Not a single country, and we won't pretend otherwise.
Some vendors lead with “EU-hosted”. We can’t match that literally, so here is the actual picture. What we have instead is a legal status rather than an infrastructure claim, and for an EMEA procurement team it travels further: StrutFit is a New Zealand company, and New Zealand holds a European Commission adequacy decision - one of around fifteen countries that does.
We give 30 days notice before adding a sub-processor or changing what one processes. If you object, you can terminate within 30 days regardless of your remaining term.
Transfers outside the EEA rely on an adequacy decision (New Zealand holds one), the EU-US Data Privacy Framework, or the Standard Contractual Clauses in our DPA.
Three products, three different answers.
These get blurred together constantly, usually in the vendor’s favour. They’re not the same, so here they are separately.
Nothing is captured at all. All camera processing happens entirely on the shopper's device, in real time, and is discarded immediately when the session ends. No biometric data is derived, extracted or retained. No GDPR Article 9 special-category processing occurs and no CCPA biometric information is collected.
Generated try-on images are deleted within 48 hours. Google processes them transiently, with no permanent storage of biometric signals.
Retained as the shopper's own profile until they delete it. Session and interaction data is retained for up to 24 months, then anonymised or deleted.
Precisely, rather than with a blanket denial.
“We never use your data” would be easier to say and it would be false - it would also contradict our own “scanned once, sized everywhere” network. The true version is more useful to you anyway.
- We never use identifiable personal data for model training. Improvement uses anonymised, aggregated data only.
- OpenAI runs zero-retention on our account and does not train on our data.
- A shopper's profile is shared only with the retailer they used it on.
- No selling, no sharing, and no cross-context behavioural advertising. We operate as a CCPA service provider.
Contractual commitments, not intentions.
StrutFit is compliant. We tell shoppers when they’re interacting with AI, and no biometric identification takes place - Size works from measurements, and the AR try-on never captures or retains an image.
The StrutFit Sizing Application conforms to WCAG 2.2 Level AA and EN 301 549 V3.2.1, the harmonised European standard behind the EU Accessibility Act.
151 Supports, 47 Not Applicable, and zero Partially Supports, Does Not Support or Not Evaluated.
Ask and we'll send it.
Effective 17 July 2026. Covers Module Two Standard Contractual Clauses, the UK Addendum and the Swiss FADP, and includes the sub-processor table above.
Request from nish@strut.fitCovers both shopper data (Part A) and business customer data (Part B), including retention, shopper rights and the New Zealand adequacy position.
Read itThe agreement between StrutFit and you as a customer. Effective 18 May 2026, covering billing, liability, data, IP and termination.
Read itVPAT 2.5Rev format, report date June 2025. Covers the StrutFit Sizing Application.
Request from dev@strut.fitPublished on this page, and in every DPA we sign.
Privacy contact: nish@strut.fit. Accessibility contact: dev@strut.fit. Evaluating StrutFit and need something specific in writing? Ask us.
Procurement questions, answered
Where is shopper data hosted?
Client and product data is stored with Amazon Web Services in Europe. Application database hosting is with Supabase in the USA, Find uses OpenAI and Try uses Google, both in the USA. We don't claim to be EU-hosted, because that wouldn't be accurate. What we do have is a legal status rather than an infrastructure claim: StrutFit is a New Zealand company, and New Zealand holds a European Commission adequacy decision. Transfers to US sub-processors rely on that adequacy, the EU-US Data Privacy Framework, or the Standard Contractual Clauses in our DPA.
Are try-on photos and foot scans deleted?
It depends which one, and the three answers are genuinely different. Live camera AR captures nothing at all - processing happens on the shopper's device and is discarded when the session ends, so there is no image to delete. Photo-based try-on images are deleted within 48 hours. Foot scans and measurements are kept as the shopper's own profile until they delete it, with session data retained up to 24 months and then anonymised or deleted.
Do you train models on our shoppers' data?
Not on identifiable data, ever. Accuracy improvements use anonymised, aggregated data only. OpenAI runs zero-retention on our account and does not train on our data. We won't claim we never use data at all, because that would be false and would contradict our own 'scanned once, sized everywhere' network: a shopper's profile follows the shopper, not the brand, and it is shared only with the retailer they used it on.
Is a DPA available, and do you publish your sub-processors?
Both. The DPA is dated 17 July 2026 and covers Module Two Standard Contractual Clauses, the UK Addendum and the Swiss FADP. The sub-processor list is published on this page. We give 30 days notice before adding a sub-processor or changing what one processes, and if you object you can terminate within 30 days regardless of your remaining term.
What is your position on the EU AI Act?
StrutFit is compliant. We tell shoppers when they're interacting with AI, and no biometric identification takes place - Size works from measurements, and the AR try-on never captures or retains an image.
Is StrutFit accessible?
The StrutFit Sizing Application conforms to WCAG 2.2 Level AA and EN 301 549 V3.2.1, the harmonised European standard behind the EU Accessibility Act. The Accessibility Conformance Report recorded 151 Supports, 47 Not Applicable, and zero Partially Supports, Does Not Support or Not Evaluated criteria. The report is a self-assessment in VPAT 2.5Rev format, which is the standard and accepted form, and it scopes to the Size module rather than the whole platform. Request it from dev@strut.fit.
How quickly would you tell us about a breach?
Within 48 hours. That commitment is in the DPA, alongside annual independent penetration testing with remediation of significant findings, and your right to audit.