What we collect.
And what we don’t.
MirraFit puts a virtual fitting room on a fashion brand's product page. This page describes what actually happens to a shopper's photo and data inside that software — not what a template says should happen.
Last updated · 31 July 2026
Who this covers
This notice covers two groups of people. Shoppers who use the Try On button on a brand’s online store, and brands (we call them merchants) who install MirraFit or use this website.
The distinction matters legally. For everything collected through the fitting room, the brand whose store you are on is the data controller — they decide that the try-on runs on their products and they set its limits. MirraFit is their processor: we handle that data on their instructions and for no purpose of our own. Their privacy notice applies alongside this one, and a request to delete your data is usually fastest through them.
For merchant account data, for enquiries sent through this website, and for the security and abuse-prevention measures described below, MirraFit is the controller.
What we collect from shoppers
Everything in this table is collected by the MirraFit try-on widget or by our servers. Nothing else is.
| What | When | Why |
|---|---|---|
| The photo you upload | Each time you run a try-on | To render the garment onto you. See section 03 — it is not stored. |
| The product image | Each time you run a try-on | It is the garment being rendered. It comes from the store, not from you. |
| A device identifier | The first time you open the fitting room | A random ID generated in your browser, used to count your try-ons against the store's per-shopper limit. |
| A one-way hash of your IP address | Each time you run a try-on | Abuse backstop, so one person cannot drain a store's whole allowance. The raw address is never stored. |
| A record of the try-on | Each time you run a try-on | Which product and variant, whether it succeeded or failed and why, how long it took, its cost to the brand, and whether you were on mobile, tablet or desktop. |
| Your name and email | Only if you choose to fill in the optional form | Passed to the brand as a marketing contact, in exchange for extra try-ons. Never collected silently. See section 05. |
| Cart and checkout events | Only if you have granted analytics consent on that store | To tell the brand whether try-ons lead to purchases. See section 06. |
What happens to your photo
This is the part most people care about, so here is the whole path, step by step.
- Your photo is uploaded over an encrypted (HTTPS) connection to our server.
- It is checked, converted to JPEG, rotated the right way up and resized. The embedded EXIF metadata is stripped — which removes, among other things, any GPS location your camera wrote into the file.
- It is sent to Google Cloud twice: once for an automated check that a person is actually visible in the frame, and once to the try-on model that renders the garment onto you.
- It is never written to disk on our servers and never stored in our database. It exists only in memory for the seconds the request takes, then it is gone.
- The result image is stored as a private object in Amazon S3. It is never public. It can only be retrieved through a signed link that stops working after one hour, and it is deleted automatically by a storage rule set to expire objects within three days.
MirraFit does not use your photo to train any model of its own, and we do not sell or share it. The try-on itself runs on Google Cloud Vertex AI, where under Google’s service terms customer data is not used to train Google’s models.
We perform no facial recognition and no biometric matching. The only automated question ever asked about your photo is whether it contains a person at all — a yes or no — so that we do not spend the brand’s money rendering a garment onto a photo of a chair.
The device identifier, and your IP address
- The device identifieris a random UUID your browser generates the first time you open the fitting room. It is not derived from anything about you or your hardware — it is just a random number. It is kept in that store’s browser storage and in a first-party cookie called
mirrafit_did. It is not linked to any identity unless you volunteer your email. Clearing the site’s cookies and site data resets it. - Your IP address is hashed the moment the request arrives — SHA-256, with a secret salt only we hold — and only the hash is used. The raw address is never written to our database and never written to our logs. The hash exists for one reason: so that someone cannot bypass a store’s per-shopper limit by opening a private window and getting a fresh device ID. Without the salt the hash cannot be turned back into an address.
Name and email — only if you give them
Some brands offer extra try-ons in exchange for your details. If they have, a short form appears — and only after you have used up the store’s per-shopper allowance, never before, and never as a condition of the first try-on.
- The form asks for a name and an email address, with a required consent checkbox agreeing to receive email from that brand. Our server rejects any submission without it — an address given without consent is not stored at all.
- What you submit is shared with the brand whose store you were on, who can export it from their MirraFit dashboard. From that point they are responsible for it under their own privacy notice, and they are the sender of any marketing you receive.
