Data Lifecycle & Retention Rules🕒 Updated: 2026-08-03📖 3 min read

Data Retention & Deletion Policy

Fittera maintains strict data minimization standards, keeping records only as long as necessary to provide service, fulfill merchant preferences, or satisfy legal requirements.

256-bit AES Encrypted
GDPR & CCPA Compliant
Built on Shopify's App Platform
99.9% Uptime Target

Active Installation Data Lifecycle

During active app installation, catalog configurations, model avatars, credit logs, and generated try-on visual results are retained to support store features.

Merchant Data Controls: Store owners can manage each customer's product access and credit balances at any time from the vendor dashboard. Deletion of customer photo history and generated try-on logs happens automatically when Shopify's compliance webhooks fire, or on request to our Privacy Officer.

Automated Webhook Purging (Shopify Compliance)

Upon receiving valid Shopify compliance webhooks:

  • customers/redact: Associated customer portraits, try-on history, and SHA-256 hashes are permanently deleted from database records.
  • shop/redact: Merchant store configurations and API access session tokens are completely removed within 48 hours.

Uninstallation Data Disposition

When a merchant uninstalls Fittera, OAuth session tokens are invalidated immediately. Remaining shop-scoped data is queued for automatic purging following Shopify's standard 48-hour redaction protocol.

Submitting Manual Deletion Requests

To submit a manual cryptographic data deletion request, contact our Privacy Officer at [email protected] specifying your .myshopify.com store domain.