Privacy

    Aabhas Privacy Policy

    This policy explains how Aabhas handles information across our website, Studio, Store, Shopify, virtual try-on, analytics, and AI-assisted product experiences.

    Last updated: May 24, 2026

    Clause 01

    Scope, interpretation, and application

    This Privacy Policy describes how Aabhas, including its affiliates, product teams, service operators, contractors, and authorized processors, collects, receives, uses, stores, discloses, transfers, protects, retains, and otherwise processes personal data in connection with Aabhas websites, software products, dashboards, retail experiences, Shopify applications, virtual try-on workflows, communications, support channels, demonstrations, beta features, and related services.

    This policy is intended to be read together with any applicable order form, statement of work, data processing agreement, merchant agreement, product-specific notice, consent screen, or other written arrangement governing a particular Aabhas product or service. If a product-specific notice applies to a particular processing activity, that notice supplements this general policy and may contain more specific terms.

    For purposes of this policy, personal data includes information relating to an identified or identifiable natural person, and may include equivalent terms such as personal information, personal data, personally identifiable information, personal digital data, or personal information under applicable data protection laws. References to processing include collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, transmission, restriction, erasure, destruction, and analogous activities.

    Clause 02

    Roles of Aabhas, customers, merchants, and end users

    Depending on the context, Aabhas may act as an independent controller or data fiduciary, a processor or service provider acting on documented instructions, a subprocessor, or an operational service provider for a merchant, organization, retailer, or customer. The applicable role depends on the product, contract, data source, and purpose of processing.

    Where a merchant, organization, retailer, or business customer determines the purpose and means of processing, that party is ordinarily responsible for giving required notices, obtaining required consents, honoring customer rights, configuring retention settings, selecting lawful processing bases, and ensuring that its own use of Aabhas complies with applicable law. Aabhas processes such data in accordance with the relevant contract, applicable law, and technical instructions made available through the service.

    Where Aabhas determines independent operational purposes, including security, fraud prevention, service reliability, billing administration, internal compliance, product administration, or legal defense, Aabhas may process data as an independent controller or data fiduciary to the extent permitted by applicable law.

    Clause 03

    Categories of data processed

    The categories of data processed by Aabhas vary by product and feature. Aabhas may process business contact details, account registration information, authentication identifiers, role and permission metadata, organization and shop information, merchant configuration records, support communications, billing metadata, usage logs, technical diagnostics, device and browser information, approximate location derived from network data, product catalog data, garment imagery, user-uploaded images, generated media, event telemetry, and operational metadata.

    Virtual try-on and image-generation products may process uploaded photographs, garment photographs, generated outputs, image dimensions, file type, upload timestamps, processing identifiers, signed URL metadata, template identifiers, job identifiers, model workflow metadata, error logs, and storage lifecycle status. Aabhas does not require users to submit government identifiers, payment card numbers, passwords for third-party systems, or unrelated sensitive personal data for ordinary virtual try-on use.

    • Account and identity data: name, email address, authentication provider identifiers, session metadata, and account role.
    • Commercial and merchant data: shop domain, product identifiers, catalog information, app configuration, usage plans, credits, billing references, and commerce event metadata where enabled.
    • Image and media data: uploaded images, product images, generated outputs, thumbnails, derived variants, and associated processing metadata.
    • Technical data: IP address, user agent, browser capability, device type, request identifiers, logs, error traces, and security events.
    • Communication data: support requests, feedback, issue reports, sales inquiries, product demos, and administrative correspondence.

    Clause 04

    Sources of data

    Aabhas may receive data directly from users, merchants, organizations, employees, contractors, website visitors, Shopify storefronts, Shopify Admin APIs, app proxies, webhooks, pixels, Studio interfaces, Store interfaces, uploaded files, connected services, payment or billing systems, cloud infrastructure, support tools, and operational logs.

    Where Aabhas receives data from a merchant or organization rather than directly from an end user, that merchant or organization is responsible for ensuring that it has the authority to disclose such data to Aabhas and that the end user has received any legally required notice.

    Clause 05

    Purposes of processing

    Aabhas processes data for the purposes reasonably necessary to provide, maintain, secure, improve, support, and administer its services. These purposes include account administration, authentication, authorization, virtual try-on generation, image processing, catalog readiness, retail session handling, Shopify app operation, analytics, troubleshooting, billing, abuse prevention, system monitoring, customer support, contractual performance, compliance with legal obligations, and protection of rights and property.

