Legal
Privacy Policy
Effective 13 July 2026
Mira operates OnMe. OnMe is a Mira product that provides AI virtual try-on technology for online stores. This policy explains what happens to a shopper's photo, what information we handle for merchants and website visitors, and the choices available to you.
1. Who operates OnMe and when this policy applies
“Mira,” “we,” “us,” and “our” mean the operator of the OnMe product and service. “OnMe” means the virtual try-on product, website, and Shopify app. You can contact us at [email protected].
This policy applies when you use an OnMe try-on widget on a merchant's storefront, install or administer the OnMe Shopify app, visit tryonme.xyz, or contact us.
For a storefront shopper's photo and generated image, the merchant is the controller and Mira is its processor through the OnMe service. The merchant decides to offer the feature; Mira processes the image only to provide the requested try-on. Mira acts as controller for merchant account and service-administration information, direct correspondence, and the limited website information described below.
2. Information we process
| Information | Why we use it | Retention |
|---|---|---|
| Shopper photo | Generate the one try-on the shopper requests. | Deleted on the render's final outcome; 24 hours at the absolute latest. |
| Generated try-on image | Return the result privately to the shopper. | Up to 24 hours. Its private viewing link expires after about 30 minutes. |
| Short-lived rate-limit hash | Prevent automated abuse. It is derived from IP address and browser information using a secret, rotating salt; the source IP address and browser string are not stored in the app database. | 24 hours. |
| Usage events | Show merchants aggregate funnel performance and operate the service. Events use a random session identifier that is not tied to an account, IP address, or browser fingerprint. | May be retained as non-identifying analytics while the merchant uses OnMe; removed with the shop's app data. |
| Order attribution | Show a merchant aggregate revenue associated with tried-on items. | An opaque order reference, currency, and amounts are retained while the app is installed and removed with shop data. OnMe does not store the buyer's name, email, address, or customer record. |
| Merchant and shop data | Install and secure the app, mirror enabled products, save settings, provide plans, measure usage, support merchants, and meet Shopify requirements. Shopify session data can include authorized merchant or staff contact information. |
Generally for the installation and then removed through
Shopify's uninstall and shop/redact process. Limited
billing, compliance, and security records may be kept where
needed for legal obligations, disputes, or audit evidence.
|
| Messages you send us | Answer questions, provide support, and keep an appropriate record of the conversation. | For as long as reasonably needed for the request, follow-up, and legal obligations. |
| Website request metadata | Deliver and protect the public website. Cloudflare may process IP address, request time, requested URL, device or browser data, and security signals. | For the periods needed by Cloudflare and Mira to deliver, secure, and troubleshoot the site, subject to provider settings and legal requirements. |
3. How a try-on photo moves through OnMe
The shopper's device reduces the image before upload. The image travels over an encrypted connection through the merchant's Shopify storefront to OnMe's access-controlled Google Cloud environment. Google Cloud's Vertex AI Virtual Try-On processes the person image and garment image to create the result.
OnMe deletes the staged shopper photo when the render succeeds, fails permanently, expires, or is safety-blocked. A retryable processing error may keep the staged photo only long enough to retry. A separate Cloud Storage lifecycle rule deletes any remaining staged object by 24 hours as a backstop. Generated results are also subject to a 24-hour lifecycle rule. OnMe does not put image contents in application logs or backups.
4. Purposes and legal bases
- Shopper consent: the widget explains the purpose and deletion before the shopper affirmatively chooses a photo for one render.
- Contract: we process merchant and shop information needed to provide the app and its plans.
- Legitimate interests: we secure the service, prevent abuse, troubleshoot failures, answer requests, and provide non-identifying performance information without overriding individual rights.
- Legal obligations: we may keep or disclose limited records when required for billing, compliance, fraud prevention, or valid legal process.
Where consent is the basis, it can be withdrawn before upload by not selecting a photo. Once a render has completed, the source photo is normally already deleted and cannot be retrieved.
