Legal
Privacy Policy
Last updated and effective 7 July 2026.
Last updated: 7 July 2026
Effective date: 7 July 2026
This Privacy Policy explains how yaava collects, uses, stores, shares, and protects personal data in connection with its AI-powered virtual try-on platform.
The yaava Service is operated by:
Ievgenii Solovei
Sole proprietor registered in Poland
ul. Piłsudskiego 91/1
50-019 Wrocław
Poland
NIP/VAT number: 8982302556
Email: legal@yaava.eu
Website: yaava.eu
In this Privacy Policy, “yaava”, “we”, “us”, and “our” refer to Ievgenii Solovei operating the yaava platform.
1. Scope of This Privacy Policy
This Privacy Policy applies to personal data processed through:
- the yaava website;
- the yaava Shopify application;
- the yaava merchant dashboard;
- the yaava storefront try-on widget;
- yaava analytics and conversion tracking;
- yaava customer support;
- yaava billing and subscription management;
- related APIs, integrations, and services.
This Privacy Policy covers personal data relating to:
- Merchants and their authorized users;
- Shoppers who interact with the yaava widget;
- visitors to the yaava website;
- persons who contact yaava;
- persons whose data is processed through a connected Shopify store.
2. Definitions
Merchant means a business, Shopify store owner, company, agency, developer, or other commercial user that installs, subscribes to, or uses yaava.
Shopper means an individual who interacts with the yaava virtual try-on widget on a Merchant’s Shopify store.
Shopper Photo means a photograph uploaded or captured by a Shopper for the purpose of generating a virtual try-on result.
Shopper Output means an AI-generated virtual try-on image created using a Shopper Photo.
Personal Data means information relating to an identified or identifiable individual.
Processing means any operation performed on Personal Data, including collection, storage, access, use, transmission, analysis, alteration, or deletion.
Controller means the party that determines why and how Personal Data is processed.
Processor means a party that processes Personal Data on behalf of a Controller.
3. Our Data Protection Roles
The role of yaava depends on the context in which Personal Data is processed.
3.1 Merchant account and website data
yaava generally acts as an independent Controller when processing:
- Merchant account details;
- Merchant contact information;
- subscription and billing records received by yaava;
- yaava website visitor information;
- customer support communications;
- security, fraud prevention, and operational logs;
- communications concerning yaava products and services.
3.2 Shopper data
For Personal Data processed through a Merchant’s Shopify store, including Shopper Photos, Shopper Outputs, and store conversion events:
- the Merchant generally acts as Controller;
- yaava generally acts as Processor on behalf of the Merchant.
The Merchant determines whether and how the yaava widget is made available in its store and is responsible for establishing an appropriate legal basis for processing Shopper data.
The processing relationship between yaava and the Merchant is further governed by the yaava Data Processing Agreement.
3.3 Independent processing by Shopify and payment providers
Shopify and applicable payment providers may process Personal Data as separate or independent Controllers under their own terms and privacy notices.
Where Paddle acts as Merchant of Record, Paddle independently processes billing, payment, fraud prevention, invoicing, and tax information.
4. Personal Data We Collect
4.1 Merchant account data
When a Merchant installs or uses yaava, we may collect:
- first and last name;
- business email address;
- business telephone number;
- company or trading name;
- Shopify store name;
- Shopify store domain;
- Shopify store identifier;
- Merchant account identifier;
- country and business location;
- tax or VAT information;
- subscription plan;
- subscription status;
- billing provider identifiers;
- transaction and invoice references;
- account settings;
- widget configuration;
- user roles and permissions;
- support requests and communications.
We do not receive or store complete payment card numbers. Payment card information is processed by Shopify, Paddle, or another authorized payment provider.
4.2 Shopify store data
Depending on the permissions granted to the yaava application, we may process:
- store name and domain;
- store identifier;
- store currency;
- store country and time zone;
- product information;
- product titles and descriptions;
- product and variant identifiers;
- product images;
- product categories;
- product availability;
- product pricing;
- app and widget settings;
- theme-related information required for the integration;
- order and conversion event references;
- app installation and uninstallation events.
yaava requests only the Shopify permissions reasonably necessary to provide the Service.
