Privacy Policy

VCenter Live  ·  Last updated: 1 September 2026

Também disponível em português.

VCenter Live provides an AI outfit-building application for Shopify merchants, together with the storefront experience it powers. This policy explains what personal data we process, why, who we share it with, and the rights available to the people it concerns.

1. Who we are, and in which role

VCenter Live is contactable at [email protected]. We act in two distinct roles, and it matters which one applies:

2. What we process

2.1 Merchant store customers (we act as processor)

When a merchant installs our app, Shopify grants us access to a limited set of their customers' data. We process only the following:

DataWhy we need it
First and last nameTo identify the signed-in customer in the storefront experience and address them by name.
Email addressTo link an order to the customer's account, and to send restock alerts the customer explicitly asked for.
Shopify customer IDThe stable key that lets a customer see their own looks and orders after signing in. An email address can change; this cannot.
Order detailsOrder number, totals, currency, line items, and financial and fulfilment status — so the merchant can see which outfits led to sales.

What we deliberately do not process. We do not request, receive or store telephone numbers, shipping or billing addresses, or any payment or card data. Payment is handled entirely by Shopify Checkout and never passes through our systems.

2.2 Shoppers with a VCenter Live account (we act as controller)

2.3 Merchants and their staff (we act as controller)

Name, business email address, role within the store, and authentication credentials, for the purpose of operating the backoffice and supporting the account.

3. Purposes and legal bases

We use personal data only for the purposes set out above. We do not use it to train machine-learning models, we do not use it for advertising, and we do not use it for automated decisions producing legal or similarly significant effects.

4. We do not sell personal data

We do not sell personal data, and we do not share it for cross-context behavioural advertising. There is consequently nothing to opt out of in that respect. Where a customer records a consent or opt-out preference with the merchant, we honour it.

5. Subprocessors

We use the following subprocessors. Each is bound by a data processing agreement, and the table states honestly what each one actually receives:

SubprocessorPurposeLocationReceives personal data?
Amazon Web ServicesHosting, database, encrypted backupsEU (eu-west-3, Paris)Yes — all of the above
CloudflareDNS, TLS termination, CDNGlobal edgeTraffic metadata in transit
Microsoft (Graph / 365)Transactional email deliveryEUName and email address
OpenRouterLanguage model inferenceUSNo — product and catalogue text only
GroqLanguage model inferenceUSNo — product and catalogue text only
Jina AIText embeddings for product searchEU / USNo — product and catalogue text only
FASHNVirtual try-on renderingUSNo — product and model imagery only
fal.aiImage background and upscalingUSNo — product and model imagery only

The AI providers listed above receive product photography and catalogue text. They do not receive customer names, email addresses, order data or any other personal data.

6. International transfers

Personal data is hosted within the European Economic Area (AWS eu-west-3, Paris). Where a subprocessor processes data outside the EEA, the transfer relies on the European Commission's Standard Contractual Clauses together with supplementary technical measures, principally encryption in transit and at rest.

7. Retention

We keep personal data only as long as it serves the purpose it was collected for. In practice:

DataRetention
Store customer data (name, email, customer ID)For as long as the app is installed. Erased on an erasure request, and in full within 48 hours of uninstall.
OrdersAnonymised — not deleted — on an erasure request: the record of a sale belongs to the merchant and outlives the customer account. The personal data attached to it is removed. All order records are erased on uninstall.
Shopper accounts and profilesErased within 30 days of a deletion request, or immediately on a Shopify erasure request.
Merchant backoffice accountsDisabled as soon as the store is gone, and permanently deleted 30 days later.
Social media tokensDeleted immediately when consent is withdrawn.
Encrypted backupsDatabase backups expire after 365 days; disk snapshots after 7 days. An erasure request is applied to live systems immediately; residual copies in backups age out on this schedule.

8. Erasure and data requests through Shopify

We implement Shopify's three mandatory privacy webhooks, and every one of them verifies Shopify's cryptographic signature before any record is touched:

9. Your rights

Under the GDPR you have the right of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent at any time without affecting the lawfulness of prior processing.

If you are a customer of a store that uses VCenter Live, please address your request to that merchant: they are the controller of your data, and we will act on their instruction. You may also write to us at [email protected] and we will route it to them. If you hold an account directly with us, contact us at the same address.

You also have the right to lodge a complaint with your supervisory authority — in Portugal, the CNPD (Comissão Nacional de Protecção de Dados).

10. Security

11. Cookies

We use cookies that are strictly necessary for the service to function (session, segment preference), and analytics cookies to understand how the storefront is used. Non-essential cookies are set only with consent.

12. Changes to this policy

We may update this policy. The current version is always available at this address, and we will notify merchants of material changes by email or through the backoffice.

13. Contact

For any privacy question, or to exercise a right described above: [email protected]