OLVARA

Privacy Policy

Data di entrata in vigore: 2026-07-30Ultimo aggiornamento: 2026-09-13Versione: 1.3.0

This Privacy Policy explains how personal data is processed in connection with the Olvara service. It is drafted to meet Swiss Federal Act on Data Protection (FADP) transparency expectations and, where the EU General Data Protection Regulation (GDPR) applies, to support GDPR transparency (including purposes, legal bases, recipients, transfers, and rights).

This policy describes current implementation. If processing changes (for example enabling PostHog, Stripe, or new AI providers), this policy and related product controls will be updated together.

1. Controller

Controller

R. Gilvert Brunngasse 14c 4124 Schönenbuch Switzerland Email: hello@olvara.luxe

operating the Olvara service.

No data protection officer (DPO) is appointed at this time.

2. Categories of personal data

2.1 Account and authentication

  • email address
  • authentication identifiers managed by our auth provider
  • password authentication (passwords are handled by Supabase Auth; we do not store plaintext passwords)
  • magic-link authentication
  • Google OAuth and Apple OAuth (we do not receive or store third-party OAuth passwords)

2.2 Profile information

  • display name
  • age band (optional demographic band; not an age gate)
  • role (for example user, perfumer, admin)
  • consent / preference flags (for example analytics, skin capture, image retention)

2.3 Fragrance preference and personalization

  • fragrance ratings and “owns” flags
  • want-to-try (curiosity) lists
  • wishlist / want-to-own acquisition lists (separate from want-to-try)
  • pairwise preference choices
  • wear-test information and observations
  • contextual preferences and defaults
  • free-text notes and queries you provide
  • collection data
  • recommendation interactions and related history held in your client or account state
  • a derived olfactory / preference profile inferred from the evidence you provide

2.4 Images and optical capture

Bottle photographs. Bottle photographs may be uploaded for recognition and related features. Based on the current implementation, bottle captures may be retained server-side with your account data. Authorized staff with admin or perfumer roles may access uploads and related collection data for review, quality, and support purposes under access controls.

Skin Scan. During the standard Skin Scan, camera frames are processed transiently on your device in the product session to derive an Observed Optical Skin Profile. Olvara does not retain the raw Skin Scan frames or video after processing. With explicit measurement consent, Olvara may keep a derived measurement and timestamped colour-signal record (numeric colour samples over time — not a photograph). If you are not signed in, that record is stored under a pseudonymous measurement subject rather than an account identity. After you create or sign in to an account on the same device, the measurement may be associated with your account without changing the original record. Withdrawing skin-measurement consent deletes retained colour-signal series locally and all product measurements and subject links for that measurement subject. Derived optical measurements do not currently influence Taste Fit, Discover candidate generation, or fragrance-preference ranking. Skin-related optical measurements are not used to diagnose disease, health status, or dermatological conditions.

Historical / internal optical validation. Earlier internal validation captures collected under retired research protocols may remain in restricted admin research records. They are not a customer product, are not offered as a customer research beta, and are not used for fragrance ranking.

2.5 Guest / local data

Before account registration, preference and related data may be stored locally in your browser (for example via localStorage). When you create an account, local preference state may be migrated once into your cloud account if remote state is empty; otherwise remote state is preferred. See also our storage inventory for counsel/audit.

2.6 Analytics events

First-party funnel / product analytics events may be recorded in the client (and logged in development). Events can include landing views, acquisition CTA clicks, profiling milestones, identity feedback, and account creation, together with optional attribution parameters (for example UTM values) stored locally.

Vercel Web Analytics may also record cookieless page-view metrics (for example path and referrer aggregates) via our hosting provider when analytics preference allows. Explicit opt-out or a denied analytics preference in Settings prevents loading this script.

Mixpanel may receive first-party product events when you explicitly allow analytics in Settings. After that consent, Mixpanel may also store your account email as a profile attribute and a coarse location (country / region) derived from IP. The Mixpanel browser SDK is loaded only in the production environment, only after that explicit consent, and events are sent to Mixpanel’s EU ingestion endpoint. The SDK is not loaded for guests who have not set a preference, on local or preview builds, or after opt-out.

Journal exception. Public Journal index and article read events (and related Journal clicks or shares) may be sent to Mixpanel in production without Settings analytics consent, using a first-party anonymous path that does not load the Mixpanel browser SDK, does not send your email, and does not derive location from IP. A first-party anonymous reader identifier may be stored in localStorage so unique Journal readers can be counted. Explicit opt-out or a denied analytics preference in Settings stops Journal Mixpanel events as well. PostHog is not currently shipped as an active analytics destination.

2.7 Paid access / payment metadata (when Stripe is activated)

When paid access is enabled, Stripe will process payment-card information. Olvara will not receive or store full payment-card numbers. We may store payment administration metadata such as Stripe customer/subscription IDs, checkout session and payment intent IDs, product/price references, one-time access expiry timestamps, status, period dates, and invoice/transaction references. Paid access is currently offered.

