Privacy policy

Your privacy at Todifit

Last updated: 19 July 2026

What we collect

When you use Todifit we collect the information you give us — your name, email, delivery address, and order history — plus a small amount of technical information your browser sends automatically (your IP address, device type, and pages you viewed).

Why we collect it

  • To deliver the products you buy.
  • To estimate delivery options for your order (we use your address to work out delivery from the store fulfilling it).
  • To process payments securely via Stripe.
  • To prevent fraud and abuse (for example, rate-limiting AI try-on requests so the feature stays sustainable).
  • To send you receipts and order updates.

What we don't do

  • We don't sell your personal information to anyone.
  • We don't share your data with advertisers for behavioural tracking.
  • We don't store your full payment card details — Stripe handles that under PCI DSS Level 1 standards.

AI try-on photos

When you take or upload a photo to use the AI try-on feature, the photo is sent to Google's Vertex AI service to generate the try-on image. We don't store your photo on our servers after the request completes; Google's data-handling terms for Vertex AI apply to the request itself.

Account access by authorized staff

To provide support, troubleshoot problems, investigate security issues, or meet a legal obligation, a limited number of authorized Todifit staff may securely access your account on your behalf — for example, signing in to a retailer's dashboard to diagnose an issue. This access is restricted to authorized personnel, logged in an audit trail (who accessed which account and when), and used only for the purpose above. We never sign in to read or use your account for marketing or any unrelated purpose.

Connected stores (Shopify, Square)

When a retailer connects an external store platform such as Shopify or Square to Todifit, we access that store's product catalog data on the retailer's behalf: products, variants, sizes and colours, product images, descriptions, prices, inventory levels, and store locations. We use this data only to import the retailer's catalog into Todifit and to keep stock levels in sync in both directions, and we do not use catalog data for any purpose other than powering the retailer's Todifit storefront.

If you order from a retailer whose catalog is connected this way, we also create the matching order in that retailer's own store platform, so they can pack and post it from the system they already use. That order carries what they need to fulfil it: your name, delivery address, email address and phone number, alongside the items and amounts. We send this only for fulfilment, and only to the retailer fulfilling your order. We do not read the connected store's existing customer records, and we do not use any of it for marketing or any unrelated purpose.

The access token that authorizes this connection is stored encrypted at rest (AES-256-GCM). When a retailer disconnects the integration or uninstalls the app from their store platform, we deactivate the connection and delete the stored access token. We honour the store platform's data-deletion requests — including Shopify's mandatory customers/data_request, customers/redact, and shop/redact compliance webhooks — and erase the associated data on request.

Cookies

We use a small number of essential cookies to keep you signed in and remember your cart. We don't use third-party analytics or advertising cookies.

Your rights

You can request a copy of the data we hold about you, ask us to correct it, or ask us to delete your account at any time by emailing support@todifit.com.

Contact

Questions about this policy? Reach us at info@todifit.com or via our contact page.