ScenePose / Legal
Privacy policy
Last updated August 30, 2026
This policy explains how CC Lab ("we", "us", or "our") handles information when a Shopify merchant installs or uses ScenePose (the "App").
Information the App processes
The App processes the minimum information needed to generate and publish room scene images:
- The merchant’s Shopify shop domain and Shopify access credentials.
- Product identifiers, titles, categories, selected variants, dimensions, and product image URLs selected by the merchant.
- Generation settings and prompts created from the selected product data.
- Generated images, generation status, and Lookbook publication status.
The App does not request access to Shopify customer, order, payment, or buyer personal information.
How information is used
We use this information to authenticate the merchant, retrieve selected products, generate room scenes, display generation history, publish merchant-approved Lookbooks to the merchant’s storefront, operate the App, troubleshoot failures, and protect the service from misuse.
The App requests the read_products scope only. It does not write to the merchant’s catalog. Storefront content is published as app-owned metaobjects, which are created and read by this App alone.
Storefront visitors
The App adds a theme block to the merchant’s online store so that shoppers can view published Lookbooks and add the products in them to their cart. That block sets no cookies, loads no third-party scripts, runs no analytics or tracking, and collects no information about the people who visit the store. Adding products to a cart is handled entirely by Shopify.
Website contact form
If you use the ScenePose website form, we receive the name, work email, optional store URL, area of interest, and any message you choose to provide. We use those details only to respond to your request, arrange a demo, or answer questions. The form does not ask for Shopify customer, order, payment, or buyer information.
The form is delivered through our cloud infrastructure and email-delivery providers. We retain the request only as long as reasonably needed to respond, provide support, maintain business records, or comply with legal obligations.
Website analytics
The ScenePose website uses Microsoft Clarity to understand how visitors use the site, including interactions such as clicks and scrolling. Clarity may use non-essential cookies and collect pseudonymous usage information, such as a visitor’s session and device details. This analytics service is used on scenepose.com and is separate from the ScenePose Shopify storefront theme block.
For more information, see Microsoft’s Clarity cookie documentation.
Service providers
We use a small number of service providers to deliver the App, and share with them only what each one needs:
- A cloud infrastructure provider hosts the App and stores its data and generated images.
- An AI image generation provider receives the selected product images and the generated prompt in order to produce each room scene. This happens only when a merchant requests a generation.
- Shopify stores the public projection of published Lookbooks so that a merchant’s theme can render them, and provides subscription information for the App.
- Microsoft Clarity provides analytics for the ScenePose website, as described above.
These providers act on our instructions under contractual data protection terms and may not use the information for their own purposes. Generated images may carry model-provider provenance or invisible watermarking identifying them as AI-generated.
Merchants who need the identity of a specific provider—for a vendor assessment, a data processing agreement, or a records-of-processing obligation—can request it at the contact address below and we will provide it.
Where information is processed
Our providers operate globally, so information handled by the App may be stored or processed in countries other than the merchant’s own, including the United States. We rely on our providers’ contractual data protection terms for these transfers.
Retention and deletion
App data is retained while the App is installed and as needed to provide its generation and publishing history. Shopify access credentials are deleted when the App receives an uninstall notification. When Shopify sends a shop-redaction request after uninstall, the App deletes that shop’s stored product metadata, prompts, job history, Lookbooks, publication records, and generated images. Failed deletion work is retained as a deletion task and retried automatically until completed.
Because the App does not store customer or order information, customer data access and redaction requests normally have no App records to return or delete.
Security
The App authenticates every request, stores access credentials that expire and rotate, restricts generated images to expiring signed links, encrypts data in transit over HTTPS, and verifies the signature of every incoming webhook. No method of storage or transmission can be guaranteed to be completely secure.
Merchant rights and contact
Merchants can uninstall the App to stop further processing and initiate the Shopify deletion lifecycle. Depending on where a merchant is located, they may also have rights to access, correct, export, or delete personal information we hold about them, or to object to or restrict its processing.
Questions, privacy requests, and provider disclosure requests can be sent to [email protected], and are answered within 30 days.
Changes
We may update this policy when the App or applicable requirements change. The date at the top identifies the latest revision.