Shopify VTO Privacy

    Virtual Try-On Privacy

    This Shopify-specific notice explains how the Aabhas Virtual Try-On app processes storefront, shopper, merchant, analytics, and image data.

    Last updated: May 24, 2026

    Clause 01

    Application of this Shopify VTO privacy notice

    This Shopify Virtual Try-On Privacy Notice applies specifically to the Aabhas Virtual Try-On app, embedded Shopify admin surfaces, Shopify theme extensions, storefront widget, app proxy routes, commerce webhook ingestion, analytics events, upload flows, generated try-on previews, and related support operations used by Shopify merchants and their shoppers.

    This notice supplements the general Aabhas Privacy Policy. If this notice conflicts with the general Privacy Policy for Shopify VTO processing, this notice controls for that specific Shopify VTO processing activity.

    Clause 02

    Merchant, shopper, and Aabhas roles

    The Shopify merchant controls the storefront, customer relationship, product catalog, theme placement, customer privacy settings, and commercial transaction. For many shopper-facing activities, the merchant is the controller, data fiduciary, or equivalent party determining the purpose of the storefront interaction. Aabhas generally acts as a processor, service provider, or technology provider for the merchant's installation of the app, subject to separate operational purposes that Aabhas may control for security, compliance, and service administration.

    Shoppers should understand that their relationship for purchases, returns, refunds, product availability, pricing, delivery, and storefront privacy notices remains with the merchant. Aabhas provides the virtual try-on technology and related processing infrastructure.

    Clause 03

    Shopify VTO data categories

    The app may process uploaded shopper photos, selected product images, garment images, product identifiers, variant identifiers, collection metadata, product category metadata, shop domain, anonymous session identifiers, generated try-on outputs, result URLs, signed upload URLs, signed read URLs, app proxy request metadata, browser and device details, telemetry events, error messages, and configuration data.

    Where enabled by the merchant and authorized by Shopify scopes, the app may process commerce metadata such as product views, add-to-cart events, checkout status, order data, returns, refunds, and fulfillment-related events for analytics and attribution. The app does not require unrelated protected customer data that is not necessary for the installed feature set.

    Clause 04

    Shopper photo upload and generated previews

    When a shopper uploads a photo, Aabhas processes that photo with the selected product or garment image to generate a virtual try-on preview. The uploaded photo and generated preview may be personal data if the shopper is identifiable. The uploaded image is not intended to be used for identity verification, authentication, law enforcement identification, credit decisions, employment decisions, health diagnosis, or biometric recognition.

    The generated preview is a visual approximation. It may include artifacts or inaccuracies. Aabhas does not guarantee that the preview will reflect actual fit, size, color, material, availability, purchase suitability, or merchant quality standards.

    Clause 05

    Purpose limitation

    Aabhas processes Shopify VTO data to provide virtual try-on previews, support app configuration, verify storefront requests, prevent abuse, enforce credits and availability rules, troubleshoot errors, provide merchant analytics, support app installation and onboarding, honor privacy requests, maintain service security, and comply with applicable obligations.

    Aabhas does not currently use shopper-uploaded Shopify VTO images or generated Shopify VTO outputs for model training. If Aabhas later introduces Shopify VTO model improvement or training involving shopper media, such use will require an applicable opt-in or equivalent lawful authorization, updated disclosures, and safeguards such as face blurring, identity masking, metadata removal, retention controls, restricted access, and deletion or exclusion mechanisms where required or technically feasible.

    Clause 06

    Storefront notices and shopper consent

    The app displays upload-time disclosure text linking to the Shopify VTO privacy notice and terms. The merchant remains responsible for ensuring that its storefront privacy policy, cookie banner, consent settings, and regional notices accurately disclose the merchant's use of the Aabhas app and any related analytics or tracking.

    If a jurisdiction requires explicit consent for shopper image processing, biometric-related processing, analytics, cookies, or optional reuse, the merchant is responsible for enabling the appropriate consent mechanism unless Aabhas separately provides a feature-specific consent control.

    Clause 07

    Compliance webhooks and privacy requests

    Aabhas supports Shopify privacy compliance webhooks for customer data requests, customer redaction requests, and shop redaction requests. Verified Shopify compliance webhook payloads are handled separately from commerce analytics and are not appended to the normal analytics event stream.

    For customer data requests, Aabhas identifies customer-linked backend records based on customer identifiers supplied by Shopify. For customer redaction, Aabhas deletes matching customer-linked analytics and webhook records where identifiers are present. For shop redaction, Aabhas deletes shop-scoped Shopify backend state including shop configuration, entitlement state, provisioning state, try-on job metadata, analytics events, and webhook receipts.

    Clause 08

    Retention and deletion

    The current Shopify VTO shopper upload path is designed for reduced-retention or no-persist operation for shopper photos and generated previews, except where transient processing, signed delivery, operational logs, compliance handling, merchant configuration, or technical error handling requires limited metadata or temporary references. In no-persist mode, replay may be unavailable and the shopper may need to upload again for a new try-on.

    Aabhas Store and related retail features support configurable retention periods through admin or organization settings where enabled. These settings may support session retention, limited retention, short-term replay, merchant review, quality troubleshooting, or shopper account history depending on the enabled product. Such modes may retain raw uploaded images, prepared images, generated outputs, or derived metadata for the configured period when the product experience requires it.

    Shopify VTO media and metadata are retained only as needed for the configured service, support, merchant analytics, security, compliance, and operational requirements. Retention may vary by merchant configuration, storage policy, admin retention settings, Core organization settings, app behavior, and technical limitations. Analytics and aggregate records may be retained longer than raw media unless a deletion request or uninstall cascade requires removal.

    Clause 09

    Protected customer data and minimization

    Aabhas requests and processes Shopify data only to the extent needed for the installed app functionality, configuration, analytics, compliance, billing, troubleshooting, and security. If additional Shopify protected customer data access is required for a future feature, such access must be justified, configured, reviewed, and limited to the feature requirement.

    Aabhas seeks to avoid collecting full customer profiles where an anonymous session, product identifier, shop domain, or non-identifying event is sufficient for the relevant virtual try-on function.

    Clause 10

    Sharing and subprocessors

    Aabhas may share Shopify VTO data with infrastructure providers, cloud storage providers, authentication systems, logging and monitoring systems, support tools, legal advisers, and subprocessors only as necessary to provide, secure, support, and comply with obligations related to the app. Aabhas does not sell shopper-uploaded VTO photos.

    Clause 11

    Security and signed URLs

    Aabhas uses signed upload URLs and signed read URLs where applicable so that browser uploads and previews can be handled without exposing permanent internal storage paths. Signed URLs are time-limited. Internal object keys and durable storage paths are intended to remain server-side metadata.

    App proxy requests and Shopify webhooks are verified using Shopify signature mechanisms. Internal app-to-backend calls use internal tokens. These controls are designed to reduce unauthorized access, replay, and request forgery risks.

    Clause 12

    International processing, legal rights, and contact

    Aabhas is based in India and may process Shopify VTO data in India and other regions used by its cloud infrastructure and subprocessors. Cross-border processing is supported by contractual, technical, and organizational safeguards where required.

    Aabhas maintains a founder-led privacy and data protection function. Until a separate full-time data protection officer is appointed, the founder or an authorized senior officer designated by Aabhas will act as the privacy escalation and DPO-equivalent contact where required by contract, merchant onboarding, or applicable law. Shoppers should direct storefront privacy requests to the merchant. Merchants and Shopify may send verified privacy requests to Aabhas through Shopify's compliance webhook process. For privacy questions about the app, contact support@aabhas.tech.