Skiply Privacy Policy

Last updated: Aug 2026

The short version

This is some text inside of a Skiply helps retailers decide what to do with returned products. Our software looks at a photo or video of an item, assesses its condition, and recommends the channel where that item is worth the most.

Here is what matters most about how we handle data:

We work for retailers.

When a shopper scans a returned item, we process that data on behalf of the retailer they bought from. The retailer's own privacy policy governs that relationship.

We care about the item, not the person.

Our models are built to recognize products, packaging, and condition. We do not use images to identify people, and we do not build or use facial recognition or biometric matching.

We do not sell personal information.

We never have and we do not intend to.

We collect as little as we can.

We ask retailers to send us the minimum data a return actually requires.

We are an early-stage company.

We say what is true today and what we are committing to as we grow. Where a practice is a commitment rather than something already running, we say so.

This summary is here for clarity. The full policy below is what governs.div block.

Who we are and what this policy covers

Skip Industries, Inc., doing business as Skiply ("Skiply," "we," "us"), is a Delaware corporation based in Boston, Massachusetts. We build returns intelligence software that uses computer vision to assess returned products and route them to the highest-value disposition channel.

Skiply is an early-stage company. Our product is in development and we are working with a small number of prospective retail partners. This policy covers both what we do today and how we will handle data as the product moves into production. We will update it as our practices change.

This policy explains how we handle personal information in two different roles.


As a controller.

We decide how information is handled when it comes from our website, our marketing, our conversations with prospective customers and partners, our support channels, and the accounts of people who administer our platform.

As a processor or service provider.

We handle information on a retailer's behalf when their shoppers, employees, or logistics partners use Skiply to scan and route returned items. In that role we act on the retailer's instructions under our contract with them.

If you are a shopper who used a Skiply-powered scan flow during a return, the retailer you bought from is the right place to start with questions about your data. We will always help route a request that reaches us directly.

Information we collect as a controller


Information you give us.

Name, business email, phone number, job title, company, and anything else you choose to send us when you request a demo, contact us, subscribe to updates, apply for a job, or reach out for support.

Account information.

Credentials, role and permission settings, and configuration choices for users who administer Skiply for a retailer.

Billing information.
Billing contact, addresses, and transaction records. If and when we bill customers, card and bank details will go directly to a third-party payment processor. We do not store full payment card numbers.

Usage and device information.

IP address, browser and device type, operating system, pages viewed, referring URLs, timestamps, and error logs. We collect this through cookies and similar technologies, described under Cookies and analytics below.

Communications.

Emails, support messages, and notes from conversations. If we record a call, we tell you first and ask for consent where the law requires it.

Information we process on behalf of retailers

When a retailer deploys Skiply, data flows into our platform through one or more paths. The retailer controls which paths are used and what fields are sent.


Item capture data.

Photos, video, or scans of a returned product, along with capture metadata such as timestamp, image dimensions, device type, and image quality signals. Depending on the retailer's configuration, capture may happen on a shopper's own phone through a retailer-branded flow, on a device operated by store, warehouse, or carrier staff, or through images the retailer sends to our API from systems they already run.


Return and order context.

Order or RMA number, SKU, product identifiers, purchase date, return reason, price paid, and similar transaction details the retailer sends us so we can assess the item.

Limited shopper identifiers.

Where the retailer's integration includes them, this may cover a return ID, an email address, a name, or a shipping location. We ask retailers to send us the minimum needed for the return to work. We do not need direct shopper identifiers to assess an item.

Outputs we generate.

Condition assessments, completeness signals, estimated resale value by channel, and the routing recommendation itself.

How we treat this data.

We use it to deliver the service to the retailer, to keep the platform working and secure, and, in de-identified and aggregated form, to improve our models. We do not use it for our own advertising. We do not sell it. We do not share one retailer's identifiable data with another retailer.

Item images and what we do not do with them

Item images are the core input to our product, so we want to be specific about them.

What we analyze.

