Anddress for Brands — Merchant Terms and Data Processing Agreement

Last updated: 21 September 2026

Language / Idioma

تتوفر هذه الاتفاقية باللغتين الإنجليزية والإسبانية. تسري النسخة الإنجليزية أدناه.

Who we are and scope

These Merchant Terms, the Data Processing Agreement (Part B) and the Merchant Privacy Notice (Part C) (together, the "Agreement") govern the use of Anddress for Brands (the "Service"): the virtual try-on widget, the Shopify app, the merchant dashboard at brands.anddress.com and the related APIs. • Provider: Jorge Andrés Ayala V., an individual domiciled in Colombia, doing business as "Anddress" ("Anddress", "we", "us"). • Merchant: the business that installs the Shopify app, subscribes to a plan or otherwise uses the Service ("Merchant", "you"). • Contact for legal, privacy and security matters: soporte@anddress.com. The Service is offered only to businesses for use in their commercial activity. By installing the app, starting a free trial or subscribing, you accept this Agreement and confirm that you have authority to bind the business you represent. If you do not accept it, do not use the Service.

PART A — MERCHANT TERMS 1. The Service

The Service lets your shoppers see an AI-generated image of a garment from your catalog on a model: a stock model supplied by us, a model created by you, or — only if you enable it — a photo the shopper uploads of themselves. • Results are AI-generated visual simulations for style reference. They are not measurements, do not guarantee size, fit, colour or drape, and may contain inaccuracies. The widget labels them as AI-generated and the images carry an AI-generation label in their metadata. • You decide which sources (stock models, your models, shopper photo) are shown in your store, from the dashboard. • We may improve, change or discontinue features. If we remove a feature that is material to your paid plan, we will tell you at least 30 days in advance and you may cancel.

2. Plans, free trial and billing

• Plans, included try-ons per billing period and the price of each additional try-on are those shown on our pricing page and in the app at the time you subscribe. • Every try-on shown to a shopper counts towards your quota, including results served from our cache. • Free trial: 40 try-ons, once per store. It does not renew monthly. • Shopify stores are billed by Shopify through the Shopify Billing API: a recurring monthly charge plus usage charges for additional try-ons, up to the spending cap you approve in Shopify. Shopify's terms apply to those charges. • Other websites are billed by Paddle.com Market Ltd. as Merchant of Record. Paddle's terms apply to those payments. We do not receive or store card details. • Prices exclude taxes unless stated otherwise. We will give at least 30 days' notice of any price increase; it will apply from your next billing period after the notice. • You may cancel at any time. Cancellation takes effect at the end of the current billing period; we do not refund partial periods except where the law or the billing platform's policy requires it.

3. Your responsibilities

You represent and undertake that: • You own or are licensed to use every image, product description and trademark you give us, and that its use in the Service does not infringe third-party rights. • Your store's privacy policy tells your shoppers that you use a virtual try-on provider, what data it processes and why, and links to or reflects Part B of this Agreement. • Where the law requires it, you obtain your shoppers' consent for analytics (for Shopify stores, through Shopify's customer privacy settings, which the widget and the pixel respect). • You do not direct the "shopper photo" feature at children, and you comply with the laws that apply to your store and your customers. • You keep your dashboard access and API keys confidential and tell us promptly at soporte@anddress.com if you suspect unauthorised use.

4. Acceptable use

You may not use the Service to: process images of minors or of people without their consent; create sexual, violent, defamatory or deceptive content; impersonate real people; reverse-engineer, resell or benchmark the Service for a competing product; bypass quotas, rate limits or security controls; or break any law. We automatically block images that our moderation classifies as showing minors or explicit content. We may suspend the Service, after notice where reasonably possible, if your use breaches this section or puts shoppers, other merchants or the Service at risk.

5. Intellectual property

• You keep all rights to your catalog, images and brand. You grant us a non-exclusive, worldwide, royalty-free licence to host, process and display them solely to provide the Service to you, for as long as you use it. • You may use the images generated for your store in your store and marketing, subject to the rights of the people depicted and to the law. We do not claim ownership of generated images. • We keep all rights to the Service, its software, stock models and documentation. Nothing in this Agreement transfers them to you. • We do not use your catalog, your models or your shoppers' data to train AI models.

