Legal / Trust & Data
Photos are transient. By architecture.
This page states plainly what OmnyFit does with shopper photos, merchant catalogue data and analytics events.
Last updated — 1 August 2026
Shopper photos
A shopper photo is uploaded over TLS, held in volatile memory for the duration of the render, and discarded when the session ends. Photos are not written to durable storage and are never used to train or fine-tune models.
Rendered output is served from a signed URL that expires after 24 hours by default, or immediately on session close where the merchant enables strict mode.
Merchant data
OmnyFit reads product, variant and size-chart data with read-only credentials. We do not write to your catalogue, orders or customer records.
Return-rate figures used in reporting are supplied by the merchant, either as aggregate exports or through platform analytics scopes.
Hosting and regions
Rendering runs in EU and US edge regions. Merchants may pin processing to a single region on request.
Analytics events are stored in the region matching the merchant's account.
Security controls
Encryption in transit (TLS 1.3) and at rest for all stored records, scoped API keys, mandatory SSO and MFA for internal access, and least-privilege role separation between rendering and analytics systems.
Penetration testing is performed annually by an external firm; summaries are available under NDA.
Sub-processors
A current list of sub-processors, their function and their processing region is available on request and is referenced in the Data Processing Addendum.
Questions about this document? Email legal@omnyfit.com.
