AppCroft

Privacy Policy

Last updated: 14 September 2026 · Applies to Appcroft: AI Try-On & Chat

In short. Appcroft AI is a Shopify app that lets shoppers see a product on a photo of themselves and ask an assistant about the shop's catalogue. To do that we process the photos shoppers choose to upload, the questions they ask, and a small amount of data from the merchant's Shopify store. Photos are kept only as long as the merchant configures (30 days by default, 90 at most), conversations for 7 days, and everything is deleted when the shop uninstalls the app. We never sell data, never use shoppers' photos to train models, and never identify a shopper across stores.

  1. 1. Who we are
  2. 2. Merchants and shoppers
  3. 3. Data from the merchant's store
  4. 4. Data from shoppers
  5. 5. How AI models are used
  6. 6. How long we keep data
  7. 7. Who processes data for us
  8. 8. Security
  9. 9. Your rights
  10. 10. Shopify's privacy requests
  11. 11. Children
  12. 12. Changes
  13. 13. Contact

1. Who we are

Appcroft: AI Try-On & Chat (“the app”, “Appcroft AI”) is developed and operated by AppCroft, a project of Veltical (veltical.com). In this policy “we”, “us” and “our” refer to AppCroft. We are the data controller for the data described in section 3 and, as explained in section 2, a data processor acting for the merchant for the data described in section 4.

2. Merchants and shoppers

The app touches two kinds of people:

For shoppers, the merchant is the data controller: they decide to offer the try-on and the assistant in their store, they choose how long photos are kept, and they are responsible for informing their customers under their own privacy policy. We process shoppers' data on the merchant's behalf and on their instructions, as set out in this policy and in our Terms of Service. The app gives merchants a setting to ask shoppers for explicit agreement before a photo is used, with a link to the merchant's own policy.

3. Data from the merchant's store

When a merchant installs the app, we receive and store:

We use the merchant's contact email to send the emails they turn on in the app (a weekly report, low-credit alerts) and for messages that are necessary to operate the service, such as a billing problem or a security notice.

4. Data from shoppers

Nothing is collected from a shopper until they choose to use the try-on or the assistant. Browsing a store with the app installed sends us no personal data. When a shopper does use it, we process:

We do not use shoppers' photos or conversations to train any model, ours or anyone else's. We do not build profiles of shoppers, do not combine data across stores and do not advertise.

5. How AI models are used

The app's two features run on AI models:

Generated images are approximations. They are labelled as such to the shopper, and a result our checks consider unreliable is flagged and not charged to the merchant.

6. How long we keep data

Data Kept for
Shoppers' photos, own items and generated images The period the merchant sets in the app, between 1 and 90 days (30 by default), counted from upload. Deleted automatically by a daily sweep, or earlier when the shopper removes them.
Assistant conversations 7 days after the last message.
Usage events (try-ons, cart events, assistant prompts) 1 year, then removed; Insights never look back further.
Webhook delivery log 90 days — kept so the same delivery is never processed twice.
Merchant's catalogue, settings and store identity While the app is installed.
Credit ledger and billing records Kept as financial records after uninstall, attached to an anonymised store stub. They contain amounts and dates, no personal data.
Audit log of administrative actions 2 years.
Database backups Daily, kept 30 days (weekly copies 12 weeks). A copy is stored off-site with the same provider. Data deleted from the live system disappears from backups as they expire.

When a merchant uninstalls the app, Shopify sends us a shop/redact request 48 hours later and we delete the store's data — catalogue, settings, shoppers' photos, results and conversations — as described in section 10.

7. Who processes data for us

We use a small number of service providers. Each receives only what its job needs, under a contract that limits it to that job.

Provider What for Where
Hetzner Online GmbH Hosting of the application, database, file storage and backups. Photos and results are stored here. European Union (Germany)
fal.ai (Features and Labels, Inc.) Runs the image, vision and language models. Receives the photo, the product image and the assistant's prompt for the duration of a request. Models available through fal.ai may be built by third parties (for example OpenAI); fal.ai routes the request to them under its own terms. United States
Shopify Inc. The platform the app runs on: authentication, billing, webhooks, the storefront proxy through which shoppers reach the app. Canada / global
Cloudflare, Inc. DNS for our domains. Does not receive photos or conversations. Global
Resend, Inc. Sends the emails merchants opt in to (reports, alerts). United States

Where data leaves the European Economic Area, we rely on the provider's Standard Contractual Clauses or its participation in the EU–US Data Privacy Framework. Merchants who prefer their AI requests to be made under their own contract can connect their own fal.ai key in the app.

8. Security

If we become aware of a breach affecting personal data, we will notify the affected merchants without undue delay so they can meet their own obligations to their customers.

9. Your rights

Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal data, to restrict or object to its processing, and to complain to a supervisory authority.

Shoppers: please contact the store you used the app in. The merchant is the controller for your data and can act on your request through Shopify (section 10); we will carry out their instructions. You can also delete a saved photo yourself from the try-on window at any time.

Merchants: you can change or delete most data directly in the app. Uninstalling the app deletes the rest, as described above. For anything else, contact us (section 13).

10. Shopify's privacy requests

The app implements Shopify's three mandatory privacy webhooks, and they do real work:

11. Children

The app is not directed at children and we do not knowingly process their data. Merchants are responsible for the audience of their own stores.

12. Changes

We will update this policy when the app changes in a way that affects it, and note the date at the top. Material changes are announced to merchants inside the app or by email.

13. Contact

Questions about this policy or about your data: contact@appcroft.com.