PRIVACY POLICY
last updated August 10, 2026
This Privacy Notice for AL UMA ALRAQAMI COMPUTER SYSTEMS DESIGN (License No. 1183327), doing business as "Face Age" ("we," "us," or "our"), describes how and why we collect, store, use, and share ("process") personal information when you use our services (the "Services"), including when you:
Visit our website or panel at https://panel.getfaceage.com, https://www.getfaceage.com, or any site that links to this Notice;
Use the Face Age AI Skin & Face Analysis solution — our quiz and camera/photo-upload widget — as a business, developer, or as a shopper on a merchant's storefront;
Integrate the Face Age JavaScript SDK, connect to the Face Age API, or install the Face Age Shopify application on your store; or
Otherwise engage with us, including through support, marketing, or events.
If you do not agree with this Notice, please do not use the Services. Questions can be sent to dev@getfaceage.com.
1. Who We Are and What This Policy Covers
1.1 The Four Components This Notice Covers
Face Age is delivered through four technical components that work together. This Notice applies across all of them, and identifies where a practice is specific to one component:
The Panel — the account and administration dashboard used by businesses and developers to manage their Face Age account, API keys, and integration settings.
The API Backend (core.getfaceage.com) — the central system that authenticates businesses, stores accounts, and stores analysis records and results.
The AI Processing Service — the machine-learning service that analyzes a submitted photo and returns face and skin metrics to the API Backend.
The SDK and Shopify Application — the widget embedded on a business's website or Shopify storefront that end shoppers interact with directly to take the quiz, submit a photo, and view results.
Businesses and Shopify merchants that embed our widget on their own storefronts are, in relation to their own customers, independent data controllers. Face Age acts as their data processor / service provider for the personal data of their end customers, and as a data controller for the accounts, billing, and support data of the businesses themselves. Section 15 explains this distinction in more detail.
2. Summary of Key Points
What we collect: account and business details, payment identifiers, and — when the skin/face analysis feature is used — a photo of a face and the skin/face metrics derived from it, which we and applicable law treat as special category (biometric/health-adjacent) data. See Section 3.
Do we process sensitive data? Yes. Facial images and derived skin/face metrics are processed only with explicit consent, obtained before the camera or upload feature activates. See Sections 3.2 and 6.
Is my photo stored, or only analyzed in real time? By default, your photo is used only to perform the analysis and is deleted from our servers once processing is complete. If the business you interacted with has enabled the optional "History" feature (see Section 3.2), a copy of the photo and its results is kept — in your browser and, to support that feature, on our servers — until it is cleared or the business disables the feature. If History is not enabled, nothing is retained.
Who do we share information with? Service providers that help us operate (hosting, AI processing, payments, email/CRM, analytics) and, if you interact with Face Age through a merchant's store, that merchant. See Sections 8 and 9.
Your rights: access, correction, deletion, restriction, portability, and objection, exercised by contacting us or, where available, through in-product self-service tools. See Section 13.
3. Personal Information We Collect
3.1 Account, Business, and Panel Information
When you or your business registers for the Panel or the API, we collect:
Account holder details: full name, email address, mobile phone number, password (stored as a bcrypt hash, never in plain text), and, if you sign in with Google, LinkedIn, or GitHub, your provider ID and the profile details that provider shares with us;
Business/merchant details: business name, website and domain, contact email and phone, physical address, business size, logo, and, if applicable, your Shopify shop ID;
Access credentials: API access keys and authentication tokens issued to your business (these expire and are revoked automatically or on request);
Preferences: your marketing-email opt-in status and language/notification preferences.
3.2 Facial Images and Skin/Face Analysis Data (Special Category Data)
This is the most sensitive category of information the Services process. Where you (as an individual using the widget, whether directly or on a merchant's storefront) submit a photo, we and our AI Processing Service collect and derive:
The photo you submit, taken by camera or uploaded from your device;
Facial geometry used to perform the analysis (for example, face position and orientation);
Derived skin and face metrics, such as an apparent age estimate, and scores for wrinkles (fine, eye, and deep), dark circles and eye bags, pore size, pigmentation, acne, redness, oiliness, dryness, and sagginess;
Any free-text notes you submit alongside a request (for example, a question you ask our AI-assisted help feature).
We treat this information as "special category" personal data under Article 9 GDPR (biometric data, and, in relation to the skin-condition metrics, health-adjacent data). We process it only on the basis of your explicit consent, given by checking the consent box presented before the camera or upload feature activates. You may decline, in which case this feature will not be available to you.
