S SkinStack ← Back to home
Legal

Privacy Policy

Last updated 28 May 2026

This Privacy Notice for Van Global Ltd (Company Number 17247311), doing business as SkinStack, describes how and why we might access, collect, store, use, and/or share your personal information when you use our services, including when you download and use our mobile application (SkinStack).

Questions or concerns? Contact us at support@skinstack.online.

Table of Contents 1. What Information Do We Collect? 2. How Do We Process Your Information? 3. What Legal Bases Do We Rely On? 4. When and With Whom Do We Share Your Personal Information? 5. Do We Offer AI-Based Products? 6. Is Your Information Transferred Internationally? 7. How Long Do We Keep Your Information? 8. How Do We Keep Your Information Safe? 9. Do We Collect Information From Minors? 10. What Are Your Privacy Rights? 11. Controls for Do-Not-Track Features 12. Do United States Residents Have Specific Privacy Rights? 13. Do We Make Updates to This Notice? 14. How Can You Contact Us? 15. How Can You Review, Update, or Delete the Data We Collect?

1. What Information Do We Collect?

Personal information you disclose to us

We collect personal information that you voluntarily provide to us when you register on the Services or participate in activities on the Services. The personal information we collect may include:

  • Email addresses
  • Full name (optional, used for personalised greetings)
  • Contact or authentication data (we use email one-time passcodes — we do not store passwords)
  • Skin profile data you provide during onboarding (skin type, concerns, sensitivity level, country)
  • Family member profiles created by you (name, age group, skin concerns) — adults only may create these on behalf of dependants
  • AI chat conversations with Mel, our AI skin guide (processed to generate responses; see Section 5)
  • Billing information (handled by Apple or Google — we do not store card details)

Sensitive Information. Skin profile data (skin type, concerns, and sensitivity level) and family member skin profiles may constitute health-related personal data under applicable law. We collect this data solely to provide personalised AI analysis. We do not use it for advertising or share it beyond what is necessary to provide the Service.

Payment Data. All payment data is handled by Apple (iOS App Store) or Google (Google Play). We do not store or have access to your full payment card details. See Apple's Privacy Policy and Google's Privacy Policy.

Application Data. We may also collect the following when you grant permission:

  • Camera. To photograph skincare product labels. Images are processed for AI analysis and are not stored on our servers after analysis is complete.
  • Push Notifications. If you enable notifications, we store a device push token to deliver alerts. You may disable notifications at any time in your device settings or the app.
  • Approximate Location. If you enable weather-aware notifications, we request your approximate city-level location to retrieve weather conditions. We do not store location data on our servers; it is discarded after the notification is generated. You may revoke this permission at any time in device settings.
  • Device Data. Device model, OS, unique device ID, and other technical information used for security, troubleshooting, and analytics.

Information automatically collected

We automatically collect certain information when you use the Services, including your IP address, device characteristics, operating system, language preferences, and usage data. This is used primarily to maintain security and operation of our Services.


2. How Do We Process Your Information?

We process your personal information for the following reasons:

  • To facilitate account creation and authentication.
  • To deliver services to the user, including AI-powered ingredient analysis and Mel AI chat personalised to your skin profile.
  • To send push notifications, including weather-aware skin alerts (only if you have opted in).
  • To respond to user enquiries and offer support.
  • To send administrative information about products, services, and policy changes.
  • To fulfil and manage your orders, payments, and subscriptions.
  • To save or protect an individual's vital interest.

3. What Legal Bases Do We Rely On?

If you are located in the EU or UK, the GDPR and UK GDPR require us to explain the valid legal bases we rely on. We rely on: Consent (for skin profile data, family profiles, push notifications, and location); Performance of a Contract (for delivering the Service); Legal Obligations; and Vital Interests.

If you are located in Canada, we may process your information with your express or implied consent. You can withdraw consent at any time.


4. When and With Whom Do We Share Your Personal Information?

The third parties we may share personal information with are as follows:

  • Anthropic — AI ingredient analysis and Mel AI Chat (Claude AI). Your product images, skin profile data, and Mel chat messages are sent to Anthropic's API to generate responses.
  • OpenWeatherMap — Weather data for skin notifications (only if location permission granted). Only city-level coordinates are shared; no personal identifying information.
  • Resend — Transactional email delivery.
  • Supabase — Database, authentication, and cloud sync.
  • Apple — iOS in-app purchase processing.
  • Google — Android in-app purchase processing.

We may also share or transfer your information in connection with any merger, sale of company assets, or acquisition of all or a portion of our business.


5. Do We Offer AI-Based Products?

We offer products powered by artificial intelligence through Anthropic. Your input (including product images, skin profile data, and Mel chat messages), output, and personal information are shared with Anthropic to enable our AI Products.

Our AI Products include:

  • Image analysis (reading skincare product ingredient labels)
  • AI insights (personalised ingredient assessments, ingredient matcher, routine conflict detection)
  • Mel AI Chat (conversational AI skin guide anchored to your most recently scanned product)

Mel AI Chat — Data Handling: Messages you send to Mel are transmitted to Anthropic's API and are not stored on our servers beyond session continuity. Mel conversations are not used to train AI models and are not retained across app sessions.

Important Disclaimer: AI-generated analysis and Mel AI Chat responses are for informational and educational purposes only. They do not constitute medical or dermatological advice. Always consult a qualified healthcare professional before making skincare decisions, particularly if you have a skin condition, allergy, or are pregnant.


