Try Instant Fit

International Privacy Policy & Global Data Governance

Effective: 16 September 2026

Platform Provider: Try Instant Fit (“Company,” “We,” “Us,” or “Our”)
Service Covered: tryinstantfit.com Dashboard, APIs, Virtual Try-On Engine, and Embeddable Client Modules

This Privacy Policy forms an integral part of our Terms of Service and describes how personal data is processed, protected, and purged. Its descriptions of how we handle data reflect how the platform actually operates. The policy has not yet been reviewed by qualified privacy counsel, so its legal sufficiency in any particular jurisdiction is not warranted; we will remove this note once that review is complete.

1. Zero-Retention Customer Image Guarantee

Real-time ephemeral processing. End-User body photos submitted for virtual try-ons are processed in volatile memory strictly to generate the fitting visual. They are never written to our databases or to cloud file storage.

No server-side storage of results. The generated try-on image is returned directly to the browser session that requested it and is not uploaded to our cloud storage. We do not save, store, back up, archive, or train AI models on End-User body photos or on the generated try-on images produced from them.

Local device downloads. End Users may manually download their generated try-on result to their own device. A download is a local file transfer to the End User’s hardware. Once the End User navigates away, closes the tab, or refreshes the page, the image is gone from the session. We retain zero copies.

No issue-report image collection. We do not operate a try-on issue-reporting or refund-review flow, and we do not invite, accept, or store customer photographs, screenshots, or generated images for review purposes.

Historical data. Try-on images generated before 16 September 2026 were retained on cloud storage under an earlier version of this policy. On 16 September 2026 those images and every database reference to them were deleted — 289 stored files in total. They are no longer accessible to anyone, including us. Our storage provider retains deleted files briefly in an internal recovery buffer that guards against accidental deletion, after which they are erased from its systems as well.

Non-biometric processing. We do not perform facial recognition, iris scanning, body measurement cataloguing, biometric template extraction, or biometric identification mapping. We do not use customer images to identify, verify, or track any individual. Because no biometric identifier or template is created or retained, we do not maintain a biometric database.

2. Merchant asset security & database isolation

Vendor-uploaded clothing photos, product titles, prices, and metadata are stored using enterprise-grade cloud database infrastructure. Stored merchant data is safeguarded via Row-Level Security (RLS) policies providing multi-tenant database isolation to prevent cross-merchant data leakage or unauthorised catalogue exposure. Our infrastructure providers maintain recognised industry security certifications such as SOC 2; that certification is held by those providers rather than by Try Instant Fit.

3. Conditional lead generation & contact data governance

Passcode-protected sessions (optional data). When an End User accesses a virtual try-on session using a Merchant-issued passcode, submitting personal contact details (full name, email address, WhatsApp/phone number) is optional unless the issuing Merchant specifies otherwise.

Sponsored / free public sessions (mandatory data). When an End User accesses a free or public virtual try-on campaign sponsored by a Merchant, where no passcode is required, submitting basic contact details is mandatory to generate the fitting output. This is the consideration for accessing the free service, and it enables session verification, protects against automated abuse, tracks usage limits, and allows the sponsoring Merchant to verify contest entries or promotional offers.

Merchant as Data Controller. Contact details collected during try-on sessions are transferred to the sponsoring Merchant and stored in their private, isolated Merchant Dashboard to support fitting follow-ups, stock updates, contest management, and marketing inquiries.

Try Instant Fit as Data Processor. We maintain a secure copy of these contact transaction logs as a platform transaction record, to verify credit consumption, maintain security, conduct system auditing, and prevent fraudulent usage.

Independent Merchant responsibility. We provide the software infrastructure enabling Merchants to receive leads. We do not own, control, direct, or monitor how individual Merchants manage, store, or communicate through these leads once transferred. The Merchant operates as an independent Data Controller and bears responsibility for compliance with applicable anti-spam, privacy, and telecommunication laws when contacting End Users.

4. Data retention periods

We keep personal data only as long as stated below.

Data Retention period
End-User body photos Not retained. Processed in memory only.
Generated try-on images Not retained. Returned to the browser session only.
End-User lead contact details 6 months after the Merchant account’s last credit consumption, then permanently deleted.
Merchant catalogue and account data For the life of the account. Purged following termination for 6 months of inactivity (see Terms, Section 4).
Transaction, credit and billing records Retained as required by applicable tax and accounting law, then deleted.
Technical and security logs Up to 12 months.

