Legal
Privacy Policy
Last updated:
This Privacy Policy explains how AI Product Customizer collects, uses, stores, shares and protects personal data when you visit our website, create an account, purchase or install our WordPress and WooCommerce plugin, use our artificial intelligence services, contact support or otherwise interact with us.
Important distinction: this Policy covers personal data for which AI Product Customizer determines the purposes and means of processing. When our technology processes information on behalf of a merchant operating its own ecommerce store, that merchant may be the data controller and AI Product Customizer may act as its processor.
1. Who is responsible for your data?
The controller responsible for the processing described in this Policy is:
Trading as AI Product Customizer
Tax identification number: [NIF/CIF/VAT NUMBER]
Registered address: [FULL BUSINESS ADDRESS, SPAIN]
Privacy email: privacy@aiproductcustomizer.com
In this Policy, the controller may be referred to as “AI Product Customizer”, “we”, “us” or “our”.
Our representative or Data Protection Officer, if one is legally required or voluntarily appointed, can be contacted at: [DPO OR PRIVACY CONTACT DETAILS, IF APPLICABLE] .
2. Scope of this Policy
This Policy applies to personal data processed in connection with:
- the AI Product Customizer website;
- customer and licence accounts;
- the WordPress and WooCommerce Plugin;
- hosted AI image-generation functionality;
- free demonstrations and trial generations;
- subscriptions, billing and licence management;
- technical support and business communications;
- security, abuse prevention and rate limiting; and
- related APIs, integrations and online services.
This Policy does not govern the independent processing performed by a merchant through its Customer Store, by an external AI Provider under its own terms, or by another third-party service acting as an independent controller.
3. When we act as controller or processor
3.1 AI Product Customizer as controller
We generally act as controller when we process data to:
- operate our public website;
- create and manage customer accounts;
- sell licences or subscriptions;
- manage billing and tax records;
- provide customer support;
- send our own service or marketing communications;
- secure our systems and prevent abuse;
- measure and improve our own services; or
- comply with our legal obligations.
3.2 AI Product Customizer as processor
We may act as processor when a Customer Store sends us information about its visitors or purchasers solely so that we can provide hosted customisation or AI-generation functionality on the merchant's instructions.
In that situation, the merchant is normally responsible for:
- providing its own privacy information;
- determining an appropriate legal basis;
- responding to data-subject requests;
- configuring the Plugin lawfully;
- deciding which data is sent to our Services; and
- entering into a data processing agreement where required.
4. Personal data we may collect
| Category | Examples |
|---|---|
| Identity and contact data | Name, business name, username, email address, telephone number, postal address and country. |
| Account and licence data | Account identifier, subscription plan, licence key, authorised domains, activation status and account preferences. |
| Billing and transaction data | Billing address, tax number, invoices, purchase history, payment status, currency and limited payment-provider references. |
| Technical data | IP address, browser, operating system, device type, server logs, request time, referring page, Plugin version, WordPress version and error information. |
| Store and integration data | Store URL, domain, WooCommerce configuration, product identifiers, technical settings and connected AI Provider. |
| AI-generation data | Text prompts, generation parameters, reference images, product mock-ups, generated images, moderation results and generation status. |
| Usage data | Features used, number of generations, generation dates, usage limits, failed requests and interaction events. |
| Support data | Messages, support requests, screenshots, diagnostic information, attachments and communication history. |
| Marketing data | Newsletter preferences, campaign interactions and consent records. |
| Security and abuse-prevention data | IP-based counters, visitor identifiers, moderation flags, blocked requests, suspected misuse and security-event logs. |
We do not intentionally request special-category personal data, such as health information, biometric identifiers, political opinions, religious beliefs or information about a person's sex life or sexual orientation.
You should not include such information in prompts, reference images or support messages unless its processing is expressly supported and lawful.
