Privacy Policy
Last updated: March 20, 2026
TrySnap.io (the "App," "we," "us," or "our") provides a Virtual Try-On service for Shopify Merchants. This Privacy Policy explains how we collect, process, and protect information from Merchants and their end-customers ("Shoppers").
By installing the App, you agree to the processing of information as described herein. We act as a Data Processor for the Merchant, who remains the Data Controller.
1. Information We Collect
A. From Merchants (via Shopify API)
- Contact Information: Store name, owner name, email address, and general store performance metrics that help us tailor our solutions for you as a merchant
- Founding Member Application: Name, email, and store URL submitted through our application form
- Store Integration Data: Our App utilizes standard Shopify Theme App Extensions to integrate our Virtual Try-On widget onto your product pages. We securely access your product media and image URLs solely to facilitate the AI visualizations requested by your customers
B. From Shoppers (End-Users)
- Visual Content: Shoppers may upload photos or videos of themselves to use the Virtual Try-On feature
- Technical Data: IP address, device type, browser info, and operating system used to optimize the AI generation
C. Automatically Collected Information
When you visit our website, we may automatically collect certain information including your IP address, browser type, operating system, referring URLs, and information about how you interact with our site.
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain our services
- Process your founding member application
- Send you service-related communications
- Respond to your inquiries and support requests
- Improve and optimize our website and services
- Detect, prevent, and address technical issues or fraud
- Comply with legal obligations
3. AI Processing & Biometric Data Disclosure
Our App uses Generative AI models to synthesize images and videos.
- Processing Purpose: Images are processed solely to generate the virtual try-on output requested by the Shopper
- No Model Training: We do not use Shopper images or videos to train, improve, or fine-tune our AI models or third-party models
- No Permanent Storage: We do not store, archive, or retain uploaded photos beyond the temporary processing window
- No Distribution: We do not sell, share, or distribute uploaded photos to third parties
Biometric Data Notice: Depending on local laws (e.g., BIPA, CCPA), Shopper photos may be considered biometric data. We do not store "biometric templates" or identity-linked facial signatures. The processing is transient and data is discarded after the session (see Section 5).
4. Third-Party Data Sharing
We do not sell your personal information. To provide the Service, we transmit encrypted data to the following types of third parties:
- AI Infrastructure Providers: Secure API endpoints for image and video synthesis
- Hosting Providers: Secure cloud storage (Google Cloud Platform) for temporary asset hosting
- Shopify: Data shared as required for billing and platform compliance
- Legal requirements: When required by law, legal process, or to protect our rights, privacy, safety, or property
- Business transfers: In connection with a merger, acquisition, or sale of assets, with appropriate notice to you
5. Data Retention & Deletion
We strictly follow "Privacy by Design" principles:
- Shopper Images: Original and generated images are stored in a temporary cache and are permanently deleted within 24–48 hours of the session
- Merchant Data: Retained as long as the App is installed. You may request deletion of your data at any time by contacting us
- Shopify Mandatory Webhooks: We fully comply with Shopify's data redaction rules. Within 48 hours of a Merchant uninstalling the App, we initiate the "Shop Redact" process to purge all store-related data from our servers
6. Merchant Responsibilities
As the Data Controller, the Merchant is responsible for:
- Maintaining their own Privacy Policy that discloses the use of third-party AI processing of customer images
- Obtaining necessary Shopper consent for the collection and processing of images, as required by local laws (GDPR, CCPA, BIPA, etc.)
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your information
- Object to or restrict processing of your information
- Data portability
- Withdraw consent where processing is based on consent
To exercise any of these rights, please contact us at the email address listed below.
8. International Data Transfers
Information may be processed on servers located outside of your jurisdiction. We ensure all transfers comply with standard contractual clauses and high-level encryption protocols.
9. Security & Data Infrastructure
Infrastructure Provider: Google Cloud Platform (GCP)
9.1 Enterprise-Grade Infrastructure
Our application is hosted exclusively on Google Cloud Platform (GCP). By leveraging Google's world-class infrastructure, we inherit industry-leading security controls.
- Physical Security: Data is stored in highly secure data centers with 24/7 surveillance and biometric access controls
- Regulatory Alignment: Google Cloud maintains certifications for ISO/IEC 27001, 27017, 27018 and SOC 1/2/3. While we are a separate entity, our "Security OF the Cloud" is managed by these certified standards
9.2 Ephemeral Data Processing
Our core philosophy is Data Minimization. We believe the best way to secure data is to not hold onto it.
- Transient Storage: Shopper-uploaded photos and AI-generated outputs are stored in a secure, transient cache for a maximum of 24–48 hours to facilitate the current shopping session
- Automated Purging: After this window, the data is programmatically and permanently deleted from our servers. We do not maintain a permanent database of customer faces or bodies
- No Model Training: We explicitly do not use Merchant or Shopper data (images or videos) to train, improve, or fine-tune our AI models. Your data belongs to you; we only process it for inference
9.3 Encryption Standards
- In Transit: Data moving between the shopper's browser, Shopify, and our AI engines is encrypted using TLS 1.3 (Transport Layer Security)
- At Rest: Any temporary data stored on Google Cloud is encrypted using AES-256 (Advanced Encryption Standard), the same standard used by global banks
9.4 Secure Shopify Integration
As a verified Shopify App, we adhere to Shopify's strict "Mandatory Privacy" requirements:
- Secure Authentication: We use OAuth 2.0 for all Shopify store interactions. We never see or store your Shopify login credentials
- App Proxy Security: All customer-facing widgets are served through a secure Shopify App Proxy, ensuring the "Try-On" experience is as secure as the rest of the merchant's storefront
- GDPR/CCPA Compliance: We fully support Shopify's Mandatory Privacy Webhooks. When a store is uninstalled or a customer requests data deletion, our systems initiate a purge within 48 hours
9.5 Incident Response & Monitoring
- Continuous Monitoring: We utilize Google Cloud's Security Command Center for real-time threat detection and anomaly monitoring
- Access Control: We follow the "Principle of Least Privilege" (PoLP). Only essential, authorized personnel have access to our production environment, protected by multi-factor authentication (MFA)
10. Cookies and Tracking
We may use cookies and similar tracking technologies to collect information about your browsing activity. You can control cookies through your browser settings. Note that disabling cookies may affect the functionality of our website.
11. Third-Party Links
Our website may contain links to third-party sites. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.
12. Children's Privacy
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
13. Merchant "Quick-Check" for GDPR Compliance
Since we act as a Data Processor, our security measures are designed to help you meet your obligations as a Data Controller:
- Transparency: Our 24–48 hour deletion cycle meets the GDPR requirement for "Storage Limitation"
- Purpose: We process data only for the specific "Virtual Try-On" task requested by the user
- Security: Our use of GCP ensures "Technical and Organizational Measures" (TOMs) are in place
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website with a revised "Last updated" date. Your continued use of our services after any changes constitutes acceptance of the updated policy.
15. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:
Email: info@trysnap.io