Last updated: July 7, 2026
This Privacy Policy describes how Spaarkly s.r.l. (“Spaarkly”, “ARShades”, “we”, “us”, or “our”) processes personal data and other information in connection with the ARShades VTO for Shopify app (the “Shopify App” or the “App”).
This policy is specific to the Shopify App and is limited to the data processed in connection with Shopify (merchant, store, product, configuration and attribution data). The processing performed by ARShades end-user services — such as Virtual Try-On, 3D/AR Viewer and AR PD Meter — that may be launched through the App is not covered by this policy and is governed by the ARShades core Privacy Policy (version 5.4), available at https://github.com/Spaarkly-srl/ARS_legal and displayed to shoppers within the ARShades experiences.
Spaarkly s.r.l. acts as an independent controller for the personal data processed through the Shopify App.
Controller: Spaarkly s.r.l.
Registered address: Via della Tecnica n. 18, 85100 Potenza, Italy
Privacy contact: privacy@spaarkly.com
The Shopify App connects a merchant’s Shopify store to the ARShades platform. It allows merchants to:
The App is free to install on Shopify. The underlying ARShades service may require a separate ARShades subscription purchased outside Shopify.
When a merchant installs or uses the App, we may process:
These data are used to authenticate the merchant, operate the embedded App, maintain the App session and provide support and security.
We process information needed to connect the Shopify store to ARShades, including:
licenseId, catalogueId, viewerId, webDomain, studioDomain, has_vto and has_arpd;To match products with ARShades assets and display VTO/3D features only where available, the App may read and process:
The App may write ARShades technical metafields to Shopify variants, including catalogueVariantId and catalogueProductId. These metafields are used by the storefront theme blocks to determine whether a product or variant can launch ARShades VTO or 3D/AR Viewer.
When a shopper uses VTO or 3D/AR Viewer on the merchant’s storefront, the App may process the following technical, non-profile data:
These data are used to display the correct experience on the storefront and to power the attribution analytics described in Section 3.6.
The camera-based processing that takes place within the ARShades experiences launched from the storefront — including Virtual Try-On rendering and the AR PD Meter pupillary distance calculation — is performed by the ARShades services, not by the Shopify App, and is governed by the ARShades core Privacy Policy.
In summary, and as described in that policy: camera images and video streams are not stored; no facial templates or biometric identifiers are created; and, for AR PD Meter, camera-derived technical data that do not identify the shopper may be temporarily transmitted to the ARShades backend located in the European Union, used only to return the measurement result and discarded after processing. The Shopify App itself does not access, store or receive camera data.
The App uses a Shopify Web Pixel to measure VTO/3D attribution and conversion performance. The pixel may process:
The pixel is designed not to send direct shopper profile data such as name, email address, phone number or shipping address to the ARShades analytics backend.
The storefront pixel may use browser local storage to remember an active VTO/3D session for attribution. This local session data expires after 7 days or is cleared after a tracked purchase.
The pixel is loaded by Shopify’s pixel manager only where the visitor’s consent matches the consent categories declared by the App (such as analytics), in accordance with Shopify’s Customer Privacy API and the merchant’s consent configuration. We honor these consent signals and do not process pixel events collected without the required consent.
We process the data described above for the following purposes:
Depending on the context and applicable law, the legal bases may include performance of a contract, legitimate interests, compliance with legal obligations, and consent where required, including camera access or analytics consent requirements.
We retain data only for as long as needed for the purposes described in this policy.
shop/redact compliance webhook, unless retention is required by law or for legitimate security purposes.The App implements Shopify privacy and compliance webhook endpoints for:
customers/data_request;customers/redact;shop/redact.Webhook requests are verified using Shopify’s HMAC signature; requests with an invalid signature are rejected. We complete data request and redaction actions within 30 days of receiving the webhook.
The App database does not store direct end-customer profile data such as shopper name, email address, phone number or shipping address. For customer-level requests, we verify the Shopify webhook and respond according to the App’s data holdings.
shop/redact is sent by Shopify 48 hours after the App is uninstalled. Upon receipt, we delete the shop’s stored App data, including Shopify sessions, synced variant mappings and shop pixel settings, subject to legal or security retention requirements.
We share data only as needed to operate, secure and support the App and ARShades services.
Confirmed service providers and infrastructure used for the Shopify App and related ARShades services include:
These providers process data under their own terms and applicable data processing commitments. We do not sell or share (as defined by the California Consumer Privacy Act) shopper personal data. We do not use Shopify App data for unrelated advertising, facial recognition, biometric identification or AI model training, and we do not carry out automated decision-making that produces legal or similarly significant effects.
A data processing agreement (DPA) covering the App’s processing is available to merchants upon request at privacy@spaarkly.com.
The Shopify App and ARShades analytics and processing services are configured to process and store relevant data in the European Union where applicable.
If a service provider processes personal data outside the European Economic Area, we use appropriate safeguards required by applicable law, such as Standard Contractual Clauses or equivalent transfer mechanisms.
We use technical and organizational measures designed to protect the data processed by the App, including:
No method of transmission or storage is completely secure, but we work to maintain safeguards appropriate to the nature of the data and the risks involved.
If a security incident affects data processed by the App, we will assess the incident under Article 33 GDPR, mitigate it as quickly as possible and notify the competent supervisory authority within 72 hours where required. Because we hold merchant contact details, we will notify affected merchants directly and without undue delay, and we will cooperate with Shopify’s incident processes where applicable.
Camera access is requested by the shopper’s browser or device operating system only within the ARShades experiences (VTO, AR PD Meter). Shoppers can refuse or revoke camera access through browser or device settings; if refused, those experiences may not function. The Shopify App itself does not access the camera.
How camera data are processed within the ARShades experiences is described in the ARShades core Privacy Policy.
The App is intended for use by Shopify merchants and their storefront shoppers. We do not intentionally collect or process the personal data of any user—and therefore of any minor—in the absence of a valid legal basis and, in the case of minors below the applicable age of digital consent, of the consent of a parent or the holder of parental responsibility. Given the way ARShades is designed, we do not create accounts, do not request names or contact details and do not generate persistent identifiers, and we hold no data attributable to an identified or identifiable minor.
Should a parent or the holder of parental responsibility believe that a minor has used the service without their consent, they may contact us at privacy@spaarkly.com to request the deletion of the data, indicating the IP address used and, where available, the approximate date and time of the session. Where such details enable us to identify the relevant data, we will immediately take steps to delete it; failing that, we recall that technical data remains in any event subject to the retention limits and automatic deletion described in this Privacy Policy.
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data.
Merchants may contact us at privacy@spaarkly.com. Shoppers may also contact the merchant whose store they visited, or contact Spaarkly directly where Spaarkly acts as controller for ARShades processing.
We may need information such as shop domain, approximate date/time, event identifiers, device/session details or other information to locate relevant records.
You also have the right to lodge a complaint with a supervisory authority, such as the Italian Garante per la Protezione dei Dati Personali (www.garanteprivacy.it) or the competent authority in your country of residence.
We may update this Privacy Policy to reflect changes to the Shopify App, ARShades services, legal requirements or operational practices. When we update the policy, we will revise the “Last updated” date.
For privacy questions or requests, contact:
Spaarkly s.r.l.
Via della Tecnica n. 18
85100 Potenza, Italy
Email: privacy@spaarkly.com