    Aabhas may also process aggregated, statistical, or de-identified information to understand service performance, identify reliability trends, plan infrastructure capacity, evaluate feature usage, and improve product quality, provided such use is consistent with applicable law and applicable contractual restrictions.

    Clause 06

    Lawful bases and consent-dependent processing

    Where applicable law requires a lawful basis, Aabhas relies on one or more bases depending on the context, including performance of a contract, legitimate interests, consent, compliance with legal obligations, protection against fraud or abuse, establishment or defense of legal claims, or documented instructions from a controller, fiduciary, merchant, or organization.

    Where processing is based on consent, users may have the right to withdraw consent at any time, subject to legal, contractual, operational, security, and technical limitations. Withdrawal of consent may limit or disable certain features, including image upload, virtual try-on generation, saved history, or optional reuse of media.

    Clause 07

    Images, virtual try-on, and AI-generated outputs

    Aabhas virtual try-on features process uploaded user images and garment or product images to generate visual previews. These outputs are algorithmic renderings and may not accurately represent fit, size, material, texture, drape, color, lighting, availability, product condition, body measurements, or real-world appearance. Aabhas does not represent that any generated output is an exact, guaranteed, medically accurate, biometric, or measurement-grade result.

    Uploaded images and generated outputs may contain personal data if a person is identifiable. Aabhas applies technical and organizational controls intended to limit access, reduce unnecessary retention, and restrict use to the service purpose unless additional lawful grounds or explicit opt-in applies.

    Clause 08

    Model training and model improvement posture

    Aabhas does not currently use shopper-uploaded images or generated virtual try-on outputs from the Shopify app for model training. Aabhas also does not currently operate a customer-image training pipeline for Shopify virtual try-on uploads.

    Aabhas may, in future releases, develop model evaluation, model improvement, or training capabilities using user-uploaded images, generated outputs, garment images, or related media only where such use is supported by the applicable product terms, privacy notice, consent flow, merchant authorization, data processing arrangement, or other lawful basis. Aabhas will not silently convert a service-upload image into a training dataset where the applicable product requires opt-in or additional notice.

    Where future model improvement or model training uses personal media, Aabhas intends to apply safeguards appropriate to the risk and jurisdiction, which may include face blurring, identity masking, metadata removal, dataset segregation, role-based access, retention limits, exclusion lists, audit controls, deletion workflows, and measures to reduce direct personal identifiability before the data is used for training or evaluation.

    Aabhas may use non-personal, synthetic, merchant-provided, licensed, public-domain, or otherwise lawfully available data for research, testing, benchmarking, quality assurance, or model improvement, subject to applicable rights, restrictions, and product commitments.

    Clause 09

    Cookies, pixels, analytics, and similar technologies

    Aabhas websites and products may use cookies, local storage, session storage, pixels, SDKs, logs, and similar technologies to provide login sessions, maintain state, prevent fraud, remember settings, measure feature usage, debug issues, and understand how services are used. Some technologies are necessary for service operation, while others may be subject to consent requirements depending on the jurisdiction and deployment context.

    Where Aabhas technology is embedded in a merchant storefront, the merchant is responsible for configuring cookie notices, consent banners, privacy settings, and regional requirements applicable to that storefront, except to the extent Aabhas separately controls a specific processing activity.

    Clause 10

    Disclosure, subprocessors, and third parties

    Aabhas may disclose data to service providers, subprocessors, infrastructure vendors, authentication providers, storage providers, analytics systems, payment or billing providers, communication providers, professional advisers, auditors, legal authorities, affiliates, and business counterparties where necessary to provide the service, comply with law, enforce agreements, or protect rights and security.

    Aabhas does not sell shopper-uploaded virtual try-on images. Aabhas does not disclose such images to unaffiliated third parties for their independent advertising use. Any disclosure to processors or subprocessors is intended to be limited to service operation, infrastructure, security, support, compliance, or other authorized purposes.

    Clause 11

    International processing and transfers

    Aabhas is based in India and may process data in India and other jurisdictions where Aabhas, its affiliates, infrastructure providers, or subprocessors operate. Data protection laws in those jurisdictions may differ from the laws of the user, merchant, or organization location.

