1. Scope of this policy
We use two terms throughout this Policy. End Users are anyone who uses the Try-On feature to see how a pair of glasses looks on their face — whether on a seller’s own website or on an ARLens-hosted storefront. Clients are the eyewear sellers and shop owners who sign up for ARLens to sell their frames.
If you’re an End User, the sections on how the technology works and what it doesn’t do are the ones that matter most to you. If you’re a Client, the section on the information we collect to run your account is the relevant one.
2. How the virtual try-on technology works
When an End User taps Try On, their browser asks for camera access. Once granted, ARLens uses MediaPipe — an on-device machine learning library — to estimate roughly 468 generic reference points across the shape of a face: the distance between the eyes, the position of the nose bridge, the angle of the jaw. These are the same category of measurement you’d get from a tape measure, just captured continuously and in real time. A 3D model of the specific glasses frame is then rendered on top of that estimate using Three.js, scaled and positioned to match.
All of this — the camera feed, the landmark estimation, and the 3D rendering — happens inside the End User’s own browser, on their own device. At no point during a Try-On session is the camera feed, a photo, or a video transmitted to ARLens’s servers. If an End User uses the Screenshot or Record feature built into the try-on experience, that image or video is generated and saved directly to their own device — ARLens does not receive a copy.
The only network request the Try-On experience makes to our servers is a short check confirming the seller’s subscription is active and the requesting website is authorized. That request identifies the seller’s account — not the End User.
3. What our technology does not do
- No facial recognition. ARLens cannot and does not determine who someone is. The landmark points we estimate are generic to human face shape — they are not compared against a database and cannot identify a specific individual.
- No biometric identity database.We do not create, store, or maintain a record of any End User’s face, landmark measurements, or any identifier derived from them.
- No profiling.Our technology does not attempt to infer age, gender, ethnicity, emotional state, or any other characteristic from an End User’s face.
- No automated decisions about people.The Try-On feature renders glasses on a face-shape estimate — it does not make decisions affecting an End User’s rights, opportunities, or access to anything.
4. Information we collect from End Users
We design the Try-On experience to collect as little as possible about visitors:
- Camera/video data — processed transiently in your browser only, as described above. Not stored, not uploaded, not retained by ARLens in any form.
- Face-fit measurements — shown to you on-screen (for example, whether a frame matches your face width) and not saved against your identity.
- Aggregate usage data— a seller’s dashboard may show how many times a frame was tried on, or which frames are most popular. This is counted in aggregate; it is not linked to who you are.
- If you use a Hosted Storefront’s WhatsApp order button, tapping it opens WhatsApp with a pre-filled message and hands you off to WhatsApp directly. From that point, your conversation is governed by WhatsApp’s own privacy policy — see Section 9.
5. Information we collect from Clients
If you’re a seller using ARLens, we collect what we need to operate your account and storefront:
- Account and business details— shop name, contact email, WhatsApp number, logo, and (where relevant) a custom domain you’ve connected.
- Catalog content — photos, names, and prices of the frames you submit, used to generate 3D models and populate your storefront.
- Billing information — processed through our payment providers (Stripe, or local bank transfer / Flouci for Tunisian clients); ARLens does not store full card numbers on its own servers.
- Communications — messages you send us for support, onboarding, or account management.
- Dashboard analytics — try-on counts, WhatsApp click-throughs, and similar usage metrics for your own frames.
7. How we use information
We use the information described above to operate and maintain the Services, verify that a Client’s subscription is active before enabling Try-On, generate and review 3D models from submitted frame photos, communicate with Clients about their account and billing, and provide Clients with usage analytics for their own catalog.
8. No sale of personal data
ARLens does not sell, rent, or trade personal data — End User or Client — to third parties. Ever.
9. Third-party services we rely on
Running the Services means working with a small number of infrastructure and processing partners, each bound by their own privacy and security practices:
- Hosting & delivery — Vercel.
- File storage (3D models, catalog images) — Cloudflare R2.
- Database & authentication — Supabase.
- 3D model generation — Meshy AI and/or Tripo3D, which process the frame photos a Client submits to generate a 3D model. These are photos of eyewear products, not of people.
- Payments — Stripe (international), Flouci and bank transfer (Tunisia).
- WhatsApp— order-button redirects hand off to WhatsApp (operated by Meta), governed by WhatsApp’s own terms once you’re there.
We choose infrastructure providers that only process data on our instructions and only for the purposes described in this Policy.
10. Data retention
End User camera data is never retained — see Section 2. Client account and catalog data is retained for as long as the account is active, plus a reasonable period afterward for accounting, legal, and fraud-prevention purposes. Clients can request deletion of their account and associated data at any time by contacting us (Section 17); we’ll confirm what can be deleted immediately and what we’re required to retain briefly for legal reasons.
11. Your rights
Depending on where you’re located, you may have rights to access, correct, delete, or receive a copy of personal data we hold about you, and to object to certain kinds of processing. Because we don’t retain End User camera or biometric-adjacent data in the first place, most of these rights are most relevant to Clients’ account data. To exercise any of these rights, contact us using the details in Section 17.
12. Children & minors
The Services are intended for people old enough to make purchasing decisions or, for End Users, to consent to the camera-based Try-On experience in their jurisdiction — generally 16+ in the EU, 13+ in the US, or with a parent or guardian’s permission. We do not knowingly direct the Services at young children, and we do not knowingly collect information from them beyond the transient, on-device processing described in Section 2.
13. Biometric data notice
Some jurisdictions — including certain US states — define “biometric identifiers” broadly enough that generic facial-landmark measurements like the ones our Try-On technology estimates could fall within that definition, even though they cannot be used to identify anyone. We’d rather be upfront about this than rely on a technicality:
- The landmark estimation described in Section 2 happens entirely on your own device, for the sole purpose of rendering glasses on your face in real time.
- It is not compared against any dataset, is not stored, and is not disclosed to any third party.
- It is discarded automatically the moment your Try-On session ends.
By using the Try-On feature, you acknowledge this processing and consent to it for the duration of your session. If you don’t want your camera used this way, simply don’t activate Try-On — the rest of a seller’s site or storefront works normally without it.
14. Security
We use reasonable technical and organizational safeguards — access controls, encrypted connections, and least-privilege infrastructure design — appropriate to the limited data we actually hold (mostly Client business data, not End User biometric data). No system is 100% secure, and we can’t guarantee absolute security — but because End User camera data is never transmitted to or stored on our servers in the first place, a server-side incident would not expose it.
15. International data transfers
ARLens operates across MENA and internationally, and the infrastructure providers listed in Section 9 may process data in countries other than your own, including the United States and the European Union. Where required, we rely on those providers’ own compliance frameworks and standard safeguards for cross-border transfers.
16. Changes to this policy
We may update this Policy as the Services evolve. The “Last updated” date at the top reflects the most recent revision. If a change is significant — for example, if we begin retaining data we previously didn’t — we’ll make that clear on this page rather than burying it in a routine update.
17. Contact us
Questions about this Policy, or want to exercise any of the rights described above? Reach us at [email protected].