SECURITY, PRIVACY, AND RESPONSIBLE AI
Security & Trust Center
Trust starts with clear boundaries. WardrobeIt is designed to help ecommerce merchants deliver guided shopping experiences without giving up control of their products, customer experience, store information, or commercial decisions.
Trust at a Glance
Merchant-Controlled Information
Merchants remain responsible for the products, policies, knowledge, integrations, and shopper experiences connected with their WardrobeIt account.
Catalog-Only Product Guidance
WardrobeIt is designed to recommend products from the merchant’s connected and approved catalog rather than introducing unrelated marketplace or competitor products.
Privacy-Aware Virtual Try-On
Virtual Try-On requires clear shopper information and consent before image processing. It provides an artificial visual preview, not a fit or sizing guarantee.
Transparent Service Providers
WardrobeIt publishes information about approved subprocessors, their processing purposes, applicable data categories, and available safeguards.
Safeguards Designed Around Ecommerce Operations
WardrobeIt uses administrative, technical, and organizational safeguards intended to protect merchant accounts, store information, shopper interactions, Virtual Try-On processing, and the systems used to provide the Services.
Security is an ongoing operating responsibility. Controls are reviewed and developed as the platform, infrastructure, integrations, and risk environment change.
Access Control
Access to WardrobeIt systems and data should be limited according to role, operational need, and approved responsibilities.
Controls may include:
- Account authentication
- Role-based access restrictions
- Internal access approval
- Credential protection
- Access logging
- Periodic access review
- Removal of access when no longer required
- Separation between merchant workspaces
Merchants are responsible for protecting their account credentials, limiting Authorized User access, and reporting suspected unauthorized activity.
Data Protection
WardrobeIt is designed to protect data during transmission and within the systems used to deliver the Services.
Safeguards may include:
- Secure data transmission
- Protected infrastructure
- Restricted storage access
- Credential masking where implemented
- Data minimization
- Environment separation
- Logging and monitoring
- Controlled backup and recovery processes
- Retention and deletion procedures
No online platform can guarantee complete security. WardrobeIt continually evaluates risks and updates appropriate safeguards.
Application and Infrastructure Security
WardrobeIt’s application and infrastructure practices are designed to reduce unauthorized access, harmful activity, data exposure, and service disruption.
Relevant practices may include:
- Secure development reviews
- Dependency and vulnerability management
- Configuration review
- Environment access restrictions
- Error and performance monitoring
- Security-event investigation
- Change-management procedures
- Backup and restoration testing
- Abuse-prevention controls
Only controls that are actively implemented and verified should be displayed as current.
Security Monitoring
WardrobeIt may collect technical logs and security events needed to:
- Detect suspicious activity
- Investigate errors
- Protect merchant workspaces
- Prevent unauthorized access
- Diagnose integration failures
- Identify excessive or abusive use
- Support incident response
- Maintain service reliability
Logs should not intentionally contain complete passwords, payment-card details, merchant access tokens, or unnecessary shopper content.
What WardrobeIt Processes
The information processed depends on the merchant’s configuration, connected store, enabled features, shopper activity, and applicable plan.
Data Category | Examples | Primary Purpose |
|---|---|---|
Merchant account information | Business name, business email, account role, workspace details | Account administration and support |
Store and catalog information | Products, collections, variants, images, prices, tags, attributes, synchronized availability | Product discovery and recommendation |
Merchant Knowledge | Store policies, sizing guidance, care information, shipping, returns, approved answers | Product and Store Q&A |
Shopper interaction information | Questions, product interests, conversation context, product selections | Providing the requested shopping experience |
Commerce events | Product clicks, variant selections, cart actions, supported order outcomes | Service operation and merchant analytics |
Virtual Try-On information | Submitted image, generated preview, product selection, consent and processing events | Generating the requested visual preview |
Technical information | Device, browser, session, logs, errors, security signals | Security, performance, and troubleshooting |
Support information | Support messages, issue details, safe screenshots, store references | Merchant support and issue resolution |
The Privacy Policy provides additional information about WardrobeIt’s collection and processing of personal information.
What WardrobeIt Does Not Need
Merchants and shoppers should not provide WardrobeIt with information that is not required for the requested Service.
Do not submit:
- Ecommerce-platform passwords through email or support messages
- Complete payment-card information
- Authentication secrets
- Government identification documents
- Medical records
- Unnecessary sensitive personal information
- Images of children for Virtual Try-On
- Private customer information unrelated to the issue being resolved
WardrobeIt does not need complete shopper payment-card details to provide product discovery, recommendations, Product Q&A, Virtual Try-On, or supported Add-to-Cart actions.
The merchant’s ecommerce platform and payment providers remain responsible for checkout and payment processing.
