Fit It On - Privacy Policy

Last Updated: December 2025

Introduction

At FitItOn (referred to as 'Fit It On', 'we', 'us', or 'our'), we respect your privacy and are committed to protecting your personal information. This Privacy Policy explains how we collect, use, and safeguard your data when you use our website, apps, and services.

Scope of this Policy

This policy applies to all services provided by Fit It On, including our primary site fititon.app and our Shopify app hosted at shopify.fititon.app. Third-party services integrated with our offerings have their own privacy policies.

Information Collection

We collect information in the following ways:

We collect only the minimum data needed to deliver try-on experiences and merchant analytics. Please avoid sending sensitive or special-category personal data in free-form metadata fields.

Photo Privacy: Photos uploaded for virtual try-on are only processed and stored to generate your try-on results and to enhance your user experience by allowing you to view and manage your try-on history in your gallery. They are never shared with third parties for marketing or other unrelated purposes, are not used for training general AI models, and can be deleted by you at any time from your gallery settings.

Use of Information

Your information, including Google user data, is used solely to provide and improve our core application functionality:

Information Sharing

We share your data only under the following limited circumstances:

Prohibited Data Uses and Transfers

We strictly limit the use and transfer of all personal data, including Google user data, to providing or improving the user-facing features of Fit It On.

We DO NOT sell your personal data to third parties. This is a fundamental principle of our service.

Data Protection

We implement industry-standard measures to protect your data, including encryption in transit and at rest, encrypted backups, access controls with least privilege, role-based access that is periodically reviewed, strong-password/SSO (and MFA where available) for staff, access logging for protected data with periodic review, and separation of test and production environments. Only authorized staff may access production data for support/operations, and access is revoked when no longer needed. We maintain a documented security incident response plan and will notify affected merchants/users without undue delay if an incident affects their data, including scope, impact, and remediation steps.

We apply data loss prevention controls (e.g., egress restrictions, monitoring/alerting, code reviews) and keep production customer data out of test/staging systems; we use synthetic or de-identified data in non-production.

Data Retention and Deletion

We retain your personal data, including Google user data, Shopify store and customer event data, and uploaded photos, only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, to provide our services to you, and to comply with our legal and regulatory obligations.

Account Deletion: When you delete your account, all associated personal data — including uploaded photos and try-on history — is permanently deleted from our systems. This action is irreversible and the data cannot be recovered. You may request for your data to be deleted by deleting your account through your account settings or by contacting us at the email below.

Shopify app data: We retain Shopify store customer events and API request logs while the store remains connected and for a limited period afterward (typically up to 180 days) for security, auditing, and troubleshooting, after which they are deleted or de-identified unless a longer period is required by law. Uninstalling the app stops future ingestion and triggers scheduled deletion. Merchants may also request earlier deletion via the contact below.

Backups are encrypted and follow a rolling retention schedule; backup copies age out and are purged on rotation. Deletion requests are applied to active data and will be reflected in backups once those backups expire from the retention window.

Your Rights

You have rights regarding your personal data, including access, correction, deletion, and objection to processing where applicable.

Depending on your location, you may also have rights under laws such as the GDPR (EU/UK/Switzerland) or CCPA (California).

Automated decision-making with legal or similarly significant effects is not performed by our services.

Shopify merchants and customers: We honor Shopify redaction/denial responses and will delete or provide access to customer data we process on your behalf upon request. To make a request, contact us at the email below or uninstall the app (which stops further ingestion).

Shopify App Disclosures

Our Shopify app processes protected customer data under Shopify’s protected customer data requirements. We collect only the minimum data needed to provide merchant analytics. If Shopify denies or redacts access to certain fields (for example, phone or address), those fields will return null and we will operate without them.

Merchants are responsible for obtaining any required consents from their customers before sending data to us and for avoiding sensitive or special-category personal data in free-form metadata fields.

Changes to this Policy

We may update this policy occasionally. Updates will be posted on our website with an updated effective date. Continued use of our services after changes implies your acceptance.

Contact Us

For questions or to exercise your rights, please contact us at [email protected].