Privacy Policy — Fashion Brand Finder
1. Who is responsible
M8 Media by Manuel Bucher, Kaffeestrasse 6C, 8180 Bülach, Switzerland (CHE-203.493.947) is the controller for the personal data described here.
Contact for privacy matters: privacy@fashionbrandfinder.com
2. What this service is
Fashion Brand Finder is a directory of fashion brands and the shops that carry them. Most of it is public and needs no account: searching, browsing brands, and seeing which offers exist. An account adds personalisation, following, saving, and revealing discount codes.
3. What we collect, and why
We have written this from the actual database rather than from a template, so it is specific. Each item says what it is, why we hold it, and the legal basis.
If you only browse — no account
| Data | Why | Basis |
|---|---|---|
| Aggregate page-view counts per brand per day | To rank "Trending". We store a count against a brand and a date, nothing else — no user id, no session id, no IP, no per-view record. It is not possible for us to reconstruct what any individual looked at. | Legitimate interest (Art 6(1)(f) GDPR / Art 31 nDSG) — the interest is minimal and the data is not personal once aggregated |
| Standard server logs held by our hosting providers | Security and fault diagnosis | Legitimate interest |
We use no advertising trackers, no analytics profiling, and no cross-site tracking, and we do not sell or share data with advertisers. Paid placements on FBF are sold as fixed time slots and are not targeted at you — an advertiser never learns who saw their placement.
If we made a page about your brand and you never asked us to
Most of this directory was built by us, from public information, without the brands' involvement. If your brand name is also your own name — a sole proprietorship, or an eponymous label — then that page is personal data about you, and this section is the part of this policy that applies to you even though you have no account with us.
| Data | Why | Basis |
|---|---|---|
| Brand name, website and public social links, country, category, public certifications, a link to the brand's logo on its own site, and a short description we wrote from the brand's public About text | To run a public directory of fashion brands, and to contact the businesses in it | Legitimate interest (Art 6(1)(f) GDPR / Art 31 nDSG) — a directory of businesses cannot be built only from businesses that have already signed up, and we limit it to facts each business already publishes about itself |
| A business contact address, where one is published | To tell you the page exists and let you claim, correct or remove it | Legitimate interest — telling you is the point |
Where it comes from (Art 14(2)(f)): your own public website, and public certification listings. Your logo, where shown, is loaded from your own site and linked to it — we do not copy it, and we take no other imagery from your site; the artwork on a page we built is generated by us. The short description is written by us, in our own words and in the third person, from what your site says publicly — we do not copy your text and we do not write in your voice. The story field on a page we built is empty, and stays empty unless the brand fills it in. Values shown on such a page come only from certifications and statements the brand itself publishes; the brand can change or remove them at any time.
What you can do. Claim the page, ask us to correct specific facts without creating an account, or ask us to remove it. Removal is on request; we do not argue anyone into staying. Full detail, including the ten-working-day answer and why we ask you to show a connection to the brand before removing it, is in the notice-and-action policy §9. You can also object to us holding the data at all under Art 21 GDPR / Art 30 nDSG — that is the same route and we record it as an objection.
We accept we owe you this notice whether or not you ever contact us (Art 14). The outreach email we send when a page is created carries it, which is the point at which we are required to give it.
If you create an account
| Data | Why | Basis |
|---|---|---|
| Email address | It is how you sign in — we send a one-time code rather than storing a password | Contract (Art 6(1)(b)) |
| Display name, if you set one | To show who you are to your own team | Contract |
| Date of birth | To confirm you meet our minimum age, and to work out whether the quiz needs a parent's permission where you live (see §7) | Legal obligation / contract |
| Your country | To apply the right minimum-age rule for consent. You tell us; we do not infer it from your IP address | Legal obligation |
| Quiz answers: preferred styles, values, categories | To personalise your home page and rank search results for you. You can change or clear them at any time | Consent (Art 6(1)(a)) — and the app works without them |
| Brands and shops you follow, and your saved list | To show them to you | Contract |
| Searches you save in Discover: the filters, a label, and the brands that matched when you last opened it | To keep the search for you and to show how many new brands match it since you last looked | Contract |
| A record that you revealed a particular discount code, and when | To rate-limit abuse of the code system, and to show you your own saved codes. Codes you reveal appear in a "Your codes" list visible only to you; you can remove one at any time, which hides it from that list without deleting the record we need for rate limiting. We never show it to the brand | Contract |
If you represent a brand or shop
| Data | Why | Basis |
|---|---|---|
| Business contact email | To reach you about your listing. Held in a separate table that is not publicly readable | Contract |
| Ownership-verification evidence you upload (e.g. a commercial-register extract) | To confirm you are entitled to control the listing | Contract / legal obligation |
| Team invitations you send: the invited address and who invited them | To operate team access | Contract |
| Records of moderation decisions about your listing | To explain enforcement and handle appeals | Legal obligation (DSA Art 17) / legitimate interest |
Verification evidence is stored in a separate private bucket with no public access path. Images uploaded to the platform are stored privately and are not public until a member of staff approves them, using a review queue in our internal admin tool. An image stays private until that happens, and a rejected one never becomes public.
