NINE
Privacy policy Book a demo
Nine Labs · Legal

Biometric Data Retention & Destruction Policy

Nine Labs Inc. ("Nine," "we," "us," or "our") is committed to protecting the privacy and security of biometric data. This policy describes how we collect, use, store, and destroy biometric data in connection with our virtual try-on platform and services.

Effective July 4, 2026 · Version 1.0

1. Scope

This policy applies to all individuals who interact with Nine's virtual try-on widget deployed on any Nine partner brand's website or digital storefront, including any individual who uploads a photograph for the purpose of generating a virtual try-on composite image ("Try-On Service").

2. What biometric data we collect

When you upload a photograph to use the Try-On Service, Nine's artificial intelligence systems may derive or analyze the following from your image:

  • Facial geometry and structure
  • Body proportions and pose keypoints
  • Skin tone and coloring

These are collectively referred to in this policy as "Biometric Data." The photograph you upload is used solely to generate a virtual try-on composite image showing you wearing a garment from the brand's catalogue.

3. Purpose of collection

Nine collects and processes Biometric Data for one purpose only: to generate a photorealistic composite image showing the individual wearing a selected garment. Biometric Data is not used for any other purpose, including identity verification, advertising targeting, or resale.

4. Retention schedule

Nine retains Biometric Data — including the uploaded photograph and any derived biometric identifiers — for no longer than seventy-two (72) hours from the time of upload. This retention window exists solely to complete the try-on rendering process and to allow the user to view their results.

Upon expiration of the 72-hour window, all Biometric Data, including the original uploaded photograph, derived facial geometry data, and any intermediate processing files, is permanently and irreversibly deleted from Nine's servers and any associated processing infrastructure.

If you request deletion of your Biometric Data prior to the 72-hour window, Nine will honor that request immediately. Deletion requests may be submitted to adarsh@itsnine.com.

5. Destruction method

Nine permanently destroys Biometric Data using industry-standard secure deletion methods that prevent reconstruction or recovery of the deleted data. Nine maintains an internal deletion log recording the session identifier, timestamp of upload, and timestamp of confirmed deletion. This log does not contain any biometric identifiers or personal information.

6. No sale or profit from biometric data

Nine does not sell, lease, trade, or otherwise profit from any individual's Biometric Data. Nine does not disclose Biometric Data to any third party except as required to complete the rendering process (e.g., transmission to Nine's AI inference infrastructure), and only under terms that prohibit further disclosure or use.

7. Security

Nine stores and transmits Biometric Data using industry-standard encryption (AES-256 at rest, TLS 1.2+ in transit). Access to Biometric Data is restricted to authorized Nine personnel and processing systems on a need-to-access basis. Nine conducts regular security reviews of its data handling practices.

8. Third-party processors

Nine's AI inference processing involves transmission of uploaded photographs to Nine's cloud processing infrastructure. All third-party processors are contractually prohibited from retaining, using, or disclosing Biometric Data beyond the scope required to complete the rendering process. A current list of sub-processors is available upon request at adarsh@itsnine.com.

9. Consent

Nine collects Biometric Data only with the individual's prior informed consent, obtained through an explicit consent acknowledgment presented at the point of photograph upload. Consent is voluntary — individuals who decline to provide consent may not use the Try-On Service but may continue to browse and purchase normally.

10. Applicable law

This policy is designed to comply with the Illinois Biometric Information Privacy Act (740 ILCS 14/, "BIPA"), the Washington Biometric Privacy Act (RCW 19.375, "WCPA"), the Texas Capture or Use of Biometric Identifier Act (Tex. Bus. & Com. Code § 503.001, "CUBI"), the California Consumer Privacy Act (Cal. Civ. Code § 1798.100 et seq., "CCPA"), and the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR").

11. Contact

Questions, deletion requests, or complaints regarding Nine's handling of Biometric Data should be directed to:

Email: adarsh@itsnine.com Mail: Nine Labs Inc., Attn: Privacy, 190 North 10 St, Suite 302, Brooklyn, NY 11211 Response time: Nine will respond to all privacy inquiries within five (5) business days.

12. Updates to this policy

Nine may update this policy from time to time. Material changes will be communicated to brand partners in writing. The current version of this policy is always available at itsnine.com/biometric-policy. The version number and effective date are displayed at the top of this page.