How the photo is actually handled:
Your photo is sent over an encrypted (HTTPS) connection to our AI Processing Service, which analyzes it and returns the skin/face metrics to the API Backend;
Once the analysis is complete, the photo is deleted from our servers. By default, we do not keep a copy of your photo after your report has been generated;
The only exception is the optional "History" feature: a business can choose, in its Face Age customization settings, to enable a history function so that shoppers can revisit past results. History is off unless the business turns it on. When it is on, a copy of the photo and the resulting metrics for each history entry (up to five) is kept in your browser and, to make that history available across devices and to the business, on our servers — in the API Backend, in the analysis record described below, and, where you interacted with Face Age through a Shopify storefront, in your Shopify customer profile (metafields);
Where History is enabled, we keep that stored copy so we can show you your report and history, support the account you or the merchant hold, and let you exercise your rights of access and deletion at any time — we do not keep it for any purpose beyond delivering and supporting the Services;
Whether or not History is enabled, you may ask us to delete a specific analysis record, or all of your analysis history, at any time — see Section 13.
We also offer a privacy-preserving mode (an anonymized/masked output with a watermark) for use cases where a merchant wants to display or share a processed image without exposing the identifiable original.
3.3 Payment Information
Card payments are processed by Stripe and, where offered, PayPal. We do not store your full card number. We retain only the Stripe customer reference, the payment method type, and the last four digits of the card, together with subscription/trial status, in order to manage your billing relationship with us.
3.4 Information Collected Automatically
When you use the Services, we and our infrastructure automatically collect:
IP address, associated with each analysis request and stored alongside the request record;
Device and browser information, operating system, and general request metadata;
Usage data such as which analysis features were used, which products were viewed or added to cart following a recommendation, and error/diagnostic information generated while you use the Services;
Cookies and similar technologies described in Section 6.
3.5 Behavioral and Quiz Data
If a business has configured a quiz as part of its widget, we collect your answers (for example, self-reported skin type, age range, or lifestyle questions) and, where the widget requests it, an email address and/or phone number so a report can be sent to you.
3.6 Local Device Storage
Where a business has turned on the "History" feature described in Section 3.2, the SDK stores up to five recent analysis entries (including the images and metrics) in your browser's local storage and/or a cookie, for up to 365 days, so you can revisit recent results without re-submitting a photo. If the business has not enabled History, no such local storage entry or cookie is created. This data lives on your own device; you can clear it at any time from the widget's history controls or from your browser's site-data settings.
4. How We Use Your Information
We use the information described above to:
Create and administer accounts, and authenticate access to the Panel and API;
Perform the AI skin/face analysis you request, generate your report, and — where enabled by a business — recommend products based on your results;
Deliver reports by email and maintain your analysis history so you can track changes over time;
Process payments and manage subscriptions;
Provide customer and merchant support, and respond to inquiries;
Send administrative communications, and, where you have opted in, marketing communications;
Maintain the security of the Services, detect and prevent fraud or abuse, and enforce our Terms of Use;
Comply with our legal obligations, including responding to lawful requests from authorities.
We do not sell personal information, and we do not use facial images or derived skin/face metrics for any purpose other than delivering, supporting, and improving the Services described in this Notice, unless we ask for your separate, specific consent.
5. Legal Bases for Processing (EEA, UK, and Similar Regimes)
Account and business registration, billing, API access — Performance of a contract (Art. 6(1)(b)).
Facial/skin analysis and report generation — Explicit consent (Art. 9(2)(a), together with Art. 6(1)(a)).
Product recommendations based on analysis results — Explicit consent / legitimate interest in delivering the requested feature.
Marketing communications — Consent (Art. 6(1)(a)), withdrawable at any time.
Security, fraud prevention, and abuse monitoring — Legitimate interests (Art. 6(1)(f)).
History feature, analytics, and advertising cookies — Consent, off by default; only activated if a business enables it in its Face Age customization settings.
Compliance with legal obligations (e.g., tax, law-enforcement requests) — Legal obligation (Art. 6(1)(c)).
The History feature, and any analytics or advertising script (such as Google Analytics/Tag Manager or the Meta Pixel), is off by default and only runs if the business enables it in its Face Age customization settings. Where the Services are embedded on a merchant's own website or Shopify store, the merchant is also responsible, as the controller of its own storefront, for presenting any cookie or advertising-consent banner its own site or applicable law requires for the analytics or advertising scripts it chooses to enable.
6. Cookies and Tracking Technologies
Nothing in this section is active by default. We and the businesses that embed our widget only use the following cookies and similar technologies where a business has specifically turned the related feature on in its Face Age customization settings; if a business has not enabled a feature, the corresponding cookie or local storage entry is never created:
History cookies/local storage, which the widget uses to remember your recent results, only where the business has enabled the History feature described in Sections 3.2 and 3.6;
A session cookie used for the consent status you give before the camera or upload feature activates;
Analytics cookies, such as Google Analytics/Tag Manager, where a business has connected its own tracking ID — these are configured and controlled by that business;
Advertising cookies, such as the Meta (Facebook) Pixel, on the same basis;
Resource-delivery requests to third-party content delivery networks (for fonts and interface libraries) that, as an unavoidable feature of how web browsers work, expose your IP address to those providers when the widget loads.
