FRAGNOIR

Legal

Privacy policy

Last updated 15 August 2026 · Version 3

This privacy policy describes in detail how Innolope LLC handles personal data in connection with Fragnoir, which comprises the website published at fragnoir.com, the Fragnoir Price Companion browser extension, and, once released, the Fragnoir applications for iOS and Android, together referred to throughout this document as the Service. We have written it to be read rather than skimmed, because we would rather you finish this page understanding exactly what happens to information about you than come away with a vague impression that everything is probably fine.

The short version, which the remainder of this policy expands upon rather than contradicts, is that Fragnoir is designed to function with as little personal data as it can possibly get away with: you can read every page of this website without being tracked, no advertising network receives anything about you, analytics software is not loaded into your browser at all unless you have actively asked for it, and the information you do choose to give us — an email address when you write to us, and in the future a wardrobe of fragrances you own — is used to provide the thing you asked for and nothing else.

The browser extension is the one part of the Service that reads pages you visit, and rather than let that sit awkwardly beside the paragraph above we would rather state it plainly here. On the fragrance shops it supports, and only on those, it reads the product data the shop already publishes for search engines and contributes the price it finds to a shared index, under an anonymous identifier that rotates every week. That is how the comparison gets good enough to be worth having: the prices come from the people using it. Sections six to eight describe exactly what is read, what leaves your browser and what does not, and the extension ships with a single switch that stops all of it and a control that deletes everything it has ever contributed.

1. Who is responsible for your data

The controller of the personal data described in this policy, meaning the entity that decides why and how that data is processed and that is accountable for it under the General Data Protection Regulation, is Innolope LLC, the operator of fragnoir.com, of the Fragnoir Price Companion browser extension and of the Fragnoir applications. Wherever this policy says "we", "us" or "Fragnoir", it refers to that company acting in that capacity.

You can reach us about anything in this policy, including any request to exercise the rights described in section twelve, by writing to [email protected]. We read every message sent to that address, and privacy requests are handled by the same small team that builds the product rather than being routed into an outsourced ticketing system, which is one of the genuine advantages of being a company of our size.

2. The scope of this policy

This policy covers the Service as defined above and nothing else. In particular, it does not cover the websites and applications operated by the fragrance retailers we link to, and this distinction matters more for Fragnoir than it would for most services, because sending you to a retailer is one of the main things our product does. The moment you follow a link from Fragnoir to a shop such as Notino, Flaconi, Douglas or any other merchant, you have left our Service and entered theirs, and everything that happens from that point onwards — the cookies that shop sets, the analytics and advertising technology it runs, the account you may hold with it, and the payment details you may enter — is governed by that retailer's own privacy policy and is entirely outside our control and our knowledge. We never see, receive or store your payment details, because we never process a payment; we are an index and a comparison tool, not a shop.

The browser extension makes this boundary unusual enough to be worth spelling out, because it is the one piece of Fragnoir that runs inside a page belonging to somebody else. When the extension reads a product page at a shop and draws its panel on top of it, our responsibility as controller covers exactly that: what the extension reads, what it sends to us and what we then do with it, all of which is described in sections six to eight. It does not extend to the shop's own page, which continues to run the shop's cookies, analytics and advertising technology under the shop's own privacy policy whether the extension is installed or not. Installing it does not place us between you and the retailer, and it does not give us sight of anything the retailer does.

This policy also does not cover any correspondence you may have with us through channels other than the Service, such as a social media platform, where the platform operator is an independent controller of the message you send and applies its own terms and privacy rules to it.

3. What we collect when you simply visit this website

When you load a page on fragnoir.com, our infrastructure necessarily processes the technical information that any web server needs in order to send a page back to you and to defend itself against abuse. That information consists principally of your IP address, the page or file you requested, the date and time of the request, the referring page where applicable, and the user-agent string that identifies your browser and operating system. We process this on the legal basis of our legitimate interest under Article 6(1)(f) of the GDPR in operating a website that is available, reasonably fast and not trivially easy to attack, and we have concluded that this interest is not overridden by your interests because the data is minimal, is not used to build any profile of you, is not combined with any other dataset, and is retained only briefly as described in section eleven.

In addition to those server-side records, a single first-party cookie named fragnoir_consent may be stored in your browser. It contains nothing but a record of the choice you made about analytics, the version number of the consent notice you were shown, and the timestamp of your decision. It exists solely so that we can honour your decision and avoid asking you the same question on every page, and it is set only once you have actually made a choice.

