Privacy notice
This notice explains what personal data Chic Magnolia uses, why it is needed and the choices available to you.
Last updated 4 August 2026
1. Who is responsible for your data
Sevinj Ahmadova is the data controller for the personal data described in this notice. Chic Magnolia is currently operated as a private beta service from the United Kingdom.
Privacy questions and rights requests can be submitted through the secure support form. Please do not include passwords, full payment-card details or other unnecessary sensitive information.
2. Data we collect
- Invitation and beta-access data: the invited email address until the invitation is redeemed, a one-way hash of the invitation token, invitation expiry and redemption timestamps, and access start, expiry or revocation status. Chic Magnolia does not store the plaintext invitation token.
- Account data: email address, name, account identifiers, authentication status and account dates.
- Purchase data: retailer, product name and URL, purchase price, purchase and return dates, saved size and colour, and tracking status.
- Monitoring data: price-check results, stock status, timestamps, errors and price-drop notification history.
- Billing data: subscription status, billing-period dates and Stripe customer or subscription references. Chic Magnolia does not receive or store your full card number.
- Support data: the name, email address, topic and message submitted through the support form, the account identifier when signed in, delivery status, timestamps and the internal reference used to handle the request.
- Service and security data: limited technical logs needed to operate, secure and troubleshoot the service.
- Anonymous analytics: aggregated page-view information such as route, referrer, country, browser and device category. Chic Magnolia strips query strings before sending analytics events.
3. Where the data comes from
Invitation details are created by the private-beta operator and are matched to the email address entered during sign-up. Most other data is provided directly by you when you create an account, add a purchase, manage billing or submit the support form. Current price and stock information comes from public retailer pages for the product URL you provide. Subscription status comes from Stripe after signed webhook verification.
4. Why we use the data
- To provide the service and perform our contract: verify and redeem private-beta invitations, authenticate you, store purchases, run price and stock checks, send requested alerts, provide data export, respond to support requests and manage the subscription.
- For legitimate interests: keep the beta cohort limited, prevent invitation reuse and abuse, protect accounts, diagnose failures, maintain reliability, keep an accountable support record and understand aggregated product use. These activities are limited to what is reasonably necessary for operating the service.
- To meet legal obligations: retain or disclose limited billing, tax, fraud-prevention or compliance records where the law requires it.
Chic Magnolia does not sell personal data, use it for behavioural advertising or make solely automated decisions that have legal or similarly significant effects.
5. Service providers and recipients
Chic Magnolia uses specialist providers to operate the service:
- Supabase for authentication, invitation and access records, the application database and support records.
- Vercel for application hosting and privacy-focused web analytics.
- Stripe for Checkout, recurring billing, invoices and the Customer Portal.
- Resend for authentication messages, transactional price-drop emails and support notifications.
- Oxylabs and, for selected retailer routes, Browserless to retrieve the public retailer page associated with a saved product URL.
- GitHub Actions to initiate the protected daily-monitoring endpoint.
Providers receive only the information needed for their role. Product URLs, saved variant details and technical request data may be processed by scraping providers when a retailer check runs. Chic Magnolia may also disclose information where required by law, to protect users or to investigate misuse.
6. International processing
Some providers may process data outside the United Kingdom. Where this happens, Chic Magnolia relies on the provider's applicable transfer mechanism and contractual or organisational safeguards. Use the support form for more information about a particular provider or transfer.
7. Cookies and analytics
Supabase authentication uses cookies that are necessary to keep you signed in and protect dashboard access. Vercel Web Analytics is configured for aggregated analytics, does not use advertising cookies and is not used to follow you across other websites. Chic Magnolia does not currently use marketing or behavioural advertising cookies.
8. How long we keep data
- The invited email address is removed from the invitation record when the invitation is successfully redeemed. Unused or expired invitation records are retained only as reasonably needed to manage the limited beta and prevent abuse, then removed or anonymised.
- Account, beta-access, purchase, monitoring and notification data is generally kept while the account exists and is deleted when the account is deleted.
- Support, privacy-rights and security-report records are kept for as long as reasonably needed to respond, prevent abuse and demonstrate how the request was handled. Deleting an account removes the account link but does not automatically erase an unresolved support record.
- Failed-request and security records are kept only for as long as reasonably needed to troubleshoot, protect the service and establish or defend legal claims.
- Stripe and other providers may retain billing or compliance records under their own legal obligations even after the Chic Magnolia account is deleted.
- Backups and provider recovery systems may take a limited period to cycle out deleted data, during which it is not used for normal service activity.
9. Your rights
Depending on the circumstances, UK data-protection law may give you rights to access, correct, erase, restrict or object to processing and to receive portable data. The Settings page provides a JSON download and self-service account deletion. You can also submit a request through the support form if the self-service tools do not meet your request, including a request about an invitation sent to your email address.
You may complain to the UK Information Commissioner's Office. Details are available at ico.org.uk. We would appreciate the opportunity to address the concern first.
10. Account deletion
Deleting an account removes the Supabase authentication user and cascades deletion through the user-owned Chic Magnolia profile, beta-access grant, purchases, price checks, notifications and subscription-state record. The redeemed invitation keeps only its non-personal redemption state and loses the user link. If a Stripe customer is linked, Chic Magnolia first requests deletion of that Stripe customer, which immediately ends active Stripe subscriptions and removes saved payment details from future use. Historical records may remain where Stripe or Chic Magnolia must retain them for legal, accounting, fraud-prevention, support or dispute purposes.
11. Security
Chic Magnolia uses one-way invitation-token hashing, single-use redemption, authenticated access, database row-level security, server-only credentials, signed Stripe webhooks, encrypted HTTPS transport and restricted security headers. No internet service can guarantee absolute security, so please use a unique password and submit a security report through the support form if you believe an account or invitation has been compromised.
12. Changes to this notice
The current notice version is 2026-08-04. Material changes will be shown in the service or communicated before a new use of personal data begins. Earlier versions may be retained for accountability records.