Privacy Policy

SnapIT: AI Virtual Try On

Last updated: August 2026 · Contact: contactus@snapmydesign.com

Who we are — SnapIT: AI Virtual Try On (“SnapIT”, “we”, “us”) is a Shopify application operated by SnapMyDesign. This policy explains how we process personal data when merchants install our app and when their customers use virtual try-on on merchant storefronts.

Data we process

Merchant / staff data (Shopify Admin users)

  • Shop domain, shop name, and shop ID
  • Merchant contact email (from Shopify)
  • OAuth access tokens (stored server-side to operate the app)
  • Staff name and email (from Shopify online sessions, when applicable)
  • Billing and subscription metadata

Shopper / visitor data

  • Customer photographs submitted for virtual try-on (may constitute biometric-adjacent data in some jurisdictions)
  • Generated try-on result image URLs
  • Anonymous session identifiers and pseudonymous externalUserId values
  • Product context (product ID, title, SKU) and page URL
  • Shopify customer ID (when the shopper is logged in) — used only to link sessions for compliance; we do not store customer email in our application database

We do not request Shopify read_customers access and do not pull customer records from the Shopify Admin API.

Purposes of processing

PurposeLegal basis (typical)
Provide virtual try-onContract / legitimate interest of merchant
Operate billing and creditsContract
Fraud prevention and abuse detectionLegitimate interest
Internal quality assessment and model improvementLegitimate interest (disclosed to shoppers)
Comply with Shopify mandatory privacy webhooksLegal obligation

Retention

  • Try-on activity logs in our database are retained for 30 days, then deleted automatically.
  • Customer photographs and generated images on SnapMyDesign infrastructure may be retained for 30 days for quality assessment and service improvement, then deleted or irreversibly de-identified.
  • OAuth sessions are deleted when the app is uninstalled or upon shop/redact.
  • Browser-local storage (photos/results) is controlled by the shopper’s browser and can be cleared by the shopper.

Your rights and Shopify compliance

Merchants can submit customer data requests and redaction requests through Shopify’s mandatory compliance webhooks. We honor customers/data_request, customers/redact, and shop/redact webhooks.

Shoppers should contact the merchant (data controller) to exercise privacy rights. Merchants may contact us at contactus@snapmydesign.com for assistance.

Security

We encrypt data in transit (TLS). Application secrets are stored in Google Secret Manager. API keys are encrypted at rest in our database. Access to production systems is limited to authorized personnel with MFA.

International transfers

Data may be processed in the United States and India, where our service providers operate. We rely on appropriate safeguards where required.

Changes

We may update this policy. Material changes will be reflected on this page with an updated date.

Contact

Privacy inquiries: contactus@snapmydesign.com