Security and Data Handling

Every merchant evaluating try-on asks the same question first: What happens to my customers' photos? Here is the complete, transparent answer.

Encrypted in Transit

Every photo uploaded online or captured in store is transmitted via TLS 1.3 encryption directly to our dedicated processing nodes.

Processed in Memory

Our neural rendering engine processes garments directly in temporary GPU memory. We never retain customer photos and never train AI models on them.

Immediately Deleted

Once the rendered output is delivered to the shopper's session, the input image is permanently destroyed. If you asked us for a copy tomorrow, we would not have one.

What happens to a shopper's photo

It is encrypted in transit, processed to generate the render, and then deleted. We do not retain it. We do not train models on it.

If you asked us for a copy of a shopper's photo tomorrow, we would not have one to give you. Zero retention is our structural guarantee.

What we do store

  • The rendered output for as long as the shopper's active session needs it to display the garment.
  • Aggregated, anonymized render counts for monthly merchant billing and quota tracking.
  • Never the original raw source photo or biometric profiles.

Why zero retention is a design choice, not a policy

A corporate policy can change. An architecture is harder to walk back, which is why this is worth understanding rather than just believing.

The render pipeline produces an output and discards the input. There is no photo database to secure, no retention schedule to enforce, no deletion request to process, and no historical archive that could ever be compromised. The safest way to hold customer photos is not to hold them.

The practical effect for you: a question about customer image privacy has an unambiguous answer, and any customer deletion request is already satisfied before it is submitted.

In-Store Hardware

The LookCheck AI Smart Mirror

The same zero-retention rule applies in store. The Smart Mirror's dual camera captures a front and side view, processes them to produce the render and measurement, and immediately purges them.

Nothing is kept locally on the physical mirror device, ensuring in-store customer privacy is inviolable.

Who controls what

You are the data controller for your shoppers. We are the data processor, acting strictly on your instructions.

Audited Standards

ISO 27001:2022 Certified

Rendream holds official ISO 27001:2022 information security certification, ensuring enterprise-grade management controls, cryptographic standards, and vulnerability protocols.

ISO 27001:2022 Certified

Questions procurement and compliance teams ask

Do you train models on our customers' images?

No. Images produce the render that was requested and are then deleted. We do not use merchant or customer assets to train foundation models.

Where is processing done, and can we get a data processing agreement (DPA)?

Both are handled per deployment. Tell us your regional requirements and we will send our current DPA documentation before you commit to anything.

What is your incident response process?

Our incident response protocol is audited under Rendream's ISO 27001:2022 certification. We will gladly walk your security and compliance team through the details upon request.

Does the widget affect our own compliance posture?

The widget executes on your storefront, but image processing runs entirely on our isolated GPU cloud. Customer photos do not sit or rest in your servers or database either.

Who do we contact for security reviews?

Submit an inquiry via our contact form and select 'Security Review'. It routes directly to our technical and compliance leadership rather than sales.

Need a custom Security Review or DPA?

Contact our compliance team to receive technical architecture whitepapers, DPA templates, and penetration test overviews.