Legal

Privacy Policy

Last updated: May 10, 2026

1. Who We Are

Your Scents ("we", "us", "our") operates the website yourscents.beauty. We provide a fragrance wardrobe and scent-layering platform. This Privacy Policy explains what personal data we collect, how we use it, and your rights regarding that data.

For any privacy questions, please use the contact page.

2. Data We Collect

We collect the following categories of personal data:

  • Account data: Your name, email address, and password (hashed) when you create an account.
  • Profile data: Your subscription plan and fragrance wardrobe contents.
  • Payment data: Billing is handled by Stripe. We store only a Stripe Customer ID and Subscription ID — never your raw card details.
  • Email signups: If you submit your email for a free scent profile, we store that email address.
  • Usage data: Pages visited, features used, and session duration — collected via Google Analytics (anonymised IP).
  • Technical data: Browser type, device type, operating system, and IP address.

3. How We Use Your Data

  • To create and manage your account and subscription.
  • To provide fragrance wardrobe and stack-builder features.
  • To process payments and manage billing via Stripe.
  • To send transactional emails (account confirmation, billing receipts).
  • To send marketing emails only if you have opted in.
  • To improve the product through anonymised usage analytics.
  • To comply with legal obligations.

4. Legal Basis (GDPR)

For users in the European Economic Area (EEA), we process your personal data under the following lawful bases:

  • Contract performance: Account creation, feature delivery, billing.
  • Legitimate interests: Security, fraud prevention, product analytics.
  • Consent: Marketing emails and optional cookies.
  • Legal obligation: Tax records and regulatory compliance.

5. Third-Party Services

We share data with the following trusted third parties only as necessary:

  • Supabase — database and authentication hosting (data stored in the EU/US per their DPA).
  • Stripe — payment processing. Governed by Stripe's Privacy Policy.
  • Google Analytics — anonymised usage analytics. IP addresses are anonymised.
  • Vercel — website hosting and edge delivery.

We do not sell your personal data to any third party.

6. Cookies

We use essential cookies to keep you logged in and maintain session state. We also use Google Analytics cookies for anonymised traffic analysis. You can disable non-essential cookies in your browser settings at any time without affecting core functionality.

7. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we remove your personal data within 30 days, except where retention is required by law (e.g., billing records retained for 7 years for tax purposes).

8. Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Delete your account and associated data.
  • Restrict or object to certain processing activities.
  • Data portability — receive your data in a machine-readable format.
  • Withdraw consent for marketing emails at any time via the unsubscribe link.

To exercise any of these rights, please use the contact page. We will respond within 30 days.

9. Data Security

We use industry-standard security measures including TLS encryption in transit, encrypted storage at rest via Supabase, and Row Level Security (RLS) policies ensuring each user can only access their own data. Passwords are never stored in plaintext.

10. Children's Privacy

Your Scents is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13. If you believe we have inadvertently collected such data, please contact us immediately via the contact page.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes by email or an in-app notice. Continued use of the service after changes constitutes acceptance of the updated policy.

12. Contact

If you have any questions about this Privacy Policy or how we handle your data, please reach out via the contact page.