Updated September 15, 2026.
If you sell on Shopify, someone on your team has probably already seen the ad. A new virtual try-on tool promises to put any garment in your catalog onto a photo of your actual shopper's actual body, in seconds, for free. It sounds like the kind of thing an independent designer has been waiting for: no model day, no studio, no per-image fee. But the thing that makes it work is the thing that should give you pause. The shopper has to upload a photo of themselves. That photo is not a stock image. In a growing number of states, it is a legally protected category of personal data, and the store that installs the widget, not just the company that built it, can end up holding the liability.
The launch
Genlook, an AI virtual try-on platform operated by the French company Parakeet Labs SASU, released a new model on September 1, 2026 that generates a photorealistic image of any catalog garment on a shopper's own body in under 10 seconds, from a single photo uploaded once. The new model supports every type of fashion garment, from dresses and outerwear to swimwear, footwear and accessories, including categories earlier versions could not render reliably. The upgrade is live for every store on the platform at no extra cost. Installation takes minutes from the Shopify App Store with no theme code, and Genlook runs on Shopify, WooCommerce, PrestaShop and Shopline, with an API for teams building try-on into their own product. The widget inherits the store's theme, reads the store's language setting, and carries the merchant's logo rather than Genlook's. The company reports that shoppers who try a garment on add it to cart three times more often than shoppers who do not, and nine in ten of those try-ons happen on a phone.
Why it matters
Every AI likeness dispute this site has tracked so far, Rainbow Shops, EBY, Stability AI, has involved a brand generating an image of someone without asking. This is the inverse problem. Here, the shopper hands over her own photo voluntarily, in exchange for a better fitting decision. That consent covers the shopper's use of the tool. It does not automatically cover what happens to the photo afterward: how long it is stored, whether it trains future models, whether it is shared with the platform's infrastructure vendors, or whether it counts as biometric data under state law.
Illinois's Biometric Information Privacy Act, Texas's Capture or Use of Biometric Identifier Act, and Washington's biometric privacy law all reach scans of face and body geometry used to identify a person, and several of them impose obligations on any entity that collects or possesses the data, not only the one that built the software. A designer who bolts a third-party widget onto her own storefront is, in the eyes of most of these statutes, a party to that collection.
What the policies say
To Genlook's credit, the published documents address the biometric question head-on rather than burying it. The shopper privacy policy names BIPA, Texas Chapter 503, and RCW 19.375 by statute and states that the service does not use facial recognition and does not create faceprints, face templates, face embeddings, or scans of face geometry. The merchant policy repeats the point and says a Biometric Data Statement written for compliance reviews is available on request at privacy@genlook.app. On the three questions the original version of this post said to ask in writing, the documents answer:
- What happens to the image. Uploaded photos and generated images are deleted automatically within the configured retention window, seven days at most, with one- and three-day options and unprocessed originals deleted within a day. Live camera video for realtime try-on is never stored. Consent records are kept five years; usage events thirteen months; hashed abuse-prevention signals two years.
- Whether the model trains on uploaded photos. No, stated flatly in both policies and in section 5 of the terms.
- Who sees what. Merchants never receive access to shoppers' photos or generated results. Genlook acts as processor; the merchant is controller, under a data processing agreement incorporated into the terms and available on request rather than published.
Two details are worth pulling out of the subprocessor table. Generation does not stay in Europe: the policy discloses that Google Vertex AI runs on a global serving endpoint, that the Comfy Cloud engine is operated from the United States, and that realtime video try-on runs on Decart, a US company. And the shopper policy discloses a safety screen that locates faces and estimates age ranges, storing numeric outputs only. That is a defensible design, but it is also the step closest to the statutory line, and it is the one a plaintiff's firm will ask about first.
Genlook also labels results as "AI modified" using the European Commission's official AI-content icons, citing Article 50 of the EU AI Act, whose transparency obligations took effect on August 2, 2026. A US store is not the target of that article, but a US store running a European vendor's widget inherits the label, which is a useful thing to have when a state disclosure rule arrives.
What the contract says
Here is the part merchants should read before the privacy policy. The original version of this post suggested asking whether the vendor will indemnify you if a state biometric statute treats your store as a co-collector. The terms of service answer that question in the opposite direction.
Section 4 makes the merchant the data controller for shopper personal data and puts the affirmative duties on the merchant: comply with the privacy and consumer law of every market you sell into, disclose the try-on feature in your own privacy policy, obtain any consents required in your market, and honor your storefront's consent-management configuration. Section 13 then runs the indemnity from the merchant to Genlook, expressly including claims brought by your own shoppers relating to consents you were required to obtain. Section 12 caps Genlook's aggregate liability at the fees you paid in the preceding twelve months, or one hundred euros if you have paid nothing. Section 16 sets French law and the courts of Lyon.
None of that is unusual for SaaS, and the consumer carve-outs are drafted carefully. But it is the whole ballgame for a small brand. A free widget with a hundred-euro liability cap and a merchant-side indemnity means the vendor's excellent privacy posture is a defense for the vendor. Your defense is your own notice and consent flow.
That flow is currently thinner than the statutes contemplate. The shopper policy describes consent as "by continuing you agree to this policy," recorded in the browser. BIPA section 15(b) contemplates a written release plus written notice of the specific purpose and the retention schedule before collection. If a court ever concludes that rendering a garment onto a body involves a scan of body geometry, continuation consent is unlikely to be the written release the statute asks for, and the entity on the hook for that notice is the one that put the button on the page.
What to watch
Before turning on any try-on tool that asks for a customer photo:
- Get the documents that are not published. The DPA, the subprocessor annex, and the Biometric Data Statement are all available only by emailing privacy@genlook.app. Ask for all three and keep them. A statement written for compliance reviews is worth much more in your file than a sentence in a public policy.
- Read the indemnity before the privacy policy. Know which direction it runs and what the liability cap is. If the cap is a hundred euros, price your own compliance accordingly.
- Ask about geofencing. Nothing in Genlook's published material disables or gates photo upload for shoppers in Illinois, Texas, or Washington, the way some retailers already do for other AI features. Ask whether it can be configured, and ask in writing.
- Write your own notice and put it at the upload screen. Genlook supplies a template paragraph for your store's privacy policy, and you should use it, but a privacy-policy paragraph is not a point-of-collection disclosure. New York's synthetic-performer disclosure law and similar rules elsewhere are trending toward requiring conspicuous, plain-language notice for AI-generated imagery at the moment it happens.
- Mind the age floor. The shopper policy says the try-on is not intended for anyone under sixteen. If your customer base skews teen, that is your problem to solve at the storefront, not the vendor's.
To my knowledge, no regulator has yet brought a case against a retail virtual try-on tool specifically. That will likely change. When it does, the first defendants will probably be the stores that installed the tool without asking these questions, not the company that built it, and the contract those stores signed will say so in as many words.
Sources
- Genlook Launches New AI Virtual Try-on Model for Fashion Stores: Any Garment on the Shopper in Under 10 Seconds
- Genlook Privacy Policy (merchants, API customers, account holders), effective September 4, 2026
- Genlook Shopper Privacy Policy
- Genlook Terms of Service, effective September 2, 2026
- Genlook Legal Notice
- GenLook: AI Virtual Try On, Shopify App Store
- 740 ILCS 14, Biometric Information Privacy Act
- Tex. Bus. & Com. Code ch. 503, Capture or Use of Biometric Identifier
- RCW ch. 19.375, Biometric Identifiers
- EU AI Act, Article 50, Transparency Obligations