WardrobeIt Supports the Shopping Journey Without Replacing the Merchant’s Commerce System
WardrobeIt connects merchant-approved product information with shopper conversations and supported commerce actions.
The merchant’s ecommerce platform remains the final authority for products, valid variants, prices, availability, discounts, cart contents, checkout, payment, tax, shipping, fulfillment, returns, and refunds.
Core Data Flow
Merchant Ecommerce Store
Provides supported product, variant, pricing, image, availability, and store information.
↓
WardrobeIt Commerce Intelligence Layer
Processes shopper intent, retrieves eligible merchant products, uses approved Merchant Knowledge, and supports available shopping actions.
↓
Shopper Experience
Provides product discovery, recommendations, comparison, Product Q&A, Complete the Look, eligible Virtual Try-On, and supported cart actions.
↓
Merchant Commerce Platform
Validates the product, variant, price, availability, cart, and checkout outcome.
Shopify Connection Boundary
WardrobeIt’s current commerce focus is Shopify.
The Shopify connection should use only the permissions required for the implemented store connection and catalog synchronization.
Merchants should:
- Connect only stores they are authorized to manage
- Review the requested permissions
- Protect Shopify credentials and tokens
- Use only WardrobeIt’s approved connection fields
- Verify synchronized products and variants
- Test cart actions before publication
- Remove access when the connection is no longer required
WooCommerce, custom ecommerce, and other integrations should be presented according to their actual released status.
Merchant-Controlled Storefront Publication
WardrobeIt should not publish or replace a merchant’s live theme without merchant approval.
The merchant remains responsible for:
- Approving installation
- Selecting the relevant theme or environment
- Reviewing the storefront experience
- Testing desktop and mobile behavior
- Confirming product and cart accuracy
- Approving shopper-facing messages
- Publishing or disabling the widget
AI That Operates Within Merchant-Approved Boundaries
WardrobeIt is designed to guide shoppers using the connected merchant catalog, available product information, Merchant Knowledge, and supported configuration.
It should not invent products, policies, discounts, variants, prices, availability, delivery promises, product claims, or return terms.
Catalog-Only Recommendations
WardrobeIt is designed to recommend eligible products from the connected merchant catalog.
Recommendation quality depends on:
- Catalog completeness
- Product descriptions
- Product attributes
- Variant structure
- Product images
- Merchant Knowledge
- Synchronization health
- Shopper-provided context
The merchant should regularly review representative recommendations and correct inaccurate source data.
Merchant-Approved Knowledge
Product and Store Q&A should use:
- Synchronized product information
- Approved store policies
- Approved sizing guidance
- Approved fit notes
- Approved materials and care information
- Approved shipping and return information
- Approved brand claims
When WardrobeIt cannot confirm an answer, it should ask for clarification, explain the limitation, or provide an approved merchant support route.
Restricted Actions
WardrobeIt should not independently:
- Change merchant prices
- Create unauthorized discounts
- Modify inventory
- Publish storefront changes
- Alter return policies
- Guarantee delivery dates
- Guarantee product fit
- Complete payment
- Accept an order
- Override the merchant’s checkout
- Make high-impact decisions about individuals
Future automated or offer-related capabilities should remain clearly labelled until implemented, approved, and deliberately enabled by the merchant.
Virtual Try-On Safeguards
Virtual Try-On is available only for technically eligible products, categories, plans, and configurations.
WardrobeIt’s Virtual Try-On experience should:
- Display appropriate shopper instructions
- Request consent before image processing
- Use the image for the requested try-on purpose
- Clearly identify the result as an artificial preview
- Exclude unsupported products
- Provide an image-deletion route
- Avoid biometric identification
- Avoid sensitive-trait inference
- Avoid use involving children
Virtual Try-On does not guarantee exact sizing, fit, colour, proportions, fabric movement, or real-world appearance.
Review the Virtual Try-On and Image Privacy Policy for detailed information.
Data Minimization
WardrobeIt aims to process only the information reasonably needed to:
- Provide the requested Service
- Operate merchant integrations
- Support shoppers
- Protect accounts and systems
- Troubleshoot technical issues
- Measure supported usage and outcomes
- Meet legal obligations
Merchants should avoid uploading unnecessary customer information or sensitive data.
Purpose-Limited Processing
Merchant and shopper information should be used only for the purposes described in:
- The applicable agreement
- The Privacy Policy
- The Data Processing Addendum
- Merchant instructions
- Shopper consent notices
- Feature-specific policies
Shopper information should not be repurposed for unrelated advertising, data brokerage, or unauthorized profiling.
Retention
Different categories of information may require different retention periods.
Retention depends on:
- The purpose of processing
- Merchant instructions
- Account status
- Feature configuration
- Security requirements
- Contractual obligations
- Applicable law
- Valid deletion requests
WardrobeIt should not retain personal information indefinitely without a defined business, security, contractual, or legal reason.