6. Availability and support

We work to keep the Service available but do not guarantee uninterrupted or error-free operation. Planned maintenance and outages of our providers (including hosting, AI and payment providers) may affect the Service. Service levels (SLA) and service credits apply only if they are agreed in a separate signed document. Support is provided by email at soporte@anddress.com.

7. Warranties and limitation of liability

• The Service is provided "as is" and "as available". To the extent permitted by law, we disclaim all implied warranties, including fitness for a particular purpose, and we do not warrant any particular increase in sales or reduction in returns. • To the extent permitted by law, neither party is liable for indirect or consequential loss, loss of profits, revenue or goodwill. • To the extent permitted by law, our total liability arising out of this Agreement in any 12-month period is limited to the fees you paid us for the Service in that period. • These limitations do not apply to liability that cannot be limited under applicable law, including liability for wilful misconduct (dolo) or gross negligence (culpa grave), nor to your obligations under section 8 or your breach of section 4, and they do not limit either party's liability to data subjects or under the clauses incorporated in Part B section 7 to the extent those clauses do not allow it.

8. Indemnity

You will defend and indemnify us against third-party claims arising from content you provide, from your storefront's compliance with law (including notices and consents to your shoppers), or from your breach of sections 3 or 4, provided that we notify you promptly and let you control the defence.

9. Term, termination and your data

This Agreement lasts while you use the Service. Either party may end it at any time; you, by uninstalling the app or cancelling your plan; we, with 30 days' notice, or immediately for a material breach that is not remedied. If we end the Agreement other than for your breach, we will refund prepaid fees for the period after termination. What happens to data at the end is set out in Part B, section 9.

10. Changes to this Agreement

We may update this Agreement. For material changes we will notify you by email or in the dashboard at least 30 days before they take effect, except where a change is required by law or to address a security risk. If you do not agree, you may cancel before the change takes effect. Changes to Part B will not reduce the protection of Shopper Data unless the law requires it. If you keep using the Service after a change takes effect, you accept the updated Agreement.

11. Governing law and disputes

This Agreement is governed by the laws of the Republic of Colombia. The parties will first try to resolve any dispute in good faith by email. Otherwise, the competent courts of Colombia will have jurisdiction, without prejudice to mandatory rules of data protection law that grant jurisdiction or rights elsewhere. If any clause is held invalid, the rest remains in force. This Agreement is published in English and Spanish; if they differ, the English version prevails.

PART B — DATA PROCESSING AGREEMENT 1. Roles

For the personal data of your shoppers processed through the Service ("Shopper Data"), you are the controller (responsable del tratamiento) and we are your processor (encargado del tratamiento), including for the purposes of the EU and UK GDPR, Colombian Law 1581 of 2012 and Decree 1074 of 2015 (this Part B is the data transmission contract required by that decree), Brazil's LGPD, and US state privacy laws such as the CCPA/CPRA, under which we act as your service provider. For the data of your own staff and business contacts, see Part C. You are responsible for the lawfulness of your instructions and of disclosing Shopper Data to us, including having a legal basis and giving shoppers the notices and obtaining the consents the law requires.

2. Subject matter, duration, nature and purpose

We process Shopper Data only to (a) generate virtual try-on images, (b) protect the Service from abuse and enforce quotas, (c) bill usage, and (d) attribute orders to try-ons so you can see the results in your dashboard. Processing lasts while the Agreement is in force and until deletion under section 9.

3. Categories of data subjects and personal data

Data subjects: visitors and customers of your store who use the widget. • Shopper photo (only if you enable the "shopper photo" source and the shopper ticks the consent box in the widget): the image the shopper uploads. It is checked by an automated moderation classifier, kept in private temporary storage only while the try-on is generated and deleted when the request finishes; any copy left behind by a technical failure is removed by a daily automated process within 7 days. The resulting image is sent straight to the shopper's browser and is not stored by us. We do not create biometric templates or identify people. Our AI sub-processor may retain it temporarily as described in section 6. • Try-on records: date and time, garment reference, the source used, whether the result came from cache, and the shopper's IP address and browser user-agent. The IP address and user-agent are used for abuse prevention and are erased after 90 days; the rest of the record is kept for billing. • Attributed sales: order identifier, order value, currency, number of items and the garment tried. We do not receive the shopper's name, email, phone number or address. These records are deleted after 13 months. • Browser storage (on your store's domain, in the shopper's own browser): – the last 20 garments tried in the previous 30 days, and the identifiers of up to 50 orders already attributed, so that a later purchase is attributed once. On Shopify these are stored only if Shopify's customer privacy settings allow analytics for that visitor; – if the shopper uses the size advisor and applies a size, the chosen size and the height and weight they entered, only to remember that preference. These values stay in the browser and are not sent to us. We do not process special categories of data on purpose, we do not sell Shopper Data or share it for cross-context behavioural advertising, we disclose it only to the sub-processors in section 6, and we make no decisions with legal or similarly significant effects about shoppers. The only automated decision is the moderation check, which can prevent a photo from being used; the shopper can use a stock model instead.

