Skip to content
Floor Tape
Private betaExplore the roster and place non-binding bids. No payments are taken yet — we confirm every placement by email.Join the first round
StuntKit
← All legal documents

Everyone using StuntKit

Privacy Notice

What personal data we hold, why we hold it, how we treat body measurements and 3D scans, who we share it with, and the rights you can exercise over it.

Version
1.0
In force from
26 September 2026
Governing law
Laws of India

Who is responsible for your data

In plain terms. StuntKit decides how your data is used, and answers for it.

1.1 StuntKit is the data fiduciary under India's Digital Personal Data Protection Act 2023, and the data controller under the EU and UK General Data Protection Regulation where that applies to you.

1.2 We publish a named contact for privacy questions, as the DPDP Act requires. Write to our Grievance Officer at boom@stuntkit.com, or for anything formal, boom@stuntkit.com. We answer within thirty days and usually much faster.

What we collect

In plain terms. Account details, what you list, what you upload, and how you use the site.

2.1 Account and identity data: your name, email address, password (stored only as a hash), your role, and for brands the company you represent.

2.2 Marketplace data: your listings, floor prices, the categories you have blocked, your bids, the events you say you are attending and the invitation you uploaded to prove it, and the record of every campaign you have run.

2.3 Content you upload: garment and body meshes, artwork, reference photographs, and proof-of-delivery images and footage. For creators, this material is also governed by the Creator Terms & Content Licence, which is a separate thing from this notice and is dealt with in clause 8.

2.4 Body data: the height, chest and waist measurements, build description and reference photographs a creator provides so that we can build their 3D body, and the model built from them.

2.5 Agreement records: which legal document you accepted, which version, the sentence you agreed to, when, and the IP address and browser the acceptance came from. We keep this because an agreement without a record of it is not worth much to either of us.

2.6 Technical data: server logs and privacy-preserving, cookie-free analytics. We do not run advertising trackers on this site and there is no advertising profile of you anywhere in our systems.

Body measurements, photographs and 3D scans

In plain terms. The most personal thing we hold. Used to build and fit your model, and nothing else.

3.1 To sell a spot on a jacket, we have to know the shape of the person wearing it. That means we hold measurements, the reference photographs you send us, and the 3D model we build from them.

3.2 We treat this material as sensitive regardless of whether the law where you live formally classifies it that way. In some jurisdictions a facial or full-body scan is biometric data attracting the highest protection — Article 9 of the GDPR, and the special-category rules that follow from it — and we apply that standard everywhere rather than working out where we could get away with less.

3.3 It is used for three things: building your model, fitting artwork to it so a brand can see a placement before buying it, and rendering the previews shown on your profile and in the studio. It is not used to identify you automatically, it is not run through facial recognition, it is not matched against any other database, and it is not sold.

3.4 Reference photographs are visible only to you and to the StuntKit reviewers who build the model. The finished body and garment meshes are public, because they are the storefront — that is what a brand is shopping. You choose what to send us and you can ask us to rebuild a model from different references at any time.

3.5 Where your consent is the lawful basis for processing this material, that consent is asked for separately and specifically at the point you submit a body request. It is not bundled into your acceptance of the terms, because consent that is bundled into a contract you had to sign anyway is not freely given and we would rather have consent that actually holds.

Why we process it, and on what lawful basis

In plain terms. Mostly to perform the contract you signed. Never for advertising profiles.

4.1 To run your account, your listings, the auction, the escrow and the payout: because it is necessary to perform our contract with you.

4.2 To verify an event invitation, review proof of a campaign, and decide a dispute: because it is necessary to perform the contract, and because we and the other side have a legitimate interest in a marketplace where claims are checked.

4.3 To build and fit your 3D body: on your specific consent, and to perform the contract once you have asked us to build one.

4.4 To keep a record of which agreement you accepted: because we have a legal obligation to be able to evidence a contract, and a legitimate interest in being able to prove what was agreed.

4.5 To keep the platform safe, prevent fraud, and meet tax, accounting and law-enforcement obligations: legitimate interests and legal obligation.

4.6 We do not process your data to build advertising profiles, we do not sell it, and we do not use it for automated decisions that produce legal effects for you.

Machine learning

In plain terms. Creator content may train our own fitting models. It never goes to an outside AI company.

5.1 We train our own models — the ones that fit artwork to a garment, estimate a body from photographs and check a proof image against what was sold — and creator content is part of what they learn from, under clause 4 of the Creator Terms & Content Licence.

5.2 We do not license, sell or otherwise hand creator content to third-party AI developers as training data, and we do not use it to generate a synthetic likeness of a creator in any campaign the creator has not approved. Those two limits are commitments in the licence itself, not just statements of current practice.

5.3 That training permission is asked for separately from the terms, at its own moment, and is never bundled into your acceptance of them — section 6 of the Digital Personal Data Protection Act 2023 would not treat bundled consent as consent, and nor do we.

5.4 You can withdraw it from your account settings in one click, account-wide, effective immediately. No form, no review queue, no waiting period. We also publish the exclusion in machine-readable form so that crawlers we have no contract with are put on notice of it.

Who we share it with

In plain terms. Brands see what they are buying. Processors see what they must. Nobody else.

