01 Who We Are
Rewear ("we," "us," or "our") operates the Rewear peer-to-peer fashion rental marketplace, accessible via the Rewear mobile app and joinrewear.com. This Privacy Policy describes how we collect, use, and protect your personal information when you use our Platform.
For the purposes of applicable data protection law, Rewear is the data controller of your personal information.
02 Data We Collect
We collect information in three ways: information you give us, information generated by your use of the Platform, and information from third parties.
| Category | Examples | Source |
|---|---|---|
| Account Data | Name, email address, profile photo, password (hashed) | You |
| Listing Data | Item descriptions, photos, pricing, availability | You |
| Transaction Data | Booking history, rental amounts, payment status | You + Platform |
| Payment Data | Last 4 digits, billing address, payment tokens (full card details held by processor) | Payment processor |
| Identity Verification | Government ID (for high-value lenders), selfie photo | You |
| Communication Data | In-app chat messages between users | You |
| Device & Usage Data | IP address, device type, OS, app interactions, crash logs | Automatically |
| Location Data | Approximate location (city level) for listing discovery | Device (with permission) |
| Waitlist Data | Name, email, city, interests provided on joinrewear.com | You |
03 How We Use Your Data
We use your personal data only for the purposes described below:
- Providing the Platform β creating and managing your account, processing bookings and payments, enabling messaging between users
- Trust & Safety β verifying identities, detecting fraud, resolving disputes, enforcing our Terms of Service
- AI Condition Analysis β processing garment images you upload through our AI tools (see Section 6)
- Communications β sending booking confirmations, payment receipts, product updates, and (with your consent) marketing emails
- Improving the Platform β analysing usage patterns to fix bugs, improve features, and understand user needs
- Legal compliance β meeting our obligations under applicable law, including tax and financial regulations
We will not use your data for purposes incompatible with the above without your explicit consent.
04 Data Sharing
We do not sell your personal data. We share data only in the following limited circumstances:
- Other users β your public profile, listings, and reviews are visible to other Platform users. Your contact details are never shared directly.
- Payment processors β we use third-party payment providers to process transactions. They receive payment data necessary to complete transactions.
- Service providers β we engage trusted vendors for hosting (Firebase/Google), analytics, customer support, and email delivery. These vendors are bound by confidentiality obligations.
- Legal requirements β we may disclose data when required by law, court order, or to protect the rights and safety of Rewear and its users.
- Business transfers β in the event of a merger, acquisition, or sale of assets, user data may be transferred as part of that transaction.
05 Firebase & Google Services
Rewear is built on Google Firebase, which means your data is stored and processed on Google's infrastructure. Specifically we use:
- Firebase Authentication β secure account login and session management
- Cloud Firestore β database for user profiles, listings, bookings, and messages
- Firebase Storage β secure storage for photos and media uploads
- Firebase Cloud Functions β server-side processing including AI analysis
- Firebase Analytics β anonymised usage analytics to improve the Platform
06 AI & Image Processing
When you use our AI Condition Report feature, photos you upload are sent to Google Gemini (a Google AI service) for analysis. This processing occurs server-side via Firebase Cloud Functions.
- Images are processed in real time and are not stored by Google for model training based on our API usage terms
- Condition reports generated are stored in your Rewear account and associated with the relevant listing or booking
- You control which images you submit for AI analysis β it is always initiated by your action
By using the AI Condition Report feature, you consent to your images being processed by Google Gemini as described above.
07 Cookies & Analytics
Our website (joinrewear.com) uses cookies and similar technologies to:
- Keep you logged in across sessions
- Remember your preferences
- Understand how visitors use our site (via Firebase Analytics)
Analytics data is aggregated and anonymised where possible. You can control cookie preferences through your browser settings. Disabling cookies may affect Platform functionality.
We do not use third-party advertising cookies or share analytics data with ad networks.
08 Data Retention
We retain your personal data for as long as your account is active and for a reasonable period thereafter to comply with legal obligations and resolve disputes.
- Account data β retained while your account is active, deleted within 90 days of account closure on request
- Transaction records β retained for 7 years for tax and financial compliance
- Chat messages β retained for 12 months after the related rental ends
- Waitlist data β retained until the waitlist program ends or you unsubscribe
- Crash & usage logs β retained for 90 days then automatically deleted
09 Your Rights
Depending on where you live, you have the following rights regarding your personal data:
To exercise any of these rights, email us at privacy@joinrewear.com. We will respond within 30 days. If you are in the EU/UK, you also have the right to lodge a complaint with your local data protection authority.
California residents (CCPA): You have the right to know, delete, and opt out of the sale of personal information. We do not sell personal information. To submit a CCPA request, contact privacy@joinrewear.com.
10 Security
We take security seriously and implement appropriate technical and organisational measures to protect your personal data, including:
- Encryption in transit (TLS) and at rest for sensitive data
- Firebase security rules restricting data access to authorised users only
- Regular security reviews and access controls
- Secrets management for API keys via Firebase Secret Manager (never in source code)
No system is 100% secure. If you discover a security vulnerability, please report it responsibly to security@joinrewear.com.
11 Children's Privacy
Rewear is not directed at children under 18. We do not knowingly collect personal data from anyone under 18 years of age. If we become aware that a user is under 18, we will promptly delete their account and associated data. If you believe a child has provided us with personal data, please contact privacy@joinrewear.com.
12 International Transfers
Rewear operates globally and your data may be transferred to and processed in countries other than your own, including the United States where Google's servers are located. These transfers are made under appropriate safeguards, including Google's standard contractual clauses, to ensure your data receives equivalent protection.
13 Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or in-app notification at least 14 days before the changes take effect. The "Last updated" date at the top of this page will always reflect the most recent version. Your continued use of the Platform after changes take effect constitutes acceptance of the updated policy.
14 Contact & DPO
If you have any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact us:
π§ privacy@joinrewear.com
General Enquiries
π§ hello@joinrewear.com
π joinrewear.com
We aim to respond to all privacy-related requests within 30 days.