    Where required, Aabhas uses contractual, organizational, and technical safeguards designed to support lawful cross-border processing. Such safeguards may include data processing agreements, access controls, encryption in transit, cloud-provider storage protections, regional infrastructure choices, transfer assessments, and other measures appropriate to the relevant service and jurisdiction.

    Clause 12

    Security measures

    Aabhas maintains administrative, technical, and organizational measures designed to protect data against unauthorized access, accidental loss, misuse, alteration, and improper disclosure. Such measures may include authentication controls, role-based access, service-to-service tokens, signed URLs, logging, network restrictions, cloud identity controls, encryption in transit, managed storage protections, backup and recovery processes, vulnerability management, and operational monitoring.

    No method of transmission, storage, hosting, or computation is completely secure. Aabhas does not guarantee absolute security, but works to maintain controls appropriate to the nature of the data, the service, and the risks involved.

    Clause 13

    Retention, deletion, and storage limitation

    Aabhas retains data for the period reasonably necessary for service delivery, security, billing, compliance, support, dispute resolution, analytics, backups, business continuity, and legitimate operational purposes. Different categories of data may be retained for different periods depending on the product, configuration, contract, storage mode, legal requirements, and technical architecture.

    Image retention may be controlled by organization, shop, merchant, or admin settings where available. Aabhas supports storage and retention modes such as no-persist, reduced-retention, session-retention, limited-retention, merchant-review, and account-history modes depending on the product and configuration. The selected retention mode may determine whether raw uploaded images, prepared images, generated outputs, replay URLs, history records, logs, analytics, or derived metadata are retained, deleted, anonymized, or made unavailable after the configured period.

    Aabhas Store uses account-history behavior where needed for the customer experience. Uploaded customer images, prepared images, garment selections, generated try-on outputs, and related history may remain available to the customer across visits and devices after login until the customer deletes them through available account controls, closes the account, submits a verified deletion request, or a shorter product, legal, security, or shop-level retention rule applies.

    Aabhas may define product-specific default retention periods and may permit authorized administrators to set or change retention periods within the limits supported by the applicable product. Some media may be deleted or made unavailable earlier than related metadata. Backups, logs, derived aggregates, audit trails, and legally required records may persist for additional periods where deletion is not technically immediate or legally required to be delayed.

    Clause 14

    Privacy officer and data protection contact

    Aabhas maintains a founder-led privacy and data protection function. Until Aabhas appoints a separate full-time data protection officer, the founder or an authorized senior officer designated by Aabhas will supervise privacy requests, processor obligations, data protection escalations, security coordination, and regulatory or merchant privacy communications.

    Where a jurisdiction, contract, merchant arrangement, or enterprise customer requires a named data protection contact or DPO-equivalent point of contact, Aabhas may identify the appropriate founder, officer, or authorized representative in the relevant agreement, onboarding material, or written notice. Privacy communications may be sent to support@aabhas.tech unless another address is specified in the applicable agreement.

    Clause 15

    Rights, requests, and limitations

    Subject to applicable law, individuals may have rights to access, correct, delete, restrict, object to processing, withdraw consent, receive a copy of data, or lodge a complaint with a competent authority. The availability and scope of such rights depends on the jurisdiction, role of Aabhas, identity verification, legal exemptions, contractual restrictions, and technical feasibility.

    Where Aabhas processes data on behalf of a merchant, organization, or controller, Aabhas may refer the request to that party or act on its verified instructions. Aabhas may decline, limit, or delay a request where permitted by law, including where necessary for security, fraud prevention, legal compliance, backup integrity, dispute resolution, or protection of another person's rights.

    Clause 16

    Children and restricted users

    Aabhas services are not intended for use by children below the age at which they can lawfully consent to digital services in their jurisdiction, unless a parent, guardian, school, merchant, or authorized organization has provided the required authorization and the applicable product is configured for such use. Users and merchants must not knowingly submit children's personal data unless they have all legally required rights and consents.

    Clause 17

    Changes, conflicts, and contact

    Aabhas may update this Privacy Policy from time to time. Updates become effective when posted unless a later effective date is specified. Continued use of the applicable service after an update may be treated as acceptance where permitted by law and contract.

    If this Privacy Policy conflicts with a signed agreement, data processing agreement, or product-specific notice, the more specific document controls to the extent of the conflict for the relevant processing activity. For privacy questions, contact Aabhas at support@aabhas.tech.