Privacy Policy
This Privacy Policy explains how The Modesty House ("we", "us", "the site"), available at themodestyhouse.com, handles information about visitors. We take your privacy seriously and only collect what we need to run the site.
The Modesty House is a discovery and affiliate website for modest fashion. We do not sell products ourselves. We show items from other brands and link out to their own shops. We do not run a checkout, do not take payments, and do not have user accounts.
1. Who is responsible for your data (data controller)
The party responsible for this website and for your personal data is:
- The Modesty House, based in the Netherlands.
- Contact: [email protected]
2. What information we collect
We keep data collection to a minimum. We collect:
- Technical/server data (automatic). Our hosting provider automatically records standard technical information when you visit, such as your IP address, browser type, device type, the pages you view, and the date and time of your visit. This is normal for any website and is used for security, troubleshooting, and keeping the site running.
- Your saved favourites. If you save an item, your list is stored only in your own browser (in local storage, under the key
tmh_favs). The list itself never reaches our servers, is not linked to you, and is cleared if you clear your browser data. Each individual save is counted anonymously — see Pieces you save, below. - Style It selections. When you mix and match pieces, that happens entirely in your own browser. We do not record it.
- Page views (analytics). We use Pulse, by Ciphera, to understand how visitors use our site. It collects anonymous data: which pages are viewed, where visitors come from (the referring site), device type, browser, operating system, country, screen resolution, browser language and time zone. Pulse uses no cookies and no other persistent identifiers, so it cannot recognise you on a later visit or follow you to other websites, and the data is processed in a privacy-preserving way and is not used to identify individuals. Known bots and referrer spam are excluded. If your browser sends a Do Not Track or Global Privacy Control signal, your visit is not recorded at all.
- Clicks through to a brand. When you click a link that takes you to a brand’s own shop, we record that a click happened, using the same Pulse analytics described above. We record only which brand you went to, what kind of garment it was, and which part of our site you clicked from. We do not record which specific product you clicked, the web address you were sent to, or anything that could identify you. We do this because affiliate commission is how the site is funded, so we need to know which brands our readers actually find useful. Like the rest of Pulse, it uses no cookies and no identifier for you, and it is not recorded at all if your browser sends a Do Not Track or Global Privacy Control signal.
- Pieces you save. When you tap the heart to save a piece, we record that a save happened, using the same Pulse analytics described above. For this one we do record which product it was — its name and our internal reference for it, the brand, and the kind of garment — because which pieces readers save is the only thing this measurement is for. We record nothing about you and build no list: what we see is how many times a piece has been saved across all visitors, never who saved it or what else they saved. Like the rest of Pulse, it uses no cookies and no identifier for you, and it is not recorded at all if your browser sends a Do Not Track or Global Privacy Control signal.
- Which controls you use. Using the same Pulse analytics described above, we also count a few specific actions, so we can tell what the site is good at and what it is missing. These are: opening a product's quick view and copying a product's share link (recorded the same way as a save, above — the product, its brand and the kind of garment); changing the display currency (which currency you chose, and which you changed from); using a filter or the sort control on a grid (which filter, which value, and which page — for example “colour, olive, /directory”); signing up to the newsletter (that a sign-up happened and that it came from the footer — never your email address, which reaches us by email as described below); sending the contact form (only which topic you picked from the dropdown — never your name, address or message); opening an FAQ question or a step of the “how it works” column (which one); opening a product's photograph full size (the same product details as a save); tapping “Load more” on a grid (which page, and how many pieces are now shown); opening a navigation menu (which menu); scrolling one of the homepage rails (which rail, and which direction); opening a region on the designers map (which region); and following a sub-category link such as “Blazers” or “Undercaps” (which page and which sub-category). None of these carry anything about you.
- Buttons and links you tap, in general. Alongside the specific actions listed above, Pulse records that a click happened on a button or link and the words written on it — for example “Load more” or the name of a lane. The label is shortened to 60 characters, and any email address or long run of digits in it is replaced with
[email]or[number]in your browser, before anything is sent, so a label that happens to contain either never leaves your device intact. In the same way we record that something was copied from a page and how much — never what was copied — and, when a form is sent, the form's name and how many fields it had — never a value you typed and never a field's name. We do this so we can see which parts of the site people actually use rather than guessing. As with everything above, it uses no cookies and no identifier for you, and none of it is recorded if your browser sends a Do Not Track or Global Privacy Control signal. - Searches that find nothing. If you search and we have no matching pieces, we record the words you searched for. This is the one thing we record that you typed, and we record it only when the search found nothing, only once per search, and only up to 60 characters — never a search that worked, and never together with anything else about you. We do it because a search we cannot answer is the clearest possible statement of what the directory is missing. If you would rather it were not recorded, a Do Not Track or Global Privacy Control signal turns off all of the above, including this.
- Messages you send us. If you email us, we receive your email address and whatever you write, so we can reply.
- Contact form submissions. If you use the form at /contact, we receive the name, email address, subject and message you enter. These are sent to us as an email via Resend, our email delivery provider — we do not store them in a database. The form is protected by Cloudflare Turnstile, an anti-spam check that verifies you are not a bot; it processes your IP address and limited browser signals for that purpose, and does not track you across sites. We also briefly hold the IP address a submission came from — in the server's memory only, for about a minute, and never written to disk — so that a single source cannot flood the form.
- Newsletter sign-ups. If you enter your email address in the sign-up field in our footer, we receive that address by email so we can add you to our mailing list. We do not store it in a database on this website. You can ask us to remove you at any time by emailing [email protected], and every newsletter we send will include an unsubscribe link.