5. How we obtain personal data
We may obtain personal data:
- directly from you when you register or purchase;
- from a Customer Store when you use its customisation tool;
- automatically from your browser, device, server or installed Plugin;
- from payment and subscription providers;
- from an AI Provider used to process a generation;
- from support and communication platforms;
- from a business or organisation for which you work; and
- from public sources where this is lawful and relevant to security, fraud prevention or business contact.
6. Purposes and legal bases
| Purpose | Typical data | Legal basis |
|---|---|---|
| Create and manage your Account | Identity, contact, account and licence data | Performance of a contract or steps requested before entering into a contract |
| Provide Plugin and AI-generation services | Account, technical, usage, prompt, reference-image and Output data | Performance of a contract; processing on a merchant's documented instructions |
| Operate free demonstrations | Prompt, generated image, IP address, visitor identifier and usage counters | Steps requested by the user and our legitimate interest in providing a limited demonstration while preventing abuse |
| Process payments and maintain accounting records | Identity, billing, transaction and tax data | Performance of a contract and compliance with legal obligations |
| Provide support and resolve incidents | Contact, account, technical and support data | Performance of a contract and legitimate interests in customer support and service improvement |
| Protect the Services and prevent misuse | Technical logs, IP addresses, rate-limit counters, moderation results and security events | Legitimate interests in security, fraud prevention, service integrity and legal compliance |
| Send essential service communications | Contact, account and subscription data | Performance of a contract and legitimate interests in administering the Services |
| Send newsletters and promotional messages | Contact, marketing-preference and campaign data | Consent or another lawful basis permitted by applicable electronic-marketing law |
| Analyse and improve our website and Services | Aggregated usage, technical and analytics data | Consent where required for non-essential cookies; otherwise legitimate interests where legally permitted |
| Establish, exercise or defend legal claims | Relevant account, transaction, communication, security and usage data | Legitimate interests and compliance with legal obligations |
Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Where processing is based on legitimate interests, we consider the necessity of the processing and its potential impact on your rights before proceeding.
7. AI prompts, reference images and Outputs
7.1 Information processed
When you request an AI generation, the Services may process:
- the text prompt entered by the user;
- generation settings and product context;
- a reference image, where supported;
- the generated Output;
- technical identifiers needed to return the result;
- moderation or safety classifications; and
- usage counters used to enforce generation limits.
7.2 Transmission to AI Providers
The Input and related technical information may be transmitted to the AI Provider selected for the request. Depending on the configuration, this may be a provider selected by us or one selected and connected directly by the merchant.
We aim to transmit only the information reasonably necessary to generate the requested result. Users should avoid including names, contact information, confidential information or other personal data in prompts unless this is genuinely necessary and lawful.
7.3 Model training
We do not use private prompts, reference images or Outputs to train our own general-purpose artificial intelligence models unless we first provide clear information and obtain any consent or other legal basis required.
External AI Providers may handle data according to the product, account type and contractual configuration used. Information about the active providers is included in Section 13 of this Policy.
7.4 Storage of generated content
Generated images may be:
- returned directly to the browser or Customer Store;
- stored temporarily while the generation is completed;
- saved in the Customer Store's media library or order;
- cached temporarily to improve delivery; or
- retained for security or support where necessary.
Configuration to confirm: replace this paragraph with the actual storage model. State whether AI Product Customizer stores generated images, the exact storage period, and whether they are deleted automatically after delivery.
8. Visitors to Customer Stores
If you use AI Product Customizer through another company's online store, that company is normally responsible for the relationship with you and for explaining how it processes your data.
Depending on the merchant's configuration, our Services may receive:
- the prompt or customisation instruction;
- a reference image uploaded by you;
- the selected product or template identifier;
- an anonymous or pseudonymous session identifier;
- your IP address and basic request metadata;
- the generated result; and
- an order or cart reference, where the design is attached to a purchase.
We do not need an End Customer's full name, postal address or payment-card details merely to generate an image. A merchant should not transmit those details to us unless a specific feature genuinely requires them.
Requests relating to the merchant's order, delivery, physical product, refund or account should normally be directed to that merchant.