Our computer vision models are built to recognize products, brands, packaging, accessories, wear, damage, and other signals of condition and completeness. That is the analysis we run.

What we do not do, by design.

We do not use images to identify, verify, or track any individual. We do not create, collect, or store faceprints, voiceprints, iris or retina scans, fingerprints, hand or face geometry, or any other biometric identifier, and we do not derive one from an image. We do not perform facial recognition, emotion detection, demographic inference, or household profiling. We do not use images to build a picture of anyone's home. These are architectural choices, not settings, and they are not something a customer can turn on.

Incidental content.
A scan taken in someone's home may unintentionally capture a person, a room, or unrelated belongings in the background. We ask retailers to guide shoppers to frame only the item. Before we use any item data for model development, we commit to reviewing and removing images that contain incidental people, and we are building automated screening to do this at scale as our volume grows. If you believe an image of you was captured, email info@skiply.ai and we will locate and delete it.

Sensitive categories.

We do not seek out health, financial, biometric, precise geolocation, or other sensitive categories of personal information through item capture. Where a retailer's product catalog makes such inference possible, we handle that data under the additional protections our contract with that retailer requires.

How we use information

We use the information described above to:

- Provide, operate, and support the Skiply platform
- Generate condition assessments, value estimates, and routing recommendations
- Set up, configure, and troubleshoot retailer integrations
- Authenticate users and secure accounts
- Detect, investigate, and prevent fraud, abuse, and security incidents
- Bill for the service and manage our contracts
- Respond to questions and provide support
- Analyze usage so we can improve features, accuracy, and performance
- Develop, train, and evaluate our models using de-identified and aggregated data
- Send business communications and, where permitted, marketing you can unsubscribe from at any time
- Meet legal, tax, and regulatory obligations

Where GDPR or UK GDPR applies, we rely on these legal bases: performance of a contract, our legitimate interests in operating and improving a secure service, consent where we ask for it, and compliance with legal obligations.

How we use data to improve our models

Model quality is what makes Skiply useful, and improving it requires data. Here is our commitment on how we do that.

We use de-identified and aggregated data.

Before item data is used for model development or evaluation, we remove direct identifiers and retailer-attributable fields and separate the data from the account it came from. We do not attempt to re-identify de-identified data except to confirm that our de-identification worked.

We do not expose one customer's data to another.

No retailer's proprietary data, pricing, catalog, or performance information is disclosed to another retailer, directly or through a model output.

We do not use item images to identify people.

See Item images and what we do not do with them, above.

Your agreement can override this.

If a retailer's contract with us restricts the use of their data for model improvement, that contract controls and we honor it.

Cookies and analytics

On our website we use a small number of cookies and similar technologies to keep the site working and to understand how visitors use it. Where a cookie is not strictly necessary, we ask for your consent first in the regions that require it, and you can change your choice at any time through the cookie controls on our site or your browser settings. Blocking non-essential cookies will not break the site.

Because we do not sell personal information or share it for cross-context behavioral advertising, opt-out preference signals such as Global Privacy Control do not change how we handle your data. We will honor them if that ever changes.

Our product application uses only the cookies necessary to run the service and keep sessions secure.

How we share information

We share personal information only in these situations.

Service providers and subprocessors.

Cloud hosting, model infrastructure, data storage, error monitoring, analytics, payment processing, communications, and support tooling. Each is bound by contract to protect the data and use it only to provide services to us. A current list of our subprocessors is available on request at info@skiply.ai, and customers receive advance notice of material changes as their agreement provides.

Resale and disposition channels.
When Skiply routes an item, we transmit the information the receiving channel or partner needs to accept it, such as item condition, product identifiers, and the details the retailer instructs us to send. We do not send shopper personal information to these channels unless the retailer directs us to and the return requires it.

At the retailer's direction.

Retailers can export their data or connect Skiply to other systems they use. When they do, the data goes where they tell us to send it.

Legal and safety.

