How Tryeido handles shopper photos and personal data
Tryeido (a product of Technosys Solutions Inc.) is built around shopper privacy first. Photos and try-on outputs are owned by the shopper — never sold, never shared with merchants or third parties, never used for advertising. Below is the precise posture: what we do, what regimes we align with, and the roadmap items we're working on next.
Shoppers create accounts directly with Tryeido, agree to our privacy policy, give consent to us, and can delete their data through our widget. We — not the merchant — decide retention, encryption, sub-processors, and deletion. The merchant simply embeds the widget; they never see shopper photos and never carry GDPR Article 28 processor obligations for our half of the data lifecycle.
Practical impact for merchants: you don't need a full GDPR Article 28 DPA from us covering shopper-data processing — that legal responsibility is ours. We'll provide a lightweight DPA covering only merchant-administrative data (your dashboard accounts, audit logs, support tickets), plus a one-paragraph privacy-disclosure snippet for your own privacy notice that references Tryeido as a third-party service.
Regulatory alignment
- Lawful basis: consent at widget activation
- Right to erasure — Delete-my-data button in widget
- Privacy by design + privacy by default
- Encryption at rest, transport over TLS
- Breach-notification process internal SLA: 72h
- In-product Article 15 data portability export (JSON + photo archive)
- External audit of Article 30 processing records
- SOC 2 Type I report
- Notice + consent at first widget interaction
- Withdrawal of consent supported via Delete-my-data
- Data fiduciary responsibilities documented internally
- Storage in India-region cluster available on enterprise plans
- Significant Data Fiduciary registration once volume thresholds are met
- Formal DPO appointment as the team scales
- Right to know — privacy policy + in-widget data view
- Right to delete — Delete-my-data button
- Right to opt out of sale — N/A; we never sell shopper data
- Right to correct — supported via account update flows
- In-product verifiable consumer request workflow (today: email-driven)
- SOC 2 Type I — planned for the calendar year following first paying enterprise customer
- ISO 27001 — under evaluation
- PCI DSS — out of scope (Stripe holds the payment-card boundary; Tryeido never sees card data)
Concrete protections in place today
- Encryption at restAll shopper photos and try-on outputs are stored encrypted at rest with platform-managed keys (SSE-KMS rollout in progress).
- Shopper-controlled deletionA 'Delete my photos and try-ons' button in the widget privacy screen wipes photos, body measurements, try-on history, and family-member profiles. Erasure is immediate; no email-support ticket required.
- 180-day automatic retentionIf a shopper doesn't return for 180 days, all their photos and try-on artifacts are auto-deleted by a nightly job. Retention is not configurable by merchants — shoppers and Tryeido set the policy.
- Encrypted transportEvery connection between the merchant's site, the widget, and Tryeido servers runs over TLS 1.2+. Presigned MinIO URLs are short-lived (15-60 min).
- Content moderation at uploadEvery uploaded photo is checked by a server-side NSFW detector (NudeNet) before it touches storage. Off-policy uploads are rejected and logged for audit.
- No cross-merchant photo accessPhotos are partitioned per shopper and never shared across merchant tenants. Merchants cannot view shopper photos, only their own product images and aggregate analytics.
- No advertising or training useShopper photos are used only to generate the try-on the shopper requested. They are not used to train any model, sold to partners, or shared with advertising networks.
What we don't do
- We do not retain photos for AI model improvement. Shopper photos are processed, cached for the shopper's session, and deleted on the retention schedule.
- We do not share shopper photos with merchants. Merchants see aggregate analytics (try-on counts, conversion rates, recommended-size adoption), never the photos themselves.
- We do not sell, rent, or lease shopper data to any third party.
- We do not use shopper photos for advertising, profiling, or any purpose outside the try-on the shopper explicitly initiated.
- We do not store payment information directly. Card data is handled by Stripe and never reaches Tryeido servers.
Contact
Privacy or security questions? Data subject rights requests (access, export, erasure)? Compliance officers reviewing Tryeido for vendor onboarding?
Email privacy@tryeido.com. We respond to data subject rights requests within 30 days as required by GDPR Article 12, and faster in practice.
See also: Privacy Policy