5. Who processes information
Google Cloud
OnMe uses Google Cloud Platform, including Cloud Storage, Cloud Run, Cloud SQL, and Vertex AI Virtual Try-On, to host and process the service in the United States. Google acts under the Google Cloud Data Processing Addendum.
Mira does not train models on shopper photos and does not instruct Google to do so. Google's service terms state that Google will not use Customer Data to train or fine-tune AI/ML models without the customer's prior permission or instruction. Google may process limited service data for security, abuse monitoring, reliability, and other purposes described in its applicable cloud terms; this policy does not claim that all Google service metadata has zero retention.
Shopify
Shopify provides the merchant storefront, app installation, authorization, billing, webhooks, and commerce platform. Shopify's own handling is governed by its agreements and privacy policy. OnMe never reads the storefront proxy's logged-in customer identifier.
Cloudflare
Cloudflare hosts and protects the public marketing and legal pages. It processes request and security metadata as described in the Cloudflare Privacy Policy. Cloudflare does not receive shopper try-on photos through these marketing pages.
Mira may also disclose information when required by law, to protect rights and safety, or in connection with a genuine business reorganization, with appropriate safeguards. Merchants cannot view shopper photos or generated results through the OnMe admin.
6. International transfers
OnMe's application processing currently uses Google Cloud infrastructure in the United States, and internet infrastructure providers may process request data in multiple countries. Where European, UK, or Swiss data-protection law requires a transfer mechanism, Mira relies on contractual protections made available by its processors, including applicable Standard Contractual Clauses in Google's Cloud Data Processing Addendum, together with technical and organizational safeguards.
7. What Mira and OnMe do not do
- We do not identify or recognize a shopper, create a biometric template, or perform face recognition.
- We do not use shopper photos or results to train Mira, OnMe, or third-party AI models.
- We do not sell or rent personal information or share it for cross-context behavioral advertising.
- We do not collect a shopper's name, email address, postal address, or Shopify customer profile through the try-on widget.
- We do not use advertising cookies or optional analytics cookies on the static OnMe marketing and legal pages at the effective date of this policy.
8. Security and incidents
Controls include encrypted transport, access-controlled cloud services, least-privilege service identities, short-lived signed result links, terminal-outcome deletion, storage lifecycle backstops, and monitoring for orphaned objects. No internet service can guarantee absolute security. If Mira becomes aware of a personal-data breach affecting shopper data, it will notify affected merchants without undue delay and provide information reasonably needed for their legal obligations.
9. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, withdraw consent, or complain to a data-protection authority. These rights can be subject to legal exceptions.
For a request about a storefront try-on, contact the merchant first because it is the controller. You may also email [email protected]; Mira will assist the merchant. Because photos and generated images are deleted quickly and are not tied to an identity, there is usually no image left to locate. We will not ask you to upload another sensitive photo merely to verify a request.
For merchant-account, website, or direct-correspondence requests controlled by Mira, email the same address. Mira may ask for proportionate information to verify the request.
10. Age
OnMe's shopper try-on is for people aged 16 or older and is not directed to children. By choosing a photo, a shopper confirms that they meet the age requirement and are using a photo of themselves or one they have permission to use.
11. AI-generated images
Try-on results are generated by AI. They are approximations, not photographs or measurements, and may contain errors in body details, garment details, colour, fit, size, or drape. They should not be treated as a guarantee that an item will fit or look the same in person.
For merchants
Suggested store-policy wording: “Our virtual try-on feature is powered by OnMe. If you choose to use it, your photo is processed once to create your requested try-on image. OnMe deletes its working copy when processing ends, with a 24-hour maximum storage backstop, and does not use it to identify you or train AI models. See the OnMe Privacy Policy for details.”
The Data Processing Agreement between each merchant and Mira is included in the OnMe Terms of Service.
12. Changes and contact
We may update this policy as the service or law changes. We will post the revised policy here with a new effective date and provide additional notice when a change materially affects how we process personal information.
Privacy questions and requests: [email protected].