Privacy Policy

Last updated: 31 July 2026

Style Guru ("Style Guru", "we", "us") provides an AI stylist and sales concierge application for Shopify stores, available at www.styleguru.io and through the Shopify App Store, and FitCore, a 3D size-finder and AI virtual try-on application (together, the "Apps"). Style Guru is an independent software business operated from the United Kingdom. This policy explains what data we process, why, and the choices merchants and their customers have. Questions: support@styleguru.io.

Who this policy covers

  • Merchants — Shopify store owners and staff who install Style Guru.
  • Shoppers — customers of those stores who interact with the Style Guru chat widget.

For shopper data, the merchant is the data controller and Style Guru acts as a processor on the merchant's behalf.

Data we process for merchants

  • Store identity and settings: your myshopify.com domain, store name, widget configuration, plan and billing state (charges themselves are handled by Shopify — we never see payment details).
  • Catalogue and content, read via the Shopify API with your permission: products, variants, prices and stock; store policies, pages and blog articles. Used solely so the assistant recommends real, in-stock products and answers questions from your actual policies. Catalogue data is cached briefly (minutes) and not retained long-term.
  • Usage analytics: message counts and conversation events, used for plan metering and your dashboard analytics.

Data we process for shoppers

  • Chat messages — what a shopper types to the stylist, stored against an anonymous session identifier so conversations can continue across page visits.
  • Contact details shoppers choose to share — a name, email address or phone number submitted through the lead-capture or "send us a message" forms. These are shown only to the merchant of the store where they were submitted.
  • Order and profile data for logged-in customers — where a shopper is logged into the store and the merchant's plan includes personalisation, we read the customer's name, sizes and order history from Shopify at the moment of the conversation, verified through Shopify's signed App Proxy. This is read at runtime to personalise recommendations and answer the customer's own order questions; we do not build or retain a copy of order history.

FitCore: sizing and virtual try-on

FitCore is designed to work without identifying shoppers, and requests no Shopify data permissions ("scopes") — it cannot read a store's orders, customers or other store data.

  • Sizing inputs are anonymous. Height, weight, age and build are entered by the shopper to compute a size recommendation. They are linked to a random anonymous identifier in the shopper's own browser — not to a name, account, email or Shopify customer record — and recommendations are logged only in aggregate for the merchant's analytics (sizes served, confidence, escalations).
  • Email capture is consent-only. If a shopper chooses "email my size" (or to book a fitting) and ticks the consent box, the address they provide is stored with their size result, solely to send it — and shown only to the merchant of that store. Marketing use requires its own separate, explicit consent. Without consent, no email is collected.
  • Try-on photos are never stored. When a shopper uses AI virtual try-on (explicit consent checkbox each time), their photo is relayed once, over an encrypted connection, to our image-processing subprocessor FASHN AI, Inc. (fashn.ai) to generate a single preview, and is never written to our servers, databases or logs, nor used by us to train any model. The generated preview is hosted temporarily by the provider so the shopper can view it; we keep only a record that a render happened (billing and quality), never the photo. The result is a visual preview in the recommended size, not a record of the shopper.
  • Merchant data held for FitCore: the store's domain, the app's Shopify tokens, plan and billing status (charges themselves are handled by Shopify), size charts and fit settings the merchant uploads, and anonymous usage aggregates.
  • Sizes remembered in the browser. The size finder stores the anonymous identifier and any resulting sizes in the shopper's own browser (localStorage) so the size is remembered while browsing that store — including by the Style Guru assistant where both apps are installed. No advertising or cross-site tracking cookies are set.
  • GDPR requests. We honour Shopify's customer data-request, customer-redaction and shop-redaction webhooks for FitCore exactly as described under "Retention and deletion" below. Shoppers and merchants can also contact us directly at support@styleguru.io — we respond within 30 days — and may lodge a complaint with their local supervisory authority.

AI processing

Conversations are processed by Anthropic's Claude models to generate responses. Message content is sent to Anthropic PBC as our AI subprocessor under commercial API terms; Anthropic does not use this data to train its models. No shopper payment data is ever included.

Subprocessors

  • Anthropic PBC (AI responses)
  • Railway Corp. (application hosting and database)
  • Fly.io, Inc. (FitCore engine hosting)
  • FASHN (fashn.ai) (virtual try-on image processing — photos processed once, never stored)
  • Shopify Inc. (platform, APIs, billing)

Cookies and local storage

The widget stores an anonymous session identifier in the shopper's browser local storage so a conversation can resume. We set no advertising or cross-site tracking cookies.

Retention and deletion

  • Uninstalling Style Guru deletes the store's data from our systems, including conversations, captured leads and messages.
  • We honour Shopify's GDPR webhooks automatically: customer data requests are surfaced to the merchant, customer redaction requests delete that customer's captured details, and shop redaction requests erase all remaining store data.
  • Shoppers can ask the merchant to access or delete their data at any time; merchants can contact us at support@styleguru.io for help with any request.

Security

Data is encrypted in transit (TLS) and at rest, storefront requests are verified against Shopify's cryptographic signatures, and access to production systems is restricted. We store the minimum we need to run the service.

International transfers

Our infrastructure and subprocessors may process data in the United Kingdom, the European Union and the United States, under appropriate safeguards including standard contractual clauses offered by our subprocessors.

Changes and contact

We'll update this page when our practices change and revise the date above. Contact: support@styleguru.io.