6. Is Your Information Transferred Internationally?

Our servers are located in the United States. If you are a resident in the EEA, UK, or Switzerland, please be aware that your information may be transferred to, stored by, and processed in the United States and other countries. We have implemented the European Commission's Standard Contractual Clauses and equivalent safeguards to protect your personal information during international transfers.


7. How Long Do We Keep Your Information?

We will only keep your personal information for as long as it is necessary for the purposes set out in this Privacy Notice, or for as long as you have an account with us. When we have no ongoing legitimate business need, we will delete or anonymise your information.


8. How Do We Keep Your Information Safe?

We have implemented appropriate technical and organisational security measures. However, no electronic transmission over the Internet can be guaranteed to be 100% secure, so we cannot promise that hackers or other unauthorised third parties will not be able to defeat our security. Transmission of personal information to and from our Services is at your own risk.

Data Breach Notification: In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the UK Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach, as required by UK GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay using the contact information on your account.


9. Do We Collect Information From Minors?

The Service is intended for users aged 13 and over. We do not knowingly collect data from or market to children under 13. If we learn that an account has been created by a child under 13 without parental consent, we will deactivate the account and delete such data promptly. Contact us at support@skinstack.online if you become aware of any such data.

Family Profiles: The app allows adult users (18+) to create skin profiles on behalf of dependants, including children. By doing so, you as the parent or guardian confirm you have the appropriate authority to provide this information. We process family member skin data solely to personalise AI analysis and for no other purpose. Family member profiles are deleted when you delete your account or can be removed individually at any time within the app.


10. What Are Your Privacy Rights?

In some regions (like the EEA, UK, Switzerland, and Canada), you have certain rights under applicable data protection laws, including the right to: request access and a copy of your personal information; request rectification or erasure; restrict processing; data portability; and not to be subject to automated decision-making. Contact us at support@skinstack.online to exercise any of these rights.

If you are located in the EEA or UK and believe we are unlawfully processing your personal information, you have the right to complain to your UK data protection authority (ICO).

Automated decision-making and profiling: The Service uses automated processing of your skin profile data to generate personalised ingredient scores, product recommendations, and routine assessments. This constitutes "profiling" under UK GDPR. It is used solely to improve the relevance of AI analysis to your individual skin needs and does not produce legal or similarly significant effects. You have the right to object at any time by contacting us at support@skinstack.online.

Withdrawing consent: You may withdraw consent at any time by contacting us. This does not affect the lawfulness of processing before withdrawal.

Push notifications: Disable at any time via your device settings or the Notifications toggle in the SkinStack app settings.

Location permissions: Revoke at any time via device settings. This will disable weather-aware notifications but will not otherwise affect the Service.

Account Information

To review, change, or delete your account, use Settings → Delete Account in the app, or contact us at support@skinstack.online. Upon deletion, we will remove your account and information from our active databases, though we may retain some information where required by law.


11. Controls for Do-Not-Track Features

We do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online.


12. Do United States Residents Have Specific Privacy Rights?

If you are a resident of California, Colorado, Connecticut, or other applicable US states, you may have specific rights regarding access to your personal information.

CategoryExamplesCollected
A. IdentifiersName, email address, IP address, account identifierYES
B. Personal information (California Customer Records)Name, contact information, financial informationYES
C. Protected classification characteristicsGender, age, national originNO
D. Commercial informationTransaction information, purchase historyYES
E. Biometric informationFingerprints and voiceprintsNO
F. Internet or network activityBrowsing history, search historyNO
G. Geolocation dataApproximate city-level location (weather notifications only, if permission granted)YES (optional)
H. Audio, electronic, sensory informationImages captured through the camera featureYES
I. Professional or employment-related informationBusiness contact details or job titleNO
J. Education informationStudent records and directory informationNO
K. Inferences from personal informationPersonalised ingredient scores, product match ratings, and routine recommendations derived from your skin profileYES
L. Sensitive personal informationSkin profile data (skin type, concerns, sensitivity) — health-related; processed solely to deliver personalised AI analysisYES

We have not sold or shared any personal information to third parties for advertising or commercial purposes. We have disclosed categories A, B, D, G, H, K, and L to our third-party service providers (Anthropic, OpenWeatherMap, Resend, Supabase, Apple, Google) for business purposes only — solely to enable the delivery of our Services.

Your Rights

You have the right to know, access, correct, delete, and obtain a copy of your personal data, as well as the right to non-discrimination for exercising your rights. To exercise these rights, contact us at support@skinstack.online.


13. Do We Make Updates to This Notice?

Yes, we will update this notice as necessary to stay compliant with relevant laws. The updated version will be indicated by an updated "Last updated" date at the top. We encourage you to review this Privacy Notice frequently.


14. How Can You Contact Us?

If you have questions or comments about this notice, you may email us at support@skinstack.online or contact us by post at:

Van Global Ltd (Company Number 17247311)
doing business as SkinStack
29 Hawley Vw
Blackwater, England GU17 9FP
United Kingdom


15. How Can You Review, Update, or Delete the Data We Collect?

To delete your account and all associated data, use Settings → Delete Account in the SkinStack app. Alternatively, contact us at support@skinstack.online to request review, update, or deletion of your personal information.

© 2026 Van Global Ltd  ·  Home  ·  Terms & Conditions  ·  Contact