4.3 Shopper Photos and Shopper Outputs
When a Shopper uses the virtual try-on widget, we may process:
- the Shopper Photo uploaded or captured by the Shopper;
- the selected product or product image;
- the selected product and variant identifiers;
- technical instructions required for AI processing;
- the generated Shopper Output;
- generation status and technical error information;
- the date and time of the generation;
- a temporary generation or session identifier.
Shopper Photos and Shopper Outputs are processed to provide the requested AI virtual try-on functionality.
4.4 Shopper technical and usage data
When a Shopper interacts with the widget, we may collect:
- IP address;
- browser type;
- operating system;
- device type;
- approximate country or region derived from the IP address;
- language;
- session identifier;
- widget impression;
- widget opening;
- photo upload event;
- try-on generation event;
- product interaction;
- add-to-cart event;
- checkout event;
- purchase or conversion event;
- event timestamps;
- technical performance data;
- error and diagnostic data;
- consent status received from Shopify.
4.5 Conversion analytics data
To help Merchants understand the effect of virtual try-on functionality, yaava may process events such as:
- a Shopper viewing or opening the widget;
- a Shopper generating a try-on result;
- a Shopper viewing a product;
- a product being added to cart;
- checkout being started;
- checkout being completed;
- a purchase being attributed to a try-on session;
- product or variant identifiers;
- order value;
- currency;
- timestamp;
- pseudonymous session or event identifiers.
For standard conversion analytics, yaava does not intentionally require or collect:
- Shopper names;
- Shopper email addresses;
- Shopper telephone numbers;
- billing addresses;
- shipping addresses;
- complete payment information.
Where Shopify does not provide consent for analytics processing, yaava will not intentionally activate analytics functionality that requires such consent.
4.6 Website and communication data
When a person visits the yaava website or contacts us, we may process:
- IP address;
- browser and device information;
- cookie and consent choices;
- pages viewed;
- referral source;
- contact details;
- the content of communications;
- support tickets;
- demonstration requests;
- business enquiries;
- feedback.
5. Sources of Personal Data
We may receive Personal Data:
- directly from Merchants;
- directly from Shoppers through the try-on widget;
- from Shopify;
- from authorized Merchant team members;
- from payment and billing providers;
- from support and communication providers;
- from analytics and security services;
- automatically from browsers, devices, cookies, pixels, and similar technologies.
6. How and Why We Use Personal Data
We use Personal Data for the following purposes.
6.1 Providing the Service
We process data to:
- register and manage Merchant accounts;
- install and operate the Shopify integration;
- display the try-on widget;
- generate AI virtual try-on results;
- manage subscriptions and Credits;
- provide Merchant analytics;
- provide customer support;
- maintain account and widget settings.
For Merchant account data, the legal basis is generally the performance of a contract or steps taken before entering into a contract.
For Shopper data processed on behalf of a Merchant, yaava relies on the Merchant’s documented instructions and the legal basis selected by the Merchant.
6.2 AI virtual try-on processing
We process Shopper Photos, product images, and related technical data to generate and deliver the requested Shopper Output.
Shopper Photos are not processed for unrelated marketing, advertising, identity verification, or biometric identification.
6.3 Analytics and Service improvement
We may process usage and technical data to:
- measure widget performance;
- calculate usage and Credit consumption;
- understand how the Service is used;
- troubleshoot errors;
- improve reliability;
- improve user interfaces and workflows;
- prevent misuse;
- plan infrastructure capacity.
Where yaava acts as Controller, this processing is generally based on our legitimate interests in operating, securing, and improving the Service.
We do not use Shopper Photos, Shopper Outputs, or Merchant product images to train or fine-tune AI models.
6.4 Conversion measurement
We process conversion events to:
- attribute purchases to try-on interactions;
- provide aggregated Merchant analytics;
- calculate conversion metrics;
- evaluate product and widget performance.
