Effective Date: July 31, 2026 · Last Updated: July 31, 2026
This Privacy Policy explains how Amora ("we", "us", or "our") collects, uses, and protects personal information when you use the Amora virtual try-on platform, our website, our Shopify app, and our APIs and embeddable widgets (together, the "Services").
This policy covers merchants, direct-API customers, and website visitors. If you are a shopper using an Amora try-on tool embedded on a merchant's store, our Shopper Privacy Policy applies to you instead, and the merchant — not Amora — is the controller of your personal data.
Amora provides AI virtual try-on ("VTO") software. A shopper uploads a photo of themselves and a garment image, and our systems generate an image showing the shopper wearing that garment.
Contact: shrut@amora.org.in
Account and billing information: Name, email address, business name, authentication identifiers, API keys and public tokens, plan and tier, and payment identifiers and records processed through our payment provider.
Content you provide: Product images, garment images, catalogue data, brand assets, configuration, and — for direct-API customers who upload through our tools — photos submitted for try-on generation and the try-on images generated from them.
Merchant integration data: For Shopify merchants, your shop domain, an encrypted platform access token, installed-product VTO settings, and product metadata.
Usage and technical data: Log data, request metadata, timestamps, approximate location derived from IP, device and browser information, feature usage, and error diagnostics.
Support communications: Messages you send us and their contents.
We use the information we collect to:
Legal bases (EEA/UK): performance of a contract (providing the Services); legitimate interests (security, abuse prevention, service improvement in aggregate, direct B2B communications); consent (where required, e.g. certain cookies); and compliance with legal obligations.
We do not use your content, your customers' photos, or generated images to train, fine-tune, or otherwise develop AI or machine-learning models.
Photos and generated images are used only to produce the try-on result you requested and to operate the Service — for example, transient processing, delivery, and short-term storage within the retention windows below.
We do not create face templates, faceprints, or any other biometric identifier from any photo, and we do not use facial-recognition technology to identify or verify individuals. Photos are processed only to render a garment onto the person shown in the image. We do not use photos to infer health, ethnicity, or other special-category characteristics.
| Data | Retention |
|---|---|
| Unprocessed original uploads (photos received but not yet processed) | Deleted within 1 day |
| Uploaded photos and generated try-on images (all channels) | Automatically deleted within 72 hours of processing |
| Usage logs and request metadata | Up to 12 months for billing, security, and analytics, then deleted or aggregated |
| Account and billing records | Life of the account, and as long as required afterwards by tax and accounting law |
| Support communications | Up to 24 months |
When your account is closed, we delete or anonymise account data within 90 days, except records we must retain by law. Backups are purged on a rolling cycle not exceeding 35 days.
We share personal information only with:
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
We operate in India and use providers in other regions. Where personal data of EEA/UK individuals is transferred outside those regions, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK Addendum.
We use encryption in transit, encryption at rest for sensitive credentials, access controls, network isolation for our processing services, and short retention windows to limit exposure. No system is perfectly secure; we cannot guarantee absolute security.
Depending on where you live, you may have the right to:
EEA/UK (GDPR / UK GDPR): you have all of the rights above and the right to lodge a complaint with your supervisory authority.
California (CCPA/CPRA): you may request access, correction, and deletion, and you may request the categories and specific pieces of personal information we hold. We do not sell or share personal information as those terms are defined under the CPRA. We will not discriminate against you for exercising your rights.
To exercise any right, email shrut@amora.org.in. We may need to verify your identity. We respond within the timeframes required by applicable law.
The Services are for businesses and adults. They are not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us personal information, contact us and we will delete it.
Our website and dashboard use strictly necessary cookies and, subject to consent where required, analytics cookies. You can control cookies through your browser settings and, in supported regions, our consent banner.
We will post any changes on this page and update the "Last Updated" date. Material changes will be notified by email or in-product notice before they take effect.
Amora
shrut@amora.org.in
© 2026 Amora. All rights reserved.