PRIVACY POLICY
Last updated: 10/10/2025
Who we are: FLYP LTD, Flat 4, 88 Kensington Park Road, London, W11 2PL, United Kingdom (“FLYP”, “we”, “our”).
Contact: info@flyp.space
This Policy explains how we collect, use, share and protect personal data when you use our website and app (the “Platform”). It covers creators and buyers using FLYP to create and sell fashion, including our integrations with YouTube and Google Merchant Center.
1) Data we collect and why
1.1 Account & service data (Contract)
What: name, email, profile photo, username, phone (if provided); creator storefront/catalog data.
Why: create/manage your account, provide support, power selling features.
Legal basis: Contract (perform the service).
1.2 Transactions & fulfilment (Contract / Legal obligation)
What: buyer/seller name and city/country, order details, payment status, delivery info.
Why: process orders, prevent fraud, provide customer service, keep tax/accounting records.
Legal basis: Contract; Legal obligation (records/tax).
1.3 Google account data (YouTube / OAuth)
We request the minimum necessary Google permissions to power creator features.
Scopes requested (exact strings) & purpose
-
https://www.googleapis.com/auth/youtube.third-party-link.creator — read/write: link your Merchant Center to your YouTube channel so products can be published to YouTube Shopping.
-
openid and https://www.googleapis.com/auth/userinfo.email — read: identify your Google account and email to associate your channel with your FLYP account.
-
https://www.googleapis.com/auth/youtube.readonly — read: read channel/video metadata to support storefront setup and reporting.
-
https://www.googleapis.com/auth/youtube.force-ssl — read/write: manage channel resources required to identify account type and link your channel to our backend.
-
https://www.googleapis.com/auth/youtubepartner — read/write: use channel/video metadata (title, description, channel name, subtitles) to generate garment listings from videos where partner features are required.
-
https://www.googleapis.com/auth/content — read/write: sync products with Google Merchant Center (Shopping Content API).
Offline access (refresh tokens). We request offline access so key features continue to work when you’re not online.
-
YouTube tokens: streamline product creation from videos.
-
Merchant Center tokens: keep products in sync via the Content API.
-
Storage & security: tokens are stored in separate projects for YouTube and Merchant Center and encrypted at rest using Google Cloud KMS (google.cloud.kms).
-
Retention: tokens are kept until you unlink the integration (see User controls).
-
Legal basis: Contract (to provide the features you enable).
1.4 Analytics & measurement (Consent in EEA/UK)
Tools: Google Analytics 4 (GA4) and Mixpanel.
What: device/usage events and conversions as described below.
Legal basis (EEA/UK): Consent for non-essential analytics/measurement. See Cookies & similar technologies.
2) YouTube Shopping & Google Merchant Center
If you connect your YouTube channel and Merchant Center to sell on YouTube:
-
Linking: during onboarding, we link your Merchant Center account with your YouTube channel to enable YouTube Shopping.
-
Syncs (server-to-server): our backend keeps product changes in sync with Merchant Center using the Shopping Content API (https://www.googleapis.com/auth/content) — e.g., product creation/updates, prices, and availability.
-
Data shared with Google: product details (title, price, images, identifiers), account/channel and merchant IDs, and programme status information needed to publish products on YouTube.
-
Legal basis: Contract (to make your products available on YouTube as you requested).
3) Conversion measurement (sharing with analytics/Google)
To attribute sales and improve reporting we record purchase/conversion events:
-
Fields sent: orderId, productId, quantity, price, timestamp, and a user identifier:
-
Logged-in: Firebase UID
-
Logged-out: anonymous UID
-
-
Destinations: GA4 and Mixpanel. (If you enable YouTube/Google conversion measurement on the web, the conversion events described above may also be used to attribute purchases resulting from YouTube.)
-
No hashed email/phone: we do not currently send hashed contact data with conversions.
-
Legal basis (EEA/UK): Consent for ads/measurement. If you decline Ads/Measurement in our banner, we limit tags accordingly and (for Google tags) reflect your choice via Consent Mode v2.
-
No selling & limited use: we do not sell personal data. We do not use conversion data to build profiles for unrelated advertising.
4) Cookies & similar technologies
We use strictly necessary cookies to run the Platform and, with your consent, analytics and measurement cookies.

Your choices: Use Cookie settings in the footer to grant/withdraw consent anytime. In the EEA/UK, we use a consent banner and implement Consent Mode v2 so Google tags honour your choice.
5) Sharing your data
-
Other users during a transaction: we share buyer/seller name and city/country to facilitate communication and fulfilment.
-
Service providers (processors): we use third parties to operate the Platform (hosting, analytics, payments, support, CDN). See Sub-processors.
-
Legal, safety, and corporate events: we may share data to comply with law, protect rights, or as part of a merger/acquisition.
We do not disclose full addresses or direct contact details to other users unless required for fulfilment with appropriate safeguards.
6) International transfers
We may transfer data outside the UK/EEA. Where we do, we use appropriate safeguards such as EU Standard Contractual Clauses and the UK Addendum, and conduct transfer impact assessments where required.
-
Primary hosting region: europe-west2 (London).
-
Key vendors & countries: see Sub-processors.
7) Retention
-
Account data: we will retain your personal information for the period necessary to fulfill the purposes outlined in this privacy policy, according to our data retention schedule, unless a longer retention period is required or permitted by applicable law. You can request deletion of your personal information at any time
-
Orders/transactions: retained to meet legal/accounting obligations.
-
Products: may remain by reference to your UID for catalogue integrity.
-
OAuth tokens: kept until you unlink your YouTube or Merchant Center connection; deleted immediately upon unlink.
-
Logs: 30 days for security/troubleshooting.
-
Analytics: retained according to each tool’s configuration (e.g., up to 14 months for GA4).
8) Security (summary)
-
Hosting & region: cloud hosting in europe-west2 (London).
-
Encryption: TLS for data in transit; encryption at rest. OAuth refresh tokens are encrypted using Google Cloud KMS.
-
Access controls & logging: access to production is restricted by role; administrative and data-access events are logged.
9) Sub-processors
We use third-party service providers that process data on our behalf:

10) Your rights & controls
-
Disconnect Google/YouTube: use our Disconnect flow in Settings. This revokes tokens and stops future data sharing.
-
Export or delete your data / account: email info@flyp.space
-
What remains after account deletion: order records (legal/accounting) and products by UID reference may persist as required.
-
Other rights: access, rectification, restriction/object, and portability. Contact info@flyp.space
If you’re in the UK/EEA, you can also complain to your local authority. In the UK, that’s the ICO (ico.org.uk).
11) Children
The Platform is not intended for users under the age of 16. If you believe a minor has provided personal data, contact us and we will take appropriate action.
12) Changes
We’ll post any changes to this Policy here and update the “Last updated” date. For material changes, we may notify you by email or in-app.
Contact: info@flyp.space