4. Analytics, and why nothing loads until you say so

Fragnoir uses Google Analytics 4 to understand which pages people find useful, how visitors arrive, and where they give up — the ordinary questions that any product team asks in order to decide what to improve next. We have deliberately implemented this in the strictest way that the technology allows: the Google Analytics script is not merely disabled, blocked or told to withhold consent when you have not opted in, it is not inserted into the page at all, which means that in the absence of your consent your browser never makes a single network request to any Google domain on our behalf and Google therefore never learns that you visited us. This is a meaningfully stronger position than the common industry practice of loading the tag immediately and setting a consent flag afterwards, and we chose it on purpose.

Where you do consent, the legal basis is your consent under Article 6(1)(a) of the GDPR together with the applicable national implementations of the ePrivacy Directive, we instruct Google to anonymise IP addresses, and we disable the advertising and personalisation features of the product so that the data is used for audience measurement rather than for building an advertising profile. Your consent is entirely voluntary, refusing it costs you nothing and changes no feature of the Service, and you may withdraw it at any moment with effect for the future by opening the "Cookie settings" link that appears in the footer of every page and choosing the essential-only option, which removes our analytics from any subsequent page load.

5. What we collect when you contact us

If you write to us through the contact form or by email, we process the email address you provide, the content of your message, and any information you voluntarily include within it, for the single purpose of reading your message, investigating whatever it concerns and replying to you. The legal basis is our legitimate interest under Article 6(1)(f) in responding to people who take the trouble to contact us, or, where your message concerns a contract or a potential contract with us, the pre-contractual and contractual basis in Article 6(1)(b).

Messages sent through the contact form are delivered to our inbox by our email processor, Resend, which acts on our documented instructions under a data processing agreement and does not use the content of your message for its own purposes. Because the form does not require an account, and because we would rather not hold correspondence indefinitely, we periodically review and delete old contact threads once the matter they concern has been resolved and no legal reason to retain them remains.

6. What the browser extension reads, and where

The Fragnoir Price Companion is a browser extension that, when you are looking at a fragrance on a shop it supports, shows you what the same bottle costs elsewhere, whether it can be had as a decant or sample first, and what production date is encoded in the batch code on the box. To do that it has to read the product page you are on, and this section describes that reading exactly, because it is the most invasive thing any part of Fragnoir does and it deserves more than a euphemism.

The extension is installed with access to fourteen fragrance retailers and no other site whatsoever: notino.com, notino.de, notino.co.uk, douglas.de, flaconi.de, parfumdreams.de, sephora.com, sephora.fr, fragrancenet.com, fragrancex.com, jomashop.com, lookfantastic.com, thefragranceshop.co.uk and creedfragrances.co.uk. On a page at one of those shops, and nowhere else, it looks at the structured product data the shop already publishes for search engines — the JSON-LD Product block, schema.org microdata, and Open Graph product meta tags — and takes from it the product title, the brand, the barcode, the price, the list price it was struck through from, the currency, the stock status, and the address of the page reduced to its origin and path with the query string and fragment discarded. The size in millilitres and the concentration, meaning whether the bottle is an eau de toilette or an extrait, are worked out from the wording of the product title rather than read from any field of their own. That is the entire read.

Everything a shopping page normally contains that is actually about you is not read: not your account or profile pages, not sign-in pages, not order history, not the basket, not the checkout, not any payment or card field, not cookies, and not anything you type into the shop's own forms. The extension has no interest in them and no code that looks at them. If a page turns out not to be a product page, or publishes no price we can read, nothing about that page is transmitted at all; what we receive is a bare counter recording that a parser failed on a given shop, carrying the shop's domain, which of our parsing layers ran and why it gave up, with no address and no page content, so that we know which parsing rule to go and fix.

Reading is governed by one switch, labelled "Price collection", in the extension's toolbar popup. It is on when you install the extension, and the welcome page shown at install says so. Turning it off does not merely stop the sending: the script that reads the page checks the switch before it does anything else, so with collection off a supported shop's page is not examined at all, no panel is drawn, and nothing is queued or transmitted. You can turn it back on in the same place at any time.

