Privacy Policy
GetTryOn — Online Fitting Room (gettryon.ai) Last updated: 23 July 2026
This Privacy Policy explains how Aleksandr Spiridonov, individual developer, trading as GetTryOn ("GetTryOn", "we", "us") collects, uses, and protects personal data in connection with the GetTryOn virtual try-on service (the "Service"), including our Shopify app, WooCommerce plugin, embeddable widget, and API.
The Service is used by two groups of people, and this policy addresses each separately:
- Merchants — store owners who install GetTryOn on their online store.
- Shoppers — visitors to a merchant's store who use the try-on widget.
1. Data we collect from Merchants
When you create a GetTryOn account or install our app, we collect:
- Account information: email address, store name, and store domain, used to create and administer your account, authenticate you, and contact you about the Service.
- Store platform identifiers: for Shopify merchants, your shop domain and app installation status, received through the Shopify App installation flow.
- Product information: product titles, types, tags, and product images from pages where the widget is active, used solely to generate try-on images and classify garment types. Garment classification runs in the shopper's browser; we do not build a copy of your catalog.
- Usage and billing records: number of try-on generations, plan status, and transaction identifiers. For Shopify merchants, all charges are processed through the Shopify Billing system; for other platforms, payments are processed by Stripe. We never receive or store card numbers or other payment instrument details.
- Support communications: messages you send to our support address.
2. Data we collect from Shoppers
When a shopper uses the try-on widget on a merchant's store:
- Uploaded photo: the shopper voluntarily uploads a photo of themselves to see how a garment would look on them. Before upload, an automated check runs locally in the shopper's browser to verify the photo shows a suitable full- or half-body pose. This local check does not transmit any data to us and does not create or retain any biometric identifier, template, or measurement.
- Generated image: the AI-generated try-on result produced from the shopper's photo and the merchant's product image.
- Technical data: transient request metadata (timestamps, anonymized request identifiers, coarse error diagnostics) needed to operate and secure the Service.
We do not:
- collect shoppers' names, email addresses, phone numbers, or account details — the widget has no login and requests none of these;
- access any customer data held by the merchant's store platform (our Shopify app requests zero customer data API scopes);
- use photos for identification, facial recognition, or profiling of any kind;
- create, derive, or store biometric identifiers or biometric templates from photos;
- use shopper photos or generated images to train AI models;
- sell or share personal data for advertising purposes.
3. Purposes and legal bases
Where UK GDPR / EU GDPR applies, we process personal data on the following bases:
| Data | Purpose | Legal basis |
|---|---|---|
| Merchant account & billing data | Providing and administering the Service; invoicing | Performance of a contract (Art. 6(1)(b)) |
| Merchant usage records | Metering plans, preventing abuse, improving reliability | Legitimate interests (Art. 6(1)(f)) |
| Shopper photos & generated images | Producing the try-on image the shopper requested | Consent, given by the shopper's affirmative act of uploading a photo after seeing the in-widget notice (Art. 6(1)(a)) |
| Technical logs | Security, fraud prevention, debugging | Legitimate interests (Art. 6(1)(f)) |
Shoppers may withdraw consent at any time by contacting us (Section 8); withdrawal does not affect processing that has already occurred.
4. Sub-processors and data sharing
We share personal data only with service providers who process it on our behalf under contractual data-protection obligations:
| Provider | Purpose | Location |
|---|---|---|
| Cloudflare R2 (EU jurisdiction) | Storage of uploaded photos and generated images | European Union (Cloudflare, Inc. is US-incorporated; the bucket carries an EU jurisdictional restriction guaranteeing EU storage) |
| fal.ai | AI image generation. Photos are transmitted for processing and are not retained by the provider after the generation completes, and are not used to train models. | United States |
| Render | Application hosting | Frankfurt, European Union |
| Stripe | Payment processing (non-Shopify merchants) | United States / EU |
| Shopify | App distribution, merchant billing, installation events | Canada / global |
We do not sell personal data. We may disclose data where required by law or to protect the rights, safety, or property of GetTryOn, our merchants, or shoppers.
5. International transfers
Where personal data is transferred outside the United Kingdom or the European Economic Area (for example, to fal.ai in the United States for image generation), we rely on appropriate safeguards, including the UK International Data Transfer Addendum and/or the European Commission's Standard Contractual Clauses, or an applicable adequacy decision (including the UK–US Data Bridge / EU–US Data Privacy Framework where the recipient is certified).
6. Retention
- Shopper photos and generated images are automatically and permanently deleted no later than 60 days after upload. Access before deletion is via time-limited, signed URLs only.
- Merchant account data is retained for the life of the account and deleted within 30 days of account deletion, except for records we must keep for tax and accounting law.
- Technical logs are retained for up to 90 days.
7. Shopify data requests (merchants and their customers)
Our Shopify app implements Shopify's mandatory privacy webhooks:
customers/data_request— because the app requests no customer data scopes and shopper photos are never linked to Shopify customer records, we hold no Shopify customer personal data to return; we respond accordingly.customers/redact— same as above; there is no linked data to erase, and any residual data is handled per Section 6 retention.shop/redact— on receipt, we delete the merchant's store data associated with the uninstalled shop within the timeframe required by Shopify.
8. Your rights
Depending on your location, you may have the right to access, correct, delete, restrict, or object to the processing of your personal data, the right to data portability, and the right to withdraw consent. To exercise any right, contact alex@gettryon.ai. We respond within one month.
If you are in the UK, you may lodge a complaint with the Information Commissioner's Office (ico.org.uk). If you are in the EEA, you may complain to your local supervisory authority.
California residents: we do not sell or share personal information as defined by the CCPA/CPRA. You may exercise access and deletion rights via the contact above; we do not discriminate for exercising them.
9. Security
We protect personal data using TLS encryption in transit, encryption at rest, short-lived signed URLs for image access, origin-restricted API keys, least-privilege access controls, and isolation between production and test environments.
10. Children
The Service is not directed at children under 16, and we do not knowingly process their personal data. If you believe a child has uploaded a photo, contact us and we will delete it.
11. Cookies and similar technologies
The try-on widget does not use advertising cookies and does not track shoppers across sites. It uses only functional browser storage strictly necessary to operate a try-on session. Our own website (gettryon.ai) may use analytics as described in its cookie notice.
12. Changes to this policy
We may update this policy from time to time. The current version is always available at gettryon.ai/privacy. For material changes affecting merchants, we will provide notice via email or the app dashboard.
13. Contact
Aleksandr Spiridonov, individual developer, trading as GetTryOn Registered address: available on request via the email below Email: alex@gettryon.ai