5. Sub-processors

We use the following sub-processors to deliver the Services. Each receives only the data necessary for its function and is bound by contractual data-protection terms.

Provider Function Data processed
Google Cloud (including AI image processing) Try-on image generation; merchant file storage Garment images; End-User photo transiently during generation, not retained by us
Supabase Database and authentication Merchant account data, catalogue metadata, lead records
Vercel Application hosting and delivery Request metadata and technical logs
Google Analytics Aggregate website usage measurement Site usage and device metadata

We will update this list before engaging a new sub-processor that processes personal data. Merchants may contact us to object to a change.

6. International privacy compliance

European Union & UK (GDPR). Data transfers outside the EEA rely on EU Standard Contractual Clauses (SCCs). Processing of merchant data relies on legitimate interest and contractual necessity; shopper contact submission relies on explicit consent and contractual necessity for free gated services.

Data Processing Agreement (DPA). For Merchants operating in the EU or EEA, a GDPR-compliant Data Processing Agreement incorporating SCCs is available on request and, once executed, forms part of these Terms — defining Try Instant Fit as Data Processor and the Merchant as Data Controller. Merchants requiring a signed DPA should contact info@tryinstantfit.com.

United States (CCPA/CPRA). We do not sell or share End-User or Merchant personal information to third parties for commercial gain or targeted behavioural advertising.

Middle East (UAE Law No. 45/2021 & Saudi PDPL). Cross-border data handling adheres to encryption standards in transit and at rest, and consent for lead submissions may be revoked at any time by contacting the Merchant or Try Instant Fit.

Pakistan and other jurisdictions. Platform operations, digital contracting, and cross-border service delivery adhere to applicable electronic transaction and cybercrime protection frameworks in the jurisdictions where we operate.

7. Your rights and how to exercise them

Depending on your jurisdiction, you may have the right to access, correct, delete, or receive a copy of your personal data; to object to or restrict processing; and to withdraw consent.

How to make a request. Email info@tryinstantfit.com with the subject line “Data Request” and tell us what you want done. For lead data, include the email address or phone number you submitted and, if known, the brand whose try-on you used.

Our response. We acknowledge requests within 7 days and aim to complete them within 30 days, extendable once where a request is complex. We may ask for information to verify your identity, and we will not charge a fee except where a request is manifestly unfounded or excessive.

Limits. Where a Merchant is the Data Controller for lead data, we will action your request against our own copy and pass the request to that Merchant. Some records must be kept where required by tax, accounting, fraud-prevention, or legal-claims obligations. EU and UK users may also lodge a complaint with their local supervisory authority.

8. Security & data breach notification

We use access controls, encryption in transit and at rest, tenant isolation, and reasonable technical safeguards. No online system is risk-free, and users must protect their account credentials, access links, passcodes, and devices.

In the event of a personal data breach likely to result in a risk to affected individuals, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk to individuals, we will also notify affected Merchants and, where we hold the necessary contact details, affected End Users without undue delay. Notifications will describe the nature of the breach, its likely consequences, and the measures taken.

9. Session storage & tracking

We use essential session storage strictly to maintain passcode authorisation states and remaining try-on counts during an active session. We use Google Analytics to measure aggregate site usage. We do not use persistent tracking cookies for cross-site behavioural advertising.

10. Minors protection

The platform is not directed to or intended for individuals under 16, or under 13 in applicable US jurisdictions, without verifiable parental consent. We do not knowingly collect personal data from minors. A lawful parent or guardian must authorise any image of a child, and Merchants must not direct free try-on campaigns at children. If we learn that a minor has submitted contact details without the required consent, we will delete that data. Contact info@tryinstantfit.com to report such a case.

11. Analytics & usage telemetry

We collect aggregated usage metrics to populate Merchant analytical dashboards, including scan-to-try conversion rates, top-performing garment leaderboards, and outbound link click-through counts. Where a free or sponsored session required contact details, the resulting activity record is linked to that submitted identity and is treated as personal data under this policy — not as anonymous data. Metrics presented in aggregate across multiple users do not identify individuals.

12. Changes to this policy

We will post material changes with an updated effective date. Where a change materially reduces protections for personal data already collected, we will provide notice to affected Merchants before it takes effect.

13. Contact information

For platform support, merchant onboarding inquiries, or data privacy requests:

Terms · Refund Policy · Home