Categories of Data Processed
- Shopify Store Metadata: Store myshopify.com domain, shop owner email address, subscription plan tier, and catalog garment images.
- Customer Selfie Portraits: User-uploaded images processed transiently for visual try-on rendering and hashed via SHA-256.
- Generated Try-On Imagery: AI visual outputs created during Mirror Room sessions and stored securely for merchant history and email sharing.
- System Audit & Telemetry: Anonymized timestamps, error logs, and credit consumption records for system reliability monitoring.
Purpose & Legal Basis for Processing
Data is collected and processed strictly to fulfill merchant-requested try-on features, authenticate merchant access via Shopify OAuth, enforce subscription credit limits, deliver try-on results via email, and prevent platform abuse.
Third-Party Sub-Processors
Fittera utilizes certified cloud infrastructure partners to maintain high availability:
- Shopify Inc.: Storefront billing, OAuth authentication, and mandatory compliance hooks.
- Hivelocity, Inc.: Cloud database hosting and encrypted application servers.
- Generative AI Compute Providers: Secure visual try-on processing APIs.
- PLACEHOLDER_REPLACE_ME: Transactional email dispatch for customer try-on sharing.
Merchant & Consumer Rights (GDPR / CCPA)
Merchants have full authority to reset credit balances and manage character model and product access for each customer from the vendor dashboard. Storefront customers and merchants can request data access or erasure at any time by contacting our Privacy Officer; Shopify's mandatory compliance webhooks additionally trigger automatic redaction (see Automated Compliance Webhooks below).
Automated Compliance Webhooks
Fittera responds automatically to Shopify's mandatory GDPR compliance webhooks:
- customers/data_request: Provides exported records of any customer data stored under a store domain.
- customers/redact: Permanently purges customer portrait records and associated try-on logs.
- shop/redact: Purges all merchant store configurations within 48 hours of app uninstallation.
Security Standards & Privacy Officer Contact
Application database keys are encrypted at rest, route handlers enforce tenant isolation, and web traffic uses TLS 1.3 encryption.
Legal Business Address: 519-521, Iscon Emporio, Jodhpur Village, Ahmedabad - 380015, Gujarat, India