Security & Privacy at Ello

Ello Virtual Try-On adds an AI try-on to online-store product pages: a shopper uploads a photo and sees the product on themselves before buying. This page describes how Ello protects that photo and the merchant's data. In short: shopper photos are processed in memory and never stored, all data is encrypted in transit and at rest, and Ello runs on SOC 2 and ISO 27001 certified infrastructure.

How Ello handles shopper photos

A shopper's uploaded photo is held in memory only for the seconds it takes to render the try-on, then discarded. It is never written to Ello's databases or object storage, and never used to train any AI model. The finished try-on image is saved only in the shopper's own browser, on their device, unless they delete it. AI rendering runs on Google Cloud under paid-tier terms that prohibit using inputs to train Google's models; the fallback provider stores no inputs and deletes results within 60 minutes.

Platform security practices

Sub-processors and inherited compliance

Ello runs on Google Cloud (SOC 1/2/3, ISO 27001/27017/27018, PCI DSS), Supabase (SOC 2 Type II), Cloudflare (SOC 2, ISO 27001, PCI DSS), Vercel (SOC 2 Type II), Shopify (PCI DSS Level 1), and FASHN.ai (no input storage, results deleted within 60 minutes). Payments are handled by Shopify and Stripe, both PCI DSS Level 1.

Privacy and compliance

Ello acts as a data processor and CCPA service provider, with a Data Processing Addendum (EU Standard Contractual Clauses plus the UK Addendum) available to sign, a published sub-processor list, and Shopify's mandatory GDPR compliance webhooks implemented and HMAC-verified. Ello requests Shopify protected customer data at Level 1 only and reads no name, email, phone, or address fields. The Ello widget never loads on checkout or payment pages, so Ello is out of PCI scope.

Biometric privacy (BIPA, CUBI)

Ello does not create, store, or match a face template or faceprint and does not identify anyone — it renders how a product looks on a photo the shopper chose to upload. Shoppers see a consent notice before any upload, nothing is retained, and Ello's approach is documented in a written biometric policy available on request.

Frequently asked questions

Does Ello store shoppers' photos?

No. A shopper's uploaded photo is processed in memory only to render the try-on, then discarded — it is never written to Ello's databases or storage. The finished try-on image is saved only in the shopper's own browser, and photos are never used to train AI models.

Is Ello SOC 2 or ISO 27001 certified?

Ello runs entirely on SOC 2 and ISO 27001 certified infrastructure (Google Cloud, Supabase, Cloudflare, Vercel). Ello's own SOC 2 examination is on the roadmap ahead of enterprise contracts; a Security Overview, Data Processing Addendum, and sub-processor list are available on request at security@ellotryon.com.

Does the Ello widget run on the checkout page?

No. The widget only runs on product pages, never on checkout or payment pages, and Ello never sees card data. Ello is out of PCI scope.

Contact the security team at security@ellotryon.com or read the Privacy Policy.