If you apply to be a creator
| Data | Why | Basis |
|---|---|---|
| Your legal first and last name, and date of birth | To confirm your real identity and that you are old enough (18+) to enter brand relationships. Held privately and never shown to brands | Contract / legal obligation |
| A phone number, if you give one | To reach you about your application, and later about a payout | Contract |
| The platforms and handles you create on, your portfolio links, and a link to a post you make promoting us | So a member of staff can review that your reach is real before any brand can discover you | Contract / legitimate interest |
| Your display name, short bio, and the niche, style, values and audience you choose | To build the creator profile brands see once you are approved | Contract |
Your creator profile. Once you have applied, you can fill in a fuller profile. Brands search by these fields, so each one is a fixed choice or a list, not free text. Every field below is optional unless it says otherwise. What you leave empty is simply not there.
| Data | Why | Basis |
|---|---|---|
| Creator type: solo, duo, family or collective | So a brand can look for the kind of account it wants to work with | Contract |
| Gender identity, solo creators only, optional. You pick from a list, describe it in your own words, or say "prefer not to say" | Shown on your profile to brands, and brands can filter by it. We ask only because brands cast for it. You do not have to answer, and you can remove the answer at any time from your profile; it is then gone from your profile and from the filters | Consent (Art 6(1)(a) GDPR / Art 6(6) FADP) |
| For family accounts: whether children appear in your content, and if so whether their faces are shown or always hidden | Brands with children's lines filter on it. We store the answer only; we never ask for a child's name, age or image | Contract |
| Where you live (country and city), where you are from (country), the languages you speak and post in, and whether you travel for shoots | Brands search by market and language. "Where you are from" is a country. It is not ethnicity, and we do not ask for ethnicity | Contract |
| Representation: whether you are self-managed, with an agency or with a manager; the agency or manager's name and contact; who posts on the account; any exclusivity you are under | So a brand contacts the right person. The agency or manager's contact is shown to brands only when you say you are not self-managed | Contract |
| Business details: private person, sole trader or company; business name; VAT number | For invoices between you and a brand later. Brands see only which of the three you are. The business name and VAT number are never shown to brands | Contract |
| The casting card: height, clothing sizes (top, bottom, dress), shoe size, hair colour and length, eye colour, visible tattoos or piercings, glasses. All optional | Brands cast by fit and size, the way a model agency lists them. A size-inclusive brand can search for the sizes it makes | Contract |
| Content formats you make, each with an example: an image you upload and/or a link to a post, with a short caption | So a brand sees what you make. An image is reviewed by a member of staff before any brand sees it; a rejected image is never shown. A link is shown as you gave it | Contract |
| The platforms you are on, with your handle, a link and the follower count you type in | To list where you create and how large each audience is. A number you typed in is shown to brands as your own figure | Contract |
| If you connect your Instagram account: the account id and username, follower count, a daily follower snapshot, engagement rate, 30-day growth, and your recent posts with their reach and interaction figures | To show brands live numbers next to your own figures, and to mark that platform as verified. You authorise this at Instagram; the access token is kept in a separate vault, not on your profile. You can disconnect at any time, which stops the sync | Contract for the profile figures; the connection itself rests on the permission you give at Instagram |
| Interests, from a list we keep | Brands search for creators who share a hobby with their customers | Contract |
| How you work: collaboration types you take, the usage rights you offer, your availability, the brands you have worked with, the brand values you insist on, a one-line pitch | So a brand knows before contacting you whether you are a fit | Contract |
| Your rates, if you enter them | Shown to brands only while you switch "show rates" on. Off is the default, and off means no brand sees a number. We set no rates and take no money between you and a brand | Contract |
| The brands you follow on FBF | Following is private for every account. It is shown to brands only if you switch it on in your creator profile. Then brands see the list and can filter for creators who follow them. Switch it off and the list and the filter go dark again | Consent (Art 6(1)(a)). You give it in your profile, and you can take it back there at any time |
| A shipping address, if you enter one | For a brand to send you product once you have agreed a collaboration. It is private. No brand can see it today, and nothing in the app releases it yet. If we build a release, it goes to one brand, inside a collaboration you accepted, and this policy is updated first | Contract |
What we do not collect. There is no field, no note and no free text for ethnicity, skin tone, religion, health, disability or sexual orientation, and we will not add one. If you put such information in a free-text field, we may remove it.
Collaboration deals. A brand with a paid plan can post a deal: what it offers, what it wants, a deadline, and which creator attributes it is aimed at. Your profile is checked against those attributes; a deal is shown to you in the app only if you match, and a brand is not told who did not match. If you apply, the brand sees your application note together with your creator profile. If the brand picks you, a conversation opens between you and the brand in the app, and you get a notification. If the brand declines, it can leave a short note that only you read. You can withdraw an application while it is still open. Our staff can see every deal and every application, to moderate them.
