Privacy Policy
1. Overview
Diamente LLC, a Texas limited liability company (“Diamente
LLC,” “MakeOutfit,” “we,” “our,” or “us”),
respects your privacy. This Privacy Policy describes how we collect,
use, disclose, retain, and protect personal information when you access
or use the MakeOutfit platform at makeoutfit.com, the subscription
portal at subscription.makeoutfit.com, or any associated mobile
application (collectively, the “Platform”), and the
rights and choices available to you under applicable U.S. federal and
state privacy laws.
This Privacy Policy is part of, and incorporated into, our Terms of
Service and (for boutiques, brands, and retailers) our Subscriber
Agreement. Capitalized terms not defined here have the meanings given in
those agreements. By using the Platform, you agree to the practices
described in this Privacy Policy.
The Platform is offered to users in the United States only. The
Platform is not directed to, and is not offered to, residents of the
European Economic Area, the United Kingdom, or Switzerland. The AI
Virtual Try-On Feature is further restricted from Illinois
residents.
2. Who This Policy Applies To
This Privacy Policy applies to everyone who interacts with
MakeOutfit, including:
- Visitors who browse the Platform without creating an
Account; - Consumers who create an Account and use Platform
features; - Consumers who purchase Try-On Credits;
- Users who activate the AI Virtual Try-On Feature;
- Subscribers and Brand Partners — boutiques,
brands, retailers, and the individuals who manage their accounts — who
purchase a paid Subscription and list products on the Platform (see
Section 4).
This Privacy Policy does not apply to third-party websites or
services linked from the Platform; please review the privacy policies of
those services separately.
3.
Information We Collect from Consumers and Visitors
3.1 Information You Provide
Directly
- Account information — name, username, email
address, password, profile photo, age confirmation, jurisdiction
confirmation; - Payment information — billing name, billing
address, and payment-card information (processed and stored by our
payment processor; we do not store full card numbers); - User Content — outfit creations, comments,
reviews, and photographs uploaded to the Platform, including
Self-Photographs uploaded to the Try-On Feature; - Communications — messages and inquiries you send
to us, customer-support requests, and survey responses; - Marketing preferences — your subscription to
email lists and opt-in / opt-out status.
3.2 Information We Collect
Automatically
- Device and browser information — IP address,
device identifiers, operating system, browser type, language
settings; - Usage information — pages visited, features
used, click data, search queries, time spent on the Platform, referring
/ exit pages; - Approximate location — derived from IP address,
used for geofencing and regional content; - Cookies and similar technologies — see Section
9.
3.3 Biometric Data
When you use the Try-On Feature, we process biometric identifiers and
biometric information (“Biometric Data”) derived from your uploaded
Self-Photograph, including facial- and body-geometry measurements.
Biometric Data is processed solely to generate AI Outputs. We collect
Biometric Data only after you provide separate, affirmative consent in
the Biometric Data Notice and Consent flow, and only if you are not a
resident of, or located in, Illinois. See Section 8.
3.4 Information from Third
Parties
- Social-login providers — if you sign in via
Apple, Google, or Facebook, we receive the information you authorize
through those providers (typically name, email, profile
picture); - Payment processors — transaction confirmations
and limited card metadata (last four digits, card brand,
expiration); - Analytics and advertising partners — see Section
9; - Brand Partners — when you interact with Partner
content, the Partner may share interaction data with us as permitted by
their own privacy practices.
3.5 Information We Do Not
Collect
We do not knowingly collect personal information from children under
13. We do not collect government identification numbers from consumers,
except where required for legal compliance (for example, tax-reporting
information we may collect from Subscribers under Section 4). We do not
collect health information unless you voluntarily provide it (which we
discourage).
4.
Information We Collect from Subscribers and Brand Partners
This Section describes the information we collect from boutiques,
brands, and retailers who purchase a Subscription and list products on
the Platform, and from the individuals who create and manage those
accounts. This is in addition to the consumer practices above where an
individual Subscriber also uses consumer features.
4.1 Business and Account
Information
- Business name, legal entity type, and business contact details
(contact name, email, phone, business address); - Account login credentials for the subscription portal;
- Store, brand, and inventory information you submit, including
product images, product descriptions, pricing, and links; - Marketing and communication preferences.
