Uverest Privacy Policy

Last revised: 10 July 2026
Company (Controller): MTLAB, Inc. ("Uverest", "we", "us", "our")
Registered Address: 1111B S Governors Ave, STE 20261, Dover, Delaware, USA 19904
Contact: service@mtlab.ai

THIS POLICY EXPLAINS HOW WE COLLECT, USE, AND STORE YOUR FACIAL AND BODY DATA FOR VIRTUAL TRY-ON (SECTION 4A). PROVIDING THIS DATA IS VOLUNTARY. BY CHOOSING TO USE VIRTUAL TRY-ON AND PROVIDING YOUR IMAGES, YOU PROVIDE YOUR INFORMED WRITTEN CONSENT TO THE COLLECTION, USE, STORAGE, AND PROCESSING OF THAT DATA AS DESCRIBED IN SECTION 4A. YOU CAN WITHDRAW CONSENT AND DELETE YOUR DATA AT ANY TIME.

Scope: This Privacy Policy ("Policy") explains how we collect, use, disclose, transfer, and protect personal data when you visit or use Uverest's websites, mobile apps, browser extensions, and other platforms we own or control (the "Services"), including any linked pages or blogs, features, and content (collectively, "Content"). The Services are offered to, and intended for, residents of the United States.

Uverest is the Controller of your personal data for the purposes set out in this Policy, except where a Partner acts as its own controller for its processing (see Section 6).

1. What this Policy covers

This Policy covers how we handle personal data when you access the Services and/or interact with the Content. It explains what we collect, why we collect it, how we use and share it, where we store it, and the choices and rights available to you.

2. Data we collect

We collect the following categories of information (depending on how you use the Services):

  • Identifiers & Contact Details: name, username, email, phone, addresses (billing/shipping), age/date of birth (where permitted/required).
  • Account & Profile Data: preferences (size, fit, style, budget), saved items/wishlists, avatars/profile photos, social sign-in identifiers.
  • Order & Transaction Data: items viewed/purchased, order IDs, prices, quantities, taxes/duties, returns/exchanges, delivery information. Payment card data is handled by our payment processors and not stored in full by Uverest.
  • Device/Technical Data: IP address, device IDs, OS, app version, browser type, SDK logs, diagnostics, crash reports, security signals.
  • Usage Data: event logs (clicks, views, searches), session timestamps, referral URLs, cookie IDs/SDK identifiers (see our Cookie Policy).
  • Location Data: city/region (derived from IP); where you opt in, coarse or device-level location for localised features.
  • Biometric & Body-Related Data (Virtual Try-On): to create your try-on, we collect and process a scan of your facial and body geometry from the images you provide ("Body Data"), and we store the try-on result images we generate. Depending on your jurisdiction, Body Data may qualify as biometric information under BIPA, Texas CUBI, the Washington My Health My Data Act, and similar laws. We handle all of this as described in Section 4A. We do not use Body Data to identify you or for biometric verification, and we do not sell it.
  • User Generated Content (UGC) & Social Data: reviews, lists, comments, likes, prompts, photos (including try-on images), and any content you upload, generate, or interact with on our public feed.
  • Communications: emails, in-app messages, support tickets, survey/interview recordings (with notice).
  • Inferences: taste/style predictions, size recommendations, scores and segments derived from other data.

3. How we collect data

  • Directly from you: account registration, profile setup, checkout, support, surveys/interviews, UGC uploads, try-on images you provide, and interactions on the public feed.
  • Automatically: cookies/SDKs, analytics, logs when you browse, search, or interact with the Services.
  • From third parties: identity providers (e.g., Apple/Google), payment processors, anti-fraud providers, logistics partners and analytics/advertising partners where necessary to track referrals and attribute sales.

See our separate Cookie Policy for details on cookies, SDKs, and similar technologies.

