← All articles
virtual try-onprivacyAI imageryshopify appsfashion ecommerce

Virtual Try-On on Shopify: Who Carries the Risk When a Shopper Uploads a Photo?

Angadi Labs2 October 202615 min read

In short: A try-on app is built by a vendor, but the merchant is the one who invites the shopper to upload a photo, shows the result on their own product page, and, so far, gets named in the lawsuit. Courts have already rejected "a third-party vendor did it" as a defence. Every case to date is about faces, so clothing try-on is untested rather than safe. In the EU, AI-generated product imagery has carried labelling duties since 2 August 2026. Before you install a try-on app, vet the vendor the way a plaintiff's lawyer would. The ten-question scorecard below is how.

Try-on apps are pitched on conversion and returns. Those are fair reasons to look. The question that tends not to come up until later is a simpler one: when a shopper hands your store a photo of their face or body, whose problem is that photo?

The answer from the cases so far is that it is yours.

What the cases actually say

There are four US cases worth knowing. None of them is about a small Shopify brand, and all four are about the shape of liability rather than its size.

Svoboda v. Amazon. Amazon's Virtual Try-On let shoppers see makeup and eyewear on their own face. A class of Illinois users sued under the Biometric Information Privacy Act (BIPA). Pre-certification discovery found at least 163,738 Illinois users. The district court certified the class, and on 17 December 2025 the Seventh Circuit affirmed that certification. Amazon built its own tool, so the vendor question did not arise here. What the case shows is the scale: a try-on feature becomes a class action counted in users.

Theriot v. Louis Vuitton. Louis Vuitton's eyewear try-on was supplied by a third-party vendor, FittingBox. LV argued that FittingBox, not LV, collected the face scans. In December 2022 the Southern District of New York rejected that argument: inviting users to the tool was enough. This is the case that ends the "the app does it" defence. (The court did dismiss the claim about LV's retention policy, for lack of standing.)

Kukovec v. Estée Lauder. Estée Lauder tried to move the claim to arbitration under its terms of use. In November 2022 the Northern District of Illinois refused, because the terms were browsewrap: a footer link buried among fifteen other site links and six social links, which shoppers never had to accept. The court let only the negligence theory proceed, at $1,000 per violation rather than $5,000. The case was dismissed in January 2024 with leave to file an amended complaint, so it may not be over. The lesson does not depend on how it ends: a consent you never made the shopper see is not a consent.

Warmack-Stillwell v. Christian Dior. This one went the brand's way, and it is the one most likely to be misread. In February 2023 the court dismissed it under BIPA's health-care exemption, because sunglasses are FDA Class I medical devices. That exemption is about eyewear, and it is narrowing even there. In 2024 an Illinois appellate court held, in Marino v. Gunnar Optiks, that someone trying on non-prescription glasses is not a patient in a health-care setting. In July 2026 the Seventh Circuit revived an eyewear try-on suit in Clements v. Gunnar Optiks, reasoning that "[b]etter-appearing glasses are not medical treatment." Nothing about the exemption carries over to a dress.

The money is set by statute. BIPA allows $1,000 per negligent violation and $5,000 per reckless or intentional one. A 2024 amendment, SB 2979, limited recovery to one per person rather than one per scan, which takes away the most catastrophic arithmetic and leaves the rest. Multiply $1,000 by the number of Illinois shoppers who used your try-on. Texas has its own statute, CUBI, which requires informed consent before capturing face geometry for a commercial purpose. Only the Attorney General can enforce it, at up to $25,000 per violation, and in 2024 Texas used it, alongside its consumer-protection law, to reach a $1.4 billion settlement with Meta.

Apparel is untested, not safe

Every case above is face-based: makeup, eyewear, jewellery, hair colour. That is because the first generation of try-on worked by mapping face geometry, which is exactly what BIPA and CUBI name.

Clothing try-on mostly works differently. A shopper uploads a full-body photo and a generative model produces an image of them in the garment. We found no US lawsuit over that kind of try-on, and no ruling either way on whether it collects biometric identifiers.

That is a gap in the case law, not a safe harbour. A model that has to place a collar on a neck and a hem at a knee is reading the body's geometry to do it, and many of these apps also detect the face to keep it intact in the output. Whether that counts as a "scan of face geometry" is the question the first apparel case will decide. You do not want to be the store that finds out.

The independent evidence on how these tools behave in practice is not reassuring. A 2024 academic audit, "Try On, Spied On?", published in Springer's LNCS series, looked at 138 try-on websites and 28 Android apps. It found that 43 of the websites stored users' images, 37% used providers that extract facial geometry, 11% violated their own privacy policies, and 22% used misleading disclaimers. Those are the vendors you are choosing between.

The EU layer

If you sell into Europe there are two separate regimes, and they ask different questions.