We do not knowingly collect sensitive personal data, and we do not ask you to create an account or give us your name, address, or payment details.
3. Why we use your data and our legal basis (GDPR)
Under the EU General Data Protection Regulation (GDPR), we must have a legal basis for using your data. We rely on:
- Keeping the site secure and working (server logs) — to prevent abuse and fix problems. Legal basis: legitimate interest, Art. 6(1)(f).
- Sending you the newsletter, if you signed up for it — to send occasional updates you asked for. Legal basis: your consent, which you can withdraw at any time.
- Replying to your emails and contact form messages — to answer your question. Legal basis: legitimate interest, or your consent.
- Anti-spam and abuse prevention on the contact form (Cloudflare Turnstile, rate limiting) — to stop automated abuse. Legal basis: legitimate interest, Art. 6(1)(f).
- Affiliate click tracking by third-party networks — to earn the commission that funds the site. Legal basis: legitimate interest, or consent where required.
- Measuring how the site is used (Pulse analytics) — to understand which pages are useful. Because it uses no cookies and stores no identifier for you, we rely on legitimate interest, Art. 6(1)(f). If we ever add analytics that identify you or follow you across sites, we will ask for your consent first.
4. Affiliate links and third parties
The Modesty House earns commission through affiliate programs. When you click a product and go to a brand's shop, that click may be tracked by an affiliate network so the brand knows the visit came from us. If you then buy something, we may earn a commission at no extra cost to you.
The affiliate networks and partners we may use include:
- Skimlinks
- Awin
- LTK (rewardStyle)
- The brands and retailers we link to
These third parties may set their own cookies and process data (such as your IP address and the fact that you clicked) under their own privacy policies, which we do not control. We recommend reading the privacy policy of any site you click through to.
We also use:
- Cloudflare — sits in front of this site and does three things: it provides our network and security layer, which means it sees the IP address and request details of every visit; it runs the Turnstile anti-spam check on the contact form; and it routes inbound mail addressed to [email protected], so anything you email us passes through it. Cloudflare is a US company; see Section 7 on international transfers.
- Pulse (ciphera.net) — our analytics provider. It receives the anonymous page-view information described in Section 2. Its script and its event endpoint are delivered through a European content network (Amsterdam); see Section 7. For more information, see Pulse's documentation.
- Resend — our outbound email provider. Messages you send through the contact form are delivered to us through Resend, which means the name, email address and message you enter pass through it. Resend is a US company; see Section 7 on international transfers.
- Railway — our hosting provider, which processes server and request data as described above. Railway is a US company; see Section 7 on international transfers.
- Shopify — product images shown on this site are loaded directly from the brands' own Shopify content network (
cdn.shopify.com), which means your browser requests those images from Shopify. - Pinterest — we distribute content on Pinterest; if you arrive from Pinterest, Pinterest's own privacy policy applies to your activity there.
5. Cookies
A cookie is a small file stored on your device. We use cookies and similar storage only where needed:
- Strictly necessary storage — used for the site to function, such as remembering the items you have favourited. This stays in your browser and does not require consent.
- A short-lived analytics record — so the same page view is not counted twice during one visit. It is cleared when you close the tab, and contains no identifier for you.
- An opt-out flag — stored only if you choose to exclude yourself from analytics, so we can remember that choice.
- Third-party affiliate cookies — set by affiliate networks (Section 4) when you click a product link, so a sale can be credited to us.
We use no advertising cookies and no analytics cookies. Our analytics (Section 2) is cookieless — it stores no identifier for you and cannot follow you between websites — which is why we do not ask you to accept a cookie banner for it, and why it does not build a profile of you. If we ever add advertising or cross-site tracking cookies, we will update this policy and ask for your consent first.
You can block or delete cookies in your browser settings at any time. Some features may not work as well if you do.
6. Sharing your data
We do not sell your personal data. We only share data with:
- Service providers who help us run the site (such as our hosting provider), and
- Affiliate networks and linked brands, as described in Section 4,
and only as far as needed for those purposes, or where we are legally required to.
7. International data transfers
Some of our partners — for example our hosting provider, Cloudflare, Resend, Pulse, affiliate networks, and the image network described in Section 4 — may process data outside the European Economic Area (EEA), including in the United States. Where that happens, those transfers are covered by safeguards recognised under GDPR, such as the EU Standard Contractual Clauses or an adequacy decision.
8. How long we keep data
- Server logs: kept only as long as needed for security and troubleshooting, then deleted or anonymised.
- Emails and contact form messages: kept as long as needed to handle your request and for our records, then deleted. Form submissions reach us only as email — no copy is kept on the website.
- Contact form anti-flood records: the IP address a submission came from is held in the server's memory for about a minute and then discarded. It is never written to disk.
- Analytics: raw event data is automatically deleted by Pulse after 6 months; aggregated statistics may be kept longer. Because no cookie or persistent identifier is used, none of it is linked to you as an individual.
- Favourites and Style It selections: never stored by us — they stay in your browser.
9. Your rights under GDPR
If you are in the EU/EEA, you have the right to:
- Access the personal data we hold about you.
- Rectify data that is wrong or incomplete.
- Erase your data ("right to be forgotten").
- Restrict or object to our use of your data.
- Data portability — receive your data in a usable format.
- Withdraw consent at any time, where we relied on consent.
To exercise any of these, email [email protected]. We will respond within one month.
You also have the right to complain to the Dutch data protection authority, Autoriteit Persoonsgegevens — autoriteitpersoonsgegevens.nl.
10. Children
This site is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top shows the latest version. Significant changes will be noted on the site.
12. Contact
Questions about your privacy or this policy?
The Modesty House — [email protected]