4. Why we use your data (purposes)

We use personal data to:

  • Provide the Services: account creation, product discovery, cart/checkout, order routing, returns assistance.
  • Personalise & recommend: curate items and looks based on your style, size, and behaviour; remember settings; show relevant Content.
  • Operate Try-On & Sizing: render AR/AI previews and generate your virtual try-on; offer fit/size guidance (advisory only).
  • Power Social Features & Public Feed: display your profile, published try-on images, comments, and likes to other users if you choose to participate.
  • Enable "Re-Try-On" Functionality: if you publish a try-on image to the public feed, our AI will process the garment and styling data from your image so other users can virtually try on that specific look. This processing is strictly limited to clothing/style extraction and does not extract or share your facial or biometric data.
  • Process payments: via third-party processors/wallets; manage authorisations, captures, refunds, chargebacks.
  • Communicate: order and service messages, support, technical notices; with your consent where required, marketing and sale alerts.
  • Improve & secure: analytics, debugging, service quality, fraud prevention, abuse detection, community moderation, security monitoring.
  • Research & development: surveys/tests to improve features and models (with safeguards; training on your UGC or Body Data only with your opt-in).
  • Legal & compliance: recordkeeping, sanctions/export controls, tax and accounting, responding to lawful requests.

4A. Biometric & Body-Related Data (Virtual Try-On)

This Section is our biometric data retention and destruction policy for purposes of BIPA and comparable laws. It governs the facial and body data we process to provide virtual try-on.

What we collect.

To generate your try-on and fit preview, we collect, from the image(s) you provide, a scan of your facial and body geometry, together with technical representations derived from it (for example, fit and measurement data). We also store the 2D try-on result images we generate. We refer to all of this as your "Body Data."

Consent (voluntary).

Providing Body Data is voluntary and entirely your choice. By voluntarily choosing to use virtual try-on and providing your image(s), you acknowledge and provide your informed written consent to our collection, use, storage, and processing of your Body Data as described in this Section. If you do not consent, do not use virtual try-on. You may withdraw consent and delete your Body Data at any time (see below).

Possible classification as biometric data.

Depending on your jurisdiction, Body Data may be classified as biometric information or a biometric identifier under the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), the Washington My Health My Data Act, and similar statutes. Where those laws apply, we comply with them, including by obtaining consent, limiting our use, not selling the data, and following the retention and destruction schedule below.

Purpose.

We use Body Data only to generate, display, and improve your virtual try-on and fit results. We do not use it to identify you, for surveillance, for security screening, or for advertising.

We never sell it.

We do not sell, lease, trade, or otherwise profit from your Body Data, and we do not create biometric identifiers ("faceprints") for identification.

Who we share it with (processors only).

To generate your try-on, we transmit your image(s) and derived data to third-party AI image providers — currently Google LLC and OpenAI, L.L.C. — and we use Amazon Web Services, Inc. (US) for hosting/storage and a content delivery network (CDN) provider for delivery. Each acts solely as our processor under written contract. They may use the data only to perform the try-on or hosting on our behalf, may not retain it beyond what is necessary, and may not sell it, use it for their own purposes, or use it to train their own models.

Retention.

We retain Body Data only as long as needed to provide the try-on service, and we permanently destroy it when the purpose has been satisfied or within three (3) years of your last interaction with Uverest, whichever comes first. Try-on result images saved privately to your Try-On Gallery are retained for up to 60 days, then deleted; try-on images you publish to the public feed are retained until you delete them or remove them from the feed.

Destruction.

On a deletion trigger above, primary copies are permanently removed from our systems; residual encrypted backups at our cloud provider roll off within standard backup cycles (typically ≤30 days). Our processors follow our deletion instructions and their cache/backup cycles.

Your controls.

You can delete any try-on image (public or private) and your Body Data at any time from the Try-On Gallery or by emailing service@mtlab.ai.

Minors.

If you are under 18, virtual try-on requires the consent of a parent or legal guardian who accepts this Section on your behalf.

5. Your Consent

Where we rely on your consent — for example, to process your biometric and body-related data for virtual try-on (see Section 4A), to send marketing messages, to use precise location, to set non-essential cookies/SDKs, to publish your images to the public feed, or to use your images to train or improve our models — that consent is voluntary and you may withdraw it at any time. You can withdraw consent by adjusting your settings, deleting the relevant data, or emailing service@mtlab.ai. Withdrawing consent does not affect processing we carried out before you withdrew it, and does not affect processing we carry out on another lawful basis (such as completing a transaction you requested or meeting a legal obligation).

