Privacy Policy
Last updated: 14 September 2026 · Applies to Appcroft: AI Try-On & Chat
In short. Appcroft AI is a Shopify app that lets shoppers see a product on a photo of themselves and ask an assistant about the shop's catalogue. To do that we process the photos shoppers choose to upload, the questions they ask, and a small amount of data from the merchant's Shopify store. Photos are kept only as long as the merchant configures (30 days by default, 90 at most), conversations for 7 days, and everything is deleted when the shop uninstalls the app. We never sell data, never use shoppers' photos to train models, and never identify a shopper across stores.
- 1. Who we are
- 2. Merchants and shoppers
- 3. Data from the merchant's store
- 4. Data from shoppers
- 5. How AI models are used
- 6. How long we keep data
- 7. Who processes data for us
- 8. Security
- 9. Your rights
- 10. Shopify's privacy requests
- 11. Children
- 12. Changes
- 13. Contact
1. Who we are
Appcroft: AI Try-On & Chat (“the app”, “Appcroft AI”) is developed and operated by AppCroft, a project of Veltical (veltical.com). In this policy “we”, “us” and “our” refer to AppCroft. We are the data controller for the data described in section 3 and, as explained in section 2, a data processor acting for the merchant for the data described in section 4.
2. Merchants and shoppers
The app touches two kinds of people:
- Merchants — the Shopify store owners and staff who install the app and use its admin pages.
- Shoppers — visitors and customers of a merchant's store who use the try-on button or the assistant on the storefront.
For shoppers, the merchant is the data controller: they decide to offer the try-on and the assistant in their store, they choose how long photos are kept, and they are responsible for informing their customers under their own privacy policy. We process shoppers' data on the merchant's behalf and on their instructions, as set out in this policy and in our Terms of Service. The app gives merchants a setting to ask shoppers for explicit agreement before a photo is used, with a link to the merchant's own policy.
3. Data from the merchant's store
When a merchant installs the app, we receive and store:
- Store identity — the store's domain, name, contact email, country, currency and primary language, as provided by Shopify.
- An access token that lets the app read the catalogue and receive webhooks. It is stored encrypted and is never displayed or exported.
- The catalogue — products, variants, images, prices, categories and inventory availability. This is what the try-on renders and what the assistant answers from. It is refreshed through Shopify webhooks whenever a product changes.
- Shipping rules — the store's own free-shipping threshold, so the assistant can tell a shopper how far their cart is from it.
- Theme information — whether the app's blocks are present in the published theme, so the setup checklist can tell the truth.
-
Order events — from
orders/paid,orders/updated,orders/cancelledandrefunds/createwebhooks. We read only the order id, the line items (product, variant, quantity, price) and the customer's Shopify id. We do not read or store the customer's name, email address, phone number or postal address. Order events are used to attribute sales to a try-on or an assistant conversation in the merchant's Insights, and to deliver credits when a merchant sells credit packs to their own customers. - Billing — the plan the merchant chose, subscription and one-time purchase status as reported by Shopify Billing, and the credit ledger. Payment is handled entirely by Shopify; we never see card or bank details.
- Settings and usage — everything the merchant configures in the app, the try-ons generated, the assistant's message counts, and per-shop AI cost, so the merchant's Insights and our billing are accurate.
- An optional AI key — merchants on some plans may connect their own fal.ai API key. It is stored encrypted and used only for that merchant's requests.
We use the merchant's contact email to send the emails they turn on in the app (a weekly report, low-credit alerts) and for messages that are necessary to operate the service, such as a billing problem or a security notice.
4. Data from shoppers
Nothing is collected from a shopper until they choose to use the try-on or the assistant. Browsing a store with the app installed sends us no personal data. When a shopper does use it, we process:
- Photos the shopper uploads to try a product on. A photo is checked first (it must show one person, with nothing that could not be rendered safely); a photo that fails the check is rejected with a reason and is not kept. Accepted photos are stored so the shopper can reuse them without uploading again, and are deleted after the retention period the merchant set (section 6). The shopper can remove a saved photo at any time from the try-on window.
- Generated images — the try-on results, kept for the same period, so the shopper can download, share or return to them.
- Photos of their own items, where the merchant's plan allows a shopper to add a garment they already own to the look. Same treatment as photos.
- Assistant conversations — the questions a shopper types and the answers given, kept for 7 days so the conversation can continue and a merchant can look into a support question.
- Usage events — that a try-on happened, that a product was added to the cart from a try-on or a conversation, that an assistant prompt was shown, opened or dismissed. These feed the merchant's Insights and are aggregated after a year.
-
A device identifier — a random token stored in the shopper's browser
(
localStorage, not a cookie) that lets a guest find their saved photos and results again, and lets us apply the merchant's per-visitor limits. It contains no personal information and is not shared with anyone. - A per-store customer reference — when a shopper is signed in to the store, Shopify tells us their customer id. We store it only as a one-way hash that is different for every store, so a shopper's saved photos follow their account in that store, and so nobody — including us — can tell that the same person shops in two different stores.
