LEGAL
Hey Lullae: Styling Concierge & Boutique Checkout Policies
LAST UPDATED · 13 JULY 2026
Introduction
Hey Lullae ("Hey Lullae", "we", "us", "our") operates a private AI styling concierge and unified boutique checkout platform. Our AI concierge curates fashion tailored to your silhouette, style profile and personal inspiration, and Hey Lullae acts as the checkout of record for purchases from a network of independent boutique partners — a single, unified checkout experience across multiple brands. The two sides of the product are operated by the same entity and governed by the same policies below.
These policies establish trust with our customers, protect our brand, and satisfy the mandatory legal compliance guidelines required by our payment processors and local regulatory frameworks (such as the Protection of Personal Information Act, 2013 (POPIA) in South Africa).
Part 1: Privacy Policy
Introduction
This Privacy Policy explains what information we collect, how we use it, how we protect it, and the choices you have. It applies to heylullae.co.za, heylullae.com, and any connected services.
We comply with the Protection of Personal Information Act, 2013 (POPIA), and align our practices with international standards, including the General Data Protection Regulation (GDPR).
1. Information We Collect
We only collect information that is necessary to deliver a personalised styling experience and process your secure multi-merchant purchases:
- Account & Contact Information, your name, email address, phone number, physical billing address, and physical delivery address when you create an account or complete a purchase.
- Style & Silhouette Profile, measurements, body-shape, colour and fit preferences you provide during onboarding, and any optional contour photos you upload.
- Inspiration You Upload, images you scan into your boutique to be matched with our Retail Fashion Partners.
- Pinterest Board Data (Opt-In), when you choose to connect your Pinterest account, we use Pinterest's official OAuth flow. We only read the boards and pins you explicitly select so we can map them to your silhouette profile and personal style graph.
- We never see or store your Pinterest password.
- We never post, comment, follow, or write anything back to your Pinterest account.
- You can disconnect Pinterest at any time from your profile, this immediately revokes our access.
- You can request deletion of any Pinterest-derived data.
- Transaction & Payment Information, all payment details entered during checkout are captured directly by our secure, PCI-DSS compliant payments partner, PayFast. Hey Lullae does not store, process, or have direct access to your raw credit or debit card numbers, security codes, or banking PINs.
- Usage Data, pages visited, items saved, scans run, device type, and IP address, used to improve the service and protect against abuse.
- Referral Data, the referral or Style Ambassador code that brought you to Hey Lullae, and conversions you generate, so we can credit your virtual wallet.
- Banking Details (Wallet Redemptions, Optional), if, and only if, you choose to redeem your Curation Dividend wallet balance via EFT to a South African bank account, we store the banking details you provide, account holder name, bank name, account number, branch code, and account type (Cheque / Savings / Transmission), in a private, owner-only path on your user record (
/users/{your-uid}/private/bank).- These details are classified as high-sensitivity financial information under POPIA and are treated accordingly.
- Only you can read or update this record. Hey Lullae admins, support staff, and Retail Fashion Partners cannot read your stored banking details from this path.
- When you submit an EFT redemption request, a one-time snapshot of the banking details is written onto that specific redemption document as your explicit, transaction-scoped consent to disclose them to the settlement reviewer processing that payout. No other redemption, admin, or partner can read that snapshot.
- You may delete or overwrite your saved banking details at any time from your Wallet, and you may choose voucher redemptions instead of EFT to avoid providing banking details altogether.
- We never store banking passwords, PINs, or online-banking credentials, only the account routing details listed above.
2. How We Use Data
We use the information above solely to provide and improve your personalised virtual styling experience and fulfill unified orders:
- Generating personalised styling recommendations tailored to your silhouette and taste.
- Processing your unified checkout transactions securely via PayFast.
- Routing shipment data to our Retail Fashion Partners to fulfill and dispatch your items.
- Matching pieces from our Retail Fashion Partners to your inspiration boards and scans.