Who sees a creator profile. A creator profile is never public: it is not visible to consumers, to other creators, or to search engines. It is shown to the team of a verified brand or shop whose plan includes creator discovery, and only after a member of staff has reviewed and approved your application. Our staff see the whole profile, including the private parts above, to run the review and handle reports. If you are turned down we keep the application so you can revise and reapply, and you can ask for all of it back or have it erased in the same ways as any other account data (§6). The in-app data export includes your application, your profile details, your platform accounts, your examples (links and captions), your connected accounts' figures (never their tokens) and your deal applications.
4. Where your data is
Our database and file storage are hosted by Supabase in Zurich, Switzerland (eu-central-2). For most users, data does not leave Switzerland.
Our subprocessors are:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | Switzerland (Zurich) |
| METANET | The server the website runs on (self-managed) | Switzerland |
| Google (Google Analytics) | Counting website visits — only after you allow "Statistics" on the website's cookie banner or settings; advertising features switched off | Ireland, with transfers to the USA under the EU–US Data Privacy Framework and SCCs |
| Expo / EAS | Building and delivering the mobile app | USA |
| Resend | Sending transactional email | USA |
| Stripe | Subscription billing for brands (not consumers) | USA / Ireland |
We send you notices about things you did — a report you filed, an image you uploaded — in an inbox inside the app. Anything promotional needs your explicit permission first, is limited to one message a day, and is never sent during the night in your country. Brands cannot send you messages and are never told who received one.
The one analytics provider is Google Analytics on the website, and it runs only under the choice described in the cookie and tracking notice — never in the mobile app. We use no error-reporting provider and no push-notification provider today. If we add one, it appears in this table before it starts working, and the cookie notice's §5 lists what else has to happen first.
Where a provider is outside Switzerland or the EEA, the transfer relies on Standard Contractual Clauses and the Swiss addendum.
We never take payment from consumers. If you use a discount code, you buy from the brand's own shop under the brand's terms, and we do not see your payment details.
5. How long we keep it
| Data | Retention |
|---|---|
| Your account and preferences | Until you delete your account |
| Creator application and profile details, platform accounts, Instagram connection and its figures | Until you delete your account. Each field goes when you clear it; the whole set is deleted with the account |
| Creator example images and links | Until you remove the example, or with your account. A removed example stops being shown at once |
| Your applications to deals, and a brand's decision note | Until you delete your account. The brand's deal itself stays with the brand, without you in it |
| Aggregate brand view counts | 400 days |
| Verification evidence | 24 months after a final decision |
| Moderation and audit records | 10 years, per the OR 127 limitation period |
| Accounting records (brand invoices) | 10 years (OR 958f — a legal obligation we cannot waive) |
6. Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or object to it — and to withdraw consent for the quiz-based personalisation at any time, which does not affect anything we did before you withdrew it. Creators can also withdraw the two consents on their profile at any time: remove the gender identity, or switch off "show the brands I follow". Both take effect at once.
How to delete your account. In the app, open your profile and choose Delete my account. We schedule the deletion for seven days later and show you the date. Until then you can undo it from the same screen — the delay exists so that somebody who gets into your account cannot erase it before you notice. You can also write to hello@fashionbrandfinder.com, and we will delete it within one month either way.
If you are the sole owner of a brand or shop page, we will ask you to hand that page to a colleague, or to ask us to remove it, before we delete your account. Otherwise one person's deletion would take a company's listing with it.
Deleting your account removes your quiz answers, your follows, your saved lists, your marketing choices and the record of which codes you revealed, and clears your name, email, date of birth and country from your profile. If you are a creator, it also deletes your creator application, profile details, platform accounts, example images and links, Instagram connection and figures, and your applications to deals. A small set of records survives because the law requires it: accounting records, any contract you accepted, and the record of a moderation decision. Those are kept with your identity removed.
Getting a copy of your data. In the app, choose Download my data in your profile. It produces one file, straight away, containing everything this account holds about you — including the full history of the marketing choices you made and when. You do not have to ask us, and we do not see that you did it.
Write to privacy@fashionbrandfinder.com. You can also complain to the Swiss FDPIC (edoeb.admin.ch), or in the EU to your national supervisory authority.
7. Minimum age
You must be at least 13 to create an account. Anyone can browse the public directory without one. If we learn that an account belongs to someone under 13, we delete it.
Some countries require a parent's permission before a child under 16 (or 15, or 14, depending on the country) can consent to having their data used. Where that applies to you, you can still have an account and use everything else — but the preference quiz stays switched off until a parent agrees, and your home page shows the same non-personalised version everyone sees before signing in.
The reasoning behind the age rules is kept in our internal age policy; ask us if you want it.
8. Automated decisions
We do not make automated decisions with legal or similarly significant effects. Ranking brands for you by your stated preferences is personalisation of a listing, not a decision about you, and you can turn it off by clearing your quiz answers.
9. Changes
We will post a new version here, dated, and where the change matters we will email you before it takes effect. Earlier versions are kept so you can see what changed.
10. Who to contact, and our representatives
Write to hello@fashionbrandfinder.com about anything in this policy.
Under the EU Digital Services Act we also have to name a legal representative in the EU (Art 13) and points of contact for authorities (Art 11) and for users (Art 12), and under GDPR Art 27 a representative for data protection. None of these has been appointed yet. They will be named in the notice and action policy, and this policy is not complete until they exist.