The extension deliberately does not ask for access to every website when you install it. Because the set of fragrance shops in the world is not knowable in advance, it declares the ability to request other sites, but never exercises it on its own initiative: if you are on a shop we do not cover and you press the add button in the popup, your browser asks you to grant that one domain, and only if you agree does the same product-page reader begin running there. Removing that shop from the list in the popup revokes the permission and unregisters the script. Separately, and only while you have the popup open, the popup reads the hostname of the tab in front of you so that it can offer you that button; it reads no content from the page to do so.

7. The shared price index, and the identifier that rotates

A price observation the extension makes is held on your own device first, in the extension's local storage, and is uploaded in batches roughly every half hour or once fifty have accumulated, rather than as a request per page you open. The local queue is capped at five hundred observations and two hundred parse-failure counters, the oldest being discarded past that point. The popup lists what is currently queued, so the claim in the section above is one you can audit rather than take on trust.

Observations are contributed under a rotating anonymous client identifier. That identifier is a random value generated on your device, is not derived from your hardware, your browser, your network or anything else about you, and is replaced with a fresh random value every seven days. We store it alongside each observation rather than discarding it on receipt, and it is worth being exact about why, because it would be easy to claim otherwise: the identifier paired with a fingerprint of the observation is what lets us recognise the same reading arriving twice when a batch is retried, it is what the popup counts when it tells you how much is held, and it is the only thing that makes the delete control described below capable of finding your contributions at all. A promise to drop it would be a promise to take that control away. We also keep a small record per identifier — when it was first and last seen, how many observations it has sent, how many failed a plausibility check, and whether it has been blocked for abuse — which is what stops one client poisoning the index for everybody.

Two honest qualifications. The endpoint that receives observations will record an account identifier against them where the request carries one, so that route from a contribution to an account exists in our system rather than being ruled out by design; the extension as published does not authenticate when it contributes, so in practice the field is empty, and nothing about the comparison asks you to sign in. We would rather describe the door than tell you there isn't one. And while a batch is in transit the request necessarily carries an IP address, as every request on the internet does. We do not store the address with the observation and we do not attempt to resolve either into a person.

Observations are deleted automatically one hundred and eighty days after they are made, by a rule the database enforces itself rather than a policy someone has to remember to run. That window is what a trailing price median needs in order to mean anything, and past it the row is a log entry we would not read again. What survives is not the observation but its effect: the price it helped establish, which is a fact about a bottle at a shop. The legal basis for collecting them is our legitimate interest under Article 6(1)(f) of the GDPR in building an accurate price index for the people using it, and the balancing that sits behind that conclusion is the design described in section six: a fixed and disclosed list of shops, product data the shop already publishes publicly, no reading of anything personal on the page, an identifier that rotates weekly and expires with the data, and an unconditional switch. Your right to object under Article 21 is the switch itself, and it takes effect immediately and completely.

The popup also carries a control that deletes what you have contributed. Pressing it clears the local queue and asks our servers to delete everything held against every identifier the extension still knows about, which is the current one together with the identifiers it has rotated through before it, and then issues you a fresh identifier so that the deletion is not immediately undone by the next page you open. Because identifiers are retired as they rotate, this reaches roughly the last six months of contributions; anything older has already lost the only thread that connected it to your copy of the extension, which is the same property that makes it not personal data any more. The popup shows how many observations are held against your current identifier so that you can see what the control will act on.

Two further things leave the extension, and neither is joined to the identifier above. When the panel opens, the product's title, brand and barcode are sent to us so that we can work out which fragrance in our catalogue you are looking at and send back the comparison; this is a lookup, and it is not stored as a record of your browsing. When you type a batch code into the panel — the one thing the extension asks you to type — the code and the brand are sent to be decoded and the answer returned. That is a query about a manufacturing code printed on a box, it carries no identifier of any kind, and we do not keep it against you.

8. Affiliate links inside the extension

The comparison the extension shows you is ordered by price, cheapest first, exactly as it is on the website, and whether a retailer pays us commission plays no part in that ordering and cannot buy a place in it. Where an offer is one we may earn commission on, and it is at a different shop and cheaper than the page you are standing on, the link is marked with an arrow, and the panel carries the disclosure in plain sight rather than leaving you to find this page.

Following such a link is the one interaction inside the extension that we record. When you click it, the extension asks our servers for the destination, sending the identifier of the offer you clicked together with the rotating client identifier described in section seven, and then opens the shop. The purpose is the one set out in our affiliate disclosure: so that a commission our partners report can be reconciled against a real click, and so that fraudulent or automated clicking can be detected, which is a genuine risk that can cost us an affiliate account outright. What the retailer receives is what it receives from the website — the network's tracking parameters and a reference for that particular click — and it does not include your name, your email address, or anything about a Fragnoir account. Click records are retained as described in section eleven. Clicking nothing costs you nothing: every offer in the panel can equally well be reached by typing the shop's name into your browser yourself.

9. Accounts, and what the applications will process once they launch

The extension offers an optional sign-in to a Fragnoir account, and it is genuinely optional: the price comparison, the decant list and the batch-code decoder all work without one, and the extension never prompts you to create an account in order to use them. You may sign in from the popup with an email address and password or with Google, in both cases through Google Identity Platform, which issues the session. A password typed into the popup goes to Google and never to us. The session tokens Google returns are stored locally in the extension, and the short-lived one is sent to our own API when, and only when, a request needs to act on your account — reading your wishlist for the price check described next. The single thing an account currently unlocks in the extension is a daily check of the fragrances on your wishlist against their current prices, which raises a notification on your own device when one has fallen by at least a tenth. Signing in does not change what the extension reads from a page or what it contributes to the price index: those observations are sent without any account credential either way, as section seven describes.

The Fragnoir applications for iOS and Android are in development at the time of writing and are not yet available, so nothing described in the remainder of this section is happening today. We are nevertheless setting out our intentions here, because a privacy policy that only tells you about the past is of limited use when deciding whether to trust a product.

When the applications launch they will process, in broad terms, the following categories of data: an account identifier and, where you choose to create a full account rather than remain anonymous, an email address or the identifier supplied by Apple or Google when you use their sign-in services; the barcodes you scan and the fragrance pages you open, which are needed in order to show you results and to tell you what you have already looked at; the contents of your fragrance wardrobe, meaning the bottles you mark as owned, wished for or merely sampled, together with any personal ratings and private notes you attach to them; the ratings, note votes and reviews you submit to the community, which are published under the identity you choose and are therefore visible to others; and pseudonymous records of the outbound clicks you make to retailers, which exist so that our affiliate partners can attribute a sale to us and so that we can detect fraud and understand which comparisons are useful.

Those processing activities will rest on the contractual basis in Article 6(1)(b) insofar as they are necessary to deliver features you have asked for, on consent under Article 6(1)(a) for optional analytics and for push notifications, and on legitimate interest under Article 6(1)(f) for fraud prevention, moderation and security. Before any of it begins, you will be shown an in-app privacy notice describing it in specific terms, this policy will be updated accordingly, and the applications will ship with data export and complete account deletion built into the settings screen from the first release rather than added later under pressure.

10. Who else is involved, and where your data goes

We use a small number of carefully chosen service providers, each of which processes personal data only on our documented instructions under a data processing agreement that meets the requirements of Article 28 of the GDPR. Cloudflare provides our domain name service, network-level security and content delivery, and consequently handles connection metadata as your request reaches us. Our hosting provider operates the servers on which the Service runs, which are located within the European Union. MongoDB Atlas provides the managed database in which our content and, in future, your account data will be stored, on infrastructure we have configured in the European Union. Resend delivers transactional email on our behalf. Google, through Google Analytics 4, receives usage measurement data, but only from those visitors who have actively consented to it, and, through Google Identity Platform, operates the sign-in that issues account sessions in the applications and in the extension. The browser extension adds no processor of its own: it talks to the same Fragnoir infrastructure listed here and to nothing else, and in particular it loads no third-party script, no advertising tag and no analytics product into any page you visit.

Where any of these providers processes data outside the European Economic Area, that transfer is covered either by an adequacy decision of the European Commission or by the Commission's Standard Contractual Clauses supplemented by the technical and organisational measures our providers publish. Beyond these processors, we do not sell personal data, we do not share it with data brokers, we do not participate in advertising exchanges or real-time bidding, and we do not disclose personal data to third parties except where we are compelled to do so by a valid legal obligation, where it is necessary to establish, exercise or defend legal claims, or in the event of a corporate transaction such as a merger or acquisition, in which case you would be informed and the acquirer would be bound by commitments no weaker than these.

11. How long we keep things

We retain server and security logs for a maximum of thirty days, after which they are deleted, because their purpose — spotting an attack, diagnosing an outage, understanding a spike in traffic — has no useful life beyond that window. The consent cookie is stored for twelve months, at which point it expires and we ask you again, since a preference expressed a year ago should not be treated as an indefinite mandate. Correspondence you send us is kept for as long as the matter it concerns remains live and is then deleted, unless a specific legal obligation requires us to keep it longer.