Where consent is required for analytics or pixel processing, yaava relies on the applicable Shopify consent status.
6.5 Billing and subscription management
We may process billing-related information to:
- manage subscription plans;
- calculate usage;
- calculate additional Credit charges;
- verify payment status;
- provide transaction records;
- manage refunds and disputes;
- prevent payment fraud;
- satisfy tax and accounting obligations.
The applicable legal bases may include contract performance, legal obligations, and legitimate interests.
6.6 Security and abuse prevention
We may process account, device, network, log, and usage data to:
- detect unauthorized access;
- prevent fraud;
- prevent misuse of free Credits;
- enforce usage restrictions;
- investigate suspicious activity;
- protect yaava, Merchants, Shoppers, and Third-Party Providers;
- maintain the security and integrity of the Service.
This processing is based on our legitimate interests and, where applicable, legal obligations.
6.7 Legal compliance
We may process and preserve information where necessary to:
- comply with applicable law;
- respond to lawful authority requests;
- comply with tax and accounting obligations;
- respond to data protection requests;
- establish, exercise, or defend legal claims;
- enforce our Terms and Conditions.
6.8 Communications
We may use Merchant contact information to send:
- account notices;
- billing notices;
- service updates;
- security alerts;
- support responses;
- changes to legal terms;
- operational communications.
Marketing communications will be sent only where permitted by applicable law. A recipient may unsubscribe from marketing communications at any time.
7. AI Processing and fal.ai
yaava uses fal.ai as an AI infrastructure and image processing provider.
For a standard virtual try-on request, yaava may transmit to fal.ai:
- the Shopper Photo;
- the relevant Merchant product image;
- technical generation parameters;
- a temporary request identifier;
- other data required to perform the generation.
yaava does not intentionally provide Shopper names, email addresses, telephone numbers, postal addresses, or payment information to fal.ai for a standard try-on generation.
fal.ai processes the submitted data as a service provider or subprocessor for the purpose of performing the requested AI operation.
yaava configures available provider retention controls to minimize the storage of request data and media.
8. No Facial Recognition or Biometric Identification
yaava does not use Shopper Photos for:
- facial recognition;
- identity verification;
- identifying a specific individual;
- matching a person against a database;
- creating biometric templates;
- authentication;
- surveillance;
- determining sensitive personal characteristics.
A Shopper Photo may contain a person’s face or body, but yaava processes the image only to generate a visual virtual try-on result.
yaava does not intentionally infer:
- race or ethnic origin;
- health conditions;
- religious beliefs;
- political opinions;
- sexual orientation;
- other sensitive personal characteristics.
9. No AI Model Training
yaava does not use and does not authorize its AI providers to use the following data to train or fine-tune AI models:
- Shopper Photos;
- Shopper Outputs;
- Merchant product images;
- Merchant store data;
- Merchant proprietary content.
This restriction applies to both yaava-owned models and general-purpose third-party model training.
yaava may use anonymized and aggregated operational statistics that do not identify an individual to understand Service usage, improve reliability, and plan capacity.
10. Merchant Access to Shopper Data
Merchants are not provided with access to original Shopper Photos through yaava.
Merchants are not provided with functionality to:
- view Shopper Photos;
- download Shopper Photos;
- export Shopper Photos;
- retrieve Shopper Photos from the yaava dashboard;
- use Shopper Photos for advertising;
- use Shopper Photos for product pages;
- use Shopper Photos for social media;
- use Shopper Photos for user-generated content campaigns.
Merchants are also not provided with Shopper Outputs for marketing or promotional purposes.
Merchants may receive aggregated or pseudonymous analytics, including:
- number of widget impressions;
- number of try-on generations;
- number of product interactions;
- add-to-cart rates;
- checkout events;
- conversion metrics;
- Credit usage.
yaava personnel may access a Shopper Photo or Shopper Output only where technically necessary to provide the Service, investigate a specific issue, address security or abuse, or comply with law. Such access is limited to authorized personnel and is logged or otherwise controlled where reasonably possible.