When we are required to by law, subpoena, or court order, or when we believe in good faith that disclosure is necessary to protect rights, safety, or the integrity of our service. Where we are permitted to, we will notify the affected customer before disclosing.

Corporate transactions.
In connection with a merger, acquisition, financing, or sale of assets, subject to this policy continuing to apply to the transferred data.

We have never sold personal information, and we have never shared it for cross-context behavioral advertising as those terms are defined under U.S. state privacy laws. We do not intend to.

Security

We are an early-stage company and we would rather be accurate than impressive.

Where we are today.

Our product is in development. We have not yet begun processing production returns data at scale, and we are deliberately limiting the data we hold while we build. We rely on the encryption and access controls provided by our cloud infrastructure and the reputable third-party services we use, and we keep access to our systems restricted to the small number of people who need it.

What we are building.

Before we process production returns data for a retail customer, we commit to having the following in place, and we will describe our progress honestly to any customer who asks:

- Encryption of data in transit and at rest
- Role-based access control on the principle of least privilege
- Multi-factor authentication on all internal systems
- Logical separation of each customer's data
- Access and application logging with review
- A written incident response plan
- Security review of each subprocessor before onboarding
- Confidentiality obligations and security training for everyone with access to customer data

Our Trust and Security page describes this in more detail and is the page we keep current.

What we will not tell you.

That any system is completely secure, or that we have certifications we do not have. If we learn of a breach affecting personal information, we will notify affected customers and individuals as required by law and our contracts, and we will tell you what we know as we know it.

How long we keep data

These are the retention limits we apply. Where a customer's contract sets a shorter period, that period controls.
Data Retention
Item images and capture media No longer than 180 days after the return is resolved, then deleted or irreversibly de-identified, unless the retailer's contract sets a different period.
Return and order context For the term of the retailer's agreement, then deleted or de-identified within 90 days of termination unless the law requires longer.
De-identified and aggregated data Retained indefinitely, since it is no longer linked to any individual or customer.
Account and administrator data For the term of the agreement, then up to 90 days after termination.
Billing and tax records Seven years, as tax and accounting rules require.
Website and marketing contacts Until you unsubscribe or ask us to delete, then removed from active systems within 30 days.
Backups follow their own rotation and are purged on a rolling schedule.

Your rights and how to exercise them

Depending on where you live, you may have the right to know what personal information we hold about you, get a copy of it, correct it, delete it, limit how we use sensitive information, opt out of sale or targeted advertising, and appeal a decision we make on your request. Where we rely on consent, you can withdraw it at any time.

If you dealt with Skiply directly

(you visited our site, talked to our team, or administer a Skiply account), email info@skiply.ai. We will verify your identity and respond within the time the law allows, generally 45 days, with an extension where permitted.

If you are a shopper whose return was processed through Skiply,
the retailer you purchased from controls that data. Contact them first. If you contact us, we will forward your request to that retailer and support them in fulfilling it.

We will not discriminate against you for exercising any of these rights.


European Economic Area, UK, and Switzerland.

You have the rights described above under GDPR and UK GDPR, including the right to lodge a complaint with your supervisory authority. If we transfer personal data out of these regions, we will do so under Standard Contractual Clauses, the UK Addendum, or another approved transfer mechanism.

Illinois, Texas, Washington, and other biometric privacy jurisdictions.

As stated above, Skiply does not collect, capture, store, or use biometric identifiers or biometric information as those terms are defined in applicable law, and does not use images for facial recognition or biometric matching.

Children

Skiply is a business service and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child's information reached us, email info@skiply.ai and we will delete it.

Changes to this policy

We will update this policy as our product and the law change, and we expect to update it as we move from development into production. When we make a material change we will update the date at the top, post the revised policy here, and give notice by email or in the product before it takes effect. Prior versions are available on request.

Contact us

For privacy questions, data requests, security reports, and anything else, email info@skiply.ai.

Mailing address:

Skip Industries, Inc. (dba Skiply) Boston, MA

Building the valuation infrastructure
for the footwear industry.

Legal

© 2026 Skiply