Legal
Privacy Policy
Effective August 14, 2026
1. Scope and roles
This policy explains how ProductTryOn processes information through producttryon.com, the Shopify app, and the virtual try-on storefront experience. For merchant account data, ProductTryOn acts as a controller. For shopper data submitted through a merchant's store, ProductTryOn generally acts as that merchant's processor or service provider.
2. Information we process
Merchant and store information: store name, myshopify.com domain, Shopify shop identifier, app authorization scopes, encrypted access credentials, workspace settings, support messages, and subscription status.
Catalog information: product titles, descriptions, handles, product and variant identifiers, prices, availability, product images, and product URLs retrieved with the read_products permission.
Try-on information: a shopper's selected product and variant, generation status and duration, an anonymous session identifier when provided, and actions such as adding the selected item to cart.
Image information: when a shopper requests a try-on, the uploaded photo and product image are sent through ProductTryOn to our AI processing provider to generate the requested image. ProductTryOn does not write the uploaded photo or generated output to its application database. Temporary network, infrastructure, or processor copies may exist for service delivery and security under the relevant provider terms.
3. How we use information
We use information to install and operate the app, sync eligible products, generate requested previews, display merchant analytics, provide support, secure the service, prevent abuse, administer Shopify billing, and meet legal obligations. We do not sell personal information or use shopper photos to identify people.
4. Service providers and disclosures
We disclose information only as needed to operate the service, including Shopify for installation, authentication, billing, and storefront delivery; fal.ai and the FASHN model service for virtual try-on image processing; hosting, database, security, and support vendors acting on our instructions; and authorities or transaction counterparties when legally required or as part of a business transfer.
5. Shopify data
The app requests read_products so it can display and configure eligible products. It does not request Shopify customer, order, or payment permissions. We validate Shopify's mandatory privacy webhooks. Customer data access and erasure requests are acknowledged even though the app does not retrieve Shopify customer records. A validated shop redaction request deletes the associated ProductTryOn workspace and its linked catalog, configuration, connection, and try-on session records.
6. Retention
Merchant configuration, catalog data, and try-on session metadata are kept while the app is installed or as needed to provide the service. Access credentials are removed when Shopify sends a validated app/uninstalled webhook. Workspace data is deleted when Shopify sends the later validated shop/redact webhook. We may retain limited security, billing, or legal records where required by law. Image inputs and outputs are not intentionally persisted in the ProductTryOn application database.
7. Security
We use transport encryption, encrypted Shopify credentials, signed Shopify session tokens and app-proxy requests, webhook signature verification, access controls, and scoped Shopify permissions. No online service can guarantee absolute security.
8. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal information. Shoppers should usually contact the merchant whose store they used; merchants can contact us directly. We will support verified requests and merchant instructions as required by applicable law.
9. International processing and children
Service providers may process information in countries other than where it was submitted, subject to appropriate contractual safeguards where required. ProductTryOn is a business service and is not directed to children. Merchants are responsible for configuring their storefront experience for their audience and applicable law.
10. Changes and contact
We may update this policy as the service or legal requirements change. Material changes will be communicated through the app or other appropriate channels.
Privacy requests and questions: privacy@producttryon.com. General support: support@producttryon.com.