GDPR asks what you did with the photo. A photo is personal data. If it is processed to identify someone, it becomes biometric data under Article 9, which needs explicit consent or another narrow condition. Try-on processing may cross that line, and as Mishcon de Reya points out, skin colour in an image can reveal racial or ethnic origin by inference, which is special-category data in its own right. There is no definitive regulator guidance yet on whether a photo used only for generative try-on, without a face mesh, is Article 9 data. That uncertainty is a reason for explicit consent, not a reason to skip it.

The AI Act asks what you showed the shopper. Article 50 has applied since 2 August 2026. The Digital Omnibus (Regulation (EU) 2026/1744) delayed the high-risk rules but left Article 50 in place, with one exception: generative systems already on the market have until 2 December 2026 to add machine-readable marking. The Commission's guidelines, as law firms including Davis+Gilbert and Bird & Bird have summarised them, treat an AI-generated product image that misleads about the product's actual appearance as a deepfake that must be disclosed. A real product photographed against an AI-generated background is not one.

A try-on output is an AI-generated image of a real product on a real person. That is close to the centre of what the guidelines describe.

Who owes the label is less clear. The Commission's Q&A defines a deployer as anyone using an AI system under their authority, and says a company stays the deployer even when a contractor operates the system. It also says deployers cannot simply rely on the machine-readable marking the provider embeds. Whether a merchant whose shopper triggers the try-on is the deployer has not been decided. Fines reach €15 million or 3% of worldwide turnover. When the answer is open and the ceiling is that high, plan as if it is you.

The try-on vendor risk scorecard

Ten questions. Each has a threshold, and each is tied to something a court or regulator has already said. Read the app listing, the privacy policy, the terms and the data processing agreement, then score it. A vendor that cannot answer a question in writing fails it.

# Question Pass Fail Why it matters
1 Where are photos processed? On the shopper's device, or a named server region "Our secure cloud," with no location GDPR transfers; the Louis Vuitton ruling puts the vendor's handling on you
2 How long are photos kept? Stated in hours, for uploads and outputs separately "As long as necessary" BIPA requires a public retention schedule
3 Are uploads used for training? No, stated in the terms Silence, or an opt-out Training is a second purpose the shopper did not consent to
4 Is there consent before upload? Clickwrap: a checkbox before the upload control appears Consent implied by uploading, or a footer link Estée Lauder: browsewrap was not enforced
5 Is there a public retention and destruction policy? A public URL you can link to Only inside the DPA, or nowhere BIPA requires it to be public
6 Does the DPA name controller and processor? Yes, with sub-processors listed No DPA, or roles left blank GDPR Article 28; tells you what you are on the hook for
7 Are photos of children blocked? Yes, in the terms and in the product No mention Google's own try-on rules prohibit children's photos
8 Are outputs labelled for EU shoppers? Visible on-screen label plus machine-readable marking Marking only, or nothing AI Act Article 50; deployers cannot rely on the provider's marking alone
9 What Shopify data does the app request? Products, and theme access for the widget Customer or order data with no stated reason Every extra scope is more data you are accountable for
10 Do the terms push liability back to you? Vendor indemnifies for its own processing "Merchant is solely responsible for obtaining consent" That clause is where the vendor moves the lawsuit onto you

Some of this is already visible in the market, and it helps to see what a pass and a fail look like in practice. As vendor claims, not audited facts: Photta says it deletes shopper photos within one hour and generated images within 24 hours. virtual.fit says it deletes uploads and outputs within 24 hours and does not use them for training without separate consent. Both would pass question 2 on their own description. Vensa also deletes uploads within 24 hours and says it never trains on them, so it passes questions 2 and 3. But its privacy policy, as updated on 21 September 2026, lists the legal basis for shopper photo processing as "implied consent when the shopper voluntarily uploads a photo to use an image-based feature." That is the pattern question 4 is written to catch, and it is the argument Estée Lauder lost. A vendor can get retention right and still leave you without a consent you could show a court.

Google's own try-on in Search is a useful benchmark for question 7 and question 10 together. Its rules say shoppers must not upload photos of children and that the uploader is solely responsible for having consent. Google is putting the consent burden on the person uploading. A vendor putting the same burden on you, the merchant, is doing the same thing one step up the chain.

A vendor that passes eight or more is worth a trial. A vendor that fails question 4 or question 10 is not, however many it passes, because those are the two that decide whose name is on the complaint.

Where Angadi sits

Angadi builds outfits from your own product photography. It never generates an image of a garment or a person, and it never asks a shopper for a photo, so most of this scorecard does not apply to it. That is a design choice with a cost: Angadi cannot show a shopper how a dress looks on them. If that is what you need, use the scorecard above to pick the vendor.

Full disclosure: Angadi is our product.

What to do before you install

Read the four documents, score the ten questions, and get the answers you could not find in writing from the vendor. If you already have a try-on app live, do the same exercise now and start with question 4: look at your own product page and check whether a shopper has to tick something before the upload control appears.

