aisthetix. WooCommerce plugin

Privacy Policy

Last updated: June 21, 2026

Aisthetix Virtual Try-On for WooCommerce

1. Introduction

Aisthetix ("we", "our", "us") provides an AI-powered virtual try-on service for fashion e-commerce. This Privacy Policy explains how we collect, use, and protect information when you use the Aisthetix Virtual Try-On plugin for WooCommerce ("the Plugin") and the hosted Aisthetix service it connects to ("the Service").

By using the Plugin and the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use them.

2. Data Controller

For storefront and shopper data processed through the Service, the merchant operating the store is the data controller and Aisthetix acts as the processor. You can contact us at:

3. Information We Collect

3.1 Merchant (store) data

When you connect your WooCommerce store to the Service, we collect:

  • Your store URL / domain, used to identify your store
  • Subscription and billing information (plan, status, period)
  • Try-on usage records (aggregated counts) for quota and billing

During connection, the Service provisions two API keys, a public (publishable) key and a secret key, which the Plugin stores on your own WordPress server. The secret key is used only for server-to-server status checks and is never sent to the browser.

3.2 Storefront analytics (optional, off by default)

By default the Plugin collects no analytics. If you enable "Anonymous analytics" (off by default), or a supported consent banner on your site grants analytics/statistics consent, the Plugin sends anonymous behavioural events to the Service so you can measure how virtual try-on affects your store:

  • Product-view, add-to-cart, and try-on-completed events on your storefront
  • On a paid order: the order id, product ids, order value and currency, and an anonymous visitor id, used to attribute a purchase to an earlier try-on

These events are keyed to a random, non-personal visitor id (see Cookies, section 7). No Shopify Web Pixel is used. We do not collect shopper names, email addresses, phone numbers, postal addresses, payment details, or IP addresses, and we do not use this data for marketing or share it with third parties.

3.3 Shopper photos & image processing

When a shopper actively starts a try-on (an explicit click, behind the widget's own consent step):

  • The shopper's photo is sent from their browser directly to the Service over an encrypted HTTPS connection: it never touches your WordPress server
  • The image is processed entirely in server memory to generate the result: it is never written to disk or stored permanently
  • The shopper's uploaded photo and their try-on history live only in the shopper's own browser storage (localStorage)
  • Results may be held in a temporary in-memory cache (maximum 1 hour), and asynchronous processing jobs are stored in Redis with a time-to-live of 1 hour, after which they are automatically deleted

4. How We Use Your Information

We use the information we collect to:

  • Provide and operate the virtual try-on service
  • Process and manage merchant subscriptions and billing (via Stripe)
  • Track usage for billing and quota management
  • Where you enable analytics, measure how virtual try-on affects your store (conversion funnel, lift, and attributed revenue)
  • Improve our service quality and performance
  • Comply with legal obligations

We do not use advertising or cross-site tracking cookies, collect shopper email addresses, or sell shopper data. Storefront behavioural events, where collected, are used solely to produce your effectiveness metrics.

5. Data Retention

Data Type Retention Period
In-memory image cache 1 hour (automatic expiry)
Redis processing jobs 1 hour (automatic expiry)
Shopper photo & try-on history Not retained by us: held only in the shopper's own browser until they clear it
Merchant subscription & usage data While the store is connected / subscription is active; deleted on request or disconnection
Storefront behavioural events (only if analytics enabled) Retained to compute your metrics; deleted on request
Visitor-id cookie (aisthetix_vid) About 13 months, stored first-party in the shopper's browser (only if analytics enabled)

6. Third-Party Services

We use the following third-party services to operate Aisthetix:

  • Google: AI image generation for virtual try-on. Images are sent transiently for processing and are not stored by us. Google's own data handling is governed by their Privacy Policy.
  • fal.ai: AI image generation for certain garment categories (such as swimwear). Images are sent transiently for processing and are not stored by us.
  • Stripe: Merchant billing and subscription management.
  • MongoDB Atlas: Encrypted database (at rest and in transit) for merchant subscription, usage, and storefront behavioural-event data.
  • Redis: Temporary job storage with automatic expiry.

7. Cookies and Analytics

By default the Plugin sets no cookies and sends no analytics: nothing is tracked passively. A shopper-initiated try-on still works: it is an explicit action, not passive tracking.

If you enable "Anonymous analytics", the Plugin sets a first-party cookie named aisthetix_vid, a random, non-personal visitor id (lifetime about 13 months) used to attribute a later purchase to an earlier try-on, and sends the anonymous events described in section 3.2. If your site uses a supported consent banner (Cookiebot, Complianz, or Google Consent Mode), the shopper's analytics/statistics choice controls those browser-side events. We do not use advertising cookies, third-party ad pixels, or any form of cross-site tracking.

8. GDPR Compliance (EEA Users)

If you are located in the European Economic Area (EEA), the following additional rights and information apply to you under the General Data Protection Regulation (GDPR).

Lawful Basis for Processing

  • Legitimate Interest: Processing virtual try-on requests to deliver our core service.
  • Contract Performance: Managing merchant subscriptions and billing under the service agreement.
  • Consent: For optional storefront analytics and any communications where applicable.

Your Rights as a Data Subject

Under the GDPR, you have the following rights:

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate personal data.
  • Right to Erasure: Request deletion of your personal data.
  • Right to Data Portability: Receive your data in a structured, machine-readable format.
  • Right to Restrict Processing: Request that we limit processing of your data.
  • Right to Object: Object to processing based on legitimate interest.
  • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.
  • Right to Lodge a Complaint: File a complaint with your local data protection supervisory authority.

How to Exercise Your Rights

Shoppers should exercise these rights through the merchant whose store they used; merchants can contact us directly at davide_mastricci@aisthetix.com. We will respond within 30 days.

Merchant & Shopper Data Requests

On request, we make available or delete the data we hold for a store (subscription, usage, and any storefront behavioural events). When a store disconnects the Plugin, we delete its associated data. Storefront behavioural events, where collected, are keyed to an anonymous visitor id; a shopper can remove their local try-on data at any time by clearing their browser storage.

International Data Transfers

Image processing is performed via third-party AI providers (including Google Cloud infrastructure), which may involve transferring data outside the EEA. These transfers are covered by standard contractual clauses and the providers' data processing agreements.

Data Protection Officer

For GDPR-related inquiries, contact our DPO at davide_mastricci@aisthetix.com.

9. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • All data transmission is encrypted via HTTPS/TLS
  • Images are processed in-memory only and never persisted to disk
  • Merchant authentication uses encrypted tokens and scoped API keys
  • Database access is restricted with authentication and access controls
  • Temporary data is automatically purged via time-to-live expiration

10. Children's Privacy

Our services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately so we can take appropriate action.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be reflected on this page with an updated "Last updated" date. We encourage you to review this page periodically to stay informed about how we protect your data.

12. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us: