AI Product Customizer

Legal

Privacy Policy

Last updated: July 10, 2026

This Privacy Policy explains how AI Product Customizer collects, uses, stores, shares and protects personal data when you visit our website, create an account, purchase or install our WordPress and WooCommerce plugin, use our artificial intelligence services, contact support or otherwise interact with us.

Important distinction: this Policy covers personal data for which AI Product Customizer determines the purposes and means of processing. When our technology processes information on behalf of a merchant operating its own ecommerce store, that merchant may be the data controller and AI Product Customizer may act as its processor.

Contents

  1. Who is responsible
  2. Scope of this Policy
  3. Our privacy roles
  4. Data we collect
  5. Sources of data
  6. Purposes and legal bases
  7. AI generation data
  8. Store visitors
  9. Payments
  10. Cookies
  11. Communications
  12. How data is shared
  13. Service providers
  14. International transfers
  15. Data retention
  16. Security
  17. Your rights
  18. Complaints
  19. Automated decisions
  20. Children
  21. Third-party websites
  22. Policy changes
  23. Contact

1. Who is responsible for your data?

The controller responsible for the processing described in this Policy is:

[FULL LEGAL COMPANY OR TRADER NAME]
Trading as AI Product Customizer
Tax identification number: [NIF/CIF/VAT NUMBER]
Registered address: [FULL BUSINESS ADDRESS, SPAIN]
Privacy email: privacy@aiproductcustomizer.com

In this Policy, the controller may be referred to as “AI Product Customizer”, “we”, “us” or “our”.

Our representative or Data Protection Officer, if one is legally required or voluntarily appointed, can be contacted at: [DPO OR PRIVACY CONTACT DETAILS, IF APPLICABLE] .

2. Scope of this Policy

This Policy applies to personal data processed in connection with:

  • the AI Product Customizer website;
  • customer and licence accounts;
  • the WordPress and WooCommerce Plugin;
  • hosted AI image-generation functionality;
  • free demonstrations and trial generations;
  • subscriptions, billing and licence management;
  • technical support and business communications;
  • security, abuse prevention and rate limiting; and
  • related APIs, integrations and online services.

This Policy does not govern the independent processing performed by a merchant through its Customer Store, by an external AI Provider under its own terms, or by another third-party service acting as an independent controller.

3. When we act as controller or processor

3.1 AI Product Customizer as controller

We generally act as controller when we process data to:

  • operate our public website;
  • create and manage customer accounts;
  • sell licences or subscriptions;
  • manage billing and tax records;
  • provide customer support;
  • send our own service or marketing communications;
  • secure our systems and prevent abuse;
  • measure and improve our own services; or
  • comply with our legal obligations.

3.2 AI Product Customizer as processor

We may act as processor when a Customer Store sends us information about its visitors or purchasers solely so that we can provide hosted customisation or AI-generation functionality on the merchant's instructions.

In that situation, the merchant is normally responsible for:

  • providing its own privacy information;
  • determining an appropriate legal basis;
  • responding to data-subject requests;
  • configuring the Plugin lawfully;
  • deciding which data is sent to our Services; and
  • entering into a data processing agreement where required.

4. Personal data we may collect

Category Examples
Identity and contact data Name, business name, username, email address, telephone number, postal address and country.
Account and licence data Account identifier, subscription plan, licence key, authorised domains, activation status and account preferences.
Billing and transaction data Billing address, tax number, invoices, purchase history, payment status, currency and limited payment-provider references.
Technical data IP address, browser, operating system, device type, server logs, request time, referring page, Plugin version, WordPress version and error information.
Store and integration data Store URL, domain, WooCommerce configuration, product identifiers, technical settings and connected AI Provider.
AI-generation data Text prompts, generation parameters, reference images, product mock-ups, generated images, moderation results and generation status.
Usage data Features used, number of generations, generation dates, usage limits, failed requests and interaction events.
Support data Messages, support requests, screenshots, diagnostic information, attachments and communication history.
Marketing data Newsletter preferences, campaign interactions and consent records.
Security and abuse-prevention data IP-based counters, visitor identifiers, moderation flags, blocked requests, suspected misuse and security-event logs.

We do not intentionally request special-category personal data, such as health information, biometric identifiers, political opinions, religious beliefs or information about a person's sex life or sexual orientation.

You should not include such information in prompts, reference images or support messages unless its processing is expressly supported and lawful.