- We do not verify the address, and we never send you email ourselves.
Analytics and purchase attribution
To tell a brand whether the fitting room actually sells clothes, we register a Shopify web pixel on their store. It runs in Shopify’s strict sandbox and Shopify only loads it when you have granted analytics consent on that store. Decline, and it never runs at all — the trade-off is simply that the brand’s purchase numbers are incomplete.
It listens for two events, and reads only this from them:
| Event | What we read | What we do not read |
|---|---|---|
| Added to cart | Product and variant ID, line amount, currency, and Shopify's own browser client ID | Your name, email, phone or address |
| Checkout completed | Order ID (or the checkout token if the order ID is not set yet), order total and currency, and Shopify's browser client ID | Your name, email, phone, address or payment details |
The pixel declares itself as analytics only. It declares no marketing and no preferences purpose, and it declares that it does not participate in the sale of data — because MirraFit does not sell or share shopper data for advertising.
How long we keep things
| Data | Retention |
|---|---|
| The photo you upload | Not kept. Held in memory for the request only — never on disk, never in the database. |
| The try-on result image | A private object in Amazon S3, reachable only through a link that expires after one hour, deleted automatically by a storage rule set to expire objects within three days. |
| The job record used for polling | In server memory only, discarded one hour after the try-on finishes. |
| Try-on event records and cart/purchase attribution | 90 days, then deleted by an automated sweep that runs every day. |
| Anonymous device records | Deleted once the device has been idle for 90 days. |
| Device records carrying an email you submitted | Kept until the brand deletes them, you ask for deletion, or the brand uninstalls MirraFit. These are the brand's consented contacts, so they are deliberately not swept at 90 days. |
| Daily aggregate counters | Kept indefinitely. See below. |
| The device identifier in your browser | The cookie is set to expire after one year. Browser storage lasts until you clear the site's data. |
Where your data goes
We are not going to pretend this all stays in one place, because it does not. A single try-on crosses a border and comes back:
- Your photo is sent to Google Cloud in the United States (region
us-central1) for the person check and the render. - The result image, our application server and our database are in Amazon Web Services in Europe (Stockholm,
eu-north-1). - Shopify processes storefront and checkout events on its own global infrastructure.
Our use of Google Cloud and Amazon Web Services is governed by each provider’s standard data processing terms, which incorporate the European Commission’s Standard Contractual Clauses for transfers out of the EEA and the UK.
Your rights, and how to use them
Depending on where you live you have the right to access the data held about you, to have it corrected, to have it deleted, to withdraw consent you gave, to object to or restrict processing, to receive your data in a portable form, and to complain to your data protection authority.
- Through the brand (fastest). Because the brand is the controller for try-on data, ask them. Shopify’s customer data-request and customer-redaction requests reach us automatically and we act on them — a redaction hard-deletes the matching device record, its try-on history and its attribution records.
- Directly. Email us at privacy@mirrafit.co. Tell us which store you used and the email address you gave there, if you gave one — that is what we search on.
- To withdraw marketing consent, contact the brand. They hold the mailing list; we do not send marketing email to shoppers.
Merchants, and this website
When a brand installs MirraFit we store their myshopify domain, their plan and usage counts, their widget settings and try-on limits, their store timezone, and a Shopify session token. Authentication and billing are handled by Shopify; we never see card details.
If you submit the demo request form on this website we store what you typed — brand, name, work email and the rest of the form — on our own server so that we can reply to you. It is not passed to any third party. You can ask us to delete it at any time at privacy@mirrafit.co.
Merchants should also read the merchant terms and data processing addendum, which set out the controller and processor obligations in full.
Children
MirraFit is not directed at children and we do not knowingly collect data from anyone under 16. If you believe a child has uploaded a photo through the fitting room, contact us and we will delete the record.
Changes, and how to reach us
When this notice changes materially we will update the date at the top of the page and, for merchants, notify the contact address on the Shopify account. The version on this page is always the current one.
Privacy questions, access requests and deletion requests: privacy@mirrafit.co. For anything else, use the contact form.
