← Back to TailorFlow

Privacy Policy

Last updated · June 2026

1. Who we are

TailorFlow ("we", "us", "our", the "Service") is an AI-powered virtual-fitting platform provided to custom clothiers, tailor shops and their end-clients. This policy explains what personal data we collect, why we collect it, how we handle it, and what rights you have. Contact us at privacy@tailorflow.tech for any question about this policy.

2. Our role — controller vs. processor

When a custom clothier ("Retailer") uses TailorFlow to render looks for their customer ("End-Client"):

  • The Retailer is the data controller — they decide which photos and details to upload and hold the primary relationship with the End-Client.
  • TailorFlow is the data processor — we process the data on the Retailer's documented instructions to render the requested looks.

When you sign up directly as a Retailer, we are the controller of your account data (name, email, billing info).

3. What we collect

Retailer / account data

Name, business email, store name, business address, phone number, billing details processed via Stripe.

End-Client data (uploaded by Retailer)

End-Client name, headshot photo, height, build, fitting notes, generated looks. Headshot photos may include facial features. We process these images solely to generate personalised garment renderings on behalf of the Retailer — we do not perform facial recognition, we do not build a face template, and we do not sell or share this data.

Usage & telemetry

Login timestamps, feature usage counts, IP addresses, browser type. Retained for security auditing and product improvement.

What we do NOT collect

Social security numbers, government IDs, health records, precise GPS location, credit card numbers (Stripe handles those directly).

4. Facial and biometric data — special notice

We understand that photographs of an End-Client's face are sensitive. Our posture on facial data:

  • Photos are used only to render that specific End-Client's looks — they are never used to train AI models.
  • We do NOT extract facial geometry, biometric templates, or FaceID embeddings.
  • We do NOT perform face-matching, face-search, or identity verification.
  • Retailers must obtain the End-Client's consent BEFORE uploading a photo and are contractually required to do so.
  • End-Clients may withdraw consent and request deletion at any time by emailing privacy@tailorflow.tech.
  • Where Illinois BIPA, GDPR Article 9, or any other biometric-specific law applies, TailorFlow processes the data solely under the Retailer's written instruction and consent flow.

6. Third-party service providers

We use a small number of carefully-vetted third-party service providers to deliver the Service (secure cloud infrastructure, AI processing, payment processing and transactional email). Each is bound by data-processing terms compatible with GDPR / CCPA, and none is permitted to use your data for its own purposes or to train AI models.

Retailers with a signed Data Processing Agreement may request our current subprocessor list at any time by emailing privacy@tailorflow.tech. We will notify Retailers of any material change to that list.

7. Data retention

  • Client photos and rendered looks — kept while the Retailer's account is active. Deletable by the Retailer at any time from the client card.
  • Inactive End-Client records — auto-deleted 24 months after the last activity, unless the Retailer explicitly extends.
  • Financial/billing records — retained for 7 years to comply with tax law.
  • Retailer account data — deleted within 30 days of account closure request.

8. Your rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion ("right to be forgotten")
  • Restrict or object to processing
  • Data portability (receive your data in a machine-readable format)
  • Withdraw consent at any time
  • File a complaint with your local data-protection authority

End-Clients whose photos have been uploaded by a Retailer should contact that Retailer directly first. If you cannot reach them or need help, contact us at privacy@tailorflow.tech and we will respond within 30 days.

9. Security

  • Data in transit is encrypted with TLS 1.2+
  • Data at rest is encrypted with AES-256
  • Authentication uses JWT tokens delivered via HttpOnly, Secure cookies
  • Every API request is scoped to the calling Retailer's data — cross-tenant reads are prevented at the query layer
  • Access to production systems is limited to authorised engineering personnel with 2FA
  • We are actively pursuing SOC 2 Type II attestation

In the event of a personal-data breach, we will notify affected Retailers without undue delay and, where required, within 72 hours of becoming aware.

10. International transfers

We may transfer personal data outside the country where it was collected. Where such transfer would otherwise be restricted (e.g., transfers from the EEA/UK to the US), we rely on the EU Standard Contractual Clauses (SCCs) and, where applicable, the UK International Data Transfer Addendum.

11. Children

The Service is intended for use by adult Retailers with adult End-Clients. We do not knowingly collect data from anyone under 16. Retailers must not upload photos of minors without documented parental / guardian consent. If we become aware of data from a minor collected without appropriate consent, we will delete it.

12. Cookies

We use only strictly-necessary cookies (authentication session, CSRF token, user preference for the sidebar collapsed state). We do NOT use third-party advertising cookies, tracking pixels, or behavioural analytics beyond our own basic feature-usage counters.

13. Changes to this policy

We will update the "Last updated" date at the top of this page whenever we change this policy. Material changes will be notified to Retailers by email. Continued use of the Service after a change constitutes acceptance of the updated policy.

This policy is provided in good faith to describe our current practices. It is not legal advice. Retailers with specific compliance obligations should consult their own counsel and sign our Data Processing Agreement before onboarding End-Clients.

Powered by TailorFlow