4.2 Billing and Tax
Information
- Billing name, billing address, and payment-card or other
payment-method information (processed and stored by our payment
processor); - Subscription plan, billing history, trial and coupon usage, and
renewal and cancellation records; - Tax-reporting information where required by law — for example, a
completed IRS Form W-9 and taxpayer identification number (TIN/EIN) when
payment or reporting thresholds apply. We collect and use this
information solely for tax compliance and store it with heightened
access controls.
4.3 Performance and Analytics
Data
We collect data about how consumers interact with your products and
content on the Platform (for example, views, saves, clicks, and outfit
inclusions). We use this to operate the Platform, to provide you with
performance reporting, and to improve the service.
4.4 How We Use Subscriber
Information
We use Subscriber and Brand Partner information to: provide and
manage the subscription service and the listing of your products;
process Subscription payments and manage billing, trials, coupons,
renewals, and cancellations; communicate with you about your account,
billing, and service changes; provide performance reporting; comply with
tax, accounting, and other legal obligations; prevent fraud and enforce
our agreements; and, where you have opted in, send marketing
communications (which you may opt out of at any time).
4.5 Sharing of Subscriber
Information
We share Subscriber information with service providers (hosting,
payment processing, tax/accounting, analytics, and communications) under
written agreements; with tax and regulatory authorities where required
by law; and as otherwise described in Sections 6 and 7. We do not sell
Subscriber personal information for monetary consideration.
5. How We Use Information
We use personal information to:
- Provide, operate, and maintain the Platform;
- Authenticate users and prevent fraud, abuse, and unauthorized
access; - Process Subscription payments, Try-On Credit purchases, and
manage billing; - Generate AI Outputs through the Try-On Feature (using Biometric
Data only with your separate consent and only for that
purpose); - Personalize your experience, including recommendations of
clothing and Brand Partner content; - Communicate with you about your Account, Subscription, Credits,
and Platform changes; - Send marketing communications where you have opted in (you may
opt out at any time); - Conduct analytics and improve the Platform, subject to the AI
restrictions in Section 8; - Comply with legal obligations and enforce our Terms of Service
and Subscriber Agreement; - Establish, exercise, or defend legal claims.
5.1 We
Do Not Train AI on Your Photographs or Biometric Data
| Important. We do not use your uploaded photographs, Self-Photographs, AI Outputs, or Biometric Data to train, fine-tune, evaluate, or develop any artificial-intelligence or machine-learning model. Biometric Data is used only to render the specific AI Output you request and is then destroyed in accordance with Section 8. Any analytics we perform to improve the Platform use aggregated or de-identified data that is not used to re-identify you. |
6. Legal Bases for Processing
Where required by applicable state law (such as the Texas Data
Privacy and Security Act, the California Consumer Privacy Act as amended
(Cal. Civ. Code § 1798.100 et seq.), the Virginia Consumer Data
Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy
Act, the Utah Consumer Privacy Act, and similar statutes), we process
personal information on the following bases:
- Contractual necessity — to perform our agreement
with you (for example, to provide the Platform or Subscription you
signed up for); - Legitimate interests — to operate, secure, and
improve the Platform, including fraud prevention and analytics, where
consistent with applicable law; - Consent — for Biometric Data processing,
marketing communications, optional cookies, and other processing
requiring affirmative consent; - Legal obligation — to comply with applicable
laws, regulations, court orders, or governmental requests; - Vital or public interest — in narrow
circumstances permitted by law.
7. How We Share Information
We share personal information only as described below.
7.1 Service Providers
We share personal information with vendors and service providers that
perform services on our behalf — including hosting, AI processing,
payment processing, tax and accounting, analytics, customer support,
communications, and security. These providers are bound by written
confidentiality and data-processing agreements that limit their use of
personal information to the services we have engaged them to perform.
Our AI-powered Virtual Try-On feature is processed by Google LLC (Gemini
API), which acts as our AI processing service provider for that feature
under such an agreement and is contractually prohibited from using your
information to train its models or for any purpose other than providing
the Try-On service to us.
7.2 Brand Partners
We may share aggregated, de-identified analytics with Brand Partners
(for example, overall product-performance statistics). We do not share
personal data of consumers with Brand Partners except (i) as you direct
(for example, when you elect to follow a Partner or share content), (ii)
as permitted by your privacy preferences, or (iii) as required by
law.