5. How we obtain personal data

We may obtain personal data:

  • directly from you when you register or purchase;
  • from a Customer Store when you use its customisation tool;
  • automatically from your browser, device, server or installed Plugin;
  • from payment and subscription providers;
  • from an AI Provider used to process a generation;
  • from support and communication platforms;
  • from a business or organisation for which you work; and
  • from public sources where this is lawful and relevant to security, fraud prevention or business contact.

6. Purposes and legal bases

Purpose Typical data Legal basis
Create and manage your Account Identity, contact, account and licence data Performance of a contract or steps requested before entering into a contract
Provide Plugin and AI-generation services Account, technical, usage, prompt, reference-image and Output data Performance of a contract; processing on a merchant's documented instructions
Operate free demonstrations Prompt, generated image, IP address, visitor identifier and usage counters Steps requested by the user and our legitimate interest in providing a limited demonstration while preventing abuse
Process payments and maintain accounting records Identity, billing, transaction and tax data Performance of a contract and compliance with legal obligations
Provide support and resolve incidents Contact, account, technical and support data Performance of a contract and legitimate interests in customer support and service improvement
Protect the Services and prevent misuse Technical logs, IP addresses, rate-limit counters, moderation results and security events Legitimate interests in security, fraud prevention, service integrity and legal compliance
Send essential service communications Contact, account and subscription data Performance of a contract and legitimate interests in administering the Services
Send newsletters and promotional messages Contact, marketing-preference and campaign data Consent or another lawful basis permitted by applicable electronic-marketing law
Analyse and improve our website and Services Aggregated usage, technical and analytics data Consent where required for non-essential cookies; otherwise legitimate interests where legally permitted
Establish, exercise or defend legal claims Relevant account, transaction, communication, security and usage data Legitimate interests and compliance with legal obligations

Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Where processing is based on legitimate interests, we consider the necessity of the processing and its potential impact on your rights before proceeding.

7. AI prompts, reference images and Outputs

7.1 Information processed

When you request an AI generation, the Services may process:

  • the text prompt entered by the user;
  • generation settings and product context;
  • a reference image, where supported;
  • the generated Output;
  • technical identifiers needed to return the result;
  • moderation or safety classifications; and
  • usage counters used to enforce generation limits.

7.2 Transmission to AI Providers

The Input and related technical information may be transmitted to the AI Provider selected for the request. Depending on the configuration, this may be a provider selected by us or one selected and connected directly by the merchant.

We aim to transmit only the information reasonably necessary to generate the requested result. Users should avoid including names, contact information, confidential information or other personal data in prompts unless this is genuinely necessary and lawful.

7.3 Model training

We do not use private prompts, reference images or Outputs to train our own general-purpose artificial intelligence models unless we first provide clear information and obtain any consent or other legal basis required.

External AI Providers may handle data according to the product, account type and contractual configuration used. Information about the active providers is included in Section 13 of this Policy.

7.4 Storage of generated content

Generated images may be:

  • returned directly to the browser or Customer Store;
  • stored temporarily while the generation is completed;
  • saved in the Customer Store's media library or order;
  • cached temporarily to improve delivery; or
  • retained for security or support where necessary.

Configuration to confirm: replace this paragraph with the actual storage model. State whether AI Product Customizer stores generated images, the exact storage period, and whether they are deleted automatically after delivery.

8. Visitors to Customer Stores

If you use AI Product Customizer through another company's online store, that company is normally responsible for the relationship with you and for explaining how it processes your data.

Depending on the merchant's configuration, our Services may receive:

  • the prompt or customisation instruction;
  • a reference image uploaded by you;
  • the selected product or template identifier;
  • an anonymous or pseudonymous session identifier;
  • your IP address and basic request metadata;
  • the generated result; and
  • an order or cart reference, where the design is attached to a purchase.

We do not need an End Customer's full name, postal address or payment-card details merely to generate an image. A merchant should not transmit those details to us unless a specific feature genuinely requires them.

Requests relating to the merchant's order, delivery, physical product, refund or account should normally be directed to that merchant.

9. Payments and financial information

Payments may be handled by an independent payment processor. Payment-card information is generally entered directly into that provider's secure payment interface and is not stored in full on our systems.

We may receive limited transaction information, including:

  • customer and billing details;
  • payment status;
  • transaction and subscription identifiers;
  • payment method type and limited card details;
  • invoice and tax information; and
  • fraud or payment-dispute notifications.

