Legal · Shopify App Store Compliant

Privacy Policy

EffectiveDecember 9, 2025
Last UpdatedMarch 27, 2026
Contactprivacy@stylepass.ai
No AI Training
Your photos stay yours

We never use shopper photos or generated images to train our models.

Auto-Deletion
30-day hard limit

All uploaded photos and generated images are permanently deleted within 30 days.

Shopify Compliant
All 3 webhooks live

customers/redact, shop/redact, and data_request fully implemented and verified.

Welcome to StylePass AI (“StylePass AI,” “we,” “our,” or “us”). We are committed to protecting personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, and share information when merchants install StylePass AI via the Shopify App Store, and when shoppers use the virtual try-on widget on merchant storefronts.

By installing or using StylePass AI, you agree to this Policy.

Section 01

Scope & Roles

This Policy applies to two audiences:

Merchants (Store Owners)

Shopify merchants who install StylePass AI via the Shopify App Store. When you install the app, you act as the Data Controller for your customers' personal data. StylePass AI acts as the Data Processor, handling that data only on your instruction and in accordance with this Policy and our Data Processing Agreement.

Shoppers (End Users)

Customers of merchant stores who interact with the virtual try-on widget on a product page. As a merchant, you are responsible for ensuring your store's privacy policy informs your customers about the StylePass AI try-on feature. See Section 8 for suggested language.

Section 02

Information We Collect

From Merchants (via Shopify API)

Upon installation, we receive from Shopify's APIs:

  • Store domain, owner name, and email address
  • Shopify shop ID and contact details
  • App configuration data and preferences
  • Billing status — managed via Shopify's Billing API
  • Automated usage logs related to your use of the app

From Shoppers

When a shopper uses the virtual try-on widget:

  • Photos uploaded for try-on generation
  • Generated try-on output images
  • Session and device identifiers
  • Basic device and browser metadata

Merchants do not have access to view individual shopper-uploaded photos or generated try-on images. These are processed by StylePass AI solely to deliver the experience.

What We Do NOT Collect

We do not collect phone numbers, government IDs, payment card details, passwords, or other sensitive personal identifiers from shoppers. We do not require shoppers to create accounts.

Section 03

How We Use This Information

  • To generate virtual try-on previews for shoppers on merchant product pages
  • To provide merchants with conversion and funnel analytics
  • To process billing and manage merchant subscriptions via Shopify
  • To communicate with merchants about updates, support, and billing
  • To monitor app performance and fix errors
  • To comply with applicable laws and Shopify mandatory requirements

Absolute commitment: We do NOT use shopper photos, generated try-on images, or any merchant or shopper data to train, fine-tune, or improve our AI models. Ever.

Section 04

Data Retention

Data TypeRetention Period
Shopper uploaded photosAuto-deleted within 30 days
Generated try-on imagesAuto-deleted within 30 days
Merchant account dataDeleted within 30 days of uninstall
Analytics & session dataUp to 12 months, then anonymized

When a merchant uninstalls the app, we process the shop/redact webhook within 30 days and permanently delete all data.

Section 05

Compliance Webhooks

StylePass AI implements and responds to all three mandatory Shopify compliance webhooks:

customers/data_request

We provide relevant resource IDs to the store owner within 30 days of request.

customers/redact

We permanently erase specific shopper data from our systems within 30 days.

shop/redact

We permanently erase all data associated with a store within 30 days of uninstall.

All webhooks are verified using Shopify's HMAC signature validation. Unverified requests are rejected.

Section 06

Data Sharing & Subprocessors

We share limited data only with the following trusted subprocessors solely to operate the Service:

ProviderPurposeRegion
ShopifyIntegration and billingGlobal
Google CloudAI inference (Vertex AI)USA / EU
AWSStorage and hostingUSA / EU
MixpanelProduct analyticsUSA
SentryError monitoringUSA
Section 07

Your Rights

EEA / UK — GDPR

Legal bases include performance of a contract, legitimate interests, and consent. You may lodge a complaint with your local DPA.

California — CCPA

You have the right to know what personal info we collect and to request deletion. StylePass does not sell personal information.

To exercise any rights, contact privacy@stylepass.ai.

Section 08

Merchant Responsibilities

Merchants are responsible for informing their customers about the try-on feature. You may use the following suggested text:

“This store uses StylePass AI, a virtual try-on tool powered by generative AI. When you use the try-on feature, you upload a photo that is processed to create a preview. Your photo and generated image are automatically deleted within 30 days and are never used to train AI models.”

Section 09

Security

We apply industry-standard security measures including HTTPS/TLS encryption in transit, encrypted storage at rest, strict role-based access controls, and secure deletion procedures. While no system is completely secure, we follow best practices to protect all data.

Section 10

Children

The Service is not intended for individuals under 13. If we become aware that we have collected personal data from a minor without verifiable parental consent, we will promptly delete it.

Section 11

Policy Changes

We may update this Policy. Material changes will be communicated via in-app notice or email. Continued use after an update constitutes acceptance of the revised Policy.

Section 12

Contact

For privacy-related questions or data requests:

privacy@stylepass.ai

Ready to transform how
your customers shop?

Join the brands and agencies using StylePass to drive conversion, cut returns, and deliver the shopping experience your customers actually want.

SOC 2 CompliantGDPR & CCPA Ready99.9% UptimeLive in <15 min