Overview
Scope and our role
Woven Looks provides virtual try-on, sizing, saved-look, product merchandising, and related analytics features for Shopify merchants. This Privacy Policy applies to the Woven Looks Shopify app, its storefront features, and wovenlooks.com.
A Shopify merchant decides whether and how to offer Woven Looks on its store. For shopper information processed through that store, the merchant is generally responsible for the relationship with the shopper and Woven Looks processes information to provide the service to that merchant. We are responsible for information we collect for our own website, support, security, and business operations.
Collection
Information we collect
From merchants and Shopify APIs
When a merchant installs or uses Woven Looks, we receive the shop domain, app authorization and session information, authorized staff account details such as name, email, locale, and account role, plan and subscription status, app settings, and support communications. Through Shopify APIs we process authorized store data needed for the app, including product, variant, image, catalog, size-chart, and order attribution information. We also keep usage counts, configuration, catalog eligibility decisions, and merchant-created outfit rules.
From shoppers
To create a virtual try-on, Woven Looks processes shopper photos and selected garment images. The shopper photo is downscaled in the browser and image metadata is removed before upload. Depending on the active provider, a request payload can be held in a short-lived retry record that expires after five minutes and is then removed by an hourly deletion process. The photo is sent to an AI processing provider solely to produce the requested preview. Woven Looks does not use shopper photos to train artificial-intelligence models.
We calculate a cryptographic hash of the photo to recognize an identical try-on request without reconstructing the original image. We also process the generated preview, selected products and variants, consent time and policy version, and technical job status.
If a shopper uses sizing, we store height, weight, and fit preference. For signed-in shoppers, Shopify supplies a store-scoped customer identifier. For guests, we use a signed anonymous device identifier. We may also use a one-way hash of the network address for abuse and rate-limit protection; we do not store the raw network address in the app database.
Website and operational information
Our hosting and security providers may create standard request logs, such as network address, browser and device information, requested page, and timestamp. The storefront feature uses a signed identifier to keep guest activity scoped to that browser. Shopify may use its own cookies and technologies under Shopify's policies.
Use
How we use information
We use information to:
- provide virtual try-ons, sizing, Lookbook, and merchant tools;
- authenticate merchants and keep shopper histories separated;
- avoid charging plan allowance for identical cached try-ons;
- measure plan usage, attribute saved-look commerce events, and show app analytics;
- operate, secure, troubleshoot, and improve service reliability;
- respond to support and privacy requests; and
- comply with law and enforce our agreements.
We do not sell personal information or use shopper photos for advertising or model training.
Lifecycle
Retention and deletion
- Short-lived photo retry records expire five minutes after creation and are removed by the hourly purge process. Operational delays can extend the time required to complete deletion.
- Generated try-on previews, job records, consent records, and sizing profiles for guests expire after 72 hours.
- Generated try-on previews and sizing profiles for signed-in shoppers remain available in their Lookbook and Fit card until deletion is requested or the merchant uninstalls Woven Looks.
- Merchant configuration, catalog records, subscription state, usage, and analytics are kept while the app is installed or as needed to provide the service and meet legal, accounting, security, or dispute obligations.
When Shopify sends a valid customer deletion request, we remove that shopper's linked try-on, consent, sizing, and private render records. When a merchant uninstalls the app, we delete the shop's app records and generated objects through our uninstall process, except where a limited record must be retained by law.
Control
Your choices and rights
Merchants and shoppers may ask to access, correct, or delete personal information handled by Woven Looks, or object to or restrict certain processing where applicable. A shopper should usually contact the Shopify merchant first because the merchant controls the store relationship. The merchant can send the request to us, and Shopify's mandatory privacy webhooks also support customer data access and deletion requests.
You may also contact us directly at [email protected]. We may need to verify the request and may be unable to fulfill parts of it where an exception under applicable law applies.
Safeguards
Security and international transfers
We use safeguards designed to protect information, including private storage for generated previews, expiring signed access tokens, authenticated and shop-scoped requests, one-way hashing for sensitive technical identifiers, and scheduled deletion. No security measure is perfect, and we cannot guarantee absolute security.
Woven Looks and its service providers may process information in countries other than where the merchant or shopper lives. Where required, we rely on contractual or other lawful safeguards for these transfers.
Updates
Changes to this policy
We may update this policy as Woven Looks, our providers, or legal requirements change. We will publish the revised policy here and update the effective date. If a change is material, we will provide additional notice where appropriate.
Questions
Contact us
For privacy questions or requests, email [email protected]. Please include the Shopify store domain involved so we can route the request securely.