Privacy Policy
Vigente desde
This policy explains what Nymbo SpA, DBA Stitchly, collects when you visit embroiderydesignmaker.com or use Stitchly, why we hold it, who else processes it, and what you can ask us to do about it. It describes the service as it works today.
Who we are
Stitchly is operated by Nymbo SpA, DBA Stitchly, a company incorporated in Chile. Nymbo SpA decides why and how the personal data described here is used, which makes it the controller of that data.
Write to hello@embroiderydesignmaker.com about anything in this policy, including a request about your own data. That address reaches us directly.
Your account and profile
Using the editor requires an account. The account record holds your name, your email address, whether that address has been verified, a profile image address if your sign in method supplies one, and the times the record was created and last changed.
You can change your name and your email address yourself in Account, and you can delete the account from the same place.
Signing in
Signing in creates a session record. It holds a session identifier and its token, the expiry, the times it was created and last used, the IP address the sign in came from, and the browser user agent string. We keep this so we can recognize you on your next request and so we can tell a stale session from a live one.
Alongside the session we keep the records our authentication library needs to identify you: the identifier of the sign in method attached to your account, any credential or provider token that method requires, and short lived verification records for actions such as confirming an email address. Sessions expire, and signing out removes the session record.
Projects and Documents
A Project stores the title you give it and its Document: the Hoop dimensions, the position and transform of every design and piece of Lettering, the text you typed, the Thread Choices you picked, a revision number, and timestamps. We store Documents so your work is waiting when you return and so an export can be produced from them.
Projects are readable only by the account that owns them. Every server request that touches a Project checks that ownership first.
Uploads, Artifacts, and design search
When you upload artwork, an embroidery file, or a font, we store the file and everything derived from it: the converted or sanitized design, its preview image, and, for each export, the machine file and the printable Run Sheet. Each stored file carries its size, its content type, a SHA-256 digest of its bytes, and the key it lives under. Processing also records whether it succeeded and, when it did not, a diagnostic message that can include the file name you chose.
So that your own designs can be found by meaning rather than by exact words, we send the name, tags, and category of a design together with its preview image to Voyage AI, which returns a list of numbers called an embedding. We store the embedding in a Cloudflare Vectorize index. The words you type into design search are sent the same way, so they can be compared against those embeddings. Uploaded fonts and machine files are not sent to Voyage AI.
Billing
Pro Plan subscriptions are sold and processed by Polar, which acts as the merchant of record. Checkout, payment details, invoices, and any card data stay with Polar. We never see or store your card number.
What we store is the record Polar sends back: your Polar customer and subscription identifiers, which product you bought, the status of the subscription, the date the current period is paid through, whether it is set to cancel at the end of that period, and when the last update arrived. We use it to decide whether your account has the Pro Plan.
Analytics and cookies
The cookie the product cannot work without is the one that keeps you signed in. It carries your session and nothing else, and it is never used for advertising.
Where product analytics is switched on for a deployment, PostHog runs in your browser and records how the interface is used along with the technical detail a browser reports, such as the page address, the referring page, the browser, and the device. PostHog keeps its own identifiers in your browser storage. We do not sell any of this, we run no advertising network on the site, and we build no advertising profile.
Every page of the site, signed in or not, loads its typefaces from Google Fonts. Requesting a font tells Google the IP address of your browser.
When you write to us
Mail you send to hello@embroiderydesignmaker.com is kept together with our reply so we can follow the conversation and check what was agreed. Please do not send us anything sensitive that the question does not require.
Why we use it
Each of the uses above serves one of these purposes.
- Providing the service you asked for: creating your account, keeping your Projects, converting uploads, generating exports, and giving you the Pro Plan you paid for.
- Consent that you gave and can withdraw: the newsletter, and analytics where the law where you live requires consent for it.
- Keeping the service standing up: rate limiting, abuse prevention, diagnosing failures, and understanding which parts of the product are used.
- Obligations we cannot opt out of: tax, accounting, and other records the law requires us to keep.
Where Chilean Law 19.628 on the protection of private life applies, we rely on your consent to the uses described in this policy and on the agreement between us that the Terms of Service set out.
Who else processes your data
We use a small number of service providers. They process data on our instructions, for the purposes above.
- Cloudflare: hosting, application runtime, the database that holds accounts and Projects, the object storage that holds uploads and exports, the search index, and delivery of our outbound email.
- Polar: subscription checkout, payment, and merchant of record duties for the Pro Plan.
- Voyage AI: turning design names, tags, categories, previews, and search queries into embeddings.
- PostHog: product analytics, where it is switched on.
- Google: serving the typefaces every page of the site uses.
International transfers
Nymbo SpA is in Chile. The providers above operate outside Chile, largely in the United States, and Cloudflare serves the site from data centers around the world. Using Stitchly therefore means your data is transferred to and processed in countries whose data protection rules may differ from those where you live.
Security
Traffic to the site uses HTTPS. Projects, uploads, and exports are scoped to the account that owns them, and the server checks that ownership on every request rather than trusting the browser. Confirmation and unsubscribe tokens are stored as digests. Beyond our own code we depend on the security of the providers listed above.
We hold no security certification and have not been independently audited, and we do not claim that a breach is impossible. No online service can honestly promise that.
How long we keep it
- Account records, Projects, uploads, and generated exports: while your account exists.
- