Também disponível em português.
VCenter Live provides an AI outfit-building application for Shopify merchants, together with the storefront experience it powers. This policy explains what personal data we process, why, who we share it with, and the rights available to the people it concerns.
VCenter Live is contactable at [email protected]. We act in two distinct roles, and it matters which one applies:
When a merchant installs our app, Shopify grants us access to a limited set of their customers' data. We process only the following:
| Data | Why we need it |
|---|---|
| First and last name | To identify the signed-in customer in the storefront experience and address them by name. |
| Email address | To link an order to the customer's account, and to send restock alerts the customer explicitly asked for. |
| Shopify customer ID | The stable key that lets a customer see their own looks and orders after signing in. An email address can change; this cannot. |
| Order details | Order number, totals, currency, line items, and financial and fulfilment status — so the merchant can see which outfits led to sales. |
What we deliberately do not process. We do not request, receive or store telephone numbers, shipping or billing addresses, or any payment or card data. Payment is handled entirely by Shopify Checkout and never passes through our systems.
Name, business email address, role within the store, and authentication credentials, for the purpose of operating the backoffice and supporting the account.
We use personal data only for the purposes set out above. We do not use it to train machine-learning models, we do not use it for advertising, and we do not use it for automated decisions producing legal or similarly significant effects.
We do not sell personal data, and we do not share it for cross-context behavioural advertising. There is consequently nothing to opt out of in that respect. Where a customer records a consent or opt-out preference with the merchant, we honour it.
We use the following subprocessors. Each is bound by a data processing agreement, and the table states honestly what each one actually receives:
| Subprocessor | Purpose | Location | Receives personal data? |
|---|---|---|---|
| Amazon Web Services | Hosting, database, encrypted backups | EU (eu-west-3, Paris) | Yes — all of the above |
| Cloudflare | DNS, TLS termination, CDN | Global edge | Traffic metadata in transit |
| Microsoft (Graph / 365) | Transactional email delivery | EU | Name and email address |
| OpenRouter | Language model inference | US | No — product and catalogue text only |
| Groq | Language model inference | US | No — product and catalogue text only |
| Jina AI | Text embeddings for product search | EU / US | No — product and catalogue text only |
| FASHN | Virtual try-on rendering | US | No — product and model imagery only |
| fal.ai | Image background and upscaling | US | No — product and model imagery only |
The AI providers listed above receive product photography and catalogue text. They do not receive customer names, email addresses, order data or any other personal data.
Personal data is hosted within the European Economic Area (AWS eu-west-3, Paris). Where a subprocessor processes data outside the EEA, the transfer relies on the European Commission's Standard Contractual Clauses together with supplementary technical measures, principally encryption in transit and at rest.
We keep personal data only as long as it serves the purpose it was collected for. In practice:
| Data | Retention |
|---|---|
| Store customer data (name, email, customer ID) | For as long as the app is installed. Erased on an erasure request, and in full within 48 hours of uninstall. |
| Orders | Anonymised — not deleted — on an erasure request: the record of a sale belongs to the merchant and outlives the customer account. The personal data attached to it is removed. All order records are erased on uninstall. |
| Shopper accounts and profiles | Erased within 30 days of a deletion request, or immediately on a Shopify erasure request. |
| Merchant backoffice accounts | Disabled as soon as the store is gone, and permanently deleted 30 days later. |
| Social media tokens | Deleted immediately when consent is withdrawn. |
| Encrypted backups | Database backups expire after 365 days; disk snapshots after 7 days. An erasure request is applied to live systems immediately; residual copies in backups age out on this schedule. |
We implement Shopify's three mandatory privacy webhooks, and every one of them verifies Shopify's cryptographic signature before any record is touched:
Under the GDPR you have the right of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent at any time without affecting the lawfulness of prior processing.
If you are a customer of a store that uses VCenter Live, please address your request to that merchant: they are the controller of your data, and we will act on their instruction. You may also write to us at [email protected] and we will route it to them. If you hold an account directly with us, contact us at the same address.
You also have the right to lodge a complaint with your supervisory authority — in Portugal, the CNPD (Comissão Nacional de Protecção de Dados).
We use cookies that are strictly necessary for the service to function (session, segment preference), and analytics cookies to understand how the storefront is used. Non-essential cookies are set only with consent.
We may update this policy. The current version is always available at this address, and we will notify merchants of material changes by email or through the backoffice.
For any privacy question, or to exercise a right described above: [email protected]