Payment-provider information: [ADD STRIPE, PADDLE, PAYPAL OR THE ACTUAL PROVIDER] .

10. Cookies and similar technologies

Our website may use cookies, local storage, pixels or comparable technologies to:

  • maintain sessions and account access;
  • remember preferences;
  • protect forms and prevent misuse;
  • measure website performance;
  • understand how the Services are used; and
  • support marketing where consent has been obtained.

Non-essential cookies will not be activated before consent where applicable law requires consent.

More information, including cookie names, providers, purposes and durations, is available in our Cookie Policy.

11. Service and marketing communications

11.1 Service communications

We may send messages that are necessary to operate your Account or subscription, including licence notices, invoices, security alerts, service changes and responses to support requests.

These messages are not promotional and may continue while you maintain an active Account or where we have an outstanding legal or contractual reason to contact you.

11.2 Marketing communications

We may send promotional communications when you have consented or when another lawful basis permits us to do so. You may unsubscribe through the link included in the communication or by contacting us.

Opting out of marketing does not prevent us from sending essential contractual, transactional or security messages.

12. When personal data may be shared

We do not sell personal data. We may share it with:

  • hosting, infrastructure and content-delivery providers;
  • AI Providers used to complete generations;
  • payment, invoicing and subscription providers;
  • email and customer-support providers;
  • analytics and cookie providers, subject to consent;
  • professional advisers, including lawyers, accountants and auditors;
  • public authorities where disclosure is legally required;
  • a purchaser or successor in a merger, restructuring or sale of the business; and
  • other parties where you have expressly instructed or authorised us to share the data.

Providers acting as processors may only use personal data according to our instructions and the applicable contractual safeguards.

13. Main service providers and subprocessors

The providers used may depend on the plan, geographic location, technical availability and Customer configuration.

Provider Purpose Data potentially processed Location or transfer
[HOSTING PROVIDER] Website, API, database and file hosting Account, technical, usage and service data [COUNTRY / REGION]
Cloudflare Security, DNS, content delivery, rate limiting and, where enabled, AI processing IP address, request metadata, security logs and AI Input where Workers AI is used Global infrastructure; applicable transfer safeguards
[GOOGLE GEMINI — REMOVE IF UNUSED] AI image generation Prompt, reference image, parameters and generated content [VERIFY ACCOUNT AND REGION]
[HUGGING FACE — REMOVE IF UNUSED] AI model inference Prompt, reference image, parameters and generated content [VERIFY PROVIDER AND REGION]
[POLLINATIONS — REMOVE IF UNUSED] AI image generation Prompt, generation parameters and generated content [VERIFY LEGAL ENTITY AND REGION]
[PAYMENT PROVIDER] Payment, subscription and fraud management Identity, billing and transaction data [COUNTRY / SAFEGUARD]
[EMAIL PROVIDER] Transactional and marketing email Name, email address and communication data [COUNTRY / SAFEGUARD]
[ANALYTICS PROVIDER OR NONE] Website analytics Cookie identifiers, technical and usage data [COUNTRY / SAFEGUARD]

Do not publish this provider table without reviewing it. Remove services that are not used and add the actual hosting, payment, email, analytics and AI providers.

14. International data transfers

Some providers may process personal data outside the European Economic Area.

Where personal data is transferred to a country that has not been recognised as providing an adequate level of protection, we will use an appropriate transfer mechanism where required, such as:

  • the European Commission's Standard Contractual Clauses;
  • an adequacy decision adopted by the European Commission;
  • the EU–US Data Privacy Framework for participating and certified recipients, where applicable; or
  • another legally recognised safeguard or exception.

You may contact us for further information about the safeguards relevant to a particular transfer.

15. How long we retain personal data

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including contractual, legal, accounting, security and dispute-resolution requirements.

Data Typical retention criterion
Active Account and licence data For the duration of the Account or contractual relationship
Invoices and accounting records For the period required by applicable tax, accounting and commercial law
Support communications While required to resolve the request and establish the history of the service
Technical and security logs Normally for a limited security and diagnostic period, unless an incident requires longer retention
Free-demo usage counters For the period required to enforce daily generation limits and investigate abuse
Prompts and temporary generation data [SPECIFY EXACT PERIOD OR STATE THAT THEY ARE NOT PERSISTENTLY STORED]
Generated images [SPECIFY EXACT PERIOD AND STORAGE LOCATION]
Marketing preferences Until consent is withdrawn, plus a minimal suppression record where necessary to respect the opt-out
Legal claims and disputes Until the relevant limitation periods and proceedings have expired

Data may remain for a limited additional period in protected backups before being overwritten according to the backup cycle.