11. Sharing of Personal Data
We may share Personal Data with the following categories of recipients.
11.1 AI processing providers
We share Shopper Photos, product images, and technical generation data with fal.ai or another disclosed AI provider where necessary to generate a try-on result.
11.2 Hosting and infrastructure providers
We may use providers for:
- cloud hosting;
- application hosting;
- database hosting;
- object storage;
- content delivery;
- networking;
- backups;
- security.
11.3 Shopify
We exchange information with Shopify where necessary to:
- install and authenticate the application;
- access approved store data;
- receive events and webhooks;
- operate the widget;
- manage billing where applicable;
- respond to privacy requests.
11.4 Payment providers
Shopify, Paddle, or another payment provider may process payment and billing information.
yaava normally receives limited information such as:
- transaction identifier;
- subscription status;
- plan;
- payment status;
- amount;
- currency;
- invoice reference;
- tax status.
11.5 Analytics and monitoring providers
We may use providers for:
- product analytics;
- performance monitoring;
- error tracking;
- security monitoring;
- log management.
Shopper Photos and Shopper Outputs must not be intentionally included in analytics or error-monitoring payloads.
11.6 Communication providers
We may use external providers for:
- transactional emails;
- customer support;
- service notifications;
- business communications.
11.7 Professional advisers
We may disclose information to lawyers, accountants, insurers, auditors, and other professional advisers where reasonably necessary.
11.8 Authorities and legal recipients
We may disclose Personal Data where required to:
- comply with law;
- respond to a valid legal request;
- protect legal rights;
- investigate fraud;
- prevent harm;
- establish, exercise, or defend legal claims.
11.9 Business transfers
Personal Data may be transferred as part of a merger, acquisition, reorganization, financing, sale of assets, or transfer of the yaava business.
Any recipient will be required to process Personal Data consistently with applicable data protection law.
12. Subprocessors
yaava uses subprocessors to provide parts of the Service.
The subprocessor list may include providers of:
- AI processing;
- cloud infrastructure;
- storage;
- databases;
- payment services;
- analytics;
- error monitoring;
- email delivery;
- customer support;
- security.
An up-to-date list of material subprocessors will be made available on the yaava website or provided to Merchants on request.
Where required by the applicable Data Processing Agreement, yaava will notify Merchants before adding or replacing a material subprocessor.
13. International Data Transfers
Some Third-Party Providers may process Personal Data outside Poland or the European Economic Area.
Where Personal Data is transferred to a country that is not recognized as providing an adequate level of protection, yaava uses an appropriate transfer mechanism where required, such as:
- European Commission Standard Contractual Clauses;
- an applicable adequacy decision;
- another legally permitted safeguard.
Where appropriate, we also assess supplementary technical, contractual, and organizational protections.
Merchants may contact legal@yaava.eu for additional information about applicable international transfer safeguards.
14. Data Retention
We retain Personal Data only for as long as necessary for the purposes described in this Privacy Policy or as required by law.
14.1 Shopper Photos
Shopper Photos are retained for no longer than 7 days after upload.
They may be deleted earlier where:
- the generation is completed and temporary storage is no longer required;
- the Shopper or Merchant submits a valid deletion request;
- the relevant account or session is deleted;
- retention is not technically necessary.
14.2 Shopper Outputs
Shopper Outputs are retained for no longer than 7 days after generation.
After this period, the output is deleted or placed into an automated deletion process.
14.3 AI provider request data
yaava configures available AI provider settings to minimize or disable the storage of request inputs and outputs where reasonably possible.
Temporary provider-side storage remains subject to the configured media expiration period and the applicable provider infrastructure.
14.4 Product and store data
Merchant product, integration, and configuration data is generally retained while the yaava application remains installed and the Merchant account remains active.
Following application uninstallation or account termination, such data is deleted, anonymized, or isolated within the period required by Shopify, the yaava Data Processing Agreement, and applicable law.
