Security & compliance

The answers your
procurement team asks.

We handle foot scans and try-on photos, so these are real questions rather than a formality. Everything below is drawn from documents we already sign or publish - the DPA, the privacy policy and our Accessibility Conformance Report - so you can hold us to it.

01Where your data lives

Not a single country, and we won't pretend otherwise.

Some vendors lead with “EU-hosted”. We can’t match that literally, so here is the actual picture. What we have instead is a legal status rather than an infrastructure claim, and for an EMEA procurement team it travels further: StrutFit is a New Zealand company, and New Zealand holds a European Commission adequacy decision - one of around fifteen countries that does.

Sub-processors
WhoWhat they processWhere
Amazon Web ServicesStorage of client data, including product information and transactionsEurope
SupabaseManaged database hosting of application dataUSA
OpenAIFind - product discovery and ranking. Zero-retention enabled. Data is not stored or used for model training.USA
GoogleImage processing. Transient processing only. No permanent storage of biometric signals.USA

We give 30 days notice before adding a sub-processor or changing what one processes. If you object, you can terminate within 30 days regardless of your remaining term.

Transfers outside the EEA rely on an adequacy decision (New Zealand holds one), the EU-US Data Privacy Framework, or the Standard Contractual Clauses in our DPA.

02What happens to photos and scans

Three products, three different answers.

These get blurred together constantly, usually in the vendor’s favour. They’re not the same, so here they are separately.

AR try-on, live camera

Nothing is captured at all. All camera processing happens entirely on the shopper's device, in real time, and is discarded immediately when the session ends. No biometric data is derived, extracted or retained. No GDPR Article 9 special-category processing occurs and no CCPA biometric information is collected.

Photo-based try-on

Generated try-on images are deleted within 48 hours. Google processes them transiently, with no permanent storage of biometric signals.

Foot scans and measurements

Retained as the shopper's own profile until they delete it. Session and interaction data is retained for up to 24 months, then anonymised or deleted.

03What we don't do with it

Precisely, rather than with a blanket denial.

“We never use your data” would be easier to say and it would be false - it would also contradict our own “scanned once, sized everywhere” network. The true version is more useful to you anyway.

  • We never use identifiable personal data for model training. Improvement uses anonymised, aggregated data only.
  • OpenAI runs zero-retention on our account and does not train on our data.
  • A shopper's profile is shared only with the retailer they used it on.
  • No selling, no sharing, and no cross-context behavioural advertising. We operate as a CCPA service provider.
04How we secure it

Contractual commitments, not intentions.

48-hour breach notification
Annual independent penetration testing, with remediation of significant findings
Right to audit
30 days notice on sub-processor changes, with a termination right if you object
TLS in transit, encryption at rest
Two-factor authentication and periodic access review
Employee screening
EU AI Act

StrutFit is compliant. We tell shoppers when they’re interacting with AI, and no biometric identification takes place - Size works from measurements, and the AR try-on never captures or retains an image.

Accessibility

The StrutFit Sizing Application conforms to WCAG 2.2 Level AA and EN 301 549 V3.2.1, the harmonised European standard behind the EU Accessibility Act.

151 Supports, 47 Not Applicable, and zero Partially Supports, Does Not Support or Not Evaluated.

05Documents and contacts

Ask and we'll send it.

Data Processing Agreement

Effective 17 July 2026. Covers Module Two Standard Contractual Clauses, the UK Addendum and the Swiss FADP, and includes the sub-processor table above.

Request from nish@strut.fit
Privacy Policy

Covers both shopper data (Part A) and business customer data (Part B), including retention, shopper rights and the New Zealand adequacy position.

Read it
Terms of Service

The agreement between StrutFit and you as a customer. Effective 18 May 2026, covering billing, liability, data, IP and termination.

Read it
Accessibility Conformance Report

VPAT 2.5Rev format, report date June 2025. Covers the StrutFit Sizing Application.

Request from dev@strut.fit
Sub-processor list

Published on this page, and in every DPA we sign.

Privacy contact: nish@strut.fit. Accessibility contact: dev@strut.fit. Evaluating StrutFit and need something specific in writing? Ask us.

FAQ

Procurement questions, answered

Where is shopper data hosted?

Client and product data is stored with Amazon Web Services in Europe. Application database hosting is with Supabase in the USA, Find uses OpenAI and Try uses Google, both in the USA. We don't claim to be EU-hosted, because that wouldn't be accurate. What we do have is a legal status rather than an infrastructure claim: StrutFit is a New Zealand company, and New Zealand holds a European Commission adequacy decision. Transfers to US sub-processors rely on that adequacy, the EU-US Data Privacy Framework, or the Standard Contractual Clauses in our DPA.

Are try-on photos and foot scans deleted?

It depends which one, and the three answers are genuinely different. Live camera AR captures nothing at all - processing happens on the shopper's device and is discarded when the session ends, so there is no image to delete. Photo-based try-on images are deleted within 48 hours. Foot scans and measurements are kept as the shopper's own profile until they delete it, with session data retained up to 24 months and then anonymised or deleted.

Do you train models on our shoppers' data?

Not on identifiable data, ever. Accuracy improvements use anonymised, aggregated data only. OpenAI runs zero-retention on our account and does not train on our data. We won't claim we never use data at all, because that would be false and would contradict our own 'scanned once, sized everywhere' network: a shopper's profile follows the shopper, not the brand, and it is shared only with the retailer they used it on.

Is a DPA available, and do you publish your sub-processors?

Both. The DPA is dated 17 July 2026 and covers Module Two Standard Contractual Clauses, the UK Addendum and the Swiss FADP. The sub-processor list is published on this page. We give 30 days notice before adding a sub-processor or changing what one processes, and if you object you can terminate within 30 days regardless of your remaining term.

What is your position on the EU AI Act?

StrutFit is compliant. We tell shoppers when they're interacting with AI, and no biometric identification takes place - Size works from measurements, and the AR try-on never captures or retains an image.

Is StrutFit accessible?

The StrutFit Sizing Application conforms to WCAG 2.2 Level AA and EN 301 549 V3.2.1, the harmonised European standard behind the EU Accessibility Act. The Accessibility Conformance Report recorded 151 Supports, 47 Not Applicable, and zero Partially Supports, Does Not Support or Not Evaluated criteria. The report is a self-assessment in VPAT 2.5Rev format, which is the standard and accepted form, and it scopes to the Size module rather than the whole platform. Request it from dev@strut.fit.

How quickly would you tell us about a breach?

Within 48 hours. That commitment is in the DPA, alongside annual independent penetration testing with remediation of significant findings, and your right to audit.

Right now, shoppers are guessing their size, struggling to find what they want, and buying blind.

Yours don't have to be.
Free trials includedShopify · Magento · Salesforce · customTrusted by world leading brands