Virtual Try-On images are subject to the additional retention information described in the image privacy policy.
Data Deletion and Privacy Requests
Depending on the applicable law and relationship, individuals may be able to request:
- Access
- Correction
- Deletion
- Restriction
- Objection
- Portability
- Consent withdrawal
- Information about processing
WardrobeIt may need to verify the requester and identify the applicable merchant, account, store, session, or data category before completing a request.
Submit a request
Open the Data and Privacy Request Form
Subprocessors
WardrobeIt may use approved providers for infrastructure, hosting, AI processing, image processing, communications, monitoring, support, and other operational services.
WardrobeIt’s Subprocessor Notice explains:
- Provider name
- Service purpose
- Data categories
- Processing location
- Applicable safeguards
- Change-notification process
- Eligible merchant objection process
Review WardrobeIt Subprocessors
International Processing
WardrobeIt and approved service providers may process information in more than one country.
Where legally required, applicable transfer protections may include contractual safeguards, adequacy mechanisms, transfer assessments, or other recognized protections.
Additional information may be provided in the Privacy Policy, Data Processing Addendum, or Subprocessor Notice.
Designed to Support Stable Merchant and Shopper Experiences
WardrobeIt monitors relevant service components to identify operational problems, integration failures, security events, and customer-impacting incidents.
Reliability practices may include:
- Service monitoring
- Error detection
- Integration-health checks
- Catalog-sync monitoring
- Incident triage
- Controlled recovery procedures
- Backup processes
- Merchant communication
- Post-incident review
WardrobeIt does not publish a guaranteed uptime percentage unless that commitment is included in an approved Service Level Agreement.
Incident Response
When WardrobeIt becomes aware of a suspected security or availability incident, the response process may include:
Identify and Triage
Confirm the issue, affected service, potential data involved, and likely impact.
Contain
Restrict unauthorized access, isolate affected systems, pause relevant processing, or disable a feature where necessary.
Investigate
Review technical logs, system activity, provider information, and other available evidence.
Recover
Restore affected services safely and validate normal operation.
Communicate
Notify affected merchants, users, regulators, or other parties when contractually or legally required.
Improve
Review the incident and apply appropriate technical, procedural, or operational improvements.
Reporting a Security Concern
Do not publicly disclose sensitive technical details before WardrobeIt has had a reasonable opportunity to investigate.
Include:
- A clear description of the concern
- The affected page or service
- Steps to reproduce the issue
- Date and time observed
- Potential impact
- Safe supporting evidence
- Your contact information
Do not include passwords, complete access tokens, payment-card details, or unnecessary personal information.
Security contact
hi@wardrobeit.com
System Status
A public status destination should display:
- Current platform availability
- Merchant Portal availability
- Catalog synchronization health
- Storefront assistant availability
- Virtual Try-On availability
- Active incidents
- Scheduled maintenance
- Incident history
The View System Status link should be activated only after WardrobeIt’s public production monitoring is live and stable. The approved architecture identifies the public status service as a post-launch operational destination.
Documentation for Merchant Reviews
WardrobeIt provides trust and legal documentation intended to support merchant security, privacy, legal, and procurement evaluations.
Depending on the relationship and request, available materials may include:
- Privacy documentation
- Data Processing Addendum
- Subprocessor information
- Virtual Try-On privacy information
- Data-retention information
- Security questionnaire responses
- Architecture information
- Incident-response overview
- Integration data-flow information
- Acceptable Use Policy
- Accessibility information
Access to confidential security information may require identity verification, an active commercial evaluation, and an appropriate confidentiality agreement.
Data Processing Addendum
WardrobeIt’s Data Processing Addendum is intended to define the parties’ responsibilities where WardrobeIt processes personal data on behalf of a merchant.
It may address:
- Processing roles
- Merchant instructions
- Confidentiality
- Security
- Subprocessors
- International transfers
- Privacy-rights assistance
- Security incidents
- Data deletion
- Audit and assurance information
Review or Request the Data Processing Addendum
Certifications and Independent Assurance
WardrobeIt does not display a certification, audit report, compliance badge, penetration-test claim, or legal-compliance statement unless it has been formally completed, reviewed, and approved for publication.
The absence of a badge should not be replaced with language that implies certification.
Current assurance information can be requested from:
hi@wardrobeit.com
Merchant Compliance Responsibilities
WardrobeIt provides technology and documentation that can support a merchant’s compliance program. It does not replace the merchant’s legal, security, privacy, accessibility, or consumer-protection responsibilities.
Merchants remain responsible for:
- Configuring WardrobeIt appropriately
- Providing accurate privacy notices
- Establishing a lawful processing basis
- Obtaining consent where required
- Reviewing Merchant Knowledge
- Testing shopper-facing responses
- Maintaining accurate product information
- Managing access permissions
- Responding to customer requests
- Meeting applicable ecommerce obligations
Review WardrobeIt Policies and Operational Information
Privacy Policy
Explains how WardrobeIt collects, uses, shares, retains, and protects personal information.
Terms of Service
Defines the commercial, account, platform, acceptable-use, intellectual-property, liability, and termination terms governing WardrobeIt.
Cookie Policy
Explains cookies, similar technologies, purposes, providers, durations, and available controls.
Data Processing Addendum
Provides contractual data-processing terms for eligible merchant relationships.
Review the Data Processing Addendum
Virtual Try-On and Image Privacy
Explains shopper consent, image processing, use, retention, deletion, AI limitations, and prohibited image uses.
Review Virtual Try-On and Image Privacy
Subprocessors
Lists approved third-party providers supporting WardrobeIt and explains applicable processing purposes and change notifications.
Acceptable Use Policy
Defines prohibited platform activity, harmful content, unauthorized access, abuse, scraping, circumvention, and enforcement.
Review the Acceptable Use Policy
Accessibility Statement
Explains WardrobeIt’s accessibility commitment, design practices, known limitations, testing approach, and feedback route.
Review the Accessibility Statement
Data and Privacy Requests
Provides a route for eligible access, correction, deletion, restriction, objection, portability, and consent-withdrawal requests.
Security and Guardrails
Explains the product controls that help keep shopper guidance grounded in merchant-approved products and information.
Explore Security and Guardrails
What does the WardrobeIt Security and Trust Center cover?
The Trust Center brings together WardrobeIt’s security approach, data boundaries, privacy practices, responsible AI safeguards, Virtual Try-On protections, subprocessors, reliability processes, incident reporting, legal documentation, and procurement information.
How does WardrobeIt protect merchant data?
WardrobeIt uses administrative, technical, and organizational safeguards intended to restrict unauthorized access, protect data transmission and storage, monitor relevant events, manage service providers, and support incident response.
The exact safeguards applied depend on the Service, data involved, infrastructure, and current implementation.
What shopper data does WardrobeIt process?
Depending on the enabled features, WardrobeIt may process shopper questions, conversation context, product interests, product selections, session information, technical events, cart activity, supported outcome events, and images submitted for eligible Virtual Try-On experiences.
The Privacy Policy and Virtual Try-On and Image Privacy Policy provide additional details.
Does WardrobeIt receive shopper payment-card information?
WardrobeIt does not need complete shopper payment-card details to provide product discovery, recommendations, Product Q&A, Virtual Try-On, or supported Add-to-Cart actions.
Payment and checkout remain within the merchant’s ecommerce and payment environment.
Can users request deletion of WardrobeIt data?
Eligible individuals may request deletion or exercise other applicable privacy rights through the WardrobeIt privacy-request process.
WardrobeIt may need to verify the requester and coordinate with the applicable merchant before completing the request.
Is WardrobeIt GDPR compliant?
WardrobeIt is designed to support merchants with privacy documentation, processor terms, data-subject request assistance, subprocessor transparency, security safeguards, and feature-specific notices.
GDPR compliance depends on the applicable processing activity, configuration, legal roles, merchant practices, and contractual arrangements. WardrobeIt does not rely on an unsupported blanket compliance claim.
How long does WardrobeIt retain information?
Retention depends on the data category, processing purpose, merchant instructions, account status, security needs, contractual requirements, and applicable law.
Feature-specific retention information is provided in the applicable privacy documentation.
Does WardrobeIt use shopper images for facial recognition?
WardrobeIt Virtual Try-On is not intended to identify or authenticate shoppers, create biometric identity profiles, or track individuals across unrelated stores.
Review the Virtual Try-On and Image Privacy Policy for the complete image-processing boundaries.
Does WardrobeIt use merchant or shopper data to train general-purpose AI models?
Merchant or shopper data should not be used to train general-purpose AI models for unrelated purposes without the required contractual authority, disclosure, and separate permission where applicable.
Production provider agreements and actual technical configurations must support this commitment.
Who should I contact about security or privacy?
Contact WardrobeIt at:
hi@wardrobeit.com
Include enough information to identify the applicable merchant, store, service, or issue, but do not send passwords, complete access tokens, payment details, or unnecessary personal information.
Have a Security, Privacy, or Procurement Question?
Contact WardrobeIt for:
- Security questions
- Privacy questions
- Subprocessor information
- Data Processing Addendum requests
- Procurement documentation
- Responsible disclosure
- Data-retention questions
- Virtual Try-On privacy questions
- Privacy-rights assistance
Contact Security and Privacy
hi@wardrobeit.com