WONOM Showroom
Privacy policy
Updated 17 September 2026 · Eesti keeles
This policy describes what personal data WONOM Showroom processes, why, for how long and who receives it. The first part is about stores that use the dashboard, the second about shoppers who use the try-on button.
1. Who we are and in what role
WONOM Showroom is provided by Wonom Digital OÜ (registry code 17580154, Juhkentali 8-5, 10132 Tallinn, Estonia). Data protection contact: privacy@wonomdigital.com.
- For store account data (dashboard, billing, e-mails) we are the controller.
- For shoppers' data (the try-on button on the store's page) the store is the controller and we are the processor, under the data processing agreement. If you are a shopper and want to know about your data, contact the store; we help the store answer.
2. Store account data
| Data | Why | How long |
|---|---|---|
| E-mail address, name (optional), password hash (scrypt), when the account was created | Account and login | Until the account is closed |
| Which version of the terms, privacy policy and data processing agreement you accepted at sign-up, and when | Proof of acceptance | Until the account is closed |
| Sign-up in progress: e-mail, password hash, name and confirmation code | Confirming the e-mail address | 30 minutes |
| Login session (stored only as a hash) | Staying logged in | 30 days or until you log out |
| Password reset link (stored only as a hash) | Resetting a password | 1 hour |
| IP address or e-mail address in an attempt counter | Limiting abuse (sign-up, login, reset) | Up to 1 hour |
| Plan, dates, Stripe customer and subscription ids, packs bought | Billing and allowance | Until the account is closed |
| Stores: name, domains, keys, settings and notification e-mail | Providing the service | Until the store is deleted or the account closed |
| Domain verification: when and how the domain was verified (meta tag or DNS). To check, we read the store's public front page and the domain's DNS records. | Protecting the key: the fitting button works only on a verified domain | Until the domain is removed, the store deleted or the account closed |
| Verified domain name, time of first verification and a one-way hash of the account id (no e-mail or name) | One free trial per domain (limiting abuse) | 2 years after the domain is removed, the store deleted or the account closed |
| Usage counters and the store's latest 500 events (no shopper identifiers, see section 3) | Dashboard figures and allowance | Up to 400 days; deleted when the account is closed |
| Invoices and payments | Accounting | 7 years at Stripe and in our accounting (Estonian Accounting Act) |
We never see or store card details: payment happens on Stripe's page. E-mails (confirmation code, password reset, store ready, purchases and allowance warnings) are sent through Resend. We receive a notice with the account's e-mail address when an account is created, a purchase is made, an account is closed or a payment fails.
Our application logs record an IP address only in shortened form (failed login, reset request for an unknown address). Our hosting providers' request logs may briefly show the full IP address under their own terms.
3. Shoppers' data through the try-on button
| Data | What happens to it | How long |
|---|---|---|
| The shopper's photo | Sent to Google's Gemini models to check the photo and make the look. It is not written to our disk or database. | With us only during the request; at Google, see subprocessors |
| The finished look | Sent to the shopper's browser and to Google for a check. If the shopper asks for a video, the look goes to Google's video model (Veo) or to fal.ai (Kling). | With us only during the request |
| The finished video | Kept on our server at a random 32-character address so the shopper can get and share it. | Up to 1 hour, then deleted automatically |
| Visitor tag: a keyed hash of the IP address (12 characters) | The shopper's daily limit and checking a video's completion. The tag is also inside the 30-minute session token. | Counters 36 hours, video receipt 24 hours |
| IP address | One-minute abuse brake in the server's memory | Up to 1 minute; never written to disk |
| Product page: address, name, images and description | Read from the store's page to make the look | During the request; the product address or name stays in the event list |
| Events: time, kind, product, model, duration, order value | The store's dashboard figures. No shopper identifier, IP address or browser data. | The store's latest 500 events; deleted when the account is closed |
| Order (only with the WordPress plugin's server key): value of tried products, order hash, product addresses | The fitting room's effect on revenue. No buyer name, address or e-mail is sent. | Value in the event list; order hash for 30 days to prevent double counting |
Shoppers' photos and looks are never used for marketing or to train AI. The store's dashboard shows numbers, not people.
4. What is stored on the shopper's device
- The widget's terms version (
sr_terms), so the terms are not asked every time. - Only if the shopper ticks the remember box in the terms window: the time of that choice (
sr_keep), the photo (sr_photo) and the looks made (databaseshowroom), for 30 days at most. After 30 days they are never used again, and the fitting room erases them the next time it is opened on that device — browser storage has no expiry of its own and only that window can reach it. “Forget my photo” deletes them at once. Without it, the photo and looks live only in the open window. - The chosen theme, until the session ends (
sr_theme). - On the store's page, to count add-to-cart clicks and revenue: the cookie
wonom_sr_tried(product number and time) and the mapsr_tried(product address and time), both for 14 days. They are written only with the shopper's consent, as the store has set it up, and deleted when the shopper withdraws consent.
The widget's fonts come from our own server, not from Google Fonts. We use no third-party tracking cookies or advertising pixels.
5. Dashboard cookies
wonom_sr_sid: login session (httpOnly, 30 days).wonom_sr_pending: sign-up in progress (httpOnly, 30 minutes).wonom_sr_lang: dashboard language (1 year).
These are needed for the service to work, so no consent is asked for them.
6. Legal basis
- Store account data: the contract (providing and billing the service), the Accounting Act (invoices) and legitimate interest (limiting abuse and security).
- Shoppers' data: the store decides the basis. Before the first fitting the widget asks the shopper to accept its terms, and separately for permission to keep anything on the device. The store's consent banner asks for the measurement cookie.
7. Who receives data
We use subprocessors to provide the service: image and video models, hosting, database, e-mail and payments. The list, with locations and data, is on the subprocessors page. Where data leaves the European Economic Area, we rely on the EU Standard Contractual Clauses or the EU-U.S. Data Privacy Framework. We do not sell data.
8. Your rights
You have the right to access your data, correct it, have it deleted, restrict its processing, receive it in a machine-readable form and object to its processing. You can download your account data as a JSON file from the dashboard's Account page, and close the account there too. Otherwise write to privacy@wonomdigital.com; we answer within 30 days. You can complain to the Estonian Data Protection Inspectorate (aki.ee).
9. Security
Data travels encrypted (TLS). Passwords, sessions and reset links are stored as hashes. The store's server key is shown once in your dashboard, when it is created or rotated, and never reaches a shopper's page. Videos sit at unguessable addresses, are deleted within the hour and are never cached or indexed. Access to a store's data is checked on every request.
10. Children
The dashboard is for businesses and the try-on button for adults. Stores must not offer fittings on products made for children. If we learn that a minor's photo was used for a fitting, we act to stop the misuse.
11. Changes
We give registered stores notice of material changes by e-mail at least 30 days in advance. Every version is dated, and sign-up records which version was accepted.