4. Our obligations as processor

We will: • Process Shopper Data only on your documented instructions, including with regard to transfers of Shopper Data to a third country, which are this Agreement and your settings in the dashboard, unless the law requires otherwise (in which case we will tell you, unless the law forbids it). We will tell you if we believe an instruction infringes data protection law. • Ensure that anyone authorised to process Shopper Data is bound by confidentiality. • Apply appropriate technical and organisational measures, including: encryption in transit (TLS) and at rest (provided by our hosting and database sub-processors); access to production data restricted to the Provider and to persons we authorise under confidentiality obligations; secret keys kept server-side; per-store keys and allowed domains; rate limits; automatic moderation of uploaded photos; and the retention periods in section 3. • Not use Shopper Data for our own purposes, and meet the CCPA/CPRA terms below. • Help you, taking into account the nature of the processing and the information available to us, to respond to requests from shoppers exercising their rights, and to carry out security, impact-assessment and prior-consultation obligations. • Make available the information necessary to demonstrate compliance with this Part B, and allow for and contribute to audits, including inspections, by you or an auditor you mandate, on at least 30 days' notice, under confidentiality, no more than once in any 12 months unless a supervisory authority requires it or after a personal data breach, and at your cost. • For Shopper Data subject to Colombian law: process it on your behalf in accordance with the principles of Law 1581 of 2012 and with your personal data processing policy, as far as it applies to the processing in this Part B; keep it confidential, also after this Agreement ends; perform the duties of a processor (encargado) under article 18 of Law 1581 of 2012; forward to you without undue delay any query or claim a shopper sends us directly and cooperate so that it is answered within the legal terms; and inform you and, where the law requires, the Superintendencia de Industria y Comercio of any breach of security codes affecting that data. • For the purposes of the CCPA/CPRA: (i) you disclose Shopper Data to us only for the limited and specified business purposes in section 2; (ii) we will not sell or share it (as defined in the CCPA), retain, use or disclose it for any other purpose or outside our direct business relationship with you, or combine it with personal information we receive from others or collect ourselves, except as the CCPA regulations permit for service providers; (iii) we will comply with the CCPA obligations that apply to us and provide the same level of privacy protection the CCPA requires; (iv) you may take reasonable and appropriate steps to ensure we use Shopper Data consistently with your CCPA obligations and, on notice, to stop and remediate unauthorised use; (v) we will notify you if we determine that we can no longer meet these obligations. We certify that we understand and will comply with these restrictions.

5. Shopper requests and Shopify privacy webhooks

Shoppers should address requests to you. For Shopify stores we process Shopify's mandatory privacy webhooks: on "customers/redact" we delete the attributed-sale records for the orders indicated; on "customers/data_request" we identify the records we hold for those orders and send them to you on request to soporte@anddress.com so you can answer the shopper; and on "shop/redact" we delete your store's data as described in section 9. For other requests, write to soporte@anddress.com and we will respond within 5 business days.

6. Sub-processors

You give us general authorisation to use the following sub-processors. We engage sub-processors only under written terms that impose data protection obligations providing sufficient guarantees for the processing they perform, and we remain responsible to you for their performance of those obligations. • Supabase Inc. — database and file storage (United States, AWS). • Vercel Inc. — application hosting and serverless functions (United States). • Google LLC (Google Cloud Vertex AI and Gemini API) — try-on image generation and photo moderation (United States and other locations where Google processes data under its terms). Google may retain inputs and outputs for a limited period for abuse monitoring under its terms. • Replicate Inc. — background removal of merchant product images only; receives no shopper data (United States). • Resend Inc. — transactional email to merchants (dashboard access, usage alerts); receives no shopper data (United States). • Paddle.com Market Ltd. — billing of web merchants; receives no shopper data (United Kingdom). • Telegram (Telegram FZ-LLC, United Arab Emirates) — internal operational alerts to the Provider containing store identifiers, the reason a result was reported and links to try-on images made with stock or merchant models; receives no Shopper Data. Shopify is not our sub-processor: it is the platform your store runs on, acts under its own agreement with you and, for Shopify stores, bills you on our behalf. We will update this list on this page and notify you by email at least 30 days before adding or replacing a sub-processor that processes Shopper Data. You may object on reasonable data protection grounds within that period; if we cannot resolve the objection, you may terminate the Agreement and we will refund any prepaid fees for the unused period. If a sub-processor must be replaced urgently for security or continuity reasons, we will notify you as soon as possible and your right to object runs from that notice.