9. Payments and financial information
Payments may be handled by an independent payment processor. Payment-card information is generally entered directly into that provider's secure payment interface and is not stored in full on our systems.
We may receive limited transaction information, including:
- customer and billing details;
- payment status;
- transaction and subscription identifiers;
- payment method type and limited card details;
- invoice and tax information; and
- fraud or payment-dispute notifications.
Payment-provider information: [ADD STRIPE, PADDLE, PAYPAL OR THE ACTUAL PROVIDER] .
11. Service and marketing communications
11.1 Service communications
We may send messages that are necessary to operate your Account or subscription, including licence notices, invoices, security alerts, service changes and responses to support requests.
These messages are not promotional and may continue while you maintain an active Account or where we have an outstanding legal or contractual reason to contact you.
11.2 Marketing communications
We may send promotional communications when you have consented or when another lawful basis permits us to do so. You may unsubscribe through the link included in the communication or by contacting us.
Opting out of marketing does not prevent us from sending essential contractual, transactional or security messages.
13. Main service providers and subprocessors
The providers used may depend on the plan, geographic location, technical availability and Customer configuration.
| Provider | Purpose | Data potentially processed | Location or transfer |
|---|---|---|---|
| [HOSTING PROVIDER] | Website, API, database and file hosting | Account, technical, usage and service data | [COUNTRY / REGION] |
| Cloudflare | Security, DNS, content delivery, rate limiting and, where enabled, AI processing | IP address, request metadata, security logs and AI Input where Workers AI is used | Global infrastructure; applicable transfer safeguards |
| [GOOGLE GEMINI — REMOVE IF UNUSED] | AI image generation | Prompt, reference image, parameters and generated content | [VERIFY ACCOUNT AND REGION] |
| [HUGGING FACE — REMOVE IF UNUSED] | AI model inference | Prompt, reference image, parameters and generated content | [VERIFY PROVIDER AND REGION] |
| [POLLINATIONS — REMOVE IF UNUSED] | AI image generation | Prompt, generation parameters and generated content | [VERIFY LEGAL ENTITY AND REGION] |
| [PAYMENT PROVIDER] | Payment, subscription and fraud management | Identity, billing and transaction data | [COUNTRY / SAFEGUARD] |
| [EMAIL PROVIDER] | Transactional and marketing email | Name, email address and communication data | [COUNTRY / SAFEGUARD] |
| [ANALYTICS PROVIDER OR NONE] | Website analytics | Cookie identifiers, technical and usage data | [COUNTRY / SAFEGUARD] |
Do not publish this provider table without reviewing it. Remove services that are not used and add the actual hosting, payment, email, analytics and AI providers.
14. International data transfers
Some providers may process personal data outside the European Economic Area.
Where personal data is transferred to a country that has not been recognised as providing an adequate level of protection, we will use an appropriate transfer mechanism where required, such as:
- the European Commission's Standard Contractual Clauses;
- an adequacy decision adopted by the European Commission;
- the EU–US Data Privacy Framework for participating and certified recipients, where applicable; or
- another legally recognised safeguard or exception.
You may contact us for further information about the safeguards relevant to a particular transfer.
15. How long we retain personal data
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including contractual, legal, accounting, security and dispute-resolution requirements.
| Data | Typical retention criterion |
|---|---|
| Active Account and licence data | For the duration of the Account or contractual relationship |
| Invoices and accounting records | For the period required by applicable tax, accounting and commercial law |
| Support communications | While required to resolve the request and establish the history of the service |
| Technical and security logs | Normally for a limited security and diagnostic period, unless an incident requires longer retention |
| Free-demo usage counters | For the period required to enforce daily generation limits and investigate abuse |
| Prompts and temporary generation data | [SPECIFY EXACT PERIOD OR STATE THAT THEY ARE NOT PERSISTENTLY STORED] |
| Generated images | [SPECIFY EXACT PERIOD AND STORAGE LOCATION] |
| Marketing preferences | Until consent is withdrawn, plus a minimal suppression record where necessary to respect the opt-out |
| Legal claims and disputes | Until the relevant limitation periods and proceedings have expired |
Data may remain for a limited additional period in protected backups before being overwritten according to the backup cycle.