- Sending price-drop, restock, and concierge alerts you have opted into.
- Processing memberships and virtual wallet rewards.
- Improving curation accuracy and the safety of the platform.
- Fulfilling legal, tax, and accounting obligations.
We do not sell your personal information, and we do not use your Pinterest or styling data to train third-party advertising models.
3. Data Security
Protecting your information is central to how we build Hey Lullae:
- Encrypted in Transit, all traffic is served over TLS/HTTPS.
- Encrypted at Rest, user data, profile photos, and inspiration content are stored in encrypted Google Cloud infrastructure.
- Access TokensOAuth tokens (including your Pinterest access token) are stored as encrypted server-side secrets, never exposed to the browser, and never shared with any third party.
- Least-Privilege Access, admin access is restricted to allow-listed team members and gated by Firestore security rules.
- Owner-Only Paths, your contour photos, saved addresses, payment tokens, and stored banking details for EFT wallet redemptions are readable only by you, admins and Retail Fashion Partners cannot query these paths.
- Secure Payments Partner, all transactions are routed through PayFast, operating under strict international security standards (PCI-DSS compliant).
No online system is perfectly secure. Please use a strong, unique password and notify us immediately if you suspect unauthorised access.
4. Sharing & Third Parties (Sub-processors)
We share personal information only with the sub-processors listed below, each of which supports a specific operational function. The list is kept current; where a processor is being phased out we note it as legacy.
- Google Cloud & Firebase, authentication, Firestore database, Cloud Storage for silhouette photos and profile assets, and encrypted infrastructure hosting. Data may be processed in Google Cloud regions outside South Africa.
- Cloudflare, edge network, DNS, TLS termination, DDoS protection, and serverless execution of our application code (Cloudflare Workers). Request metadata and IP addresses transit Cloudflare's global edge.
- Lovable AI Gateway (Lovable Inc.), routing processor for concierge AI, silhouette curation and virtual try-on. See section 4a for details.
- Google (Gemini image & text models), the underlying generative AI sub-processor reached via the Lovable AI Gateway. Processes silhouette photos, garment references and styling prompts. See section 4a.
- Inngest, durable background job and event-processing infrastructure used to reliably send transactional emails, run concierge handoffs, and trigger post-order fulfilment flows. Receives event payloads that may reference your user identifier, order identifiers and handoff details.
- Brevo, transactional email delivery (order confirmations, concierge handoff notifications, membership emails, referral rewards).
- PayFast, our primary PCI-DSS compliant payments partner for card, Instant EFT and Pay by Bank checkout, and for refund reversals against the original payment method.
- PayFast (legacy), previously used as a payment processor during earlier stages of the product. PayFast is no longer the active checkout provider; historical transaction and settlement records for orders placed via PayFast are retained for the financial-record retention periods described in section 8.
- Pinterest, only when you explicitly connect your account, and only via their official read-only API.
- Retail Fashion Partners & partner fashion boutiques, to deliver your styled items, Hey Lullae operates a direct fulfilment model. When you purchase a curated silhouette outfit, we securely share your shipping name, physical delivery address, and phone number with the specific partner fashion boutiques fulfilling your items (e.g., Aura Boutique, Maison Silhouette, Luxe Clay Studios).
- They only receive the data required to package and ship your order directly from their showrooms.
- They are contractually and legally prohibited from using your personal data for their own marketing purposes or sharing it with third parties.
We do not sell personal information to any third party.
4a. AI Processing, Virtual Try-On & Your Likeness
Hey Lullae uses artificial intelligence to power concierge styling, curation matching, the Silhouette Vault, and the Wardrobe Lounge virtual try-on renderer. Because these features materially involve your photographs and, in the case of try-on, your likeness, we disclose the processing separately here.
What is sent, and where. When you use virtual try-on or silhouette-driven curation, the following data is transmitted from Hey Lullae to a third-party generative AI model:
- Your uploaded silhouette / contour photos (front, side, back).
