Privacy Policy

Last updated: July 31, 2026

Iris (“Iris,” “we,” “us”) is a conversational product-discovery widget that merchants install on their storefront to help shoppers describe what they want and find matching products, including an optional virtual try-on feature. This policy explains what data we collect from merchants and their shoppers, why we collect it, and how it’s handled. It applies to the Iris merchant dashboard and to the Iris widget embedded on a merchant’s store.

1. Information we collect

Merchant account information. Your name, email address, and authentication details when you create an Iris account or connect your store.

Store data. Your product catalog (titles, descriptions, images, prices, inventory status) so Iris can index it for search, and your store’s access credentials, which we encrypt at rest and never expose in the dashboard or to shoppers.

Shopper interaction data. When a shopper uses the Iris widget and has given consent, we collect a first-party anonymous identifier, their chat messages and search queries, and which products they view or click. We don’t link this to a real-world identity we can independently verify.

Virtual try-on photos. If a shopper opts in to try-on, the photo they upload is used only to generate a preview image showing how an item might look on them. We don’t use that photo for any other purpose. It is kept in the browser’s own per-tab storage so a shopper can try several items without uploading it again, and the browser discards it when that tab is closed. It never leaves their device except for the request that generates a preview, and we never store it. The generated preview is saved in the shopper’s own browser for up to seven days so they can look at it again and compare it with the product photo; it is never uploaded to us. A shopper can delete it at any time with “Remove this photo”, and starting a new chat clears every saved preview.

Usage and analytics data. Aggregated event data (searches, results shown, no-results, clicks) that powers merchant-facing analytics and helps us improve search relevance.

Billing information. If you subscribe to a paid plan or purchase AI credits, payment is processed directly by Stripe. Iris never sees or stores your full card number.

2. How we use information

To operate the widget and merchant dashboard, index and search a merchant’s catalog, generate virtual try-on previews (only with consent), personalize results for returning shoppers (only when the merchant enables personalization and the shopper consents), provide merchant-facing analytics, process payments and manage subscriptions, communicate with merchants about their account, and comply with our legal obligations.

4. How we share information

We don’t sell personal information. We share data with:

  • Supabase, for database and authentication hosting
  • Voyage AI, for product search embeddings
  • OpenRouter and the AI model providers it routes requests to, for chat responses and try-on image generation
  • Shopify, to read your catalog and operate as an installed app
  • Stripe, for payment processing
  • Trigger.dev, for background catalog-indexing jobs

Each provider is bound by its own security and privacy commitments, and we only share what’s necessary for them to perform their function on our behalf.

5. Data retention

Merchant and store data is retained for as long as the account is active. Shopper conversation history persists so a chat survives navigating the store, until the shopper clears it or requests deletion. When a merchant uninstalls Iris, or a shopper requests deletion, we remove the associated data through Shopify’s standard compliance webhooks (customer data request, customer redaction, and shop redaction).

6. Your rights

Depending on where you live, you may have rights to access, correct, delete, or export your data, and to object to or restrict certain processing (for example, under the GDPR, UK GDPR, or CCPA/CPRA). Shoppers can exercise these rights through the merchant’s store or by contacting us directly. Merchants can request an export or deletion of their account data by contacting us at the address below.

7. Children’s privacy

Iris is not directed at children, and we don’t knowingly collect data from children under 16.

8. International transfers

Our infrastructure and service providers may be located in different countries than you, so your data may be transferred and processed internationally. We use providers that maintain appropriate safeguards for these transfers.

9. Security

Store credentials are encrypted at rest, and access to production systems is limited to what’s necessary to operate the service. No method of transmission or storage is completely secure, and we can’t guarantee absolute security.

10. Changes to this policy

We’ll update this page and change the “Last updated” date above whenever this policy changes, and we’ll notify merchants of any material change.

11. Contact us

Questions about this policy, or requests relating to your data, can be sent to privacy@meetirisai.com.