SnapIT: AI Virtual Try On
Last updated: August 2026 · Contact: contactus@snapmydesign.com
Who we are — SnapIT: AI Virtual Try On (“SnapIT”, “we”, “us”) is a Shopify application operated by SnapMyDesign. This policy explains how we process personal data when merchants install our app and when their customers use virtual try-on on merchant storefronts.
Data we process
Merchant / staff data (Shopify Admin users)
- Shop domain, shop name, and shop ID
- Merchant contact email (from Shopify)
- OAuth access tokens (stored server-side to operate the app)
- Staff name and email (from Shopify online sessions, when applicable)
- Billing and subscription metadata
Shopper / visitor data
- Customer photographs submitted for virtual try-on (may constitute biometric-adjacent data in some jurisdictions)
- Generated try-on result image URLs
- Anonymous session identifiers and pseudonymous externalUserId values
- Product context (product ID, title, SKU) and page URL
- Shopify customer ID (when the shopper is logged in) — used only to link sessions for compliance; we do not store customer email in our application database
We do not request Shopify read_customers access and do not pull customer records from the Shopify Admin API.
Purposes of processing
| Purpose | Legal basis (typical) |
|---|---|
| Provide virtual try-on | Contract / legitimate interest of merchant |
| Operate billing and credits | Contract |
| Fraud prevention and abuse detection | Legitimate interest |
| Internal quality assessment and model improvement | Legitimate interest (disclosed to shoppers) |
| Comply with Shopify mandatory privacy webhooks | Legal obligation |
Retention
- Try-on activity logs in our database are retained for 30 days, then deleted automatically.
- Customer photographs and generated images on SnapMyDesign infrastructure may be retained for 30 days for quality assessment and service improvement, then deleted or irreversibly de-identified.
- OAuth sessions are deleted when the app is uninstalled or upon shop/redact.
- Browser-local storage (photos/results) is controlled by the shopper’s browser and can be cleared by the shopper.
Your rights and Shopify compliance
Merchants can submit customer data requests and redaction requests through Shopify’s mandatory compliance webhooks. We honor customers/data_request, customers/redact, and shop/redact webhooks.
Shoppers should contact the merchant (data controller) to exercise privacy rights. Merchants may contact us at contactus@snapmydesign.com for assistance.
Security
We encrypt data in transit (TLS). Application secrets are stored in Google Secret Manager. API keys are encrypted at rest in our database. Access to production systems is limited to authorized personnel with MFA.
International transfers
Data may be processed in the United States and India, where our service providers operate. We rely on appropriate safeguards where required.
Changes
We may update this policy. Material changes will be reflected on this page with an updated date.
Contact
Privacy inquiries: contactus@snapmydesign.com