Skip to content
MirraFit — Innovative Tailored Attire
Legal

What we collect.
And what we don’t.

MirraFit puts a virtual fitting room on a fashion brand's product page. This page describes what actually happens to a shopper's photo and data inside that software — not what a template says should happen.

Last updated · 31 July 2026

01

Who this covers

This notice covers two groups of people. Shoppers who use the Try On button on a brand’s online store, and brands (we call them merchants) who install MirraFit or use this website.

The distinction matters legally. For everything collected through the fitting room, the brand whose store you are on is the data controller — they decide that the try-on runs on their products and they set its limits. MirraFit is their processor: we handle that data on their instructions and for no purpose of our own. Their privacy notice applies alongside this one, and a request to delete your data is usually fastest through them.

For merchant account data, for enquiries sent through this website, and for the security and abuse-prevention measures described below, MirraFit is the controller.

02

What we collect from shoppers

Everything in this table is collected by the MirraFit try-on widget or by our servers. Nothing else is.

WhatWhenWhy
The photo you uploadEach time you run a try-onTo render the garment onto you. See section 03 — it is not stored.
The product imageEach time you run a try-onIt is the garment being rendered. It comes from the store, not from you.
A device identifierThe first time you open the fitting roomA random ID generated in your browser, used to count your try-ons against the store's per-shopper limit.
A one-way hash of your IP addressEach time you run a try-onAbuse backstop, so one person cannot drain a store's whole allowance. The raw address is never stored.
A record of the try-onEach time you run a try-onWhich product and variant, whether it succeeded or failed and why, how long it took, its cost to the brand, and whether you were on mobile, tablet or desktop.
Your name and emailOnly if you choose to fill in the optional formPassed to the brand as a marketing contact, in exchange for extra try-ons. Never collected silently. See section 05.
Cart and checkout eventsOnly if you have granted analytics consent on that storeTo tell the brand whether try-ons lead to purchases. See section 06.
What we never receive.We do not get your name, email address, phone number, shipping or billing address, or any payment detail from the store’s checkout. We have no access to your Shopify account. The only way we ever learn your name or email is if you type them into the optional form yourself.
03

What happens to your photo

This is the part most people care about, so here is the whole path, step by step.

  • Your photo is uploaded over an encrypted (HTTPS) connection to our server.
  • It is checked, converted to JPEG, rotated the right way up and resized. The embedded EXIF metadata is stripped — which removes, among other things, any GPS location your camera wrote into the file.
  • It is sent to Google Cloud twice: once for an automated check that a person is actually visible in the frame, and once to the try-on model that renders the garment onto you.
  • It is never written to disk on our servers and never stored in our database. It exists only in memory for the seconds the request takes, then it is gone.
  • The result image is stored as a private object in Amazon S3. It is never public. It can only be retrieved through a signed link that stops working after one hour, and it is deleted automatically by a storage rule set to expire objects within three days.

MirraFit does not use your photo to train any model of its own, and we do not sell or share it. The try-on itself runs on Google Cloud Vertex AI, where under Google’s service terms customer data is not used to train Google’s models.

We perform no facial recognition and no biometric matching. The only automated question ever asked about your photo is whether it contains a person at all — a yes or no — so that we do not spend the brand’s money rendering a garment onto a photo of a chair.

04

The device identifier, and your IP address

  • The device identifieris a random UUID your browser generates the first time you open the fitting room. It is not derived from anything about you or your hardware — it is just a random number. It is kept in that store’s browser storage and in a first-party cookie called mirrafit_did. It is not linked to any identity unless you volunteer your email. Clearing the site’s cookies and site data resets it.
  • Your IP address is hashed the moment the request arrives — SHA-256, with a secret salt only we hold — and only the hash is used. The raw address is never written to our database and never written to our logs. The hash exists for one reason: so that someone cannot bypass a store’s per-shopper limit by opening a private window and getting a fresh device ID. Without the salt the hash cannot be turned back into an address.
05

Name and email — only if you give them

Some brands offer extra try-ons in exchange for your details. If they have, a short form appears — and only after you have used up the store’s per-shopper allowance, never before, and never as a condition of the first try-on.

  • The form asks for a name and an email address, with a required consent checkbox agreeing to receive email from that brand. Our server rejects any submission without it — an address given without consent is not stored at all.
  • What you submit is shared with the brand whose store you were on, who can export it from their MirraFit dashboard. From that point they are responsible for it under their own privacy notice, and they are the sender of any marketing you receive.
  • We do not verify the address, and we never send you email ourselves.
06

Analytics and purchase attribution

To tell a brand whether the fitting room actually sells clothes, we register a Shopify web pixel on their store. It runs in Shopify’s strict sandbox and Shopify only loads it when you have granted analytics consent on that store. Decline, and it never runs at all — the trade-off is simply that the brand’s purchase numbers are incomplete.

It listens for two events, and reads only this from them:

EventWhat we readWhat we do not read
Added to cartProduct and variant ID, line amount, currency, and Shopify's own browser client IDYour name, email, phone or address
Checkout completedOrder ID (or the checkout token if the order ID is not set yet), order total and currency, and Shopify's browser client IDYour name, email, phone, address or payment details

The pixel declares itself as analytics only. It declares no marketing and no preferences purpose, and it declares that it does not participate in the sale of data — because MirraFit does not sell or share shopper data for advertising.