Data belonging to the browser extension divides in two. What sits on your own device — the queue of observations not yet uploaded, the rotating identifier, the cached parsing rules, the shops you have added and which side of the window you dragged the panel to — stays there until the queue is uploaded, until the identifier rotates on its weekly cycle, or until you clear it from the popup or remove the extension, whichever comes first. What we hold is the price observation, which the database deletes by itself one hundred and eighty days after it was made, together with the per-identifier record described in section seven. The delete control in the popup reaches the same data sooner and on demand, and because the extension retires identifiers as it rotates them, the identifiers it can still name cover roughly the same six months the retention rule does.

Once accounts exist, account data will be retained for as long as the account does. When you delete your account we will erase the associated personal data promptly and, where a published review is involved, either delete it or sever it permanently from your identity depending on the choice you make at the point of deletion, so that the community record of a fragrance is not silently rewritten while your personal connection to it is nonetheless removed. Affiliate click records will be reduced to non-identifying aggregates after ninety days.

12. Your rights, and how to use them

The GDPR gives you a set of rights over your personal data, and we would like you to actually use them rather than treat them as decoration at the end of a policy. You have the right under Article 15 to obtain confirmation of whether we process data about you and to receive a copy of it; the right under Article 16 to have inaccurate data corrected and incomplete data completed; the right under Article 17 to have your data erased, which we will honour except where we are legally required to retain something; the right under Article 18 to have processing restricted while a dispute about accuracy or legitimacy is resolved; the right under Article 20 to receive the data you provided in a structured, commonly used and machine-readable format and to have it transmitted elsewhere; and the right under Article 21 to object at any time to processing that we base on legitimate interest, in which case we will stop unless we can demonstrate compelling legitimate grounds that override your interests.

Where processing is based on your consent, Article 7(3) additionally gives you the right to withdraw that consent at any time without affecting the lawfulness of what was done beforehand; for analytics, the "Cookie settings" control in the footer is the fastest route and takes effect immediately. For the browser extension the equivalent controls are in the toolbar popup and are faster than writing to us: the "Price collection" switch stops the reading and is how you exercise your Article 21 objection, and the delete control erases what has been contributed, locally and on our servers, in the manner described in section seven. We should be honest about one limit the design creates. Because contributed observations carry a rotating identifier and no account, we frequently cannot tell whether a given record relates to you, and Article 11 does not require us to acquire additional information merely in order to be able to identify you — which is precisely why we built the delete control into the extension, since the copy of the extension in your browser holds the identifiers and can therefore do what we cannot do from an email address alone. To exercise any other right, write to [email protected] and we will respond within one month, extending that period only in the genuinely complex cases contemplated by Article 12(3) and telling you if we do. We do not charge for these requests. If you are unhappy with how we have handled your data or your request, you have the right under Article 77 to lodge a complaint with the supervisory authority of the EU member state in which you live, work, or believe the problem occurred, and doing so does not prevent you from also pursuing a judicial remedy.

13. Security, children, and automated decisions

We protect personal data with measures appropriate to the risk it carries, including encryption of traffic in transit, encryption of data at rest in our managed database, strict limitation of access to the few people who genuinely need it, credentials held in a secrets manager rather than in source code, and a deliberately small collection footprint on the principle that the safest data is the data you never gathered. No system is perfectly secure and we will not pretend otherwise, but we will tell you and the relevant supervisory authority without undue delay if a breach occurs that is likely to affect your rights.

The Service is not directed at children under the age of sixteen and we do not knowingly collect their personal data; if you believe a child has provided us with data, write to us and we will delete it. Finally, we do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22, and we do not build advertising or behavioural profiles. The personalised recommendations planned for the applications will be based on the fragrances you have explicitly told us you like, will be visibly explicable to you, and will affect nothing except the order in which we suggest things you might enjoy.

14. Changes to this policy

Fragnoir is an actively developed product, and this policy will therefore change as the Service does. It last changed to cover the Fragnoir Price Companion browser extension, described in sections six to eight, and it will change most significantly again when the mobile applications are released and the processing described in section nine becomes real rather than planned. When we make a change we will update the date shown at the top of this page, and where the change is material — meaning it alters what we collect, why we collect it, who receives it, or the rights you have over it — we will draw attention to it on the website and, if you hold an account, in the product itself, rather than relying on you to notice a silently edited page.