Privacy Policy
Last updated: 13 August 2026
Triple8Labs is a sole proprietorship (eenmanszaak) registered with the Dutch Chamber of Commerce (KVK) under number 42133562, VAT/BTW number NL005522113B73. This policy explains what personal data we collect through triple8labs.com and why, how long we keep it, and what rights you have.
For any privacy question or to exercise your rights, contact us at [email protected].
Our full company registration details and additional Kalidos-specific terms are listed on our Statutory and Regulatory Disclosures page.
What we collect and why
Kalidos – Style Kaleidoscope
When you take the free Style Kaleidoscope quiz, we collect your answers to style questions like colour palette, silhouette, style goal, occasion, values, gender expression, and – if you unlock the full profile – further questions on footwear, accessories, fabric, hair, fragrance, budget, and grooming. These answers are sent to an AI model to generate your personalised narrative and image, and are stored against a pseudonymous profile so you can revisit or retake the quiz.
You may optionally provide:
- Your email address – used to send your result if you tick “Email me my Style Kaleidoscope.”
- Age range and country – both optional, used only to personalise your result and (if you’ve also opted into marketing) to segment future style tips by region/age group.
- Freeform notes – anything you choose to add in your own words to further personalise your Style Kaleidoscope.
Three separate, unbundled consent checkboxes control what we do beyond generating your result:
- “Email me my Style Kaleidoscope” – sends you an email containing your result.
- “Send me occasional style tips and seasonal updates” – opts you into our marketing mailing list; unsubscribe anytime via the link in any email or at the bottom of your Style Kaleidoscope result.
- “Include my anonymised preferences in aggregate style trend reports” – your anonymised responses can be included in aggregated/trend products. Your name and email are never included.
None of these are pre-selected; declining any or all of them doesn’t affect your ability to take the quiz or see your result.
Recognising you as a visitor
We set a single strictly-necessary cookie (kalidos_visitor_id, valid for one year) so we can show your own result to you if you retake the quiz, return to unlock it, or revisit later. This cookie is not used for advertising, cross-site tracking, or shared with any ad network. Some quiz interactions (starting the quiz, sharing a result) are logged against this same cookie in pseudonymous form to understand product usage – this is covered by the same strictly-necessary basis.
Payment (paid profile unlock)
Unlocking the full profile is handled entirely by Stripe, our payment processor. We never see or store your card details – only a transaction reference and (if provided at checkout) the email Stripe passes back to us, used to let you retrieve your unlocked result later.
AI processing
Your quiz answers are sent to one of several AI providers – Anthropic (Claude), Google (Gemini), Mistral, or OpenAI – to generate a personalised written profile, and to Google’s Gemini image models to generate illustrated result cards. These providers process your answers only to generate your result; under our paid API agreements with them, none of these providers use your data to train their models. Your Style Kaleidoscope results are AI-generated (this is also disclosed on the quiz and result pages), and are intended for inspiration and entertainment, not professional styling, fashion, or purchasing advice.
How long we keep your data
- No email given: your individual result is deleted after 90 days. Aggregate, anonymised statistics (if you opted in) may be retained indefinitely, as they no longer identify you.
- Email given, profile not unlocked: retained while your consent is active; we re-confirm every 24 months, and delete the identifying link if unconfirmed within a 3-month grace period after that.
- Unlocked (paid) profiles: retained for 7 years, in line with Dutch/EU tax record-keeping requirements for the underlying transaction.
- Payment records: held by Stripe per applicable tax law (~7 years); only a transaction reference reaches our own systems, never card data.
- Ratings and usage events: deleted alongside the profile/identity they belong to, on the same schedule above.
- Rate-limiting logs: to prevent abuse of the quiz and API endpoints, we log IP address alongside the endpoint called, under our legitimate interest in keeping the service secure and reliable. Kept for 7 days, then deleted automatically.
Affiliate links
The AI generated suggestions shown in the “Get This Look Now” section contain affiliate links – if you buy something through one, we may as an Amazon Associate earn a small commission from qualifying purchases at no extra cost to you. These links are generally flagged as sponsored and highlighted using site-wide affiliate disclosure notices.
Who we share your data with
We share data only with the processors necessary to run the services described above: Stripe (payments), our AI providers (Anthropic, Google, Mistral, OpenAI – to generate your result), MailPoet (if you opt into marketing emails), and our transactional email provider (to deliver result and access-link emails). We never sell your data, and we never share individually-identifiable data with advertisers or data brokers.
You can request deletion of your data at any time – see “Your rights” below – and we’ll honour it regardless of the schedule above, except where we’re legally required to retain transaction records.
Your rights
Under the GDPR, you have the right to access, correct, or delete your personal data, restrict or object to our processing of it, and receive a copy of it in a portable format. To exercise any of these, contact us at the address above. If you’re not satisfied with our response, you can lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Security
We rely on a layered security strategy, using Cloudflare alongside Web Application Firewalls (WAF) to block malicious traffic, mitigate DDoS attacks, and prevent unauthorized network access. Our infrastructure takes advantage of SSL/TLS encryption, and a pseudonymised data design, with access to experiment results controlled by a unique, randomly-generated link. No payment or credential data touches our systems.
Other site content (comments, media)
If you leave a comment on this site, we collect the data in the comment form plus your IP address and browser user-agent to help with spam detection; comments may be checked through an automated spam detection service. The comment and its metadata are retained indefinitely. This is so we can recognise and approve any follow-up comments automatically. If you upload images, avoid embedding location data (EXIF GPS) – others can extract it from images on the site.
An anonymised hash of your email may be checked against the Gravatar service (see automattic.com/privacy).
Embedded content from other websites
Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website. These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.
Changes to this policy
We’ll update this page if what we collect or how we use it changes, and update the “last updated” date above.