- Network address — used transiently to enforce rate limits and to detect abuse. It is not stored with photos or conversations, and our access logs are configured to strip identifiers such as customer ids and device tokens.
We do not use shoppers' photos or conversations to train any model, ours or anyone else's. We do not build profiles of shoppers, do not combine data across stores and do not advertise.
5. How AI models are used
The app's two features run on AI models:
- Photo checks and try-on images — the uploaded photo and the product image are sent to an image model, which returns the generated result. Before that, a vision model checks that the photo is usable. The photo is transmitted for the duration of the request only; the model provider's own retention is described in section 7.
- The assistant — the shopper's question, the recent conversation and matching products from the merchant's catalogue are sent to a language model, which writes the answer. The assistant is instructed to recommend only products that exist in the catalogue.
- Catalogue search — product texts are converted into embeddings by a model that runs on our own servers; nothing leaves them for this step.
Generated images are approximations. They are labelled as such to the shopper, and a result our checks consider unreliable is flagged and not charged to the merchant.
6. How long we keep data
| Data | Kept for |
|---|---|
| Shoppers' photos, own items and generated images | The period the merchant sets in the app, between 1 and 90 days (30 by default), counted from upload. Deleted automatically by a daily sweep, or earlier when the shopper removes them. |
| Assistant conversations | 7 days after the last message. |
| Usage events (try-ons, cart events, assistant prompts) | 1 year, then removed; Insights never look back further. |
| Webhook delivery log | 90 days — kept so the same delivery is never processed twice. |
| Merchant's catalogue, settings and store identity | While the app is installed. |
| Credit ledger and billing records | Kept as financial records after uninstall, attached to an anonymised store stub. They contain amounts and dates, no personal data. |
| Audit log of administrative actions | 2 years. |
| Database backups | Daily, kept 30 days (weekly copies 12 weeks). A copy is stored off-site with the same provider. Data deleted from the live system disappears from backups as they expire. |
When a merchant uninstalls the app, Shopify sends us a shop/redact request 48
hours later and we delete the store's data — catalogue, settings, shoppers' photos, results
and conversations — as described in section 10.
7. Who processes data for us
We use a small number of service providers. Each receives only what its job needs, under a contract that limits it to that job.
| Provider | What for | Where |
|---|---|---|
| Hetzner Online GmbH | Hosting of the application, database, file storage and backups. Photos and results are stored here. | European Union (Germany) |
| fal.ai (Features and Labels, Inc.) | Runs the image, vision and language models. Receives the photo, the product image and the assistant's prompt for the duration of a request. Models available through fal.ai may be built by third parties (for example OpenAI); fal.ai routes the request to them under its own terms. | United States |
| Shopify Inc. | The platform the app runs on: authentication, billing, webhooks, the storefront proxy through which shoppers reach the app. | Canada / global |
| Cloudflare, Inc. | DNS for our domains. Does not receive photos or conversations. | Global |
| Resend, Inc. | Sends the emails merchants opt in to (reports, alerts). | United States |
Where data leaves the European Economic Area, we rely on the provider's Standard Contractual Clauses or its participation in the EU–US Data Privacy Framework. Merchants who prefer their AI requests to be made under their own contract can connect their own fal.ai key in the app.
8. Security
- All traffic is encrypted in transit (TLS); connections to the app require HTTPS.
- Shopify access tokens and merchants' AI keys are encrypted at rest with a key that is never stored in the database.
- Stored photos and results have unguessable names, are never listed publicly and expire by policy.
- Every request from a storefront is signed by Shopify and verified; requests from outside a store, or with an old signature, are refused.
- Administrative access is limited to named operators, protected by passkeys, and every administrative action is recorded in an audit log.
- Servers are firewalled to the ports the service needs, kept updated, and backed up daily with restore drills.
If we become aware of a breach affecting personal data, we will notify the affected merchants without undue delay so they can meet their own obligations to their customers.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal data, to restrict or object to its processing, and to complain to a supervisory authority.
Shoppers: please contact the store you used the app in. The merchant is the controller for your data and can act on your request through Shopify (section 10); we will carry out their instructions. You can also delete a saved photo yourself from the try-on window at any time.
Merchants: you can change or delete most data directly in the app. Uninstalling the app deletes the rest, as described above. For anything else, contact us (section 13).
10. Shopify's privacy requests
The app implements Shopify's three mandatory privacy webhooks, and they do real work:
-
customers/data_request— we assemble everything we hold about the customer in that store (saved photos, results, conversations, usage events, credit balance) and return it to the merchant. -
customers/redact— we delete the customer's photos, results and conversations from storage first and from the database second, so a failure can never leave a photo behind. Credit ledger entries are kept as financial records; they contain no personal data. -
shop/redact— we delete the store and everything under it, and replace the store row with an anonymous stub that only the financial records hang from.
11. Children
The app is not directed at children and we do not knowingly process their data. Merchants are responsible for the audience of their own stores.
12. Changes
We will update this policy when the app changes in a way that affects it, and note the date at the top. Material changes are announced to merchants inside the app or by email.
13. Contact
Questions about this policy or about your data: contact@appcroft.com.