Trust & Security

Last updated: Aug 2026
Skiply asks retailers to trust us with two sensitive things: images captured inside their customers' homes, and the return data behind them. This page explains how we think about protecting both.

Where we are today

Our product is in development. We are working with a small number of prospective retail partners and we are not yet processing mass production returns at scale.

That shapes how we handle data right now. We hold very little of it, we collect only what a return actually requires, and we would rather delay a feature than take on data we are not ready to protect. As we move toward production, the controls below move with us, and we will keep this page current rather than let it drift.

What is true today

These are design decisions and commitments, not controls we still need to build.

We do not do biometrics.

No facial recognition. No faceprints, voiceprints, iris scans, fingerprints, or face geometry. We do not create biometric identifiers, store them, or derive them from images. This is architectural. It is not a setting a customer can enable, and it holds under Illinois BIPA, Texas CUBI, Washington's biometric and health privacy laws, and equivalent rules elsewhere.

We analyze items, not people.

Our models are built to recognize products, brands, packaging, accessories, wear, and damage. We do not infer demographics, income, household composition, or anything else about a person from what appears in the frame.

We do not sell personal information.

We never have, and we do not share it for advertising.

We do not expose one customer's data to another.

Not in a model output, not in a benchmark, not in a conversation.

We collect the minimum.

We ask retailers to send us the least data a return requires, and we do not need direct shopper identifiers to assess an item.

We use reputable infrastructure.

We run on established cloud and third-party services and rely on the encryption and access controls they provide, rather than building our own.

What we commit to before processing production data

We will have the following in place before a retailer sends us production returns data, and we will tell you honestly where we are in that process at any point during your evaluation.
Control Commitment
Encryption TLS 1.2 or higher in transit, encryption at rest for all stored data including images and backups
Access control Role-based access, least privilege, access removed same-day on departure
Authentication Multi-factor authentication required on all internal systems
Customer isolation Logical separation of each customer's data
Logging Access and application logging, retained and reviewable
Incident response A written plan covering detection, containment, remediation, and customer notification
Vendor review Security review of each subprocessor before it touches customer data
People Confidentiality obligations and security training for everyone with access to customer data
Retention Item images deleted or irreversibly de-identified no later than 180 days after a return is resolved
De-identification Direct identifiers and retailer-attributable fields removed before any data is used for model development
Our longer-term roadmap includes third-party penetration testing, formal access reviews, and a SOC 2 Type II examination. We are not going to put a date on those until we can hold it.

Item images and the home

Our capture flow can run on a shopper's own phone, inside their home. We treat that as the most sensitive part of our product, and it is the reason we made the biometric decisions above before writing a line of model code.

A scan may accidentally include a person or a room in the background. We ask retailers to guide shoppers to frame only the item. Before any item data is used for model development, we commit to reviewing and removing images containing incidental people, and we are building automated screening to do that as volume grows.

If someone believes an image of them was captured, they can email info@skiply.ai and we will locate and delete it.

Subprocessors

We use a small set of vendors to run the platform. Each is contractually bound to protect customer data and use it only to provide services to us.
Subprocessor Purpose Data location
[Cloud provider] Hosting, storage, compute United States
[Model or inference provider] Computer vision inference United States
[Error monitoring] Application error tracking United States
[Analytics] Website and product analytics United States
[Email and support] Transactional email and support United States
Customers receive advance notice of material changes to this list as their agreement provides. To get the current list or subscribe to change notifications, email info@skiply.ai.

Privacy and compliance


U.S. state privacy laws.

We act as a service provider or processor for shopper data we handle on a retailer's behalf. We process it only on the retailer's documented instructions, do not sell or share it, and do not combine it with data from other sources except as permitted.

GDPR and UK GDPR.

We will enter data processing agreements with standard contractual clauses and the UK addendum where required, and support customers in responding to data subject requests.

Payment data.

If and when we bill customers, card and bank details go directly to a PCI DSS compliant payment processor. We do not store full payment card numbers.

Certifications.

We do not hold SOC 2, ISO 27001, or any other security certification today. We would rather say that plainly than imply otherwise. A SOC 2 Type II examination is on our roadmap and we will update this page when it is underway.

Data residency.

Customer data is stored in U.S. regions. Talk to us if you have regional requirements.

Working with us on a security review

We know we are early, and we know that means your security team will have questions. We would rather answer them now than have them surface late in procurement. We can provide:

- A completed security questionnaire, including SIG Lite and CAIQ formats
- A data processing agreement with standard contractual clauses
- Architecture and data flow diagrams
- A named subprocessor list with change notifications
- Custom retention, deletion, and residency terms where your requirements need them
- A written plan and timeline for any control you need in place before you send us production data

If a control matters to you and we do not have it yet, tell us. We will either build it before you go live or tell you we cannot, and we will not pretend otherwise.

Email info@skiply.ai.

Related

Skip Industries, Inc. (dba Skiply) Boston, Massachusetts | info@skiply.ai

Building the valuation infrastructure
for the footwear industry.

Legal

© 2026 Skiply