Data Processing Agreement

Last updated: August 2026

This Data Processing Agreement (DPA) applies to Shopify merchants, kiosk store owners, and API customers using Corlen. It describes how we process personal data on your behalf when your customers use Corlen's try-on features through your store or your integration. Where data protection law (such as the GDPR) applies, you act as the data controller for your customers' data, and Corlen acts as your data processor.

Subject matter and duration

Corlen processes personal data solely to provide the virtual try-on service described in your active subscription or API plan, for as long as that plan remains active, and for the limited retention period described below afterward.

Nature and purpose of processing

Corlen receives a photo submitted by an end shopper and a garment image from your catalog, and generates an image showing the shopper wearing that garment. That single purpose, generating a try-on preview, is the only reason customer photos are processed.

Categories of data and data subjects

The personal data involved is limited to: photos submitted by end shoppers for the purpose of generating a preview, and, where a shopper chooses to leave one, an email address for follow-up or receiving their result. The data subjects are the end shoppers who use the try-on feature on your store or kiosk. We do not process special category or biometric data; we never run face recognition or facial analysis on any photo.

Sub-processors

We use the following sub-processors to operate Corlen. We will update this list if it changes.

  • Google Cloud (Vertex AI): generates the try-on image from the submitted photo and garment image.
  • Supabase: hosts our database and private file storage.
  • Resend: delivers transactional emails (verification codes, try-on results, account notices).
  • Stripe: processes subscription and usage-based payments.
  • Vercel: hosts the Corlen application itself.

Security measures

We apply the following measures to protect the data we process on your behalf:

  • Customer photos are stored in private storage buckets, never publicly accessible.
  • Access to stored photos happens only through short-lived, signed URLs generated server-side.
  • Kiosk photos are automatically deleted after 2 hours, or immediately if the shopper requests deletion.
  • Shopify storefront try-on photos are processed in memory for a single request and are never written to storage.
  • Store owner API access tokens and API keys are encrypted at rest and never exposed to any client.
  • We never run face recognition or biometric analysis on any photo we process.

Data subject rights

If an end shopper contacts you to exercise a data protection right (such as requesting deletion of a photo or email they left with your store), we will assist you in fulfilling that request. You can also have us act on such a request directly by contacting privacy@corlen.io with enough detail to locate the data (store name and approximate date is usually enough).

International transfers

Our sub-processors operate infrastructure in multiple regions. Where personal data is transferred outside the country it originated in, we rely on the safeguards those providers make available (such as standard contractual clauses) to ensure an equivalent level of protection.

Breach notification

If we become aware of a personal data breach affecting your customers' data, we will notify you without undue delay after becoming aware of it, with the information available to us at the time.

Term

This DPA remains in effect for as long as you have an active Corlen account, and applies to any personal data processed under it even after your account is closed, until that data is deleted per our retention practices.

Contact

Questions about this Data Processing Agreement can be sent to privacy@corlen.io.