Trust
Data Privacy & Security
Last updated: 11/09/2026
LookLayer handles personal photographs and client information, so we take security seriously. This page explains, in plain language, where your data lives, who hosts it, how it is protected, and how you can access or delete it. It should be read together with our Privacy Policy.
Where your data is stored
LookLayer Studio runs on managed cloud infrastructure, with data stored in a dedicated cloud database powered by Supabase, which runs on Amazon Web Services (AWS). Your application data — accounts, client profiles, products, looks and questionnaire responses — lives in this database, and photographs and product images are stored in encrypted cloud object storage attached to it.
The application itself runs on Cloudflare's global edge network, so pages load quickly and securely from data centres close to you. AI try-on images are generated through contracted AI providers; images sent for generation are processed to produce the result and are not used to train public models.
Data may be stored or processed in Australia and other countries where these providers operate. Where data crosses borders, it is protected by the safeguards described below and by our providers' own compliance programmes.
Who hosts it — and their certifications
We don't run our own servers. We rely on established, independently audited infrastructure providers:
- Amazon Web Services (via Supabase) — hosts the database and file storage. AWS holds ISO 27001, SOC 1/2/3 and PCI DSS certifications, and Supabase itself is SOC 2 Type II compliant, meaning its security controls are independently audited on an ongoing basis.
- Cloudflare — runs the application and serves the website. Cloudflare holds ISO 27001, SOC 2 Type II and PCI DSS certifications and is GDPR compliant.
In short: every layer of the stack is operated by providers with recognised, independently verified security certifications.
How your data is protected
- Encryption in transit: all traffic between your browser, our application and the database is encrypted using TLS (HTTPS).
- Encryption at rest: database contents and stored photographs are encrypted at rest (AES-256) by the underlying infrastructure.
- Private by default: client photographs are stored in private storage — they are not publicly accessible and can only be viewed by the stylist who uploaded them while signed in.
- Row-level security: database access rules are enforced at the data layer, so each account can only ever read or modify its own clients, products and looks — even if the application itself had a bug.
- Access controls: accounts are protected by password authentication; team and retail accounts use role-based permissions, and only the platform administrator can manage plans and licences.
- Share links: client lookbooks are shared through long, unguessable links rather than public listings, and can be revoked by deleting the look.
Client photographs
Client photographs are among the most sensitive data on the platform. They are uploaded by the stylist, stored in private encrypted storage, and used only to generate the try-on images the stylist requests. Photographs submitted through retail try-on widgets are processed once to produce the result and are not retained by LookLayer afterwards.
Stylists are responsible for having their clients' permission to upload photographs. Clients can ask their stylist — or us directly — to have their photographs and profile deleted at any time.
Deletion on request
You stay in control of your data:
- Stylists can delete individual clients, photographs, products and looks at any time from within the studio — deletion is immediate.
- Anyone can request full deletion of their personal information by emailing us, and we will action it within 30 days.
- If an account is closed, its associated data is deleted. Residual copies may remain in encrypted backups for a limited period before being permanently purged.
GDPR and your rights
Although LookLayer is an Australian business, we extend GDPR-style rights to everyone who uses the platform. You (or your clients) can:
- Access the personal information we hold about you;
- Correct inaccurate information;
- Delete your information ("right to be forgotten");
- Export your information in a portable format on request;
- Object to or restrict certain processing, including marketing emails (every marketing email includes an unsubscribe link, honoured automatically).
Where we process personal data on behalf of a stylist or retailer (for example, their clients' photographs), the stylist or retailer is the data controller and LookLayer acts as the data processor. To exercise any of these rights, contact us at support@looklayerstudio.com.
Data breaches
If a data breach occurs that is likely to result in serious harm, we will notify affected users and the relevant regulator in line with the Australian Privacy Act's Notifiable Data Breaches scheme (and GDPR timelines where applicable), and we will tell you what happened and what we're doing about it.
Questions
For any security or privacy question, or to report a concern, email support@looklayerstudio.com.