6. Sharing & Disclosures

We share personal data as follows, using appropriate contractual and technical safeguards:

  • Other Users & the Public: If you choose to engage with our social features (such as posting to the public feed, commenting, or liking), your profile information (username, avatar), your published try-on photos, and your interactions will be visible to other Uverest users and the public.
  • Retail/Marketplace Partners (independent controllers): to fulfil your order, manage returns/warranty, verify stock/price, and attribute referrals. Their privacy notices apply to their processing.
  • Payment & Risk Providers (processors/controllers): payment gateways, wallets, fraud prevention and chargeback services.
  • Logistics & Customer Support: shipping, returns, label/RMA providers; contact-centre tooling.
  • Cloud/IT/Engineering: hosting, content delivery, monitoring, ticketing, email/SMS providers.
  • Try-On & AI processors: third-party AI image providers (currently Google LLC and OpenAI, L.L.C.) that generate your try-on, and Amazon Web Services, Inc. (US) (hosting/storage) and our CDN provider(s) (temporary edge caching), each acting solely as our processor. They retain only as needed to provide the service, may not use it to train their models, and purge according to our deletion instructions and cache/backup cycles.
  • Analytics & Measurement: product analytics, A/B testing, app store measurement.
  • Advertising & Marketing: ad networks and platforms for interest-based advertising where permitted; you can opt out (see Sections 8 and 11). We do not use Body Data for advertising.
  • Social Sign-In & Sharing: if you connect a social account or share Content externally.
  • Corporate transactions: merger, financing, acquisition, or sale of assets (subject to continuity of protections).
  • Legal & safety: to comply with law, enforce terms, or protect rights, safety, and security.
  • With your direction or consent.

We do not sell personal data for money. Under some U.S. state laws, certain data sharing for cross-context behavioural advertising may be considered a “sale” or “sharing”; you can opt out (see Sections 8 and 11).

7. Data location

  • Primary storage: We host and store personal data in the United States (primary storage and backups).
  • Service providers: Where we use service providers or Partners to deliver the Services, we share only the data needed for that purpose and apply appropriate contractual and technical safeguards. Some providers may process data in other countries; where they do, we require protections consistent with this Policy.
  • Local laws: Your data may be subject to access by foreign authorities under their laws.

8. Advertising, cookies & signals

We and partners use cookies/SDKs to operate the Services, remember preferences, measure performance, and deliver ads. See our Cookie Policy for details and choices.

US state choices & Opt-out link requirement. Use our “Do Not Sell or Share / Opt Out of Targeted Ads” control in the app/web footer (or send a GPC signal in supported browsers). We honor Global Privacy Control signals as required by law. You can also email us with the subject line “Do Not Sell or Share My Personal Information.”

9. Retention

We keep personal data only as long as needed for the purposes above, and to comply with legal, tax, and accounting requirements. Typical periods include:

  • Account data: retained while your account is active and for up to 24 months after inactivity, then deleted or anonymised unless longer is required.
  • Orders & payments: kept for 7 years (or longer as required by tax/accounting laws).
  • Logs & analytics: typically 12–24 months.
  • Marketing consents & opt-outs: stored to evidence preferences.
  • Body Data (facial/body geometry): retained only as needed to provide try-on and permanently destroyed when the purpose is satisfied or within three (3) years of your last interaction, whichever comes first (see Section 4A).
  • Try-on result images: private Gallery kept up to 60 days, then deleted; public-feed images kept until you delete them. Upon deletion, primary copies are removed and residual encrypted backups roll off within standard cycles (typically ≤30 days). You can delete any time from the Try-On Gallery.

10. Security

We implement administrative, technical, and physical safeguards, including encryption in transit, access controls, network segmentation, and monitoring. We store and transmit Body Data using a reasonable standard of care that is at least as protective as we use for other confidential information we hold. No system is 100% secure; transmission over the internet carries risk. If you believe your account has been compromised, contact service@mtlab.ai.

