A customer's photo is personal. We treat it that way.
Virtual try-on works from images of a person's hand, neck or ear. That is sensitive by nature, so our defaults lean toward keeping as little as possible, for as short as possible.
The photo, the render, and not much else.
We collect what a try-on needs and are deliberate about what we keep once it is done.
Try-on images
The hand, neck or ear photo used for a session, plus the resulting render. Used to produce the try-on and, briefly, to let a customer revisit it.
Sizing signals
The measurements or size estimates derived from a session, so a confirmed size can travel with an order.
Try-on activity
Which catalog pieces were tried on, for analytics - kept separate from the identifiable image wherever possible.
Photos do not linger by default.
The most sensitive item - the customer image - has the shortest life in our system.
Encrypted moving and at rest, with tight access.
Encryption in transit and at rest
Data is encrypted as it travels between the customer, the store and our systems, and encrypted while stored.
Scoped access
Access to customer images is limited to what a task requires, on a need-to-use basis, rather than broadly available.
A clear deletion policy
Photos are removed after a try-on session on a defined schedule - not kept indefinitely on the chance they are useful later.
Transparent by design
A customer can be told plainly what is captured, why, and when it goes - because the answer is short.
Stated honestly, current status only.
We describe where we actually are, not where we hope to be.
Have a specific data question?
If you need detail on retention windows or access for your own review, put it to us directly and we will answer plainly.
