Privacy policy
app AI Fashion Photos — last updated: 13 August 2026
1. Data controller
WEGROW, a French simplified joint-stock company with a share capital of €500, registered under SIREN 944 708 999 (head office SIRET 944 708 999 00015), registered office at 63 boulevard d’Anvers, 67000 Strasbourg, France.
For any question about personal data: contact@chloy-buff.fr
2. Data processed
AI Fashion Photos is a Shopify app that generates product photos from a product's real images. The data below is processed on behalf of the merchant who installs it.
2.1 Shop data
- The shop's .myshopify.com domain
- The access token issued by Shopify that lets the app act on the shop
- Where Shopify provides a named session: the email address, first name, last name, language and account-owner flag of the admin user. Those people are the merchant's staff.
2.2 Catalogue data
- Product and variant identifiers
- Product title, description and type
- Existing product photos, used as colour and cut references
2.3 Data produced by the app
- The generated photos, kept in our database
- The generation settings entered by the merchant: model, poses, backgrounds, complementary garments, free-form instructions
- The shop's own variant-option classification settings
2.4 Data we do not process
The app neither requests nor accesses any data about the shop's customers: no buyer identity, no orders, no payment data, no shipping address. The permissions requested from Shopify are limited to reading and writing products and files.
3. Images you upload
The app lets you supply your own images: a photograph of a model, of a garment, or any other reference you attach to a shoot. Those images remain yours, and so does the responsibility for them.
By uploading one you confirm that you hold the rights needed to use it this way and to have it reproduced in a photo generated from it. That covers the rights to the image itself — you took it, you commissioned it, or you hold a licence that allows this use — and, where a person is recognisable in it, that person’s agreement to their image being used commercially. An image found online, or bought under a licence that excludes derivative works, does not meet that condition.
We do not check where the images you supply come from, and we are not in a position to. If a third party contests an image you uploaded, or a photo generated from it, answering that claim is yours; you agree to hold WEGROW harmless from it, and we may remove the image or suspend the account while it is being settled.
4. Purpose and legal basis
This data is processed for the sole purpose of providing the subscribed service: generating product photos, showing them to the merchant and, on request, importing them into their Shopify library. The legal basis is the performance of the contract between WEGROW and the merchant, entered into when the app is installed.
5. Recipients and transfers outside the European Union
Image generation relies on a third-party provider. The following data is sent to it on every generation the merchant asks for:
| Recipient | Data sent | Country |
|---|---|---|
| OpenAI, L.L.C. | The product photos used as references, and the text of the generation instruction, which includes the product's title, description and type | United States |
| Railway Corp. | Hosting of the application and of the database | United States |
| Shopify Inc. | Hosting platform of the merchant's shop | Canada |
These transfers outside the European Union are covered by the European Commission's standard contractual clauses. No data is sold, rented or passed on for advertising.
6. Reachability of generated photos
So that Shopify can import a generated photo into the merchant's library, that photo is served by our app at an address reachable without authentication. The address contains a random, non-sequential, unguessable identifier and is given to nobody other than the merchant and Shopify. It remains public for as long as the photo exists. Merchants who need absolute confidentiality on unreleased visuals should bear that in mind.
7. Retention
- Data is kept for as long as the app remains installed on the shop.
- On uninstall, the access token and the shop's settings are deleted immediately.
- 48 hours after uninstall, Shopify notifies us and the shop's working data is erased automatically: briefs, generated photos, generation history and settings.
- Two things outlast that erasure, and only these two: the credit balance, and the record of credit movements — grants, shoots, refunds. They are kept for two reasons. The record of what was billed is accounting, which we are required to keep for ten years; and the balance carries the mark that the welcome credits were already granted, without which the same shop could claim them again on every reinstall. Both are keyed by the shop's domain alone: no name, no address, nothing about a person.
8. Security
Traffic to the app is encrypted over HTTPS. Notifications received from Shopify are authenticated by cryptographic signature and rejected when the signature is invalid. Each shop's data is partitioned and reachable only by authenticated sessions of that shop.
9. Your rights
Under the General Data Protection Regulation you have rights of access, rectification, erasure, restriction, objection and portability over your data. You can exercise them by writing to contact@chloy-buff.fr. We reply within thirty days at most.
Uninstalling the app from your Shopify admin triggers the complete erasure described in section 7, with nothing for you to do.
You also have the right to lodge a complaint with the French data protection authority (CNIL), 3 place de Fontenoy, 75007 Paris, www.cnil.fr.
10. Changes
This policy may change along with the app. The date of the last update is shown at the top of this page. Any substantial change is notified to installed merchants.