OnMe

Legal

Privacy Policy

Effective 13 July 2026

Mira operates OnMe. OnMe is a Mira product that provides AI virtual try-on technology for online stores. This policy explains what happens to a shopper's photo, what information we handle for merchants and website visitors, and the choices available to you.

The short version: a shopper's photo is used for one requested try-on. OnMe deletes its working copy when the render reaches a final outcome, usually within minutes and within 24 hours at the absolute latest. Mira does not use OnMe to identify people, perform face recognition, sell personal information, or train AI models on shopper photos.

1. Who operates OnMe and when this policy applies

“Mira,” “we,” “us,” and “our” mean the operator of the OnMe product and service. “OnMe” means the virtual try-on product, website, and Shopify app. You can contact us at [email protected].

This policy applies when you use an OnMe try-on widget on a merchant's storefront, install or administer the OnMe Shopify app, visit tryonme.xyz, or contact us.

For a storefront shopper's photo and generated image, the merchant is the controller and Mira is its processor through the OnMe service. The merchant decides to offer the feature; Mira processes the image only to provide the requested try-on. Mira acts as controller for merchant account and service-administration information, direct correspondence, and the limited website information described below.

2. Information we process

Information Why we use it Retention
Shopper photo Generate the one try-on the shopper requests. Deleted on the render's final outcome; 24 hours at the absolute latest.
Generated try-on image Return the result privately to the shopper. Up to 24 hours. Its private viewing link expires after about 30 minutes.
Short-lived rate-limit hash Prevent automated abuse. It is derived from IP address and browser information using a secret, rotating salt; the source IP address and browser string are not stored in the app database. 24 hours.
Usage events Show merchants aggregate funnel performance and operate the service. Events use a random session identifier that is not tied to an account, IP address, or browser fingerprint. May be retained as non-identifying analytics while the merchant uses OnMe; removed with the shop's app data.
Order attribution Show a merchant aggregate revenue associated with tried-on items. An opaque order reference, currency, and amounts are retained while the app is installed and removed with shop data. OnMe does not store the buyer's name, email, address, or customer record.
Merchant and shop data Install and secure the app, mirror enabled products, save settings, provide plans, measure usage, support merchants, and meet Shopify requirements. Shopify session data can include authorized merchant or staff contact information. Generally for the installation and then removed through Shopify's uninstall and shop/redact process. Limited billing, compliance, and security records may be kept where needed for legal obligations, disputes, or audit evidence.
Messages you send us Answer questions, provide support, and keep an appropriate record of the conversation. For as long as reasonably needed for the request, follow-up, and legal obligations.
Website request metadata Deliver and protect the public website. Cloudflare may process IP address, request time, requested URL, device or browser data, and security signals. For the periods needed by Cloudflare and Mira to deliver, secure, and troubleshoot the site, subject to provider settings and legal requirements.

3. How a try-on photo moves through OnMe

The shopper's device reduces the image before upload. The image travels over an encrypted connection through the merchant's Shopify storefront to OnMe's access-controlled Google Cloud environment. Google Cloud's Vertex AI Virtual Try-On processes the person image and garment image to create the result.

OnMe deletes the staged shopper photo when the render succeeds, fails permanently, expires, or is safety-blocked. A retryable processing error may keep the staged photo only long enough to retry. A separate Cloud Storage lifecycle rule deletes any remaining staged object by 24 hours as a backstop. Generated results are also subject to a 24-hour lifecycle rule. OnMe does not put image contents in application logs or backups.

4. Purposes and legal bases

Where consent is the basis, it can be withdrawn before upload by not selecting a photo. Once a render has completed, the source photo is normally already deleted and cannot be retrieved.

5. Who processes information

Google Cloud

OnMe uses Google Cloud Platform, including Cloud Storage, Cloud Run, Cloud SQL, and Vertex AI Virtual Try-On, to host and process the service in the United States. Google acts under the Google Cloud Data Processing Addendum.

Mira does not train models on shopper photos and does not instruct Google to do so. Google's service terms state that Google will not use Customer Data to train or fine-tune AI/ML models without the customer's prior permission or instruction. Google may process limited service data for security, abuse monitoring, reliability, and other purposes described in its applicable cloud terms; this policy does not claim that all Google service metadata has zero retention.

Shopify

Shopify provides the merchant storefront, app installation, authorization, billing, webhooks, and commerce platform. Shopify's own handling is governed by its agreements and privacy policy. OnMe never reads the storefront proxy's logged-in customer identifier.

Cloudflare

Cloudflare hosts and protects the public marketing and legal pages. It processes request and security metadata as described in the Cloudflare Privacy Policy. Cloudflare does not receive shopper try-on photos through these marketing pages.

Mira may also disclose information when required by law, to protect rights and safety, or in connection with a genuine business reorganization, with appropriate safeguards. Merchants cannot view shopper photos or generated results through the OnMe admin.

6. International transfers

OnMe's application processing currently uses Google Cloud infrastructure in the United States, and internet infrastructure providers may process request data in multiple countries. Where European, UK, or Swiss data-protection law requires a transfer mechanism, Mira relies on contractual protections made available by its processors, including applicable Standard Contractual Clauses in Google's Cloud Data Processing Addendum, together with technical and organizational safeguards.

7. What Mira and OnMe do not do

8. Security and incidents

Controls include encrypted transport, access-controlled cloud services, least-privilege service identities, short-lived signed result links, terminal-outcome deletion, storage lifecycle backstops, and monitoring for orphaned objects. No internet service can guarantee absolute security. If Mira becomes aware of a personal-data breach affecting shopper data, it will notify affected merchants without undue delay and provide information reasonably needed for their legal obligations.

9. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, withdraw consent, or complain to a data-protection authority. These rights can be subject to legal exceptions.

For a request about a storefront try-on, contact the merchant first because it is the controller. You may also email [email protected]; Mira will assist the merchant. Because photos and generated images are deleted quickly and are not tied to an identity, there is usually no image left to locate. We will not ask you to upload another sensitive photo merely to verify a request.

For merchant-account, website, or direct-correspondence requests controlled by Mira, email the same address. Mira may ask for proportionate information to verify the request.

10. Age

OnMe's shopper try-on is for people aged 16 or older and is not directed to children. By choosing a photo, a shopper confirms that they meet the age requirement and are using a photo of themselves or one they have permission to use.

11. AI-generated images

Try-on results are generated by AI. They are approximations, not photographs or measurements, and may contain errors in body details, garment details, colour, fit, size, or drape. They should not be treated as a guarantee that an item will fit or look the same in person.

For merchants

Suggested store-policy wording: “Our virtual try-on feature is powered by OnMe. If you choose to use it, your photo is processed once to create your requested try-on image. OnMe deletes its working copy when processing ends, with a 24-hour maximum storage backstop, and does not use it to identify you or train AI models. See the OnMe Privacy Policy for details.”

The Data Processing Agreement between each merchant and Mira is included in the OnMe Terms of Service.

12. Changes and contact

We may update this policy as the service or law changes. We will post the revised policy here with a new effective date and provide additional notice when a change materially affects how we process personal information.

Privacy questions and requests: [email protected].