- The reference imagery of the garment you selected to preview.
- A short text prompt describing the requested rendering.
The AI model is currently Google's Gemini image model, accessed via the Lovable AI Gateway (Lovable Inc.). The gateway acts as our routing processor; Google acts as the sub-processor operating the underlying model.
Purpose & legal basis. Processing is limited to producing the requested try-on render or curation output for you, and is carried out on the basis of your consent (given by activating the feature) and our legitimate interest in operating the styling service you asked for.
No model training. Our processors are contractually prohibited from using your silhouette photos, likeness or generated renders to train, fine-tune or improve their foundation models, or for any purpose other than returning the requested output. Hey Lullae also does not use your silhouette photos or renders to train any AI model, and we do not sell or licence your likeness.
Retention. Uploaded silhouette photos remain in your private Silhouette Vault (owner-only Storage path) until you replace or delete them. Generated try-on renders are transient by default and are not persisted server-side unless you explicitly save one to your Loves. Third-party AI processors retain in-flight payloads only for the operational windows described in their own policies (typically short-lived logging for abuse detection).
International transfer. Because these AI providers operate globally, images processed for try-on and curation may be transferred outside South Africa. We rely on the standard contractual safeguards offered by those processors, as noted in section 9 below.
Your controls. You can (a) choose not to upload silhouette photos and use text-only curation instead, (b) delete any uploaded silhouette photo at any time from Profile → Silhouette, (c) delete saved renders from your Loves, and (d) request full erasure of AI feature data via the request path in section 6.
AI-generated try-on previews are illustrative renders, not photographic evidence of fit, fabric or colour. See our Terms of Service 9 for the full likeness licence and content-ownership terms.
5. Your Rights
Under POPIA and equivalent laws you may:
- Access the personal information we hold about you.
- Request correction of inaccurate information.
- Request deletion of your account and associated data.
- Disconnect Pinterest and revoke our read-access at any time.
- Object to processing for direct marketing.
- Lodge a complaint with the Information Regulator of South Africa.
6. Data Access & Deletion Request
Submit a request to access the personal information we hold about you, or to permanently erase your profile, connected Pinterest data, and contour photos from our systems. Requests are routed directly to our Information Officer.
To submit a data access or erasure request, email our Information Officer at legal@heylullae.co.za. We respond within 30 days.
7. Cookies
We use strictly-necessary cookies (authentication, referral attribution) and aggregate analytics cookies to improve the product. You can manage your preferences via the cookie banner shown on first visit, or by clearing your browser storage at any time.
8. Retention
Different categories of data are retained for different periods, because the applicable legal basis and legal obligation differ.
- General account data, retained for as long as your account is active, and for up to 12 months after closure to handle late refund, chargeback and support requests.
- Financial & transactional records, invoices, order records, payment references, refund receipts, wallet ledger entries, and EFT redemption records are retained for five (5) to seven (7) years after the transaction, as required by the South African Revenue Service (SARS), the Financial Intelligence Centre Act (FICA), the Companies Act, and the Consumer Protection Act. This retention overrides the 12-month general-data window and applies even after account closure.
- Silhouette / contour photos (borderline biometric-adjacent data), we treat your uploaded silhouette photos as special personal information under POPIA 26 and 32, because although they are not raw biometric templates, they encode body-shape characteristics from which biometric-like inferences could be drawn. They are stored in an owner-only Storage path, are never used to train any AI model, and are retained only for as long as you keep them in your Silhouette Vault. You may delete any silhouette photo at any time from Profile → Silhouette; deleted photos are removed from active storage within 30 days. You may also request full erasure of all silhouette data via the request path in section 6.
- Inspiration scans & Pinterest-derived data, removed from our systems within 30 days of deletion.
- Transient AI outputs, try-on renders are not persisted server-side unless you explicitly save one to your Loves.
Where a legal retention period applies (such as SARS/FICA financial records), we retain only the records required by that obligation and restrict access to them accordingly, even after your account is closed.
