Vitrine

Privacy Notice

Last updated: 22 July 2026

This notice explains how Vitrine handles data in two situations: (1) when a merchant installs and uses our Shopify or Etsy app, and (2) when we contact businesses about our service.

Who we are

Vitrine is operated by Online Commercial Systems LLC, 3400 Cottage Way, Sacramento, CA 95825, USA (“we”, “us”). Contact: hello@vitrine-ai.com.

The Shopify app — what we access and store

When you install the Vitrine app, we access your store through Shopify’s API using the permissions you approve (read and write products). We store: your store domain, the access token Shopify issues (a credential, kept only to call the API on your behalf), and the product data and images you choose to generate on-model imagery for. We do not access, request, or store your customers’ personal data, orders, or payment information.

How we use it

Solely to provide the service: reading a selected product’s image, generating an AI on-model image, and — only when you click “Push to store” — writing that image (and an AI-disclosure line) back to that product. Generated images are processed by our AI provider (Google) to render the result.

We do not train AI on your images

We do not use your product images, your generated images, or your store data to train, fine-tune or improve any AI model — ours or anyone else’s. Your images are sent to our AI provider (Google) only to render your result, through Google’s paid API, which under Google’s terms does not use your content to train its models. Your images stay yours.

We do not sell or share your data

We do not sell your personal data or your store’s data, and we do not share it for cross-context behavioural advertising or any purpose beyond running the Service. We disclose it only to the sub-processors listed below, under contracts that limit them to that purpose. We also do not use your data for automated decisions that produce legal or similarly significant effects about anyone.

Retention & deletion

We keep your token and generated images only while the app is installed. When you uninstall, we delete your access token immediately, and we honour Shopify’s shop/redact request (~48 hours after uninstall) to purge remaining data. You can also email us to delete your data at any time.

Privacy requests & Shopify’s data webhooks

Although we do not store your customers’ personal data, our app is registered for Shopify’s mandatory privacy webhooks. If a shopper asks a merchant to see or delete their data, Shopify sends us a customers/data_request or customers/redact message; because we hold no shopper data, we confirm there is nothing to return or erase. When you uninstall, Shopify sends shop/redact (~48 hours later) and we delete any remaining store data. We action these requests within 30 days, except where the law requires us to retain something.

The Etsy app — what we access and store

When you connect your Etsy shop, you authorise Vitrine through Etsy’s Open API using the permissions you approve (read and edit your listings). We access your active listings and their images, and we store your Etsy shop ID and the OAuth tokens Etsy issues (credentials, kept only to call the API on your behalf). We do not access, request, or store your buyers’ personal data, orders, or payment information. With your explicit per-listing approval, we add a generated on-model image to a secondary image slot on your own listing and append an AI-disclosure line to its description; we never change your primary image or your price. Your Etsy data is used solely to produce and return your own on-model images — it is not sold, shared with unrelated third parties, or repurposed.

Disconnecting the Etsy app

You can disconnect Vitrine at any time from within the app — which immediately purges your stored Etsy tokens and cached data — or by revoking access in your Etsy account settings. Because Etsy does not provide an uninstall webhook, disconnecting in-app is how you trigger deletion; you may also email us to delete your data. The term “Etsy” is a trademark of Etsy, Inc. Vitrine uses the Etsy API but is not endorsed or certified by Etsy, Inc.

Where your data is processed

Vitrine is operated from the United States, and the app data described above is processed and stored on servers in the United States. Our AI provider (Google) may process image data in the United States and other regions where it operates. If you or your store are in the UK or EEA, these transfers rely on an appropriate safeguard — the EU Standard Contractual Clauses (and UK Addendum) — as described in our Data Processing Addendum.

Security

Access tokens are held on access-controlled infrastructure and used only server-side to call Shopify on your behalf. We never expose your token to the browser or third parties.

Data breaches

We maintain safeguards to protect your data. If a breach affecting your personal data occurs, we will notify you and any affected merchant without undue delay, and cooperate as applicable law requires.

Sub-processors

We use a short list of vendors, each processing data only to provide its part of the Service: Railway (hosting, USA) — railway.com/legal/privacy; Google (Gemini AI image generation) — policies.google.com/privacy; Resend (transactional email) — resend.com/legal/privacy-policy. We give notice before adding or changing a sub-processor that handles your data.

Cookies in the app

Inside Shopify admin, the Vitrine app uses only strictly necessary session cookies/tokens to keep you signed in and secure while you use it. It sets no advertising or cross-site tracking cookies.

California privacy rights

If you are a California resident, the CCPA/CPRA gives you the right to know what personal information we hold about you, to request its deletion or correction, and to opt out of any “sale” or “sharing” of it. We do not sell or share personal information, so there is nothing to opt out of, and we will not discriminate against you for exercising these rights. To make a request, email hello@vitrine-ai.com; we may need to verify your identity before we act, and you may use an authorised agent.

Children

Vitrine is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16 (or under 13 in the United States). If you believe a child has provided us data, contact us and we will delete it.


The section below covers our business-to-business outreach (before you are a customer), not the app.

What data we process

Limited business contact data: a work email address, and where available a first/last name, job title and company name. We do not seek or process special-category data.

Where we get it

From publicly available sources — a company’s own website (contact/press pages), public business directories, and B2B contact-data providers (e.g. Hunter.io) that compile publicly published addresses. We do not buy consumer lists.

Why, and our legal basis

We use the data solely to send a one-time commercial introduction (and at most a short follow-up) about our service, relevant to the recipient’s professional role. In the UK/EU our basis is legitimate interest (GDPR Art. 6(1)(f)) for B2B marketing to corporate contacts; in the US these are commercial messages under CAN-SPAM, identified as such with our postal address and an opt-out.

Cookies & website data

Our marketing website (vitrine-ai.com) uses a strictly-necessary cookie to remember your cookie choice, and — only if you accept — Google Analytics to understand site traffic (with IP anonymisation). Analytics do not load unless you consent via the cookie banner, and you can choose “essential only”. We do not use advertising or cross-site tracking cookies. Google’s privacy terms: policies.google.com/privacy.

How long we keep it

The minimum needed to run outreach and honour opt-outs. If you don’t respond, we delete or suppress your details within 12 months. Opt-out records are kept so we do not contact you again.

Your rights

You can ask us to access, correct or delete your data, or to stop contacting you, at any time — reply to any email or write to hello@vitrine-ai.com. UK/EU residents may object to processing and complain to their data-protection authority (e.g. the UK ICO).

Opt out & sharing

Reply “unsubscribe” to any message or use the unsubscribe link; we honour opt-outs promptly and add you to a permanent suppression list. We do not sell your data, and share it only with providers that help us send email (e.g. Resend) under appropriate terms.

← Back to vitrine-ai.com