Woven Looks Add to your store

Legal

Woven Looks Privacy Policy

This policy explains what Woven Looks collects, why we use it, who helps us process it, and how merchants and shoppers can control it.

Effective September 7, 2026

Overview

Scope and our role

Woven Looks provides virtual try-on, sizing, saved-look, product merchandising, and related analytics features for Shopify merchants. This Privacy Policy applies to the Woven Looks Shopify app, its storefront features, and wovenlooks.com.

A Shopify merchant decides whether and how to offer Woven Looks on its store. For shopper information processed through that store, the merchant is generally responsible for the relationship with the shopper and Woven Looks processes information to provide the service to that merchant. We are responsible for information we collect for our own website, support, security, and business operations.

Collection

Information we collect

From merchants and Shopify APIs

When a merchant installs or uses Woven Looks, we receive the shop domain, app authorization and session information, authorized staff account details such as name, email, locale, and account role, plan and subscription status, app settings, and support communications. Through Shopify APIs we process authorized store data needed for the app, including product, variant, image, catalog, size-chart, and order attribution information. We also keep usage counts, configuration, catalog eligibility decisions, and merchant-created outfit rules.

From shoppers

To create a virtual try-on, Woven Looks processes shopper photos and selected garment images. The shopper photo is downscaled in the browser and image metadata is removed before upload. Depending on the active provider, a request payload can be held in a short-lived retry record that expires after five minutes and is then removed by an hourly deletion process. The photo is sent to an AI processing provider solely to produce the requested preview. Woven Looks does not use shopper photos to train artificial-intelligence models.

We calculate a cryptographic hash of the photo to recognize an identical try-on request without reconstructing the original image. We also process the generated preview, selected products and variants, consent time and policy version, and technical job status.

If a shopper uses sizing, we store height, weight, and fit preference. For signed-in shoppers, Shopify supplies a store-scoped customer identifier. For guests, we use a signed anonymous device identifier. We may also use a one-way hash of the network address for abuse and rate-limit protection; we do not store the raw network address in the app database.

Website and operational information

Our hosting and security providers may create standard request logs, such as network address, browser and device information, requested page, and timestamp. The storefront feature uses a signed identifier to keep guest activity scoped to that browser. Shopify may use its own cookies and technologies under Shopify's policies.

Use

How we use information

We use information to:

  • provide virtual try-ons, sizing, Lookbook, and merchant tools;
  • authenticate merchants and keep shopper histories separated;
  • avoid charging plan allowance for identical cached try-ons;
  • measure plan usage, attribute saved-look commerce events, and show app analytics;
  • operate, secure, troubleshoot, and improve service reliability;
  • respond to support and privacy requests; and
  • comply with law and enforce our agreements.

We do not sell personal information or use shopper photos for advertising or model training.

Disclosure

How we share information

We disclose information only as needed to operate Woven Looks, at a merchant's direction, or where legally required. Service providers include Shopify for the commerce platform and billing; AI processing providers such as Google or fal.ai for requested try-ons; Railway for application and database hosting; and Cloudflare for private object storage, website hosting, delivery, and security. AI processing providers receive the shopper and garment images required to generate a preview.

Providers may process information only for the services they perform for us and under their applicable contractual and privacy terms. We may also disclose information to professional advisers, authorities when legally required, or a successor in a merger, financing, acquisition, or sale of assets, subject to appropriate protections.

Lifecycle

Retention and deletion

  • Short-lived photo retry records expire five minutes after creation and are removed by the hourly purge process. Operational delays can extend the time required to complete deletion.
  • Generated try-on previews, job records, consent records, and sizing profiles for guests expire after 72 hours.
  • Generated try-on previews and sizing profiles for signed-in shoppers remain available in their Lookbook and Fit card until deletion is requested or the merchant uninstalls Woven Looks.
  • Merchant configuration, catalog records, subscription state, usage, and analytics are kept while the app is installed or as needed to provide the service and meet legal, accounting, security, or dispute obligations.

When Shopify sends a valid customer deletion request, we remove that shopper's linked try-on, consent, sizing, and private render records. When a merchant uninstalls the app, we delete the shop's app records and generated objects through our uninstall process, except where a limited record must be retained by law.

Control

Your choices and rights

Merchants and shoppers may ask to access, correct, or delete personal information handled by Woven Looks, or object to or restrict certain processing where applicable. A shopper should usually contact the Shopify merchant first because the merchant controls the store relationship. The merchant can send the request to us, and Shopify's mandatory privacy webhooks also support customer data access and deletion requests.

You may also contact us directly at [email protected]. We may need to verify the request and may be unable to fulfill parts of it where an exception under applicable law applies.

Safeguards

Security and international transfers

We use safeguards designed to protect information, including private storage for generated previews, expiring signed access tokens, authenticated and shop-scoped requests, one-way hashing for sensitive technical identifiers, and scheduled deletion. No security measure is perfect, and we cannot guarantee absolute security.

Woven Looks and its service providers may process information in countries other than where the merchant or shopper lives. Where required, we rely on contractual or other lawful safeguards for these transfers.

Updates

Changes to this policy

We may update this policy as Woven Looks, our providers, or legal requirements change. We will publish the revised policy here and update the effective date. If a change is material, we will provide additional notice where appropriate.

Questions

Contact us

For privacy questions or requests, email [email protected]. Please include the Shopify store domain involved so we can route the request securely.