Where we process data solely on behalf of a merchant, deletion and return will also be governed by the merchant's instructions and the applicable data processing agreement.
16. Security
We use proportionate technical and organisational measures intended to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Measures may include:
- encrypted HTTPS communications;
- access controls and authentication;
- restricted administrative permissions;
- rate limiting and abuse detection;
- prompt moderation and input validation;
- security logging and monitoring;
- software and dependency updates;
- backups and incident-recovery procedures; and
- contractual controls over service providers.
No online system can guarantee absolute security. Customers are also responsible for securing their WordPress installation, hosting account, credentials, API keys, plugins, themes and administrative users.
Suspected security incidents may be reported to: security@aiproductcustomizer.com .
17. Your data-protection rights
Subject to the conditions established by applicable law, you may have the right to:
- obtain confirmation as to whether we process your personal data;
- access your personal data;
- correct inaccurate or incomplete data;
- request deletion of your data;
- request restriction of processing;
- receive certain data in a structured, commonly used and machine-readable format;
- object to processing based on legitimate interests;
- withdraw consent at any time;
- object to direct marketing without providing a reason;
- request information about applicable international transfer safeguards; and
- not be subject to certain decisions based solely on automated processing that produce legal or similarly significant effects.
17.1 How to exercise your rights
Send your request to: privacy@aiproductcustomizer.com .
Please identify the right you wish to exercise and provide enough information for us to locate the relevant data.
We may request proportionate evidence of identity when necessary to prevent unauthorised disclosure. Do not send a full identity document unless we specifically request it and no less intrusive verification method is sufficient.
Requests are generally free of charge. Applicable law may permit a reasonable fee or refusal where a request is manifestly unfounded or excessive.
17.2 Data controlled by a merchant
If your request concerns data processed through a Customer Store, you should normally contact that merchant first. If we receive the request and act only as processor, we may forward it to the relevant merchant or assist that merchant in responding.
18. Complaints
We encourage you to contact us first so that we can try to resolve your concern.
You also have the right to lodge a complaint with the Spanish Data Protection Agency, or with the supervisory authority of the European Union or EEA country in which you habitually reside, work or believe an infringement occurred.
Agencia Española de Protección de Datos — AEPD
Calle Jorge Juan, 6
28001 Madrid
Spain
19. Automated processing and moderation
We may use automated systems to:
- detect prohibited or unsafe prompts;
- apply generation and rate limits;
- identify suspected fraud or service abuse;
- block malicious technical requests; and
- select an available AI Provider.
These processes may result in a prompt being rejected or temporary access being restricted. They are intended to protect the Services and generally do not produce legal effects or comparably significant effects concerning the user.
You may contact support if you believe a legitimate request was blocked incorrectly.
20. Children's data
Our website, Accounts and paid Services are not directed at children. A person must be at least 18 years old, or have reached the age of legal majority in their country, to create a paid Account or enter into a subscription.
Customer Stores are responsible for determining whether their products and customisation functions are appropriate for minors and for obtaining any parental authorisation required by law.
Contact us if you believe that a child has provided personal data to us unlawfully.
21. Third-party websites and services
Our website or Plugin may contain links to third-party websites, WordPress resources, AI Providers or ecommerce services.
Their privacy practices are controlled by their respective operators. We recommend reviewing their privacy information before providing personal data.
22. Changes to this Privacy Policy
We may update this Policy to reflect changes in our Services, providers, processing activities, security practices or legal obligations.
The effective version will be published on this page and identified by the “Last updated” date.
Where a change materially affects how we process existing personal data, we will provide additional notice where appropriate, such as through email, the Account, the Plugin or a notice on the website.
23. Contact us
For questions about this Policy or our processing of personal data, contact:
AI Product Customizer
[FULL BUSINESS ADDRESS, SPAIN]
Email: privacy@aiproductcustomizer.com