9. International Transfers
Because Hey Lullae relies on cloud, AI, payment and communications providers that operate globally, some of your personal information is transferred to, or processed in, jurisdictions outside South Africa. The processors involved are:
- Google Cloud & Firebase (multi-region infrastructure).
- Cloudflare (global edge network and Cloudflare Workers).
- Lovable AI Gateway (Lovable Inc.) and its underlying AI sub-processors.
- Google Gemini image & text models, reached via the Lovable AI Gateway.
- Inngest (durable event and background-job infrastructure).
- PayFast (payment processing and refund reversals).
- Brevo (transactional email delivery).
- Pinterest (when you explicitly connect your account).
Where a processor is located outside South Africa, we rely on the standard contractual safeguards and data-transfer terms offered by that processor, in line with POPIA 72 and equivalent GDPR international-transfer provisions.
10. Children
Hey Lullae is intended for users 18 years and older. We do not knowingly collect personal information from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page and, where changes are material, notify you via email or in-app.
12. Contact
Questions, requests, or concerns? Reach our Information Officer at legal@heylullae.co.za.
Part 2: Refund, Return & Cancellation Policy
Overview
Because Hey Lullae brings independent designers together into a single checkout experience, we provide a Unified Customer Service & Return Flow. While your items ship from and return to different boutique showrooms, Hey Lullae remains your central checkout point for processing payments and triggering refund reversals.
A. General Return Windows
We want you to love your custom silhouette looks. You may request a return or exchange within 14 days of the date your package was marked delivered by the courier.
To be eligible for a return, items must be unworn, unwashed, undamaged, and returned in their original packaging with all designer and boutique tags fully attached.
B. The Boutique-Handled Return Process (With Automated Portal Sync)
Because items are housed in independent showrooms, they must be returned directly to those specific locations. The physical return process is handled by our Retail Fashion Partners, with automatic system tracking:
- Initiate the Request, you initiate your return request directly through your Hey Lullae Style Lounge Account by selecting the specific item(s) you wish to return.
- Automated Address RetrievalHey Lullae's platform automatically approves the request guidelines and displays the specific partner fashion boutique's physical return showroom address, approved courier options, and packing instructions directly inside your user portal.
- Courier Dispatch, you dispatch the item(s) directly to the partner. If you are returning items belonging to multiple boutiques, they must be packaged and sent to each showroom separately.
- The Merchant Notification Trigger, once the Retail Fashion Partner receives your package and verifies it is in its original, unworn condition, they mark the item as "Return Approved" in their Hey Lullae Partner Dashboard. This action instantly fires an automated webhook system notification to Hey Lullae to release the funds.
C. Processing Your Refund (PayFast Reversals)
- Automatic Reversal, upon receiving the digital "Return Approved" notification from our Retail Fashion Partner, Hey Lullae instantly triggers a secure refund reversal.
- Refund Destination, because you checked out as a single transaction on Hey Lullae, the money is refunded in a single lump sum directly back to the original payment method (card, Instant EFT, or Pay by Bank) processed via PayFast.
- Processing Times, depending on your bank, refunds typically clear and reflect in your account within 3 to 7 business days after approval.
D. Return Shipping Fees
Hey Lullae does not cover, manage, or subsidize return courier fees.
All return shipping logistics and costs are handled directly by the Retail Fashion Partners and are subject to their individual store return policies. Return shipping costs are either paid by the customer upfront or deducted from the final refund total by the partner fashion boutique before they authorize the return in our portal.
If an item is defective, damaged upon arrival, or the wrong size/style was dispatched by our partner, the Retail Fashion Partner is contractually required to cover the return courier fees.
E. Order Cancellations
Because our backend system instantly alerts our Retail Fashion Partners to package and dispatch your items the moment your payment is verified via PayFast, orders cannot be canceled or modified once they are placed. If you no longer want the items, please wait for delivery and follow our standard Return Process outlined above.