Genlook Privacy Policy

Effective Date: August 4, 2026

This Privacy Policy describes how Parakeet Labs SASU, operating as Genlook ("we", "us", "our"), collects, uses, and discloses personal data. It applies worldwide and covers:

  • Merchants: stores using Genlook on Shopify, WooCommerce (WordPress), PrestaShop, or Shopline, including in-store (retail) try-on.
  • API customers: businesses using the Try-On API and its dashboard.
  • Consumer account holders: individuals using Genlook through an AI assistant (MCP) with a Genlook account and prepaid credits.
  • Visitors of genlook.app and our other websites.

If you are a shopper using the try-on feature on a store, the Shopper Privacy Policy applies to you. For shopper data, the store is the data controller and Genlook acts as processor under our Data Processing Agreement.

1. Data we collect

Merchants

  • Shopify and Shopline: at install we store your shop domain and platform access tokens (encrypted). We do not collect the store owner's name, email, or address at install. If you contact support or use the support chat, we receive the contact details you provide.
  • WooCommerce, PrestaShop, and Try-On API: a Genlook dashboard account (email, name), managed through our authentication provider Clerk.
  • Billing data: handled by the billing rail for your platform (see Section 4). We do not store card numbers.
  • Studio and catalog content: product images, and any model photos you upload to generate marketing imagery.
  • Support: emails you send us and chat conversations, including your email address and name.
  • Product usage: how you use the dashboards and in-admin tools (pages viewed, features and assistant tools used, configuration), tied to your shop domain or account.

API customers and consumer account holders

  • Account details (email, name via Clerk), API keys, credit purchases (via Stripe: email, billing country, VAT number where applicable), and the photos you upload for try-on generation, which are subject to the same automatic deletion windows as shopper photos (7 days by default).
  • Technical request data for security and abuse prevention: hashed forms of your IP address, user agent, and request metadata. Raw IP addresses are not stored with generation records.

Website visitors

On behalf of merchants (processor role): shopper photos, generated images, optional shopper emails, and widget usage events. This processing is described in the Shopper Privacy Policy and governed by the DPA. Merchants never get access to shoppers' photos or generated results.

2. How we use personal data

  • Provide and operate the services (virtual try-on generation, dashboards, API).
  • Billing and subscription management.
  • Support and service communications.
  • Product communications and marketing to merchants (you can opt out at any time).
  • Product analytics and service improvement.
  • Security, fraud and abuse prevention, and error monitoring.
  • Compliance with legal obligations.

AI training: we do not use your content, your customers' photos, or generated images to train AI models.

3. Legal bases (GDPR / UK GDPR)

Where we act as controller, we rely on:

  • Performance of a contract (Art. 6(1)(b)): operating the service, accounts, billing, support.
  • Legal obligation (Art. 6(1)(c)): accounting and tax retention, responding to lawful requests.
  • Legitimate interests (Art. 6(1)(f)): product analytics, service improvement, security and abuse prevention, error monitoring, and business communications to merchants. You can object at any time.
  • Consent (Art. 6(1)(a)): marketing cookies on our websites and, where required, marketing communications. You can withdraw consent at any time.

4. Billing

We do not store payment card details. Billing runs through:

  • Shopify: Shopify's billing system, with subscription management through Mantle.
  • Shopline: Shopline's billing system, where available.
  • WooCommerce and PrestaShop: Polar, acting as merchant of record.
  • Try-On API and consumer credits: Stripe.

5. Data retention

  • Uploaded photos and generated images (all channels): automatically deleted after the configured retention window, 7 days at most (1 or 3 days where configured). Unprocessed originals are deleted within 1 day.
  • Merchant data (Shopify/Shopline): your access tokens are deleted when you uninstall. When you uninstall our last app, everything we hold about your shoppers goes with it: shopper records, try-on history, order and refund analytics, and your synced catalog. Your store record itself is kept, meaning your settings and installation history, so a reinstall picks up where you left off. About 48 hours later the platform's redaction webhook removes your shoppers' data from our analytics warehouse as well. What remains is a record of how much our engine ran for your store, with every shopper identifier stripped, which we keep for billing and accounting.
  • Dashboard and API accounts: kept while your account is active; deleted on request at privacy@genlook.app.
  • Billing records: up to 10 years, as required by French accounting and tax law.
  • Usage analytics: widget and storefront events up to 13 months; order analytics 12 months; refund analytics up to 3 years; generation logs up to 2 years.
  • Security and abuse-prevention signals (hashed, non-identifying): as long as needed to protect the service.
  • Support communications: for as long as needed to provide support and maintain business records, reviewed periodically.