Delaware breach notice. In the event of a data breach affecting Delaware residents, we will provide notice without unreasonable delay and no later than 60 days after determination of the breach, subject to lawful delay.

11. Your choices & rights

Controls. You can update profile data, manage communications, and adjust cookie/SDK preferences (where available). You can opt out of marketing emails via unsubscribe links; you may still receive transactional messages.

Try-On & Body Data deletion controls. Delete individual try-on photos (public or private) and your Body Data directly in the Try-On Gallery, or request deletion via service@mtlab.ai. You may withdraw your biometric consent at any time.

Rights. Depending on your location, you may have rights to access, correct, delete, restrict, object (including to profiling for direct marketing), portability, and withdraw consent. To exercise rights, email service@mtlab.ai (no embedded forms). We may verify your request, and may deny or limit requests as permitted by law. If we decline, you may appeal by replying to our decision within 30 days.

Do Not Track. We currently do not respond to DNT signals. We honor GPC where required.

12. US state privacy notice (California, Delaware & others)

If you are a resident of California (CPRA) or other states with similar laws (e.g., CO, CT, VA, UT, IL, TX, WA), you may have additional rights:

  • US State Privacy Notice — Delaware (DPDPA): Delaware residents may exercise rights to access, correct, delete, obtain a portable copy of personal data, and opt out of targeted advertising and the sale of personal data. We respond to verified requests within 45 days (we may extend once by 45 days and will explain why). If we deny your request, you may appeal by replying to our decision; we will respond within 60 days. If your appeal is denied, you may contact the Delaware Department of Justice to submit a complaint.
  • Biometric information (IL / TX / WA and similar). Where the facial and body geometry we process for try-on qualifies as biometric information or a biometric identifier under state law (for example, Illinois BIPA, Texas CUBI, or the Washington My Health My Data Act), we collect it only with your consent, use it solely for try-on, do not sell it, and retain and destroy it as set out in Section 4A. We do not use it to identify you. Illinois residents: see Section 4A for our written retention and destruction schedule.
  • Categories collected: identifiers; commercial info; internet/network activity; geolocation (coarse); UGC; Body Data (where you use try-on); inferences.
  • Purposes: as in Sections 4 and 8. Sources: as in Section 3. Disclosures: to categories in Section 6.
  • Sell/Share: we do not sell for money; some disclosures for cross-context behavioural advertising may be a “sale”/“share” — you can opt out via GPC, in-app/web settings (when available), or by emailing service@mtlab.ai with the subject line above. We never sell Body Data.
  • Sensitive personal information: where we collect sensitive personal information (including biometric/Body Data or precise location), we limit use to permitted purposes and honour requests to limit its use/disclosure.
  • Teens (13–17): We do not sell personal data or process it for targeted advertising for consumers aged 13–17 without consent where we have actual knowledge or wilfully disregard the consumer’s age.
  • Non-discrimination: we will not discriminate against you for exercising your rights.
  • Authorized agents: you may designate an agent; we will need proof of authority and verification.

13. Children

The Services are not directed to children under 13, and we do not knowingly collect personal data from them. Virtual try-on and Body Data processing require you to be 18 or older, or to have a parent or legal guardian’s consent. If you believe a child under 13 has provided data, contact service@mtlab.ai and we will delete it. If local law requires a higher age of consent for certain processing, we will honour that requirement.

14. Notice of Financial Incentive (e.g., referral credits)

From time to time we offer financial incentives (e.g., referral credits). Participation is voluntary and you may withdraw at any time. We collect identifiers (e.g., email, device IDs) and commercial info (e.g., referral attribution) to provide the incentive. We estimate the value of consumer data by reference to program costs, expected engagement, and incremental revenue.

15. Changes to this Policy

We may update this Policy from time to time. The latest version will be posted with the "Last revised" date. If a change is material, we will provide reasonable notice (e.g., in app or by email). Your continued use of the Services after the effective date means you accept the updated Policy.