7.3 Legal and Safety
Disclosures
We may disclose personal information to law-enforcement, regulatory
authorities, or third parties:
- To comply with applicable law, court orders, subpoenas, or
governmental requests; - To enforce our Terms of Service, Subscriber Agreement, or other
agreements; - To investigate, prevent, or take action regarding suspected
fraud, security issues, or unlawful activity; - To protect the rights, property, or safety of Diamente LLC, our
users, or the public; - In connection with a merger, acquisition, financing, sale of
assets, bankruptcy, or similar transaction (we will require any
successor to honor this Privacy Policy or provide equivalent
protection).
7.4 With Your Consent
We may share personal information for purposes you specifically
consent to. You may withdraw your consent at any time, although
withdrawal does not affect prior processing.
7.5 No Sale of Personal
Information
We do not sell personal information for monetary consideration. We do
not sell, lease, or trade Biometric Data under any circumstances. For
purposes of state privacy laws that define “sale” or “sharing” more
broadly (such as cross-context behavioral advertising), please see
Section 12.
8. Biometric Data — Detailed
Practices
Biometric Data is highly sensitive, and we apply additional
protections to it. The following supplements (and does not replace) the
general practices described in this Privacy Policy.
8.1 What We Collect
When you use the Try-On Feature, we extract and process facial- and
body-geometry measurements from your uploaded Self-Photograph. These
measurements are used solely to align and render the AI Output.
8.2 Purpose Limitation
Biometric Data is used only to generate AI Outputs requested by you.
It is not used for identification, surveillance, advertising, marketing
profiling, training of AI models, or any other purpose without your
separate, affirmative consent.
8.3 Retention and Destruction
We retain Biometric Data only for the period strictly necessary to
provide the Try-On Feature, and we permanently destroy Biometric Data
within 72 hours after the earliest of: (a) your
deletion of the relevant photograph or AI Output; (b) your closure of
the Account; (c) your verified deletion request; or (d) the date the
Biometric Data is no longer necessary to fulfill its purpose. In no
event do we retain Biometric Data longer than required by Texas Bus.
& Com. Code § 503.001(c)(2), which sets a one-year outer limit.
8.4 No Sale or Disclosure
We do not sell, lease, or otherwise disclose Biometric Data to third
parties, except: (i) to service providers that process Biometric Data on
our behalf under binding confidentiality and data-processing agreements;
(ii) as required by court order, subpoena, or warrant; or (iii) with
your separate, written consent.
8.5 Security Safeguards
We protect Biometric Data with the same or greater care as we use to
protect other confidential and sensitive information, including
encryption in transit and at rest, role-based access controls, audit
logging, and regular security review.
8.6 Geographic Restrictions
Biometric Data is processed within the United States. We do not
transfer Biometric Data outside the United States.
8.7 Withdrawal of Consent
You may withdraw consent to Biometric Data processing at any time by
emailing [email protected], and you will be unable to use the
Try-On Feature thereafter unless and until you re-consent. Withdrawal
does not affect lawful processing prior to withdrawal.
9. Cookies and Tracking
Technologies
We use cookies, web beacons, pixel tags, and similar technologies
(collectively, “Tracking Technologies”) to operate the
Platform, remember your preferences, analyze traffic, and (where you
consent) deliver marketing.
9.1 Categories of Cookies
- Strictly necessary. Required for authentication,
security, and core Platform functionality. These cannot be disabled
through Platform settings. - Performance / analytics. Help us understand how
the Platform is used so we can improve it (for example, Google Analytics
or similar). - Preferences. Remember your settings, language,
and similar choices. - Marketing / advertising. Used (with your consent
where required) to deliver and measure advertising, including tools such
as Meta Pixel and similar.
9.2 How to Manage Cookies
You can manage cookies through your browser settings, through the
Platform’s cookie banner (where presented), and through your Account
preferences. Many browsers honor the Global Privacy Control
(“GPC”) signal as an opt-out from the sale and sharing
of personal information for cross-context behavioral advertising, and we
honor GPC where required by law.
9.3 “Do Not Track”
We process Global Privacy Control (GPC) signals as a valid opt-out
request from the sale or sharing of personal information for
cross-context behavioral advertising, as required by the California
Privacy Rights Act, the Colorado Privacy Act, and other applicable law.
Because there is no separate industry standard for general “Do Not
Track” signals, we do not currently respond to other DNT signals.
