OutfitShot
Privacy Policy
Effective 9 September 2026
OutfitShot (“we”, “us”) is a Shopify app that generates product photos for apparel and accessories with AI image models. This policy explains what data the app handles when a Shopify store (“you”, the merchant) installs it, why, and how to get it deleted. It applies to the app served from app.outfitshot.com.
1. What we collect
We only handle data that the app needs to do its job:
- Store identity and access. Your store’s
myshopify.comdomain and the offline API access token Shopify issues to the app. If Shopify includes them in the session, the name and email address of the staff member who installed the app. - Product data you choose to photograph. For the products you select: product ID, title, existing product images, product category and the standard category attributes you have filled in (such as fit, sleeve length, neckline, fabric, colour and target gender), and the optional
fashion_photo.notesmetafield. - Generated images and job records. Every generation job: which product, preset, model and scene were used, the prompt sent to the image model, the resulting image, its status and any error message. Finished images are copied into your store’s Shopify Files, so they live in your Shopify account.
- Settings and usage. Your app settings (auto-publish, default model and scene, output format) and a usage record per generated image, used to enforce your plan’s monthly quota.
- Billing status. Which subscription plan is active. Payment itself is handled by Shopify; we never see card details.
We do not collect or store data about your customers, orders, or visitors. The app does not set tracking cookies and does not run analytics scripts.
2. How we use it
- To generate the images you request and show them back to you.
- To publish generated images to your products when you (or your auto-publish setting) ask for it.
- To count images against your plan and bill through Shopify.
- To keep a history and gallery of your past generations.
- To diagnose failures when a generation or publish goes wrong.
We do not sell your data, use it for advertising, or use your product images to train AI models.
3. Who else processes it
We rely on a small number of service providers:
- Shopify — the platform the app runs on. Product data is read from, and generated images are written to, your Shopify store through the Admin API.
- fal.ai — the image generation provider. The product images you select and our own stock model reference images are sent to fal.ai to produce each photo. fal.ai hosts the generated image temporarily until we copy it into your Shopify Files.
- Railway — hosts the application and its PostgreSQL database where the records described above are stored.
- Cloudflare — provides DNS for our domain and hosts our own stock model reference images. No merchant data is stored there.
Each provider only receives what it needs for its part of the work and is bound by its own terms and privacy commitments.
4. How long we keep it
- Store identity, job records, settings and generated-image references are kept while the app is installed.
- When you uninstall the app, or when Shopify sends us a
shop/redactrequest, we delete your sessions, job records and settings from our database. Shopify sends the redact request 48 hours after uninstall; we act on it automatically. - Images already copied into your Shopify Files or attached to your products belong to your store and are not touched by uninstalling. You can delete them from Shopify at any time.
- Usage records used for billing are kept for as long as needed to document charges made through Shopify.
- Cached intermediate images produced during generation are stored without a link to your store and expire with the provider that hosts them.
5. Customer data requests
Because the app stores no customer data, Shopify’s customers/data_request and customers/redact webhooks are acknowledged and require no further action from us. If you receive such a request from one of your customers, nothing about them is held in OutfitShot.
6. Your rights
Depending on where you are, data protection law (including the GDPR in the EU/EEA, the UK GDPR, the Turkish KVKK and the CCPA) may give you the right to access, correct, export or delete the data we hold about your store, or to object to its processing. To exercise any of these, email us at hello@outfitshot.com from the email address associated with your store. We answer within 30 days.
7. Security
All traffic between your browser, Shopify, our servers and our providers is encrypted with TLS. Access tokens are stored server-side and are never sent to the browser. Access to production systems is limited to the people who operate the app.
8. Children
The app is a business tool for Shopify merchants and is not directed at children under 16.
9. Changes
If we change this policy in a way that matters, we will update the effective date above and, for significant changes, notify you inside the app.
10. Contact
Questions about privacy or this policy: hello@outfitshot.com