We are not building the first Fashion shopping assistant on the market. There have been many before us delivering instant price checks, deal finders, AI analysis, checking if your body would work with the item, style compatibility and many many more ideas. But the one key thing, the one truly important aspect is not how the assistant can help you. It is whether you can TRUST it.
Everyone who has been on the internet in the past year or so has seen the unbelievably quick rise of the Phia shopping assistant (kudos to them, it really is impressive). For those of you who don’t know, Phia is a browser extension / app that checks if the item you are looking at (mainly fashion) is on sale anywhere else on the internet and for what price. Can you get it cheaper? Are there any sales for it? Really useful app that works quickly and beautifully. But no matter how clever the features are, an assistant you can’t trust isn’t a good assistant.
Privacy risks
Downloading a browser extension is made incredibly simple nowadays and many people offer it the same amount of trust as apps on their phones. Google (owners of the Chrome Store) do review the extensions and their code is open source so anyone can check it out, but there is one major difference that makes or breaks everything. By definition, a browser extension’s job is to read and modify content on the website you are currently looking at. This is much more power than mobile apps have, since they are limited to their own data and (with rare exceptions) cannot see outside the app. This creates a few risks:
Reading what you don’t want
Did you know that many browser extensions request FULL access to every website you visit? Remember that permission prompt after installing your last extension? Probably not, and that is not on you. We are so conditioned to trust the apps and the stores to keep us safe that we don’t really read system permission prompts anymore. But once an extension holds that access, it can not only read the content on the page, it can send it back to its own servers for analytics, logging and who knows what else (often ads, or profiling for ads).
Think about what that level of access technically allows, no matter which extension is holding it:
- Open Gmail to check your emails? An extension with full access could read and log every one of them.
- Look up what a rash is? That image sits on a page an extension with full access could capture, all under the banner of deal hunting.
Editing anything on the page
Scarier than reading your emails and medical details, extensions can actually change content on the page. This is super useful for things like ad blockers that remove ads, but can be easily misused, often times not on purpose. Have you seen a website suddenly look broken, images not loading, font too big or small to read right after installing an extension? Probably, there is some bug in its code and congrats, now that website is broken for you as long as you have the extension installed.
Nefarious, bad bad things
While the extension store owners (Google, Microsoft, Apple, Mozilla) do check for malware and subject extension owners to various checks, a new type of nefarious use has been developing in recent years and that is selling a good, reputable extension to bad people. Usually hackers or just bad people will buy an already popular and trusted extension that has been installed on millions of devices and with a tiny tiny update will change its code to make it steal your data / credit card numbers / anything you have in the browser.
Here’s some nefarious extension reading emails
All of this doesn’t mean browser extensions are a bad thing, many are actually better to have! Like those ad blockers that not only block annoying ads, but also block bad ones. The purpose here is to explain how extensions actually work since most people don’t really know. Making sure people can trust our extension has been the main reason for our different approach and design that we have taken outlined below.
What is cookie stuffing? Does it make them taste better?
No, it does not. Cookie stuffing here is about stealing / changing those small pieces of code living in your browser called “Cookies” (so many banners). But why does it matter? Well, here again we are looking at trust, but this time it’s the trust that brands put into blog posters, social media influencers and ultimately shopping extensions like Phia.
How Cookie stuffing works
When a blogger, influencer, review site or shopping assistant recommends a product, they use a special link. If you click it and buy the product, the brand says, “Thanks for sending us a customer!” and pays that creator a small percentage of the sale (a commission). Usually 6-20% in the fashion space, quite a lot! The cookie is like a digital receipt proving who introduced you to the brand.
Here is the important part: almost every affiliate program pays out on last-click attribution. Whoever’s cookie is sitting in your browser at the moment of checkout wins the entire commission, no questions asked. It is a simple rule, and that simplicity is exactly the hole in it. You don’t have to be the one who actually introduced you to the product, you just have to be the last cookie standing.
Cookie stuffing completely cheats this system.
Instead of earning a commission honestly, a shopping app or extension will quietly “stuff” its own cookies into your browser behind the scenes.
1. You visit a store - You go to checkout on a website like Zara or Asos
2. The app acts secretly - Even if you didn’t click any coupons or links, the shopping extension running in the background secretly opens hidden webpage tabs you can barely see. Remember that random tiny loading tab always on the top left that suddenly appears and disappears? Felt strange? Yeah, that’s how stuffing happens.
3. The app steals the credit - It forces its own tracking code into your browser. If there was a cookie from a hard-working influencer who actually recommended the product to you, the app deletes it and overwrites it.
Bloomberg’s analysis found the tool could claim credit for sales it didn’t drive.
Do I care? No one is stealing from me.
If the price of your item stays the same, you might wonder why cookie stuffing matters to you. Well, here comes the trust part. Scandals such as the Phia one destroy the trust that brands / shops have placed in the tools themselves. Not only because this is a bad look on the brand, but many times you may have opened the Nike website on your own and some extension still tries to take credit, costing brands millions of dollars. We have seen how damaging this can be once brands stop trusting the platforms (remember the YouTube adpocalypse?).
This will ultimately force brands to scale back their online promotions and in the end prevent us from getting sweet deals. Some have begun dropping extensions like Honey already, causing a massive trickle-down effect that ultimately raises the prices for all of us. Others are considering stopping working with deal shopping extensions altogether and are scrambling to decide how to proceed from here.
