1. Scope
This policy explains how Nine AI ("Nine", "we") handles personal information collected through itsnine.com, our platform, and the try-on experiences we power on our customers' storefronts. Where we provide the Service to a brand or retailer, that brand is generally the controller of shopper data and we act as its processor; this policy then describes our practices as processor and applies alongside the brand's own privacy notice.
2. Information we collect
- Account information — name, work email, company, role, and credentials for business users.
- Shopper-submitted images — photographs uploaded or captured to generate a try-on, plus any sizing details provided.
- Generated outputs — the try-on images produced from those inputs.
- Usage data — pages viewed, features used, request logs, device and browser type, approximate location derived from IP.
- Communications — messages, demo requests, and support correspondence.
- Billing data — handled by our payment processor; we do not store full card numbers.
3. Biometric data
Nine's Try-On Service uses artificial intelligence to generate a composite image showing you wearing a garment from a brand's catalogue. To do this, Nine processes a photograph you voluntarily upload. This section explains how Nine handles the biometric data derived from that photograph.
What we collect
When you upload a photograph to use the Try-On Service, Nine processes your image to derive facial geometry, body proportions, pose, and skin tone for the sole purpose of generating your try-on result. We refer to these collectively as "Biometric Data."
How we use it
We use your Biometric Data for one purpose only: to generate the try-on composite image you requested. We do not use your Biometric Data for advertising, identity verification, model training (without your separate explicit consent), or any other purpose.
How long we keep it
Your uploaded photograph and all Biometric Data derived from it are permanently deleted from Nine's systems within 72 hours of upload. If you want your data deleted sooner, email adarsh@itsnine.com and we will delete it immediately.
Who we share it with
We do not sell or share your Biometric Data with third parties for their own purposes. We transmit your photograph to Nine's cloud AI infrastructure solely to complete your try-on render, under strict contractual terms prohibiting any further use or retention.
Your rights
Depending on your state or country of residence, you may have the right to:
- Know what Biometric Data Nine holds about you
- Request deletion of your Biometric Data at any time
- Withdraw consent for biometric data processing
- Lodge a complaint with a supervisory authority (EU/UK residents)
To exercise any of these rights, contact adarsh@itsnine.com. We will respond within five (5) business days.
Legal basis (GDPR)
For users in the European Economic Area and United Kingdom, our legal basis for processing Biometric Data is your explicit consent (Article 9(2)(a) GDPR), which you provide by clicking 'I agree' in the consent modal before uploading your photograph. You may withdraw this consent at any time by contacting adarsh@itsnine.com.
Full biometric data policy
Our complete Biometric Data Retention & Destruction Policy — including our retention schedule, destruction methods, security practices, and applicable law compliance details — is available at itsnine.com/biometric-policy.
4. How we use information
We use personal information to provide and operate the Service, generate try-on imagery, authenticate users, provide support, monitor performance and abuse, produce aggregated and de-identified analytics for our customers, meet legal obligations, and — for business contacts only — send service and marketing communications you can opt out of at any time.
5. Legal bases
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (providing the Service); explicit consent (processing shopper images); legitimate interests (security, service improvement, business communications); and compliance with legal obligations. Consent can be withdrawn at any time without affecting processing already carried out.
6. Model training
We do not train our models on shopper images or on a customer's product catalogue without that customer's written agreement. Where training permission is granted, data is de-identified where practicable and covered by the terms of the relevant agreement. Aggregate, non-identifying statistics about Service performance may be used to improve the Service in all cases.
7. Sharing and processors
We share personal information with: the brand or retailer operating the storefront where a try-on occurs; vetted sub-processors that provide cloud hosting, GPU compute, error monitoring, analytics, and payment processing, each bound by written data-protection terms; professional advisers; and authorities where legally required. In a merger, acquisition, or asset sale, information may transfer to the successor entity under this policy. We do not sell personal information and do not share it for cross-context behavioural advertising.
8. International transfers
We operate internationally and may transfer information to countries other than the one you are in. Where required, we rely on Standard Contractual Clauses, the UK Addendum, or another approved transfer mechanism, together with supplementary technical measures such as encryption in transit and at rest.
9. Retention
Shopper source images and all Biometric Data derived from them are permanently deleted within seventy-two (72) hours of upload, or immediately on request. Generated outputs follow the retention configured by the customer. Account and billing records are retained for the life of the relationship and for as long as required for tax, audit, and legal purposes. Backups are purged on a rolling schedule.
10. Security
We maintain administrative, technical, and physical safeguards including encryption in transit and at rest, least-privilege access controls, audit logging, secure software development practices, vendor review, and periodic penetration testing. No system is perfectly secure; we will notify affected customers and, where required, regulators and individuals of a personal-data breach without undue delay.
11. Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal information, to object to certain processing, to withdraw consent, and to appeal a refused request. Residents of California, Colorado, Connecticut, Virginia, and similar jurisdictions have equivalent rights and the right to be free from discrimination for exercising them. Contact us at adarsh@itsnine.com; where we act as processor we will route your request to the relevant brand. You may also complain to your local supervisory authority.
12. Cookies
We use strictly necessary cookies to keep you signed in and secure the Service, and — with consent where required — analytics cookies to understand usage. You can manage preferences through the cookie banner or your browser settings. We honour Global Privacy Control signals where applicable.
13. Children
The Service is not directed to children under 16 and we do not knowingly process their personal information or accept their images. If we learn we have done so, we will delete it promptly.
14. Changes
We may update this policy as the Service evolves. Material changes will be signalled by updating the date above and, where appropriate, by direct notice. Please review it periodically.
15. Contact
Privacy questions, requests, and data-processing agreements: adarsh@itsnine.com.