If you are weighing try-on against the other kinds of styling app, our guide to AI stylist and complete the look apps sorts them by whether they use your photography or generate new images. And if the goal behind try-on is fewer returns, what actually causes fashion returns is worth reading first, because fit is not the only cause.

This post is not legal advice. It is a merchant's reading of public rulings and regulator guidance as of October 2026. If you sell into Illinois, Texas or the EU at volume, show the scorecard to a lawyer before you sign.

Frequently asked questions

Does BIPA apply if my store is not in Illinois? It can. BIPA protects Illinois residents, not Illinois businesses, so what matters is whether Illinois shoppers use your try-on. Amazon is based in Washington and the class certified against it in Svoboda v. Amazon is made up of Illinois users. If you ship to the US and your try-on reads face geometry, assume some of your users are in Illinois.

Is a cookie banner or a privacy policy link enough consent? Probably not. In Kukovec v. Estée Lauder the court would not enforce terms behind a footer link buried among fifteen other site links and six social links, because shoppers never had to agree to them. BIPA asks for a written release before collection, and a 2024 amendment confirmed an electronic signature counts. The safe pattern is a clickwrap step, a checkbox the shopper ticks before the upload control appears, that names what is collected and how long it is kept.

Do I have to label try-on images for EU shoppers? Treat it as yes. Article 50 of the EU AI Act has applied since 2 August 2026, and the Commission's guidelines treat an AI-generated product image that misleads about how the real product looks as a deepfake that must be disclosed. Whether the merchant or the app vendor is the deployer for a shopper-triggered try-on is not settled, and the Commission's Q&A says deployers cannot simply rely on the provider's machine-readable marking. Ask the vendor how outputs are labelled on screen, in writing.

If the vendor deletes photos within 24 hours, am I compliant? No. Short retention is good and it is one question out of several. BIPA also requires informed written consent before collection and a public retention and destruction policy, and a deleted photo does not cure a missing consent step. Under GDPR, a short retention period does not replace a lawful basis or, if the processing is biometric, an Article 9 condition.

Is clothing try-on safer than makeup or eyewear try-on? It is untested, which is not the same thing. Every US case we found involves face-based try-on: makeup, eyewear, jewellery, hair colour. No court has yet ruled on full-body clothing try-on from an uploaded photo. If the app maps a face or body, the same statutes are written broadly enough to reach it.

Sources

  1. Svoboda v. Amazon.com, Inc., No. 25-1361 (7th Cir. 17 December 2025), class certification affirmed. Duane Morris, Seventh Circuit affirms certification of BIPA class, 30 December 2025. User count: Duane Morris, class certification victory over Amazon, 8 April 2024.
  2. Theriot v. Louis Vuitton North America, Inc. (S.D.N.Y. 5 December 2022). The Fashion Law, court cuts down privacy lawsuit over Louis Vuitton virtual try-on tool.
  3. Kukovec v. Estée Lauder Companies, Inc., No. 22-cv-1988 (N.D. Ill. 7 November 2022). Duane Morris, Illinois federal court rejects efforts to dismiss BIPA claims involving virtual try-on technology, 11 November 2022. Dismissal with leave to amend, 10 January 2024: Citeline.
  4. Warmack-Stillwell v. Christian Dior, Inc. (N.D. Ill. 10 February 2023). Hunton, BIPA health care exemption applies to sunglasses virtual try-on tool.
  5. Marino v. Gunnar Optiks, LLC, 2024 IL App (1st) 231826 (30 August 2024). ISBA summary.
  6. Clements v. Gunnar Optiks, LLC, No. 25-1890 (7th Cir. 10 July 2026). Opinion via FindLaw.
  7. Illinois SB 2979 (signed 2 August 2024). Byte Back, BIPA amendment bill signed into law.
  8. Texas Business and Commerce Code §503.001. Meta settlement: Hunton, Meta settles Texas biometric data lawsuit for record $1.4 billion, July 2024.
  9. European Commission, Transparency obligations under Article 50 AI Act (Q&A), updated 24 July 2026. Article 50 guidelines (adopted 20 July 2026) as summarised by Davis+Gilbert and Bird & Bird. Digital Omnibus: Regulation (EU) 2026/1744; Lewis Silkin, the Digital Omnibus on AI enters into force today, 27 July 2026.
  10. Mishcon de Reya, virtual try-on: data protection compliance considerations, 13 March 2026 (written under UK GDPR).
  11. Google Shopping Help, How the Google Try-On tool works.
  12. Ragab, Mannan and Youssef, "Try On, Spied On?", ESORICS 2023 International Workshops, Springer LNCS, published 1 March 2024.
  13. Photta Shopify integration; virtual.fit privacy policy; Vensa privacy policy (last updated 21 September 2026). All read 2 October 2026. Retention and consent statements are vendor claims, not audited.

Angadi builds complete outfits from your catalog and places them on every product page. It installs on Shopify with a 14-day free trial, and nothing goes live without your approval. See it on your store →