CabinaCabina

Privacy Policy

Last updated: August 10, 2026

This notice describes how Cabina handles personal data, under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR). It is written on how the service actually works: where a piece of data never leaves your device we say so, and where it is instead sent to an external provider we say that just as plainly.

1. Who handles your data

The data controller is Cabina di Zanre Arouna, VAT number IT03151380353. For any question, or to exercise your rights, you can write to privacy@cabina.io.

No data protection officer (DPO) has been appointed: the conditions of Art. 37 GDPR do not apply.

2. Two different roles, not to be confused

Cabina acts in two distinct capacities, and which one is in play decides who determines what happens to your data:

  • Controller — for anyone who visits this site, joins the waiting list or opens an account as a shop (merchant). In these cases we determine the purposes and means of the processing, and sections 3, 4 and 5 apply.
  • Processor — for the data of people who use the virtual try-on widget inside a shop’s website. There the controller is the shop that installed Cabina: we process that data only to deliver the service to them, on their instructions. Section 6 applies, but the notice that concerns you as a shopper is the shop’s own.

3. If you visit this site

We use no profiling cookies, no analytics and no advertising trackers. There is no Google Analytics and there are no third-party pixels: that is why the site shows you no cookie banner — it does not need one.

The provider that hosts the site (Vercel) records technical request logs, which include the IP address, for infrastructure security and diagnostics. That processing is necessary for the service to work (legitimate interest, Art. 6(1)(f) GDPR) and those logs are short-lived.

4. If you join the waiting list

  • What we collect: your email address, the page you filled the form in from, and the date you signed up. Nothing else.
  • Why: to let you know when we open the next group of shops. We send no newsletters, we do no profiling, and we pass your address to no one.
  • Legal basis: your consent (Art. 6(1)(a) GDPR), given by submitting the form and withdrawable at any time.
  • For how long: until the service opens, or until you ask us to remove you — by writing to info@cabina.io or to privacy@cabina.io. Removal is immediate and needs no explanation.

5. If you open an account as a shop

  • Sign-in: your email address, used for the sign-in link, or your Google profile if you choose to sign in with Google (we receive email and name, nothing else).
  • Use of the service: widget configuration, the catalogue of uploaded garments, session and credit counters. They are needed to deliver the service and to bill it.
  • Payments: handled by Stripe. Card details travel straight to Stripe and we never see them; we keep only the Stripe customer identifier and the purchase history.
  • Legal basis: performance of the contract (Art. 6(1)(b)) and, for tax and accounting obligations, legal obligation (Art. 6(1)(c)).
  • For how long: as long as the account exists. On deletion, the account’s data and files are permanently erased after 7 days, save for what the law requires us to keep for tax purposes.

6. The try-on widget: what leaves your device and what does not

This is the part that matters most, so we set it out properly. The widget has two modes, and they handle data differently.

  • Measurements: estimated from a photo, not stored by us. To suggest a size, your photo is sent to an external image analysis service, which estimates height, bust, waist and hips from it. You see the numbers and can correct them before continuing: we do not save them on our servers and they do not stay on your device — they disappear at the end of the session. This transfer, too, happens only after the consent you tick before uploading the photo.
  • In the generative try-on, the photo is sent to an external provider. If you choose the try-on on your own photo, the image is sent to the processing provider PrunaAI, which generates the picture with the garment on. This happens only after explicit, specific consent, which you tick before uploading the photo: until the box is ticked, uploading is not even possible, and the try-on on a preset model stays available without sending anything of yours. Consent is withdrawn by unticking that same box, at any time. Under the same consent, after generation the produced image — you wearing the garment — is sent to Novita AI for an automatic quality check: the garment in the result is compared with the product photo, and if it does not match the image is discarded and regenerated for whoever tries after you (details in section 7). We handle the image of your face and body with the care required for special categories of data (Art. 9 GDPR). At the provider your photo is deleted within 24 hours and is not used to train models; processing takes place on infrastructure in the United States — the details are in section 7.
  • The generated image lasts at most 30 days. It is kept in a private space, reachable only through temporary signed links that expire after an hour, and it is deleted automatically within 30 days. It exists only to avoid regenerating the same image. The shop has no access to these images.
  • Consent register. So that we can demonstrate consent was collected, we save a minimal and deliberately non-identifying record: date, version of the consent text, and a random session reference which is neither linked nor linkable to your identity.

7. Who else processes data for us

We rely on providers acting as processors, each for its own function:

  • Vercel — hosting of the site and the application.
  • Supabase — database, authentication and file storage.
  • Stripe — payments and invoicing.
  • Railway — the service that prepares the images and forwards them to the generative model.
  • PrunaAI — image processing for the generative try-on. Processing and temporary storage of the photo take place on infrastructure in the United States, on the basis of the standard contractual clauses (see the paragraph at the end of this section). PrunaAI in turn uses Modal as its compute provider. The photo is not used to train, fine-tune or evaluate models and is deleted within 24 hours: they confirmed this to us in writing on 16 August 2026.
  • Novita AI — image analysis: estimating body measurements from the photo, when you choose the try-on on your own photo, recognising the garment category, and — after generation — checking the quality of the result: it receives the produced image (you wearing the garment) together with the product photo and answers whether the garment matches. In every case it receives resized images and returns only numeric and textual values, never an image. The provider states that it also processes data outside the European Union, in particular in the United States, on the basis of the standard contractual clauses (see the paragraph at the end of this section), and that it applies a “zero retention” policy to transmitted content, which it does not use to train its own models.
  • Resend — sending service emails (sign-in links, plan notices).
  • Sentry — application error reporting.
  • Upstash — rate limiting, against automated abuse.

Some of these providers also process data outside the European Union, in particular in the United States. In those cases the transfer takes place on the basis of the safeguards provided for in Chapter V of the GDPR, namely the standard contractual clauses adopted by the European Commission and included in the providers’ contracts.

8. Your rights

You can ask us at any time to give you access to your data, to correct it, erase it, restrict its processing, to receive it in a readable format (portability) and to object to the processing. Where processing is based on consent, you can withdraw it whenever you like, without affecting what was done before the withdrawal.

Write to privacy@cabina.io: we reply within one month. If you believe the processing infringes the Regulation, you have the right to lodge a complaint with the Italian Data Protection Authority or with the supervisory authority of your country.

9. Changes to this notice

If the way we handle data changes, we update this page and the date at the top. When the change is substantial — a new provider that processes images, for instance — we flag it in the product too, not only here.

This document is written in Italian and translated into other languages for ease of reading. In case of any discrepancy between versions, the Italian version prevails.