7. International transfers

Shopper Data is stored and processed by our sub-processors in the locations listed in section 6 and is accessed by the Provider from Colombia. To the extent your transfer of Shopper Data to us is a restricted transfer: (a) EU GDPR: Module Two of the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914 is incorporated by reference, with you as data exporter and us as data importer; Clause 7 does not apply; Clause 9(a) Option 2 applies with the notice period in section 6; the optional wording in Clause 11 does not apply; under Clauses 17 and 18 the law and courts of Ireland apply; Annexes I and II are completed by sections 1 to 4 and Annex III by section 6; (b) UK GDPR: the International Data Transfer Addendum issued by the UK Information Commissioner is incorporated together with those clauses; (c) LGPD: the standard contractual clauses in Annex II of ANPD Resolution CD/ANPD No. 19/2024 are incorporated. If those clauses conflict with this Agreement, they prevail. Onward transfers to sub-processors are made under their data processing terms, including, where available, the Standard Contractual Clauses or the EU–US Data Privacy Framework.

8. Personal data breaches

We will notify you without undue delay, and where feasible within 72 hours, after becoming aware of a personal data breach affecting Shopper Data. The notice will describe, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. We will cooperate with you so that you can meet your own notification obligations.

9. Deletion at the end of the service

• Shopify stores: when you uninstall the app, Shopify sends us the "shop/redact" request about 48 hours later. We then delete your store's account and its data (try-on records, attributed sales, your models, catalog images and generated images). If the same account also has an active subscription paid through Paddle, we unlink it from Shopify and delete the attributed sales from that Shopify store and the IP addresses and user-agents of its try-on records; your account, models and catalog images remain for your Paddle subscription. • Other merchants: we delete that data within 30 days after cancellation takes effect, or earlier on written request to soporte@anddress.com. • Before the Service ends you may ask us at soporte@anddress.com for a copy of the Shopper Data we hold for your store (try-on records and attributed sales), which we will provide in CSV format. • We may keep data that the law requires us to keep (for example, billing records) only for as long as that obligation lasts. Backups are overwritten in the ordinary course of our providers' backup cycles.

10. Precedence

If Part B conflicts with Part A, Part B prevails in respect of Shopper Data. If you have signed a separate data processing agreement with us, that document prevails.

PART C — MERCHANT PRIVACY NOTICE

For the data of the Merchant and its staff we are the controller. We process: business name, contact email, store domains, plan and billing identifiers (Shopify or Paddle), Shopify access tokens, dashboard sessions and your usage of the Service. Purposes: to provide and bill the Service, to send service messages (access links, quota alerts, onboarding reminders) and to meet legal obligations. Legal bases: performance of the contract, our legitimate interest in operating and securing the Service, and legal obligations. We keep this data while your account is active and delete it as described in Part B, section 9. You may request access, correction, deletion or a copy, or object, by writing to soporte@anddress.com. You may also complain to your data protection authority (in Colombia, the Superintendencia de Industria y Comercio). Recipients: the providers in Part B section 6 that process merchant data (hosting, database, email, billing, alerts); this data is stored in the United States and accessed by the Provider from Colombia. For data subject to Colombian law, the person accepting this Agreement authorises this processing, and you confirm that staff whose data you give us have been informed of this notice; data subjects have the rights in article 8 of Law 1581 of 2012, including to know, update, rectify and delete their data and to revoke their authorisation where no legal or contractual duty requires us to keep it. Our personal data processing policy is available at https://anddress.com/privacy. Our website may use cookies as described in our Cookie Policy.

شروط التجار واتفاقية معالجة البيانات — Anddress for Brands