Where we process data solely on behalf of a merchant, deletion and return will also be governed by the merchant's instructions and the applicable data processing agreement.

16. Security

We use proportionate technical and organisational measures intended to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

Measures may include:

  • encrypted HTTPS communications;
  • access controls and authentication;
  • restricted administrative permissions;
  • rate limiting and abuse detection;
  • prompt moderation and input validation;
  • security logging and monitoring;
  • software and dependency updates;
  • backups and incident-recovery procedures; and
  • contractual controls over service providers.

No online system can guarantee absolute security. Customers are also responsible for securing their WordPress installation, hosting account, credentials, API keys, plugins, themes and administrative users.

Suspected security incidents may be reported to: security@aiproductcustomizer.com .

17. Your data-protection rights

Subject to the conditions established by applicable law, you may have the right to:

  • obtain confirmation as to whether we process your personal data;
  • access your personal data;
  • correct inaccurate or incomplete data;
  • request deletion of your data;
  • request restriction of processing;
  • receive certain data in a structured, commonly used and machine-readable format;
  • object to processing based on legitimate interests;
  • withdraw consent at any time;
  • object to direct marketing without providing a reason;
  • request information about applicable international transfer safeguards; and
  • not be subject to certain decisions based solely on automated processing that produce legal or similarly significant effects.

17.1 How to exercise your rights

Send your request to: privacy@aiproductcustomizer.com .

Please identify the right you wish to exercise and provide enough information for us to locate the relevant data.

We may request proportionate evidence of identity when necessary to prevent unauthorised disclosure. Do not send a full identity document unless we specifically request it and no less intrusive verification method is sufficient.

Requests are generally free of charge. Applicable law may permit a reasonable fee or refusal where a request is manifestly unfounded or excessive.

17.2 Data controlled by a merchant

If your request concerns data processed through a Customer Store, you should normally contact that merchant first. If we receive the request and act only as processor, we may forward it to the relevant merchant or assist that merchant in responding.

18. Complaints

We encourage you to contact us first so that we can try to resolve your concern.

You also have the right to lodge a complaint with the Spanish Data Protection Agency, or with the supervisory authority of the European Union or EEA country in which you habitually reside, work or believe an infringement occurred.

Spanish Data Protection Agency
Agencia Española de Protección de Datos — AEPD
Calle Jorge Juan, 6
28001 Madrid
Spain

19. Automated processing and moderation

We may use automated systems to:

  • detect prohibited or unsafe prompts;
  • apply generation and rate limits;
  • identify suspected fraud or service abuse;
  • block malicious technical requests; and
  • select an available AI Provider.

These processes may result in a prompt being rejected or temporary access being restricted. They are intended to protect the Services and generally do not produce legal effects or comparably significant effects concerning the user.

You may contact support if you believe a legitimate request was blocked incorrectly.

20. Children's data

Our website, Accounts and paid Services are not directed at children. A person must be at least 18 years old, or have reached the age of legal majority in their country, to create a paid Account or enter into a subscription.

Customer Stores are responsible for determining whether their products and customisation functions are appropriate for minors and for obtaining any parental authorisation required by law.

Contact us if you believe that a child has provided personal data to us unlawfully.

21. Third-party websites and services

Our website or Plugin may contain links to third-party websites, WordPress resources, AI Providers or ecommerce services.

Their privacy practices are controlled by their respective operators. We recommend reviewing their privacy information before providing personal data.

22. Changes to this Privacy Policy

We may update this Policy to reflect changes in our Services, providers, processing activities, security practices or legal obligations.

The effective version will be published on this page and identified by the “Last updated” date.

Where a change materially affects how we process existing personal data, we will provide additional notice where appropriate, such as through email, the Account, the Plugin or a notice on the website.

23. Contact us

For questions about this Policy or our processing of personal data, contact:

[FULL LEGAL COMPANY OR TRADER NAME]
AI Product Customizer
[FULL BUSINESS ADDRESS, SPAIN]
Email: privacy@aiproductcustomizer.com

This Privacy Policy should be read together with our Terms of Service , Cookie Policy and Acceptable Use Policy .

© 2026 AI Product Customizer. All rights reserved.