6. Service providers (subprocessors)

We share personal data with the following providers, only as needed to run the service:

ProviderPurposeLocation
Google Cloud (Storage, BigQuery)Image storage, analytics warehouseEU
Google Cloud (Vertex AI, Gemini)AI image generationGlobal (Google-managed regions)
Comfy CloudAI image generation (specialized engine)US
RenderApplication, database, and ML service hostingEU (Frankfurt)
VercelWebsite and dashboard hostingUS
ClerkDashboard authenticationUS
StripePayments (API and consumer credits)US
MantleShopify subscription managementUS
PolarMerchant-of-record billing (Woo/PrestaShop)US
Shopify / ShoplinePlatform and billingGlobal
PostHogProduct analyticsEU
SentryError monitoringEU (Germany)
CrispSupport chatEU (France)
Customer.ioMerchant email communicationsEU
KlaviyoMarketing events, only when you connect itUS
DiscordInternal operations alerts (shop domain and tool usage)US
CloudflareCDN for widget files (no personal data)Global

An up-to-date list is also maintained in the DPA annex and available at privacy@genlook.app.

7. International transfers

We host applications, databases, image storage, and our own ML services in the European Union. Error monitoring (Sentry), product analytics (PostHog), support chat (Crisp), and merchant email communications (Customer.io) also run in the EU. Some processing happens outside the EEA: AI image generation on Google Vertex AI uses Google's global serving endpoint, so a given request may be processed in the United States or another Google Cloud region; the specialized Comfy Cloud generation engine is operated from the United States; and website hosting (Vercel), authentication (Clerk), payments (Stripe, Mantle, Polar), and operations alerts (Discord) run in the United States. Where personal data leaves the EEA or UK, we rely on appropriate safeguards under Chapter V GDPR, primarily the European Commission's Standard Contractual Clauses in our providers' data-processing terms and, where the provider is certified, the EU-US Data Privacy Framework. Details: privacy@genlook.app.

8. Your rights

European Union, United Kingdom, and similar regimes: access, rectification, erasure, restriction, portability, objection (including to marketing), withdrawal of consent, and the right to lodge a complaint with your supervisory authority. Our lead authority is the French CNIL (cnil.fr).

United States (California CCPA/CPRA and other state laws): the right to know and access, correct, and delete your personal information, and to opt out of "sale" or "sharing". We do not sell personal information and do not share it for cross-context behavioral advertising; our website marketing cookies load only with your consent, and we honor the Global Privacy Control signal. We do not discriminate against you for exercising your rights.

Other jurisdictions (for example Canada PIPEDA, Brazil LGPD, Australia Privacy Act): the equivalent access, correction, and deletion rights under your local law.

To exercise any right, email privacy@genlook.app. We respond within one month, or sooner where your local law requires. If your request concerns shopper data controlled by a merchant, we will assist or redirect it to that merchant.

9. Data Processing Agreement

When you offer Genlook try-on to your customers, you are the controller of their data and we process it on your behalf (GDPR Art. 28 and equivalent laws). Our Data Processing Agreement, including security measures and the subprocessor list, is incorporated into our Terms of Service for all platforms and available at privacy@genlook.app.

10. Informing your customers (template)

You should mention the try-on feature in your own store's privacy policy. You can adapt this text:

Virtual Try-On. Our store uses Genlook, a virtual try-on service. If you choose to use it, you will be asked to upload a photo, which is processed by AI to generate a try-on image after you agree on the upload screen. Photos and results are automatically deleted after at most 7 days and are never used to train AI models. We (the store) never receive access to your photos. See the Genlook Shopper Privacy Policy.

11. Cookies and analytics on genlook.app

When you visit genlook.app, a consent banner is shown based on your region (opt-in in the EU/EEA, UK, and Switzerland; notice elsewhere), and we honor the Global Privacy Control signal.

  • Analytics (loaded only with consent where required): PostHog (EU, via our first-party proxy) and Google Analytics.
  • Marketing (loaded only with consent where required): Meta Pixel, for measuring our ads.
  • Support chat: Crisp, loaded only when you open the chat, so no chat cookies are set until you choose to use it.

You can change your choice at any time via the cookie settings link in the site footer. Your choice is remembered for 12 months, after which we ask again.

12. Security

Data is encrypted in transit (TLS) and at rest. Platform access tokens are stored encrypted. Access to production data is restricted and protected with multi-factor authentication. Our Information Security Policy is available on request.

13. Children

Our services are for businesses and adults; you must be 18 or older to hold an account. For protections applying to shoppers, see the Shopper Privacy Policy.

14. Changes to this policy

When we make material changes we update the Effective Date above and, where appropriate, notify you in-app or by email.

15. Contact

Parakeet Labs SASU (operating as Genlook) 4 Rue de la République, 69001 Lyon, France RCS Lyon, SIREN 105 375 349