Privacy Policy

Effective Date: July 31, 2026  ·  Last Updated: July 31, 2026

This Privacy Policy explains how Amora ("we", "us", or "our") collects, uses, and protects personal information when you use the Amora virtual try-on platform, our website, our Shopify app, and our APIs and embeddable widgets (together, the "Services").

This policy covers merchants, direct-API customers, and website visitors. If you are a shopper using an Amora try-on tool embedded on a merchant's store, our Shopper Privacy Policy applies to you instead, and the merchant — not Amora — is the controller of your personal data.

Who We Are

Amora provides AI virtual try-on ("VTO") software. A shopper uploads a photo of themselves and a garment image, and our systems generate an image showing the shopper wearing that garment.

Contact: shrut@amora.org.in

Information We Collect

Account and billing information: Name, email address, business name, authentication identifiers, API keys and public tokens, plan and tier, and payment identifiers and records processed through our payment provider.

Content you provide: Product images, garment images, catalogue data, brand assets, configuration, and — for direct-API customers who upload through our tools — photos submitted for try-on generation and the try-on images generated from them.

Merchant integration data: For Shopify merchants, your shop domain, an encrypted platform access token, installed-product VTO settings, and product metadata.

Usage and technical data: Log data, request metadata, timestamps, approximate location derived from IP, device and browser information, feature usage, and error diagnostics.

Support communications: Messages you send us and their contents.

How We Use Your Information

We use the information we collect to:

Legal bases (EEA/UK): performance of a contract (providing the Services); legitimate interests (security, abuse prevention, service improvement in aggregate, direct B2B communications); consent (where required, e.g. certain cookies); and compliance with legal obligations.

AI Model Training

We do not use your content, your customers' photos, or generated images to train, fine-tune, or otherwise develop AI or machine-learning models.

Photos and generated images are used only to produce the try-on result you requested and to operate the Service — for example, transient processing, delivery, and short-term storage within the retention windows below.

Biometric Data and Facial Recognition

We do not create face templates, faceprints, or any other biometric identifier from any photo, and we do not use facial-recognition technology to identify or verify individuals. Photos are processed only to render a garment onto the person shown in the image. We do not use photos to infer health, ethnicity, or other special-category characteristics.

Retention and Deletion

DataRetention
Unprocessed original uploads (photos received but not yet processed)Deleted within 1 day
Uploaded photos and generated try-on images (all channels)Automatically deleted within 72 hours of processing
Usage logs and request metadataUp to 12 months for billing, security, and analytics, then deleted or aggregated
Account and billing recordsLife of the account, and as long as required afterwards by tax and accounting law
Support communicationsUp to 24 months

When your account is closed, we delete or anonymise account data within 90 days, except records we must retain by law. Backups are purged on a rolling cycle not exceeding 35 days.

How We Share Your Information

We share personal information only with:

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

International Data Transfers

We operate in India and use providers in other regions. Where personal data of EEA/UK individuals is transferred outside those regions, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK Addendum.

Data Security

We use encryption in transit, encryption at rest for sensitive credentials, access controls, network isolation for our processing services, and short retention windows to limit exposure. No system is perfectly secure; we cannot guarantee absolute security.

Your Rights

Depending on where you live, you may have the right to:

EEA/UK (GDPR / UK GDPR): you have all of the rights above and the right to lodge a complaint with your supervisory authority.

California (CCPA/CPRA): you may request access, correction, and deletion, and you may request the categories and specific pieces of personal information we hold. We do not sell or share personal information as those terms are defined under the CPRA. We will not discriminate against you for exercising your rights.

To exercise any right, email shrut@amora.org.in. We may need to verify your identity. We respond within the timeframes required by applicable law.

Children's Privacy

The Services are for businesses and adults. They are not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us personal information, contact us and we will delete it.

Cookies and Analytics

Our website and dashboard use strictly necessary cookies and, subject to consent where required, analytics cookies. You can control cookies through your browser settings and, in supported regions, our consent banner.

Changes to This Policy

We will post any changes on this page and update the "Last Updated" date. Material changes will be notified by email or in-product notice before they take effect.

Contact

Amora
shrut@amora.org.in


© 2026 Amora. All rights reserved.