There is also the ethical / moral problem, especially when cookie stuffing steals from other creators who have worked hard and rely on the affiliate kickback as their main and only source of income. Imagine if your favourite daily fits girl can no longer post because brand partnerships are gone and she can’t make ends meet. Painful and honestly, just annoying. The browser extensions that have been caught or accused of this were already making millions in reported revenue, yet they still decided to do it (allegedly).
What makes Clottr different?
We took a look at the state of shopping browser extensions and said, there must be a better way. First, the privacy, then how we plan to solve affiliates and where we think the industry is going.
Privacy
Maybe because we are based in the EU or because I have worked at big tech (knowing how much data everyone tracks!), I am deeply privacy focused. This is why when setting out to build both the Clottr App and browser extension I made sure we collect only what we need, only after your permission. Not because this is the law or rules (we have seen others break it many times), but because I want us to build trust.
The browser extension - We read only the content of websites that you have explicitly allowed. To make it work, we have implemented a few layers (like onions!):
- Our extension never works in the background. Why would it? What reason could there be that a shopping extension checks websites in the background? If you are actively shopping you would just open it to see the full analysis and results. I never got why some extensions do it, so we do not.
- Once you open it, we still do not touch, read, or even think about the website content, until you explicitly approve. Is it a bit more annoying and less magical? Yes. But without explicit approval, the territory of accidentally reading emails is too close and I don’t like that. If you want to drop your approval, that is just 2 simple clicks and bam, can no longer read that website.
- Extension open, website approved (say https://cos.com), good. We still do nothing. Why would we do anything without your explicit action?
- Want to check if that shirt is worth the buy? Click the image overlay and run “Should I Buy?”.
- Want to tryon the jacket? Click the “See Myself” button. Otherwise, we do not send ANY data ANYWHERE.
The App and your data - As we are EU based, GDPR is one of the scariest and best laws we have to comply with. While it creates many difficulties for businesses, I believe here, it helps us double down on privacy and trust.
- While we need your images to process tryons, wardrobe data and any request, we have followed the strictest enterprise architecture guidelines (after all as an enterprise architect I used to be the one to write them) on data privacy and security. We audit all of our storage providers and locations for layered, locked down access with encryption in transit and at rest. Is it too much? Never, there is no such thing as too much security or checks.
- Minimal data that you can delete at any time. We have done our best to design the app around minimal data required from you to both function and be useful. Want to export it, delete it and go to a different wardrobe app? No worries, we have made it super simple. Keeping people locked down is not the right way to do business and if anyone tells you exports are not possible, they are just lazy and greedy.
- No AI training. No selling of your data. Period. Nothing else to say here.
This is what I call privacy and honestly, this is what I expect any extension, program, assistant to do.
Affiliate Marketing - The Plan
This is a discussion that is core even to our app. “Shop my Gaps”, “Should I buy”, deal notifications are all features that will benefit you if we can find cheaper options or active discounts. But we have to be careful because of Trust. You trust us that any analysis we perform is true, accurate and NOT influenced by potential affiliate revenue. Which is why here, we are actively working on two unique approaches that we have not seen anywhere to guarantee just that. Fingers crossed in the near future we will have more to reveal on this plan.
Provable Affiliate Attribution
There is only one way to 100% guarantee that an affiliate purchase has happened because of the sender. And this is to pay for the item from the sender directly. Instead of you paying on the website of https://zara.com, you would enter your payment info into Clottr (like Apple Pay or Link) and we will keep it securely on file. Then we will pay to Zara, Cos, Nike or anywhere you like with a one click of a button. This helps you in a few ways:
- Not sending your payment details around, Clottr will handle it and take on the risks
- Not managing multiple carts, deliveries, addresses
- Refunds? Through Clottr, simpler, unified
- But most importantly, the brand knows for a fact, where the affiliate commission came from and where to send it to. Provably, guaranteed by the payment. No cookie stuffing or other baking approaches can change that.
Doing it this way actually opens the door for another, even cooler bonus to you again.
Everything discounted, Always!
Remember that 6-20% commission that I discussed in the start of this article? Well, if we can guarantee affiliate source and payment is going through us, it makes it incredibly easy for us to give it back to you. After all, you are paying a monthly sub that allows us to support the app and give back the affiliate revenue to you.
This is the most important part and the one I am most excited about. What is the best way to guarantee that we are impartial in our “Shop my Gaps”, “Should I buy” checks? By never getting kickbacks for recommending items to you. Now the 6-20% that we would get as commission, will trickle down to you and you will see it as discount instantly on the checkout screen. Not later, not when we receive it, instantly.
So now, not only can you save money using Clottr by not buying stuff you don’t need. You will simply be getting discounts that no one else in the world can. $24.99 a month pays for itself in a few pieces that you didn’t buy because of us but wanted. The other commission discounts we will offer? Pure benefit to you.
Some thoughts
The entire affiliate market extension industry is used to pushing the boundary of privacy, data collection, cookie stuffing and attribution stealing all in the name of getting a few extra % of commission into their revenue. We are flipping the model by pushing those commissions onto you to make sure we are never even tempted to make the same mistake as the others.
The accusations of cookie stuffing referenced in this article are based on the incredible reporting by Bloomberg.
Ready to try it on a purchase you’re considering? Walk through it step by step in our Should I Buy guide, or see the Stop Shopping Regret feature page for the full pitch. For more on building a wardrobe that earns its rotation, read how to stop buying clothes you never wear and Issue 01 — The Lineup.