You can control cookies through your browser settings. Where a business has enabled History, analytics, or advertising cookies on its own site, please refer to that business's own cookie notice and consent tool for controls specific to that site.
7. Artificial Intelligence and Automated Decision-Making
Face Age's core feature is an AI-powered skin and face analysis. We use machine-learning models (operated by us) to derive skin/face metrics from your photo, and, where a business has enabled this feature, to generate personalized product recommendations from those metrics. We also use a third-party AI provider (OpenAI) to help generate plain-language explanations of results and to power an optional question-and-answer support feature; inputs sent to OpenAI may include your skin metrics, self-reported attributes (such as age range or skin type), product information, and free-text questions you submit — but not your original photo.
This processing can result in automated recommendations that affect the products shown to you. You have the right to request a human review of, or to object to, an automated recommendation by contacting dev@getfaceage.com. Declining does not affect your ability to use the underlying skin analysis feature; it only affects whether recommendations are generated automatically.
8. When and With Whom We Share Personal Information
We share personal information only as needed to provide the Services, and only under contractual terms that require the recipient to protect it. We do not sell personal information. The categories of recipients are:
Sub-processors that operate infrastructure and features on our behalf (hosting, database, AI processing, cloud storage);
Payment processors (Stripe, PayPal) to process transactions;
The Shopify platform, where you interact with Face Age via a Shopify storefront, to store customer tags and analysis metadata on your customer profile;
Marketing, CRM, and email platforms (for example Klaviyo, Omnisend, Mailchimp, HubSpot, or ReCharge) — only where the business you interacted with has connected one of these integrations, and only for the data fields that integration requires;
Analytics and advertising platforms (Google Analytics/Tag Manager, Meta Pixel) — only where the relevant business has enabled them;
Webhook endpoints that a business has independently configured to receive its own analysis data — the business, not Face Age, controls what is sent and to whom;
Professional advisors, law enforcement, or regulators, where required by law, or in connection with a business transaction such as a merger or acquisition.
9. International Data Transfers
Face Age is operated by a company established in the United Arab Emirates, but our core infrastructure — the API Backend and the AI Processing Service that handle facial images and analysis data — is hosted in the European Union, at Hetzner Online GmbH data centers in Germany. Our file storage (AWS S3, eu-north-1, Stockholm, Sweden) is also EU-based. Some of our sub-processors are located outside the EEA/UK, in the United States (for example, OpenAI, Stripe, PayPal, and several of the optional marketing/CRM integrations described in Section 8). Where personal information originating in the EEA, UK, or Switzerland is transferred to one of those non-EEA sub-processors, we rely on Standard Contractual Clauses or another valid transfer mechanism with that recipient.
10. How Long We Keep Your Information
We keep personal information only for as long as it is needed for the purposes described in this Notice, or as required by law:
Uploaded photo (default — History not enabled), held in the AI Processing Service (in-memory / temporary disk during analysis) — deleted from our servers as soon as the analysis is complete.
Photo + skin/face analysis record (History enabled by the business), held in the API Backend database and, where applicable, Shopify customer metafields — retained while History is enabled and until you request deletion, the entry ages out of your 5-entry history, or the related account is closed.
Analysis history entries (up to 5, History enabled), held in your browser (local storage / cookie) — up to 365 days, or until you clear it.
Account and business profile data, held in the API Backend database — retained for the life of the account; on deletion, most fields are erased or nulled, and your email address is retained solely for audit/anti-fraud purposes.
Payment identifiers (Stripe/PayPal references), held in the API Backend database / payment processor — retained for the account's life and any additional period required by applicable financial record-keeping law.
Application and security logs, held in the API Backend and AI Processing Service — retained for security, audit, and troubleshooting purposes; we are moving toward a fixed maximum retention window (target: 30–90 days).
One-time login/verification codes, held in the API Backend database — valid for approximately 2 minutes; purged shortly after use or expiry.
Exported data files (your data-export ZIP), held in API Backend temporary storage — available for download for a limited window after generation, then deleted.
Where a business or Shopify merchant closes its account or uninstalls the app, we delete the records under our direct control within 30 days, including the related analysis records, usage logs, and access tokens. If any of your data has already been shared with an optional third-party integration a business enabled (for example, an email marketing platform), please also contact that business, as they control that separate copy.
