1. Controller and Contact
2. Our Role and the Merchant’s Role
When a customer uses HomeVisioner through a merchant’s online store, the merchant decides to offer the feature and determines the purposes for which customer data is processed in connection with its store. In this context, the merchant is generally the data controller and HomeVisioner acts as a data processor on the merchant’s documented instructions.
Where HomeVisioner acts as a processor, processing is also governed by the HomeVisioner Data Processing Addendum, which forms part of the agreement between HomeVisioner and the merchant.
HomeVisioner is independently responsible for processing certain data relating to its own business operations, including merchant account administration, billing, service security, and legal compliance.
The merchant’s own privacy policy also applies to the merchant’s processing of personal data. Customers should contact the relevant merchant first for requests relating to data processed through that merchant’s store. HomeVisioner will assist the merchant where required.
3. Personal Data We Process
Depending on how HomeVisioner is used, we may process:
- Room images uploaded by customers to create a visualization;
- Product images and product information supplied by the merchant’s store;
- AI-generated visualizations created from room and product images;
- Merchant account and store information, such as store domain, account details, app configuration, plan, and billing-related information;
- Technical data, such as IP address, date and time of access, browser type, operating system, requested pages or services, and security or error logs;
- Authentication and session information required to provide secure access to the service; and
- Email address information where a merchant separately offers an optional email or marketing consent feature.
We do not intentionally use uploaded room images or generated visualizations to identify individuals or create biometric identifiers.
4. Purposes and Legal Bases
We process personal data only where necessary for the following purposes:
- Providing AI-powered room and product visualizations;
- Operating, maintaining, securing, and improving HomeVisioner;
- Administering merchant accounts, subscriptions, and payments;
- Responding to support requests;
- Preventing abuse, fraud, and technical failures;
- Complying with legal obligations; and
- Handling legal claims where necessary.
For merchant account, subscription, and payment-related data, processing may be necessary for the performance of a contract or to take steps before entering into a contract under Article 6(1)(b) GDPR. For service security, fraud prevention, and stable technical operation, we may rely on our legitimate interests under Article 6(1)(f) GDPR.
For customer room images and generated visualizations processed through a merchant’s store, the relevant merchant is responsible for determining and communicating the applicable legal basis. Where consent is required, processing takes place only after the required consent has been obtained.
5. AI Processing
Customers may upload a room image to generate an AI-powered visualization of a product in that room. The room image and relevant product image are processed only to provide the requested visualization.
HomeVisioner does not use uploaded room images or generated visualizations to train or improve AI models. HomeVisioner does not authorise its service providers or subprocessors, including Google Cloud and Google AI services, to use those images or visualizations to train or improve AI models.
Generated visualizations are not publicly displayed by HomeVisioner unless the customer chooses to share them through a feature made available for that purpose.
6. Merchant Access to Generated Visualizations
The merchant operating the store through which a customer uses HomeVisioner may access the AI-generated visualization created through that store in the HomeVisioner merchant administration area.
This access is limited to the merchant’s authorised users and is provided so the merchant can operate the HomeVisioner feature, respond to customer-support requests, and administer the feature for its store. The merchant does not receive access through this feature to the customer’s original uploaded room image.
Generated visualizations may contain personal data, for example where a room image includes an identifiable person or personal belongings. Merchants must handle generated visualizations in accordance with applicable data-protection law and their own privacy notice. Generated visualizations must not be used for advertising or promotional purposes.
7. Sharing a Visualization
A customer may choose to share a generated visualization from the store where it was created. Sharing is always started by the customer: nothing is published unless the customer uses the share function on their own result.
When a customer shares a result, the visualization becomes reachable at an unlisted HomeVisioner web address. The address contains a randomly generated identifier that cannot be guessed, and the page is excluded from search-engine indexing. Anyone who receives the link can open the page, so customers should only send it to people they intend to show the visualization to.
The shared page displays the generated visualization together with the title of the product it was created for, the store it is available from, and a link back to that product page. It does not display the customer’s original uploaded room image, and it does not display any account or contact details of the customer.
The shared visualization is deleted at the end of the retention period described in section 11 below. Customers who want it removed sooner can contact HomeVisioner or the relevant merchant and provide the share link or another reliable technical identifier.
The Shopify integration does not require a HomeVisioner customer account. An anonymous room image therefore cannot normally be matched to an individual using only a name or email address. If no share link or other reliable identifier is available, the image remains subject to the standard automatic retention period.
