Privacy Policy

This Privacy Policy explains what data we collect, how we use it, and your choices. By using MakeupCast, you consent to this policy.

1) Data we collect

  • Account data: email, basic profile, authentication identifiers (via Clerk/OAuth if applicable).
  • Preference/profile data: skin type, undertone, face shape, scene choices, report history (structured JSON, not raw images, unless you explicitly opt in to store them).
  • Technical data: device, browser, IP (truncated/region-level where feasible), timestamps, coarse location if you allow it for weather.
  • Payments: subscription status and transaction metadata (handled by our Merchant of Record; we do not store full card data).
  • Push/email preferences and tokens (for delivering notifications).

2) How we use data

  • Provide and improve daily reports and weather‑based tips.
  • Operate subscriptions, billing, quotas, and customer support.
  • Detect abuse and ensure service reliability and security.
  • Send push/email notifications if you opt in.
  • Run basic analytics to improve product (aggregate/limited scope).

3) Legal bases

We process data based on: (a) performance of a contract (providing the service); (b) legitimate interests (security, product improvement); and (c) consent (notifications, certain analytics).

4) Cookies & local storage

We use essential cookies/local storage for authentication, session state, and caching (e.g., a day’s report). You can control cookies in your browser settings. Some features may rely on local storage to improve speed.

5) Analytics

We use lightweight analytics (aggregate, no invasive fingerprinting) to understand feature usage and reliability. You may opt out where available in settings or via Do Not Track where supported.

6) Payments

Payments are processed by our Merchant of Record (e.g., Lemon Squeezy). We do not store full card numbers. The processor’s privacy terms apply in addition to this policy.

7) Push notifications & email

Web push requires your explicit consent; you can revoke it in the browser. Email is used for transactional messages and (optionally) product updates. You can unsubscribe at any time.

8) Data retention

We keep personal data only as long as necessary for the purposes outlined here. Report history may be retained to provide insights and allow your export requests. Backups are time‑limited.

9) Security

We use industry‑standard safeguards. No method is 100% secure; please keep your account credentials safe and report suspicious activity to support.

10) International transfers

Your data may be processed in countries other than your own. Where required, we implement safeguards such as standard contractual clauses or equivalent mechanisms.

11) Children’s privacy

Our service is not directed to children under the minimum age in your jurisdiction. If you believe we have collected data from a child without appropriate consent, contact us to delete it.

12) Your rights

  • Access/Export: request a copy of your profile/reports.
  • Deletion: request deletion of your account and associated data.
  • Objection/Restriction: where applicable by law (e.g., GDPR/CCPA), you may object to certain processing.

13) Changes

We may update this Privacy Policy to reflect product or legal changes. We will post the updated version with an effective date.

Effective date: 2025‑09‑07

14) Contact

Privacy questions or requests? Email privacy@makeupcast.com.