10. Data Retention
We retain personal information only for as long as necessary to
fulfill the purposes for which it was collected, including any legal,
accounting, or reporting requirements. General retention windows
include:
- Account information — for the life of the
Account plus a reasonable post-deletion period for backup purges
(typically 30–90 days); - Subscription, Credit, and billing records — up to seven
(7) years only where strictly required by applicable tax and accounting
laws, and only for the specific records subject to that
requirement; - User Content — until you delete it, plus
backup-purge windows; - Try-On uploads (non-biometric image data) —
destroyed within 30 days after the AI Output is generated, or sooner on
request; - Biometric Data — see Section 8.3 (within 72
hours); - Customer-support records — up to three (3)
years; - Logs and security records — up to two (2) years
for security and fraud-prevention purposes.
When personal information is no longer needed, we delete or
de-identify it. Where deletion is not technically feasible (for example,
backup media), we isolate and protect the information until deletion is
possible.
11. Security and Breach
Notification
We maintain administrative, technical, and physical safeguards
designed to protect personal information from unauthorized access, use,
disclosure, alteration, and destruction. These safeguards include
encryption in transit (TLS) and at rest, access controls and
least-privilege principles, audit logging, regular security review, and
vendor-management diligence.
No system is perfectly secure, and we cannot guarantee the absolute
security of personal information. If we become aware of a security
incident affecting your personal information, we will notify you and
applicable regulators as required by law, including under the Texas
Identity Theft Enforcement and Protection Act (which generally requires
notice without unreasonable delay and no later than 60 days after
determination of a breach) and the breach-notification laws of other
states in which affected individuals reside.
12. Your Rights — U.S.
State Privacy Laws
Depending on the state in which you reside, you may have one or more
of the rights described below. Some rights vary by jurisdiction; we
honor the rights to which you are entitled under applicable law.
12.1 Rights Available
Under State Privacy Laws
- Right to know / access. Request that we disclose
the personal information we collect, use, disclose, and (in some states)
sell or share about you. - Right to delete. Request that we delete personal
information we have collected about you, subject to legal
exceptions. - Right to correct. Request that we correct
inaccurate personal information we maintain about you. - Right to portability. Request a copy of your
personal information in a portable format. - Right to opt out of sale or sharing. Opt out of
any “sale” or “sharing” of personal information for cross-context
behavioral advertising. We do not sell personal information for monetary
consideration; “sharing” is addressed in Section 12.3. - Right to limit use of sensitive personal
information. Direct us to limit the use of sensitive personal
information, including Biometric Data, to purposes necessary to provide
the requested service. - Right to opt out of profiling. In states that
recognize this right, opt out of profiling in furtherance of decisions
that produce legal or similarly significant effects. - Right against discrimination. We will not
discriminate against you for exercising any of your privacy
rights. - Right to appeal. In states that provide an
appeal right (such as Virginia, Colorado, Connecticut, Texas, and
others), appeal any decision we make regarding your privacy request, as
described in Section 12.4.
12.2 How to Exercise Your
Rights
To exercise your rights, contact us through any of the following
channels:
- Email: [email protected];
- Online form: makeoutfit.com/privacy/request;
- Mail: Diamente LLC — Privacy Requests, 110 N Interstate
35, Ste 315 PMB 1015, Round Rock, Texas 78681,
USA.
We will verify your identity using information already on file (such
as confirmation through your Account email or matching account details)
before responding to substantive requests. We will respond to verifiable
requests within the timeframes required by applicable law (typically 45
days, with one extension of up to 45 additional days where reasonably
necessary). You may also designate an authorized agent to make a request
on your behalf, subject to verification of the agent’s authority and
your identity.