14.5 Shopify privacy requests
Information subject to a valid Shopify redaction request is deleted or anonymized within the period required by Shopify, unless yaava is legally required to retain it.
14.6 Merchant account data
Merchant account and contractual data may be retained:
- while the account is active;
- for the applicable limitation period after termination;
- while a payment or legal dispute remains unresolved;
- where required for tax, accounting, fraud prevention, or legal compliance.
14.7 Billing and tax records
Billing, invoice, transaction, and tax records are retained for the period required by applicable tax and accounting laws.
14.8 Security and technical logs
Security and technical logs are retained only for a limited period necessary for:
- security monitoring;
- troubleshooting;
- incident investigation;
- fraud prevention;
- legal compliance.
Logs may be retained longer where they are required for an active investigation or legal claim.
14.9 Backups
Deleted information may remain temporarily in encrypted or access-restricted backups until the applicable backup cycle expires.
Backup data is not used for ordinary business operations and is restored only where necessary for disaster recovery or security purposes.
15. Shopify Privacy Requests
yaava supports the mandatory Shopify privacy request process.
Depending on the request received from Shopify, yaava may:
- identify Personal Data relating to a Shopper;
- provide relevant Personal Data to the Merchant;
- delete or anonymize Shopper data;
- delete or anonymize store data following application uninstallation;
- retain only information that yaava is legally required to keep.
The applicable Shopify privacy request types include:
- customer data access requests;
- customer redaction requests;
- shop redaction requests.
Where a Shopper submitted a request directly to a Merchant, the Merchant may contact yaava for assistance.
16. Cookies, Pixels, and Similar Technologies
yaava may use cookies, local storage, session storage, pixels, and similar technologies.
These technologies may be used for:
- authentication;
- session management;
- security;
- saving user settings;
- usage measurement;
- analytics;
- conversion tracking;
- preventing fraud;
- maintaining widget functionality.
Strictly necessary technologies may be used where required to provide the Service.
Analytics, marketing, or other non-essential technologies are activated only where permitted by applicable law and relevant consent settings.
For Shopify storefront tracking, yaava is designed to respect Shopify Customer Privacy consent signals.
More detailed information may be provided in the yaava Cookie Policy and the Merchant’s own privacy and cookie notices.
17. Data Security
yaava uses technical and organizational measures designed to protect Personal Data against:
- unauthorized access;
- unauthorized disclosure;
- loss;
- alteration;
- destruction;
- misuse.
These measures may include:
- encryption in transit;
- access controls;
- role-based permissions;
- secure authentication;
- restricted production access;
- infrastructure monitoring;
- security logging;
- data retention controls;
- separation of Merchant data;
- secret and credential management;
- incident response procedures;
- security reviews of service providers.
No system can guarantee absolute security.
Merchants are responsible for protecting their own Shopify accounts, yaava accounts, user access, devices, passwords, and credentials.
18. Personal Data Breaches
Where yaava becomes aware of a Personal Data breach affecting data processed on behalf of a Merchant, yaava will notify the affected Merchant without undue delay where required by applicable law or the Data Processing Agreement.
Where yaava acts as Controller, yaava will notify the relevant supervisory authority and affected individuals where required by applicable law.
19. Your Data Protection Rights
Depending on the applicable law, individuals may have the right to:
- request access to their Personal Data;
- request correction of inaccurate Personal Data;
- request deletion of Personal Data;
- request restriction of processing;
- object to certain processing;
- receive Personal Data in a portable format;
- withdraw consent where processing is based on consent;
- object to direct marketing;
- lodge a complaint with a supervisory authority.
These rights are subject to legal conditions, limitations, and exceptions.
20. How Shoppers Can Exercise Their Rights
Because the Merchant generally acts as Controller for Shopper data, Shoppers should normally submit privacy requests directly to the Shopify Merchant whose store provided the yaava widget.
The Merchant may then submit the request to yaava through:
- the Shopify privacy request process;
- the yaava dashboard;
- legal@yaava.eu.