3. Purposes of processing

We process personal data to:

  • create and secure accounts
  • authenticate users
  • provide the Olvara service
  • maintain collections and preference state
  • generate personalized fragrance recommendations from preference and fragrance-experience evidence
  • derive preference / olfactory profiles from the evidence you provide
  • analyse bottle photographs
  • perform optical measurement and derive an Observed Optical Skin Profile, without using camera-derived measurements for current fragrance-preference ranking
  • process free-text requests and search
  • remember user preferences (including locally for guests)
  • improve product functionality and reliability
  • prevent fraud and protect security
  • provide support and service communications
  • administer subscriptions when offered
  • comply with legal and accounting obligations
  • perform first-party service analytics as described above

4. Legal bases (where GDPR applies)

Where GDPR applies, we rely on different bases depending on the purpose — not on blanket “consent to the privacy policy”:

  • Contract / steps at your request: account creation, authentication, delivering personalization and recommendations, maintaining collections, subscription administration when offered
  • Legitimate interests: security, fraud prevention, basic service diagnostics, product reliability and improvement where appropriate and balanced against your rights
  • Consent: optional analytics or marketing where we decide consent is required; feature-specific consents (for example skin capture, experimental research capture, product tips by email) where implemented in product
  • Legal obligation: accounting, tax, and regulatory compliance where applicable

Swiss FADP processing is carried out in accordance with applicable Swiss principles (including purpose limitation and proportionality).

5. Automated personalization / profiling

Olvara uses information about your fragrance preferences and interactions to infer a personalized olfactory profile and generate recommendations. Camera-derived optical measurements are not currently used to calculate Taste Fit, Discover candidate generation, or fragrance-preference ranking. This personalization does not produce legal or similarly significant effects within the meaning of automated decision-making rules that typically require additional safeguards for credit, employment, or comparable decisions.

6. Recipients and processors

Personal data may be processed by:

  • Supabase — authentication, database, profile and preference persistence, and related backend services; uploaded assets depending on storage configuration
  • Vercel — hosting and related infrastructure; Vercel AI Gateway may be used as a path to models; Vercel Web Analytics may receive cookieless page-view metrics when analytics preference allows
  • Mixpanel — product analytics events, account email, and IP-derived coarse location when you explicitly allow analytics in Settings; anonymous public Journal read events without that consent (no email / no IP country); EU ingestion; production only
  • OpenAI — AI analysis for features such as bottle-image recognition, free-text context, and search/packshot assistance. The current Skin Scan derives the Observed Optical Skin Profile from transient camera frames in the product session and does not transmit those frames to OpenAI. OpenAI is not used to calculate Taste Fit, Discover candidate generation, or fragrance-preference ranking. AI processing does not occur solely on Operator-owned infrastructure
  • Google / Apple — OAuth identity providers when you choose those sign-in methods
  • Stripe — payment processing when subscriptions are activated (not currently active)
  • Resend — authentication email delivery (via Supabase SMTP) and product/retention transactional messages (for example passport-ready, product tips when opted in, billing notices)
  • Authorized staff — admin/perfumer access to uploads and collection data for review and support

We do not claim that any AI provider does or does not train on your data unless verified against the actual API terms and configuration in use.

Exact processing locations, transfer mechanisms, and DPA status for each provider are maintained in an internal subprocessor inventory and must be verified against live account configuration before production reliance. Providers may process data outside Switzerland and, where relevant, outside the EEA.

7. Cookies and similar technologies

We use cookies and similar storage primarily for authentication sessions (Supabase Auth) and for functional / preference state (including localStorage for guest personalization and related keys). Vercel Web Analytics is configured without a marketing cookie banner: it does not rely on marketing cookies, and loading is gated by the same analytics preference / opt-out controls used for first-party funnel events (Settings analytics consent). The Mixpanel browser SDK is a third-party analytics destination loaded only after explicit Settings analytics consent, only in production, using Mixpanel’s EU endpoint. Public Journal read events may reach Mixpanel anonymously without that consent, without loading the SDK. PostHog is not shipped. A detailed classification inventory is maintained for audit.

8. Retention

Retention follows operational need rather than invented fixed schedules where the product does not yet enforce automated deletion timers:

  • Account data: while the account is active, and thereafter as needed for legal/operational purposes
  • Fragrance preferences and derived profiles: while needed to provide personalization, or until account deletion
  • Bottle images: retained according to current storage/association with the account until deleted
  • Skin Scan optical data: raw Skin Scan frames or video are not retained by Olvara after processing. For consented product scans, a derived timestamped colour-signal record and Observed Optical Skin Profile may be retained under a measurement subject (and later linked to an account) until consent is withdrawn or the account is deleted. Historical internal optical-validation records, where they exist, remain in a separate restricted admin domain and are not a customer product.
  • Analytics / local attribution: according to browser storage until cleared or opted out
  • Transaction / accounting records (when subscriptions exist): as legally required

Self-service account deletion is available in Settings and cascades account-linked preference, collection, upload, and auth data subject to legal retention exceptions that may apply once billing records exist.

9. International transfers

Service providers may process personal data outside Switzerland and/or the EEA. Transfer safeguards (for example standard contractual clauses or other lawful mechanisms) depend on provider contracts and configuration.

10. Security

We implement technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, or alteration. We do not guarantee that data can never be compromised.

11. Your rights

Depending on applicable law (including FADP and, where applicable, GDPR), you may have rights to access, correction, deletion, restriction, objection, portability, and withdrawal of consent where processing is based on consent. Rights are not identical in every jurisdiction.

To exercise rights, contact privacy@olvara.luxe.

You may also have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, where GDPR applies, with a competent supervisory authority in the EEA.

12. Children

Olvara is not directed at children. You must be at least 16 years old. Only persons with full legal capacity under applicable law (or their duly authorized representatives) may use accounts.

13. Changes

We may update this Privacy Policy. Material changes will be reflected with an updated version and date. Where appropriate, we will provide additional notice.

14. Contact

R. Gilvert Brunngasse 14c 4124 Schönenbuch Switzerland General: hello@olvara.luxe Privacy: privacy@olvara.luxe Support: support@olvara.luxe

Torna alla home