12.3 California Residents — CCPA
/ CPRA
In addition to the rights above, California residents have specific
rights under the California Consumer Privacy Act, as amended by the
California Privacy Rights Act (Cal. Civ. Code § 1798.100 et seq.). The
categories of personal information we have collected in the preceding 12
months are summarized below:
| Category (Cal. Civ. Code § 1798.140) | Collected? |
|---|---|
| A. Identifiers (name, email, IP address, account ID) | Yes |
| B. Customer records (billing / contact information) | Yes |
| C. Protected classifications (e.g., age, gender) | Limited |
| D. Commercial information (transactions) | Yes |
| E. Biometric information | Yes — Try-On only, with consent |
| F. Internet / network activity | Yes |
| G. Geolocation (precise) | No (approximate IP-based only) |
| H. Sensory data (audio, visual, similar) | Yes — photographs you upload |
| I. Professional / employment info | Limited — Subscribers only |
| J. Education info | No |
| K. Inferences from the above | Yes |
| L. Sensitive personal information (incl. Biometric Data) | Yes — see Section 8 |
We do not sell personal information for monetary consideration. To
the extent that the use of advertising cookies and analytics partners
constitutes “sharing” under the CPRA, you may opt out by submitting a
request through the channels in Section 12.2 or by enabling Global
Privacy Control in your browser. We do not knowingly sell or share
personal information of consumers under 16.
California Civil Code § 1798.83 (“Shine the Light”): California
residents may request information once per year about our disclosure of
personal information to third parties for direct-marketing purposes. We
do not disclose personal information to third parties for their
direct-marketing purposes.
California Civil Code § 1789.3: California residents may contact the
Complaint Assistance Unit of the Division of Consumer Services of the
California Department of Consumer Affairs at 1625 N. Market Blvd., Suite
N 112, Sacramento, CA 95834, or (800) 952-5210.
12.4
Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Other
Comprehensive-Law States
If you reside in a state with a comprehensive privacy statute —
including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah
(UCPA), Texas (TDPSA), Oregon (OCPA), Montana, Iowa, Indiana, Tennessee,
Florida, Delaware, New Hampshire, New Jersey, Kentucky, Maryland,
Minnesota, or Rhode Island — you have the rights described in Section
12.1 to the extent provided by your state’s law. Submit requests through
the channels in Section 12.2.
Appeal procedure. If you are denied a privacy
request and your state law provides an appeal right, you may appeal by
emailing [email protected] within 60 days of our response.
We will respond to appeals within the timeframe required by your state’s
law (typically 45–60 days). If your appeal is denied, you may contact
your state attorney general.
12.5 Sensitive
Personal Information / Biometric Opt-In
Several state privacy laws (including the Texas Data Privacy and
Security Act, the Connecticut Data Privacy Act, the Colorado Privacy
Act, and others) require affirmative consent before processing sensitive
personal information, including Biometric Data. We obtain such consent
through the separate Biometric Data Notice and Consent flow before
activating the Try-On Feature.
13. Children’s Privacy
The Platform is not directed to children under 13. We do not
knowingly collect personal information from children under 13. If we
learn that we have collected personal information from a child under 13
without verifiable parental consent (as required by COPPA, 15 U.S.C. §§
6501–6506), we will promptly delete that information.
Users 13 to 17 may use non-Try-On features only with the consent and
supervision of a parent or legal guardian. For users ages 13 to 17,
parental or guardian consent is obtained through the account creation
and Terms acceptance process, and the parent or guardian is responsible
for supervising the minor’s use of the Platform. The Try-On Feature is
restricted to users 18 and older.
Where applicable state law imposes additional duties with respect to
users under 18, we will implement required protections before making
features available to those users. We do not sell or share personal
information of consumers known to be under 16.
14. International Users
The Platform is offered to users located in the United States only.
The Platform is not directed to, and is not offered to, residents of the
European Economic Area, the United Kingdom, or Switzerland. We have
implemented technical measures intended to prevent access from those
jurisdictions. If you are located in those jurisdictions, do not access
the Platform. All personal information collected through the Platform is
stored and processed in the United States.
15. Third-Party Services
The Platform may contain links to or features that integrate with
third-party services (such as Brand Partner websites, social-networking
platforms, and payment processors). This Privacy Policy does not apply
to those services. We encourage you to read the privacy policies of any
third-party service you use.
16. Changes to This Privacy
Policy
We may update this Privacy Policy from time to time. The “Last
Updated” date at the top reflects the most recent revision. Material
changes will be communicated by email and in-Platform notification at
least 30 days before they take effect. Your continued use of the
Platform after the effective date constitutes acceptance of the updated
Privacy Policy.
17. Contact Us
For questions about this Privacy Policy or our privacy practices:
| Diamente LLC, d/b/a MakeOutfit
Attn: Privacy Officer 110 N Interstate 35, Ste 315 PMB 1015 Round Rock, Texas 78681, USA Email: [email protected] Privacy appeals: [email protected] |