A Shopper may also contact yaava directly at legal@yaava.eu.
Where yaava acts as Processor, we may need to verify the relevant Merchant and refer the request to that Merchant before taking action.
21. How Merchants Can Exercise Their Rights
Merchant users may contact legal@yaava.eu to request:
- access to their account Personal Data;
- correction of account information;
- deletion of account information;
- restriction or objection;
- information about subprocessors;
- information about international transfers;
- assistance with Shopify privacy requests.
We may request information necessary to verify identity and authority before completing a request.
22. Right to Lodge a Complaint
Individuals in the European Economic Area have the right to lodge a complaint with a competent data protection supervisory authority.
The competent authority for yaava in Poland is the President of the Personal Data Protection Office, commonly referred to as the Polish Data Protection Authority or UODO.
We encourage individuals to contact legal@yaava.eu first so that we can attempt to resolve the concern.
23. Automated Decision-Making
yaava uses automated AI systems to generate virtual try-on images.
However, yaava does not use Shopper Photos or Shopper Outputs to make decisions that produce legal effects or similarly significant effects concerning a Shopper.
The AI-generated result is a visual approximation and does not determine:
- whether a Shopper may purchase a product;
- the price offered to a Shopper;
- eligibility for a service;
- creditworthiness;
- employment;
- insurance;
- access to essential services.
24. Children
The yaava photo upload and virtual try-on functionality is not intended for children or minors.
Shoppers must not upload photographs of persons under 18 years old.
Merchants must not knowingly configure or market the yaava widget in a way that encourages children to upload photographs.
Where yaava becomes aware that a Shopper Photo depicts a minor, yaava may delete the image and restrict the relevant processing.
25. Prohibited Content
Shoppers and Merchants must not submit:
- photographs of another person without permission;
- photographs of minors;
- explicit or intimate photographs;
- unlawful content;
- images intended for impersonation;
- identity documents;
- medical documents;
- financial information;
- passwords or credentials;
- other unnecessary sensitive information.
yaava may delete prohibited content and suspend access where necessary.
26. Sale of Personal Data
yaava does not sell Shopper Photos, Shopper Outputs, Merchant account data, or Shopper Personal Data.
yaava does not disclose Shopper Photos or Shopper Outputs for cross-context behavioral advertising.
yaava does not use Shopper Photos to build advertising profiles.
27. Third-Party Websites and Services
The yaava website and Service may contain links to Shopify, payment providers, or other third-party services.
Those third parties process Personal Data under their own privacy notices.
yaava is not responsible for the privacy practices of third-party websites or services that are not operated by yaava.
28. Merchant Responsibilities
Merchants using yaava are responsible for:
- providing Shoppers with appropriate privacy information;
- explaining that Shopper Photos are processed using AI;
- identifying yaava as a service provider where required;
- establishing an appropriate legal basis;
- obtaining consent where required;
- configuring Shopify privacy and cookie settings;
- responding to Shopper requests;
- providing yaava with lawful processing instructions;
- avoiding unnecessary collection of Shopper Personal Data;
- complying with applicable data protection and e-commerce laws.
The Merchant must not remove or obscure privacy notices displayed by the yaava widget.
29. Changes to This Privacy Policy
We may update this Privacy Policy where necessary to reflect:
- changes to the Service;
- changes to AI providers;
- changes to Shopify requirements;
- changes to subprocessors;
- changes to law;
- changes to data processing practices.
The updated version will display a revised “Last updated” date.
Where a change materially affects Merchants or Shoppers, we may provide additional notice through:
- email;
- the Merchant dashboard;
- the Shopify application;
- the yaava website;
- the yaava widget.
30. Contact Information
Questions, complaints, and privacy requests may be submitted to:
yaava
Operator: Ievgenii Solovei
Legal form: Sole proprietor registered in Poland
Address: ul. Piłsudskiego 91/1, 50-019 Wrocław, Poland
NIP/VAT number: 8982302556
Privacy and legal email: legal@yaava.eu
Website: yaava.eu