Privacy in plain language

Your search should not become someone else's profile.

Trendsly uses the information needed to return a search, protect the service, understand what shoppers need, and remember choices you deliberately save locally or in a durable cart. It does not run third-party advertising or behavioural profiling scripts on these pages.

Privacy notice updated August 20, 2026

01

Words and shared searches

Search text is sent to Trendsly when you search. The page also places the text in the q part of the page URL so the search can be shared or reopened.

A shared search can therefore appear in browser history, bookmarks, messages, and a network provider's request records. Do not put private or sensitive information in a search.

02

Uploaded images

An uploaded outfit image first makes a request-scoped detector pass through a loopback service. Detector regions, confidence scores, and signed request context stay transient. Your browser then crops the detected or manually selected region locally; only that chosen crop—or the whole image when you explicitly choose that fallback—is sent to the loopback search service.

Private temporary server files are removed when each request finishes, including when it fails. Product analytics do not store uploaded image bytes, image hashes, crop boxes, detector regions, confidence scores, or detector context. Images are not added to shared URLs or used to build a public profile. Avoid uploading an image you do not have the right to use.

03

Saved finds on this device

Legacy saved products, collections, watchlists, owned-item markers, and your submitted brand-rating choices stay in this browser's local storage. They are not copied into a universal cart unless you explicitly add a product there.

Local saves remain until you remove them in Trendsly, clear this site's browser data, or use a different browser or device.

04

Durable universal carts

When you explicitly create a universal cart, Trendsly stores it on the server as anonymous, capability-owned shopping state. An opaque cart URL is created with the cart but remains private until you publish it. The URL remains durable while that share is active; revoking or expiring it permanently retires that public reference without deleting the private cart. The separate edit capability stays in this browser's local storage and is never placed in the URL. While creation is awaiting a confirmed response, the browser also keeps a random recovery key so a lost response can be retried without orphaning a second cart, then clears it after the owner response is retained. Trendsly does not attach the cart to an account, IP address, MCP client identity, or advertising identifier.

To keep a cart and purchase plan useful across visits and agents, the server retains canonical product IDs, retailer and variant selections, quantities, observed prices and availability, price watches, plan preferences, explicit replacements and substitution relationships, revisions, and timestamps. Cart estimates exclude unknown prices, tax, shipping, and any claim that a retailer order completed.

A published cart link is bearer-readable: anyone with the link can read its shared fields and machine-readable purchase manifest. Like any shared URL, it can appear in browser history, bookmarks, messages, and provider request records. You can revoke public access without losing the editable cart, or archive the cart. Never put private or sensitive information in cart notes.

Shopping-state MCP requests use the same separate edit capability. Trendsly's MCP usage analytics retain fixed capability names, outcomes, durations, result counts, and discovery facts—not prompts, search text, arguments, product IDs, cart references, share URLs, edit capabilities, IP addresses, accounts, users, or sessions.

05

Security and request records

Cloudflare and the Trendsly reverse proxy process connection information such as an IP address, time, requested URL, response status, and timing to deliver and protect the site. Provider retention is governed by the configured account and provider terms.

Origin proxy logs may include a full requested URL—and therefore shared search text—plus a source or edge address, referrer, user agent, status, and timing. Retention follows the host's active rotation configuration; a stricter Trendsly-only rotation policy is prepared but is not represented here as active until its host-level installation is verified. The current search service does not intentionally log search text or image bytes.

06

Anonymous product insights

Trendsly keeps private raw product events for about 30 days, including searches, result counts, zero-result searches, filters, product opens, retailer and affiliate clicks, fixed-choice relevance feedback, broad device class, and referring site.

Before raw event segments are removed, Trendsly creates cleaned hourly and daily aggregate counts for catalogue, search, and affiliate performance. These aggregate counts are retained on an ongoing basis so long-term trends remain useful; they do not contain session or event identifiers, raw IP addresses, uploaded images, precise device fingerprints, or advertising identifiers.

A random short-lived browser session is hashed by Trendsly. Raw search text may be included during the limited raw-event period so we can identify missing products, so do not put private information in a search. Durable search reporting is aggregated and privacy-safe.

07

Ratings, suggestions, rate limits, and cookies

Brand ratings update combined star and fixed-choice reason totals; Trendsly does not collect a written brand review. An IP-derived key is held briefly in memory to limit duplicate ratings and excessive searches; it is not added to the stored rating totals.

Brand suggestions are stored privately with the information you submit so the catalogue team can review them.

The public site does not need an account cookie. During a password-protected review, a signed, HTTP-only access cookie may be set for up to 24 hours.

08

Retailers and social links

When you open a retailer or brand website, your browser may identify https://trendsly.ca/ as the referring site. Trendsly does not send the full page address, your search text, or your filters in that referral. Evidence sources and Trendsly's social links do not receive a Trendsly referrer. Every external destination handles the request under its own privacy practices.

Contact Trendsly about a privacy question

09

Browser extension

The Trendsly extension processes page content locally to identify image and video candidates. When image discovery runs, it takes one temporary visible-tab screenshot in browser memory and reduces up to 24 candidate regions to 32×32 thumbnails for local likely-or-uncertain ranking. That screenshot, those thumbnails, their perceptual features, and candidate scores may remain ephemerally in page memory for ranking, but are never uploaded, persisted, or used in analytics. A bounded history of up to 12 content-free pipeline diagnostics may remain in session storage for local troubleshooting only. Session-only capture-alignment and selected-region metadata—including the selected box, confidence, mask, and highlight geometry—may also remain in local browser storage after a garment click so the side panel can complete the confirmed search; this metadata is not analytics. The extension sends only the visible image or frame you select, after you confirm it in the extension side panel, plus any refinement text you submit when you ask to search. Smart Assist is optional and requires site access that you can revoke in Chrome.

Extension analytics are off by default. If you enable them, Trendsly receives broad trigger, source-class, garment-category, search, result-engagement, offer, and retailer-handoff events. It does not receive page URLs, page titles, DOM content, screenshot bytes, hashes, crop boxes, detector coordinates, or advertising identifiers through analytics. A random installation identifier is hashed and kept with private raw events for about 30 days so Trendsly can measure aggregate repeat use and retention; clearing extension data creates a new identifier. Separately, a random short-lived session identifier may accompany a user-initiated same-origin retailer handoff even when optional analytics is off; Trendsly hashes it for affiliate attribution and it expires with the browser session.

10

Partnership meeting requests

If you request a partnership meeting, Trendsly stores the business contact and qualification details you submit—including your name, work email, organization, role, interests, timing, and optional message—in a separate owner-private inquiry record.

Cloudflare Turnstile may process network, device, and challenge information to protect the form from automated abuse. After a valid request is saved, Trendsly’s server sends the submitted inquiry details to its designated inbox through Google’s Gmail SMTP service. The verification token and IP address are not stored with the inquiry.

These details are used only to evaluate and respond to the request, are not added to shopper analytics or public profiles, and are kept only as long as needed for partnership review, follow-up, record-keeping, and applicable legal obligations. Contact Trendsly to request correction or deletion.

View the partnership meeting form