07

How long we keep things

DataRetention
The photo you uploadNot kept. Held in memory for the request only — never on disk, never in the database.
The try-on result imageA private object in Amazon S3, reachable only through a link that expires after one hour, deleted automatically by a storage rule set to expire objects within three days.
The job record used for pollingIn server memory only, discarded one hour after the try-on finishes.
Try-on event records and cart/purchase attribution90 days, then deleted by an automated sweep that runs every day.
Anonymous device recordsDeleted once the device has been idle for 90 days.
Device records carrying an email you submittedKept until the brand deletes them, you ask for deletion, or the brand uninstalls MirraFit. These are the brand's consented contacts, so they are deliberately not swept at 90 days.
Daily aggregate countersKept indefinitely. See below.
The device identifier in your browserThe cookie is set to expire after one year. Browser storage lasts until you clear the site's data.
Why aggregate statistics are kept forever. An aggregate row is one line of numbers per store, per day, per product: how many try-ons, how many succeeded, how many led to a cart add. It carries no device identifier, no IP hash, no email, and no link back to any individual try-on record. Nothing in it points to a person, so there is nothing in it to erase — which is precisely why deleting one shopper’s data does not silently rewrite a brand’s historical charts, and why we can keep it.
08

Who we share it with

The brand whose store you used.They see their own analytics, a list of the shoppers who used the fitting room on their store, and — where a shopper consented — that shopper’s name and email. Shoppers who did not use the form appear as a truncated device ID and nothing more.

Our sub-processors. These are the only third parties that touch this data:

Sub-processorWhat it doesWhere
Google CloudRuns the try-on model that renders the garment, and the automated check that a person is visible in the photo.United States (us-central1)
Amazon Web ServicesHosts our application server and database, and stores the try-on result image.Europe — Stockholm (eu-north-1)
ShopifyThe platform the app, the storefront widget and the pixel run on. Shopify also delivers the consent signals and the data-request and deletion webhooks we act on.Shopify's own infrastructure
AxiomApplication logging — see below for what those logs contain.As operated by Axiom

What is in our logs. Our request logs record the HTTP method, the path, the status code, timings and internal job IDs. They do not record your IP address, your photo, your name or your email. When a data request comes in, the record we assemble is deliberately never written to the log — putting it there would create a second copy of exactly the data we promise we can erase.

We do not sell shopper data and we do not share it for advertising. We may disclose data where we are legally required to.

09

Where your data goes

We are not going to pretend this all stays in one place, because it does not. A single try-on crosses a border and comes back:

  • Your photo is sent to Google Cloud in the United States (region us-central1) for the person check and the render.
  • The result image, our application server and our database are in Amazon Web Services in Europe (Stockholm, eu-north-1).
  • Shopify processes storefront and checkout events on its own global infrastructure.

Our use of Google Cloud and Amazon Web Services is governed by each provider’s standard data processing terms, which incorporate the European Commission’s Standard Contractual Clauses for transfers out of the EEA and the UK.

10

Your rights, and how to use them

Depending on where you live you have the right to access the data held about you, to have it corrected, to have it deleted, to withdraw consent you gave, to object to or restrict processing, to receive your data in a portable form, and to complain to your data protection authority.

  • Through the brand (fastest). Because the brand is the controller for try-on data, ask them. Shopify’s customer data-request and customer-redaction requests reach us automatically and we act on them — a redaction hard-deletes the matching device record, its try-on history and its attribution records.
  • Directly. Email us at privacy@mirrafit.co. Tell us which store you used and the email address you gave there, if you gave one — that is what we search on.
  • To withdraw marketing consent, contact the brand. They hold the mailing list; we do not send marketing email to shoppers.
Being honest about what we can find. We can only delete what we can match you to. If you gave a store your email through the try-on form, or if you placed an order the brand names in a deletion request, we can find your records and erase them. If you did neither, the only identifiers we hold are a random device ID, a salted IP hash and Shopify’s browser client ID — none of which a deletion request carries, so there is nothing for us to match on. Those records are deleted automatically after 90 days instead, and clearing the store’s site data in your browser removes the device identifier from your side straight away. Deletion does not remove the identifier-free daily counters described in section 07, because they contain nothing that identifies you.
11

Cookies and browser storage

MirraFit sets one first-party cookie, mirrafit_did, holding the random device identifier. It expires after one year and is set with SameSite=Lax. The same identifier is mirrored into the store’s browser storage, alongside a flag recording that you have already used the email form and a cached copy of the store’s widget settings.

We set no advertising cookies and we do not track you across other websites. The Shopify web pixel described in section 06 is governed by the store’s own consent banner.

12

Merchants, and this website

When a brand installs MirraFit we store their myshopify domain, their plan and usage counts, their widget settings and try-on limits, their store timezone, and a Shopify session token. Authentication and billing are handled by Shopify; we never see card details.

If you submit the demo request form on this website we store what you typed — brand, name, work email and the rest of the form — on our own server so that we can reply to you. It is not passed to any third party. You can ask us to delete it at any time at privacy@mirrafit.co.

Merchants should also read the merchant terms and data processing addendum, which set out the controller and processor obligations in full.

13

Children

MirraFit is not directed at children and we do not knowingly collect data from anyone under 16. If you believe a child has uploaded a photo through the fitting room, contact us and we will delete the record.

14

Changes, and how to reach us

When this notice changes materially we will update the date at the top of the page and, for merchants, notify the contact address on the Shopify account. The version on this page is always the current one.

Privacy questions, access requests and deletion requests: privacy@mirrafit.co. For anything else, use the contact form.