Last updated · June 2026
TailorFlow ("we", "us", "our", the "Service") is an AI-powered virtual-fitting platform provided to custom clothiers, tailor shops and their end-clients. This policy explains what personal data we collect, why we collect it, how we handle it, and what rights you have. Contact us at privacy@tailorflow.tech for any question about this policy.
When a custom clothier ("Retailer") uses TailorFlow to render looks for their customer ("End-Client"):
When you sign up directly as a Retailer, we are the controller of your account data (name, email, billing info).
Retailer / account data
Name, business email, store name, business address, phone number, billing details processed via Stripe.
End-Client data (uploaded by Retailer)
End-Client name, headshot photo, height, build, fitting notes, generated looks. Headshot photos may include facial features. We process these images solely to generate personalised garment renderings on behalf of the Retailer — we do not perform facial recognition, we do not build a face template, and we do not sell or share this data.
Usage & telemetry
Login timestamps, feature usage counts, IP addresses, browser type. Retained for security auditing and product improvement.
What we do NOT collect
Social security numbers, government IDs, health records, precise GPS location, credit card numbers (Stripe handles those directly).
We understand that photographs of an End-Client's face are sensitive. Our posture on facial data:
Since June 2026, TailorFlow requires the Retailer to confirm the End-Client's explicit opt-in consent before a client profile can be created. The exact agreement presented in-store:
"My client consents to their photo and details being processed by AI to generate garment visualisations, stored securely, and used only for this fitting service. They may withdraw consent and request deletion at any time."
We use a small number of carefully-vetted third-party service providers to deliver the Service (secure cloud infrastructure, AI processing, payment processing and transactional email). Each is bound by data-processing terms compatible with GDPR / CCPA, and none is permitted to use your data for its own purposes or to train AI models.
Retailers with a signed Data Processing Agreement may request our current subprocessor list at any time by emailing privacy@tailorflow.tech. We will notify Retailers of any material change to that list.
Depending on your jurisdiction, you may have the right to:
End-Clients whose photos have been uploaded by a Retailer should contact that Retailer directly first. If you cannot reach them or need help, contact us at privacy@tailorflow.tech and we will respond within 30 days.
In the event of a personal-data breach, we will notify affected Retailers without undue delay and, where required, within 72 hours of becoming aware.
We may transfer personal data outside the country where it was collected. Where such transfer would otherwise be restricted (e.g., transfers from the EEA/UK to the US), we rely on the EU Standard Contractual Clauses (SCCs) and, where applicable, the UK International Data Transfer Addendum.
The Service is intended for use by adult Retailers with adult End-Clients. We do not knowingly collect data from anyone under 16. Retailers must not upload photos of minors without documented parental / guardian consent. If we become aware of data from a minor collected without appropriate consent, we will delete it.
We use only strictly-necessary cookies (authentication session, CSRF token, user preference for the sidebar collapsed state). We do NOT use third-party advertising cookies, tracking pixels, or behavioural analytics beyond our own basic feature-usage counters.
We will update the "Last updated" date at the top of this page whenever we change this policy. Material changes will be notified to Retailers by email. Continued use of the Service after a change constitutes acceptance of the updated policy.
This policy is provided in good faith to describe our current practices. It is not legal advice. Retailers with specific compliance obligations should consult their own counsel and sign our Data Processing Agreement before onboarding End-Clients.