11. How We Keep Your Information Safe
We use a combination of organizational and technical measures designed to protect personal information, including hashing of passwords and one-time codes, encryption of integration credentials, encryption in transit (HTTPS/TLS) for all Services traffic, and access controls limiting who within our organization can view stored analysis data. AWS-hosted storage is encrypted at rest. No method of transmission or storage is completely secure, and while we work continuously to strengthen these safeguards, we cannot guarantee absolute security.
12. Children's Data
The Services are not directed to, and we do not knowingly collect personal information from, individuals under 18 (or the equivalent minimum age in your jurisdiction, such as 16 in the EEA for consent to information-society services, or 13 under COPPA in the United States). If a business chooses to make the Services available on a storefront that may be accessed by children, that business is responsible for implementing appropriate age-verification and parental-consent measures before enabling the photo-based analysis feature. If we learn that we have inadvertently processed a child's biometric data, we will delete it and, where applicable, deactivate the related account.
13. Your Privacy Rights
Depending on where you live, you may have the right to:
Access the personal information we hold about you and receive a copy of it;
Correct inaccurate or incomplete information;
Request deletion of your personal information ("right to be forgotten");
Restrict or object to certain processing, including profiling connected to automated product recommendations;
Receive your data in a portable, machine-readable format;
Withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal;
Lodge a complaint with your local data protection authority.
13.1 How to Exercise These Rights
Panel/business account holders can request an export of their account and analysis data directly through the Panel, or by emailing dev@getfaceage.com; exports are provided as a machine-readable file.
Account and analysis deletion is available directly through the Panel (verified by a one-time code sent to your registered email) or by request to dev@getfaceage.com.
If you interacted with Face Age as a customer of a Shopify merchant or another business using our widget, you may contact that business directly, or contact us at dev@getfaceage.com — we will fulfil access and deletion requests relating to the data we hold within 30 days, whether the request reaches us from you, from the merchant, or via Shopify's own customer-rights process.
We will verify your identity before acting on a request, and may decline a request or parts of it where permitted by law (for example, to preserve records required for fraud prevention or legal compliance).
14. Additional Terms for Shopify Merchants and Their Customers
14.1 Roles
Where you install the Face Age app on your Shopify store, you (the merchant) are the data controller for your customers' personal information, and Face Age acts as your data processor / service provider for the facial images, skin/face metrics, and related data our app processes on your behalf. You are responsible for obtaining valid consent from your customers before the AI Skin Analysis feature activates on your storefront, and for maintaining your own store's privacy notice, which should reference this Notice or incorporate the privacy supplement we make available to merchants.
14.2 What We Store on Your Behalf
For each of your customers who uses the widget, we (and, where applicable, Shopify's own metafield storage) hold: the customer's email, name, and Shopify customer ID; tags reflecting their skin-analysis segment; consent/marketing-opt-in status; up to five recent analysis history entries (including images and metrics); and usage events such as product views and add-to-cart actions following a recommendation.
14.3 Data Subject Requests From Your Customers
If one of your customers submits a data access or deletion request to you (including through Shopify's mandatory customer-data-request and customer-redact webhooks), we will provide the data we hold for that customer, or delete it, within 30 days of your request to us, and will remove the associated tags and metafields we control. On uninstalling the app, we remove the app-generated records under our direct control within 30 days, as described in Section 10.
14.4 Sub-Processors and Optional Integrations
Where you connect optional integrations such as Klaviyo, Omnisend, ReCharge, Google Analytics/Tag Manager, or the Meta Pixel, you are directing us to share the relevant customer data with that provider, and you are responsible for ensuring you have a valid legal basis and, where required, a Data Processing Agreement directly with that provider.
15. Controller and Processor Roles
To summarize the relationship described throughout this Notice:
For businesses' own account, billing, and support data, Face Age is the data controller.
For the personal data of a business's or merchant's end customers (photos, analysis results, contact details collected through the widget), the business is the data controller and Face Age is the data processor, acting only on the business's instructions and for the purposes described in this Notice and the applicable Data Processing Agreement.
A Data Processing Agreement, covering the categories of data processed, sub-processors used, security measures, and data-subject-request assistance, is available to business customers on request.
16. Social Logins
If you register or sign in using Google, LinkedIn, or GitHub, we receive the profile information that provider shares with us (typically your name, email address, and a provider ID). We use this only for the purposes described in this Notice. Please review that provider's own privacy notice to understand how they handle your information.
17. Changes to This Notice
We may update this Notice from time to time. The "Effective Date" at the top will change accordingly, and where changes are material we will provide additional notice (for example, by email or an in-product notice).
18. How to Contact Us
Questions, requests, or complaints about this Notice can be sent to:
Email: dev@getfaceage.com
Post: AL UMA ALRAQAMI COMPUTER SYSTEMS DESIGN, Westburry Building, Business Bay, Property Investment Office 4 — S1, Dubai, United Arab Emirates.
%202.png)