Privacy Policy
TIEX TECNOLOGIA E INOVACAO LTDA · CNPJ 52.667.724/0001-97 · Last updated September 22, 2026
This is the English version of our Política de Privacidade. Both describe the same practices.
1. Who we are
Provador de Joias is a product of TIEX TECNOLOGIA E INOVACAO LTDA, a company registered in Brazil under CNPJ 52.667.724/0001-97, based in Guaporé, Rio Grande do Sul (“Tiex”, “we”). This policy explains what personal data we process, why, who we share it with, how long we keep it, and how you exercise your rights.
It covers three situations:
- Virtual try-on: when you use the “Try it on” button in the online store of a jewelry or eyewear retailer that uses Provador de Joias.
- Merchants: when a business creates an account, uses the dashboard, subscribes to a plan, or installs our app on an e-commerce platform such as Shopify.
- Website: when you browse provadordejoias.com.br or contact our team.
2. Who is responsible for what
In the virtual try-on, the store you are shopping in decides to offer the try-on to its customers and is the controller of that data. Tiex acts as a processor: we handle your photo on the store’s behalf, only to generate the try-on and keep it safe. For our security and abuse-prevention logs, and for merchant and website data, Tiex is the controller.
3. Virtual try-on: what we process
- Your photo, taken with the camera or picked from your gallery, and the generated image with the piece applied.
- Technical access data: IP address, approximate location derived from the IP (country, state and city), device type, operating system, browser, the store and product you came from, date and time.
- A random session identifier, stored only in your browser tab (sessionStorage). We do not use cookies in the virtual try-on.
We do not ask for your name, email or phone number to try a piece on, and we do not perform facial recognition: your photo is not used to identify you or to build a biometric template.
4. Virtual try-on: how it works and why
When you confirm the photo, it is sent to our servers and to a generative artificial intelligence provider, which creates a new image showing the piece worn by you. The result appears on your screen and is available to the store so it can follow the try-ons made on its own website.
We use this data to:
- generate and display the try-on you asked for;
- let the store see the try-ons performed and the quality of the result;
- protect the service against abuse, fraud and overload (limits per device and per IP address);
- measure usage, count the store’s monthly allowance, and fix failures.
Our legal basis is your consent, given when you choose and confirm the photo, and our legitimate interest for security and measurement logs. You can stop using the try-on at any time: buying from the store never depends on it.
5. Merchants and website
- Account and dashboard: name, email, phone, company name, password (stored hashed), and the IP and browser of each session. With Google sign-in, we receive a verified name and email.
- Platform apps (such as Shopify and Nuvemshop): the store name, email and domain, the store identifier, and the access token the merchant authorized.
- Payment: subscriptions taken on our website are processed by Stripe, and card details are typed directly into Stripe’s environment and never reach our servers. Subscriptions taken through the Shopify App Store are billed by Shopify, and we never see any payment details.
- Sales contact: whatever you send through forms on our website, by email or WhatsApp, and through the forms in our Facebook and Instagram ads.
- Website analytics: we use Google Analytics and the Meta Pixel to measure visits and the results of our ads. The Pixel records page views and contact-form submissions; it is not used in the virtual try-on and never receives photos.
We use this data to deliver the service, meet legal and tax obligations, answer enquiries, send messages about the account, and for security.
6. The Shopify app
When a merchant installs our app on a Shopify store:
- The app requests no Admin API access scopes. It cannot read orders, customers, products or any other data in the store.
- We store the store’s myshopify.com domain, its name and contact email as Shopify reports them, and the access token Shopify issues, which we use only to create and read the app subscription for billing.
- We subscribe to Shopify’s three mandatory privacy webhooks —
customers/data_request,customers/redactandshop/redact. We hold no data about the store’s customers, so there is nothing to return or erase in response to the first two;shop/redactremoves the store’s own record from our systems. - When the app is uninstalled, Shopify notifies us and the access token is deleted.
- The photo a shopper uploads is never associated with a Shopify customer account, an order, or any identity held by the store.
7. Who we share data with
We do not sell personal data. We share only what is needed with the suppliers that run the service:
- Google (Gemini) and Freepik (generative AI providers; the second is used when the first is unavailable): they receive your photo and the photo of the piece in order to generate the try-on;
- Meta (Facebook and Instagram): contact details submitted in our ad forms, Pixel measurement on our website and, in encrypted form, business contacts used in ads;
- Cloudflare: image storage and content delivery;
- ipinfo.io / ipwho.is: approximate location lookup from the IP address;
- Google: web fonts on the try-on page (which receives IP and browser) and dashboard sign-in;
- Stripe and Shopify: subscription billing, depending on where the merchant subscribed;
- Resend: transactional email to merchants;
- Hosting of our servers and database in Brazil;
- the store where the try-on was made, which sees the try-ons performed on its own website;
- authorities, where required by law or court order.
Some of these suppliers process data outside Brazil. In those cases the international transfer happens in order to deliver the service, with suppliers whose protection standards are compatible with Brazilian data protection law.
8. How long we keep it
- Photos and generated images: for as long as they are needed to display the result and to let the store follow its try-ons, and deleted when you or the store ask, or when the store closes its account.
- Try-on access logs: the full IP address and browser are anonymized within 90 days; the rest of the record is deleted within 12 months.
- Merchant data: while the account is active and, afterwards, for as long as legal, tax and legal-defence obligations require.
- Platform integrations: the access token is deleted when the app is uninstalled or when the platform asks us to erase the data.
9. Security
We use encrypted connections (HTTPS), hashed passwords, per-company access control, limits against automated use, and audit logs. No system is completely immune to incidents; if a relevant incident occurs, we will notify those affected and the Brazilian data protection authority, as the law requires.
10. Your rights
You can ask us at any time for:
- confirmation that we process your data, and access to it;
- correction of incomplete or outdated data;
- anonymization, blocking or erasure of unnecessary data, and deletion of your photos;
- information about who we share it with;
- portability, and withdrawal of your consent.
For a virtual try-on, tell us the store, the approximate date and, if you can, a screenshot of the generated image — we do not ask for your name in order to try a piece on, so we have no other way to find it. You can also make the request to the store itself. We answer within 15 days.
11. Contact and data protection officer
Requests, questions and contact with our data protection officer: contato@provadordejoias.com.br. TIEX TECNOLOGIA E INOVACAO LTDA, CNPJ 52.667.724/0001-97, Guaporé, Rio Grande do Sul, Brazil.
12. Changes
We may update this policy when the service changes. The date of the last update is shown at the top of this page, and merchants are told by email about relevant changes.