6.1 Brands see your public profile, your listings, your body and garment models, and the proof of a campaign they paid for. They do not get your email address, your measurements, your reference photographs or your identity documents unless you tell us to share them.

6.2 Creators see the brand behind a bid, because you cannot decide whether to accept a brand you are not allowed to know.

6.3 Service providers acting on our instructions: hosting, payment processing, email delivery and analytics. They are bound to use the data only for what we ask and to protect it.

6.4 Authorities, where we are lawfully required to disclose — and we will tell you when we are permitted to tell you.

6.5 A buyer or successor, if the business is ever sold, on the same terms as this notice until you are given notice of any change.

Where it lives, and how long we keep it

In plain terms. Data may cross borders. We keep it while it is doing a job, then delete it.

7.1 We operate globally, so your data may be processed in countries other than your own, including India. Where we move personal data out of a jurisdiction that restricts transfers, we rely on the mechanisms that jurisdiction recognises — standard contractual clauses for the EU and UK, and the transfer rules of the DPDP Act for India.

7.2 Account data is kept while your account is open and for six years after it closes, which is how long a claim about a transaction can be brought against either of us.

7.3 Reference photographs are deleted the moment the model built from them is delivered — automatically, as part of delivery, rather than on a schedule somebody has to remember. If you want the model rebuilt later you send fresh photographs, which we think is the right trade.

7.4 The raw biometric intermediates produced while building a body — scan point clouds, depth maps and face encodings — are deleted once the model built from them is delivered and accepted, and in any event within 30 days of that. They are not the delivered artefact, they are far more sensitive than it, and keeping them beyond the build serves no purpose we can justify to you.

7.5 Financial records are kept for as long as tax and accounting law requires.

7.6 Agreement records are kept permanently. They are the evidence of what you agreed to, and deleting them would defeat their only purpose.

7.7 Everything else is deleted or anonymised when it stops being needed for the purpose it was collected for.

Deletion and the content licence — how the two fit together

In plain terms. Deleting your data and revoking the licence are different things. One you can do; the other you cannot.

8.1 This is the part most platforms leave vague, so here it is plainly. A privacy right and a copyright licence are separate legal things, they answer to different laws, and one does not switch the other off.

8.2 What deletion reaches: your account, your login, your listings, your measurements, your reference photographs, your private messages with us, and your profile as it appears on the site. Ask and it goes, subject only to the retention periods in clause 7.

8.3 What deletion does not reach: the licence you granted over material you uploaded, which clause 3 of the Creator Terms & Content Licence states is perpetual and irrevocable and survives the closing of your account. It also cannot reach a campaign that has already run — a photograph taken at an event by somebody else, a brand's own archive, a page somebody saved. Once a placement is in the world, it is in the world, and no undertaking we could give you would change that.

8.4 What we will always do, even after deletion: stop putting you in new campaigns, stop showing your profile, and honour any objection you raise to a specific continued use. Where the law where you live gives you a right of erasure or a right to object that is stronger than this, that right wins and we will apply it — see clause 10 and the riders to the Creator Terms.

8.5 If you had understood this differently when you signed up, tell us. We would rather have the argument now than have you discover it later.

Security and breaches

In plain terms. Reasonable safeguards, and we tell you when something goes wrong.

9.1 Passwords are stored hashed, access to reviewer tooling is restricted to named StuntKit staff, and uploads are served through access checks rather than by unguessable URL alone.

9.2 No system is perfectly secure and we will not pretend otherwise. If a breach affects your personal data, we will notify you and the relevant regulator — the Data Protection Board of India, and any supervisory authority that has jurisdiction over you — within the time limits that apply, and we will tell you what we know rather than the minimum we can get away with.

Your rights

In plain terms. Access, correction, deletion, objection, portability, complaint.

10.1 Wherever you live, you can ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, ask us to stop a particular use, and ask for it in a portable form. You can also withdraw a consent you gave — for body scanning, for example — and we will stop the processing that relied on it, although that does not undo processing already carried out lawfully.

10.2 Under the DPDP Act 2023 you additionally have the right to nominate another person to exercise these rights on your behalf if you die or become incapable of exercising them yourself. Tell us who, and we will record it.

10.3 Under the GDPR, if it applies to you, you also have the right to object to processing based on legitimate interests, the right to restrict processing while a dispute about it is resolved, and the right not to be subject to solely automated decision-making with legal effects. We do not carry out that last kind of processing.

10.4 Exercise any of these by writing to boom@stuntkit.com. We do not charge for it, and we will not make you use a form.

10.5 If we get it wrong, complain to us first — then, if you are still unhappy, to the Data Protection Board of India, or to your own supervisory authority if you are in the EEA or the UK, or to the equivalent regulator where you live.

Children

In plain terms. This is an adult platform.

11.1 StuntKit is not for people under 18. We do not knowingly collect personal data from a child, and we do not run any campaign directed at children. If you believe a child has given us data, tell us and we will delete it.

Changes to this notice

In plain terms. Versioned, dated, and announced when it matters.

12.1 This notice carries a version number and an effective date, and superseded versions are kept. Where we change it in a way that materially affects you, we will tell you by email before the change takes effect rather than quietly republishing the page.

Privacy Notice, version 1.0, in force from 26 September 2026. Superseded versions are kept and are available on request: whichever version you accepted is the one that governs what you have already granted.