Last updated: August 2026
Aisthetix Virtual Try-On ("the App") is operated by Aisthetix. Contact: davide_mastricci@aisthetix.com
The App collects data at the merchant (shop) level:
The App also collects storefront behavioural events through a Shopify Web Pixel so the merchant can measure how virtual try-on affects their store. These events are collected only where the shopper has given the consent required by Shopify's Customer Privacy API. We collect:
We use this data only to compute aggregate effectiveness metrics (a conversion funnel, correlational lift, and try-on-attributed revenue) shown to the merchant. We do not collect shopper names, email addresses, phone numbers, postal addresses, payment details, or IP addresses.
When a shopper asks for a size recommendation, the App processes the shopper's height, optional weight, and body measurements inferred from their photo, together with uncertainty values used to avoid overstating the recommendation. The App also uses a random browser visitor identifier and a one-way hash of the photo to reuse the same measurements across products without storing the photo itself. Uploaded photos are sent directly to our AI processing service and are not stored after processing is complete.
Separately from the merchant's metrics above, the App collects product analytics that Aisthetix uses to improve the App itself — which step of the try-on or size flow a shopper reached, and why a request failed. These are collected on the same Shopify consent as the events above: a shopper who has not granted analytics consent generates none of them. We collect:
These events never include a photo, a try-on result, a body measurement, a height, a weight, an email address, or the address of the page. Every property is checked against a fixed, versioned list before it is sent, and anything not on that list is discarded.
Where the merchant has enabled it, and only after the same analytics consent, the App may record a session replay of the try-on window — not of the rest of the merchant's page. Every image and every form field is masked before recording, so the shopper's photo and their try-on result are never captured. Recording starts when the shopper opens the try-on window and stops when they close it, and it stops immediately if the shopper withdraws consent.
The App also records merchant product analytics: which admin page a merchant opened, and the outcome of installing, configuring, subscribing and serving a first try-on. These are identified by the shop domain, never by an email address, and may include a masked session replay of the App's own admin screens where enabled.
We do not sell or share data with third parties, except:
Storefront behavioural events used for the merchant's metrics are processed only by Aisthetix; they are not shared with any third party or used for advertising. Product analytics and session replays are not used for advertising either, and are not shared with anyone beyond the processor named above.
Size-estimation cache entries — height, optional weight, inferred body measurements, uncertainty values, the random visitor identifier and the one-way photo hash — expire automatically after 30 days. The uploaded photo is not included in this cache. A merchant uninstall removes the shop's remaining measurement-cache entries through Shopify's shop/redact process.
Product analytics events are retained for 12 months, and session replays for 30 days, after which both are deleted automatically.
Other merchant data is retained for as long as the App is installed. When a merchant uninstalls the App, session data is deleted immediately and all remaining shop data — including the legal billing profile, subscriptions, usage records, and storefront behavioural events (pixel_events) — is permanently deleted within 48 hours in response to Shopify's shop/redact webhook.
When a shopper exercises their right to erasure, Shopify sends a customers/redact webhook and we delete that shopper's behavioural events and their product analytics; on a customers/data_request webhook we make that shopper's stored events available to the merchant. Both are keyed on the Shopify customer ID and order IDs supplied by Shopify.
One thing that erasure cannot single out, and we would rather say so than imply otherwise: a session replay of the try-on window carries no identifier linking it to a shopper. The recorder is deliberately never told who the shopper is — that is what stops a profile being built about them — so a replay cannot be matched to an erasure request naming a customer. It is confined to the try-on window, every field is masked and every image is blocked, and it is deleted automatically after 30 days.
If you are located in the European Economic Area, you have the right to access, correct, or delete personal data we hold. Shoppers should exercise these rights through the merchant whose store they used; merchants can contact us directly at davide_mastricci@aisthetix.com.
All data is transmitted over TLS/HTTPS. Webhook payloads are verified using HMAC-SHA256 signatures. OAuth tokens are stored securely in a database with restricted access.
We may update this policy from time to time. The latest version will always be available at this URL. Continued use of the App after changes constitutes acceptance.
Questions about this policy? Email davide_mastricci@aisthetix.com