are observed regularly and systematically on a large scale, and that doesn't happen here: the only feature that might look like it — the alert when you walk past a shop — is resolved entirely on your phone, and not a single coordinate reaches us.