8. Email Marketing
A merchant may offer customers the option to provide an email address or to consent to marketing communications. Marketing emails may be sent only where the customer has given separate, explicit consent where required by applicable law. Consent for marketing must not be preselected and may be withdrawn at any time.
The merchant is responsible for its own marketing communications and for complying with applicable marketing and privacy laws. HomeVisioner does not use uploaded room images or generated visualizations for marketing or advertising.
9. Service Providers and Data Sharing
We use the following service providers to operate HomeVisioner:
- Shopify, to provide the app within the merchant’s Shopify store;
- Google Cloud, including Google AI services, for AI processing and related cloud infrastructure;
- Supabase, for database and related service infrastructure in the EU;
- Resend, for transactional and service-related email delivery;
- Crisp, for merchant support communications;
- Cloudflare, for network security and content delivery; and
- Stripe, for payment processing relating to paid services and subscriptions.
These providers process personal data only as necessary to provide their services to us and subject to applicable contractual safeguards. We may also disclose personal data where required by law, to protect legal rights, or to prevent fraud or security incidents.
We do not sell personal data and do not disclose personal data to third parties for their own advertising purposes.
10. International Data Transfers
HomeVisioner’s primary application and image-storage infrastructure is operated in European Union regions. We also use established international service providers, including Google Cloud, to deliver the service.
Where personal data is transferred outside the European Economic Area, we ensure that an appropriate transfer mechanism is in place, such as an adequacy decision, Standard Contractual Clauses, or another lawful safeguard under applicable data-protection law.
For individuals in Australia, personal information may be processed by contracted service providers located outside Australia. HomeVisioner applies contractual, technical, and organisational safeguards and assists merchants with applicable Australian privacy requests where required.
11. Retention Periods
Uploaded room images and AI-generated visualizations are retained for up to 30 days and are then automatically deleted, unless a longer retention period is required by law or necessary for the establishment, exercise, or defence of legal claims.
Merchant account, billing, and transaction-related information may be retained for as long as necessary to provide the service, meet tax or accounting obligations, resolve disputes, and enforce agreements. Technical and security logs are retained only for as long as necessary for security, troubleshooting, and operational purposes.
12. Cookies and Similar Technologies
HomeVisioner uses technically necessary cookies or similar technologies where needed to provide core functions such as login, session management, security, and service operation.
HomeVisioner does not use uploaded room images or generated visualizations for advertising tracking. If non-essential cookies or analytics technologies are introduced in the future, we will provide any notice and obtain any consent required by applicable law before using them. A merchant’s store may use its own cookies, tracking technologies, and consent tools; those are governed by the merchant’s own privacy and cookie notices.
13. Your Rights
Subject to applicable law, individuals may have the right to:
- Access their personal data;
- Request correction or deletion of personal data;
- Request restriction of processing or receive data in a portable format;
- Object to certain processing;
- Withdraw consent at any time, where processing is based on consent; and
- Lodge a complaint with a competent data-protection supervisory authority.
Where a customer uses HomeVisioner through a merchant’s store, the customer should normally contact that merchant first. Customers may also contact HomeVisioner at [email protected], and we will assist where required.
14. Shopify Data Requests and Deletion
Where applicable, HomeVisioner processes Shopify privacy-related data requests and deletion requests in accordance with Shopify’s required privacy webhooks and applicable law. This includes requests relating to customer data, shop data, and app removal. Generated visualizations associated with a relevant request are included within the applicable deletion process.
15. Security
We use appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration, and disclosure. No internet-based service can guarantee absolute security, but we take reasonable steps to protect the data processed through HomeVisioner.
16. People, Faces, and Children
Customers must not upload room images containing people or children. HomeVisioner uses an automated image-safety control designed to detect human faces before an image is accepted for AI processing. Where a face is detected, the upload is rejected and the customer is asked to provide a room photo without people.
This safety control is used only to prevent images containing people from being processed. It is not used to identify individuals, perform facial recognition, or create biometric identifiers or biometric templates.
Automated detection cannot guarantee that every person, face, or potentially identifying detail will be detected. If such an image is processed despite the control, it is processed only as necessary to provide the requested visualization and remains subject to this Privacy Policy’s retention period. The original room image is not made available to the merchant through the HomeVisioner administration area.
Images and generated visualizations containing people or children must not be used for advertising, marketing, profiling, facial recognition, or AI-model training.
17. Changes to This Privacy Policy
We may update this Privacy Policy to reflect legal, technical, or operational developments. The updated version will be published with a revised “Last updated” date.
