Legal

Privacy Policy

πŸ“… Effective: March 1, 2026 πŸ”„ Last updated: March 1, 2026
Your privacy matters to us. This policy explains what data we collect, why we collect it, and how you can control it. We will never sell your personal data to third parties.

01 Who We Are

Rewear ("we," "us," or "our") operates the Rewear peer-to-peer fashion rental marketplace, accessible via the Rewear mobile app and joinrewear.com. This Privacy Policy describes how we collect, use, and protect your personal information when you use our Platform.

For the purposes of applicable data protection law, Rewear is the data controller of your personal information.

02 Data We Collect

We collect information in three ways: information you give us, information generated by your use of the Platform, and information from third parties.

Category Examples Source
Account Data Name, email address, profile photo, password (hashed) You
Listing Data Item descriptions, photos, pricing, availability You
Transaction Data Booking history, rental amounts, payment status You + Platform
Payment Data Last 4 digits, billing address, payment tokens (full card details held by processor) Payment processor
Identity Verification Government ID (for high-value lenders), selfie photo You
Communication Data In-app chat messages between users You
Device & Usage Data IP address, device type, OS, app interactions, crash logs Automatically
Location Data Approximate location (city level) for listing discovery Device (with permission)
Waitlist Data Name, email, city, interests provided on joinrewear.com You

03 How We Use Your Data

We use your personal data only for the purposes described below:

  • Providing the Platform β€” creating and managing your account, processing bookings and payments, enabling messaging between users
  • Trust & Safety β€” verifying identities, detecting fraud, resolving disputes, enforcing our Terms of Service
  • AI Condition Analysis β€” processing garment images you upload through our AI tools (see Section 6)
  • Communications β€” sending booking confirmations, payment receipts, product updates, and (with your consent) marketing emails
  • Improving the Platform β€” analysing usage patterns to fix bugs, improve features, and understand user needs
  • Legal compliance β€” meeting our obligations under applicable law, including tax and financial regulations

We will not use your data for purposes incompatible with the above without your explicit consent.

04 Data Sharing

We do not sell your personal data. We share data only in the following limited circumstances:

  • Other users β€” your public profile, listings, and reviews are visible to other Platform users. Your contact details are never shared directly.
  • Payment processors β€” we use third-party payment providers to process transactions. They receive payment data necessary to complete transactions.
  • Service providers β€” we engage trusted vendors for hosting (Firebase/Google), analytics, customer support, and email delivery. These vendors are bound by confidentiality obligations.
  • Legal requirements β€” we may disclose data when required by law, court order, or to protect the rights and safety of Rewear and its users.
  • Business transfers β€” in the event of a merger, acquisition, or sale of assets, user data may be transferred as part of that transaction.

05 Firebase & Google Services

Rewear is built on Google Firebase, which means your data is stored and processed on Google's infrastructure. Specifically we use:

  • Firebase Authentication β€” secure account login and session management
  • Cloud Firestore β€” database for user profiles, listings, bookings, and messages
  • Firebase Storage β€” secure storage for photos and media uploads
  • Firebase Cloud Functions β€” server-side processing including AI analysis
  • Firebase Analytics β€” anonymised usage analytics to improve the Platform
Google's use of data from Firebase services is governed by Google's Privacy Policy (policies.google.com/privacy). Google does not use Firebase user data for advertising purposes.

06 AI & Image Processing

When you use our AI Condition Report feature, photos you upload are sent to Google Gemini (a Google AI service) for analysis. This processing occurs server-side via Firebase Cloud Functions.

  • Images are processed in real time and are not stored by Google for model training based on our API usage terms
  • Condition reports generated are stored in your Rewear account and associated with the relevant listing or booking
  • You control which images you submit for AI analysis β€” it is always initiated by your action

By using the AI Condition Report feature, you consent to your images being processed by Google Gemini as described above.

07 Cookies & Analytics

Our website (joinrewear.com) uses cookies and similar technologies to:

  • Keep you logged in across sessions
  • Remember your preferences
  • Understand how visitors use our site (via Firebase Analytics)

Analytics data is aggregated and anonymised where possible. You can control cookie preferences through your browser settings. Disabling cookies may affect Platform functionality.

We do not use third-party advertising cookies or share analytics data with ad networks.

08 Data Retention

We retain your personal data for as long as your account is active and for a reasonable period thereafter to comply with legal obligations and resolve disputes.

  • Account data β€” retained while your account is active, deleted within 90 days of account closure on request
  • Transaction records β€” retained for 7 years for tax and financial compliance
  • Chat messages β€” retained for 12 months after the related rental ends
  • Waitlist data β€” retained until the waitlist program ends or you unsubscribe
  • Crash & usage logs β€” retained for 90 days then automatically deleted

09 Your Rights

Depending on where you live, you have the following rights regarding your personal data:

πŸ” Access
Request a copy of the personal data we hold about you
✏️ Correction
Ask us to correct inaccurate or incomplete data
πŸ—‘οΈ Deletion
Request deletion of your data (subject to legal retention requirements)
πŸ“¦ Portability
Receive your data in a structured, machine-readable format
🚫 Objection
Object to processing based on legitimate interests or for direct marketing
⏸️ Restriction
Ask us to restrict processing in certain circumstances

To exercise any of these rights, email us at privacy@joinrewear.com. We will respond within 30 days. If you are in the EU/UK, you also have the right to lodge a complaint with your local data protection authority.

California residents (CCPA): You have the right to know, delete, and opt out of the sale of personal information. We do not sell personal information. To submit a CCPA request, contact privacy@joinrewear.com.

10 Security

We take security seriously and implement appropriate technical and organisational measures to protect your personal data, including:

  • Encryption in transit (TLS) and at rest for sensitive data
  • Firebase security rules restricting data access to authorised users only
  • Regular security reviews and access controls
  • Secrets management for API keys via Firebase Secret Manager (never in source code)

No system is 100% secure. If you discover a security vulnerability, please report it responsibly to security@joinrewear.com.

11 Children's Privacy

Rewear is not directed at children under 18. We do not knowingly collect personal data from anyone under 18 years of age. If we become aware that a user is under 18, we will promptly delete their account and associated data. If you believe a child has provided us with personal data, please contact privacy@joinrewear.com.

12 International Transfers

Rewear operates globally and your data may be transferred to and processed in countries other than your own, including the United States where Google's servers are located. These transfers are made under appropriate safeguards, including Google's standard contractual clauses, to ensure your data receives equivalent protection.

13 Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or in-app notification at least 14 days before the changes take effect. The "Last updated" date at the top of this page will always reflect the most recent version. Your continued use of the Platform after changes take effect constitutes acceptance of the updated policy.

14 Contact & DPO

If you have any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact us:

Privacy & Data Requests
πŸ“§ privacy@joinrewear.com

General Enquiries
πŸ“§ hello@joinrewear.com
🌐 joinrewear.com

We aim to respond to all privacy-related requests within 30 days.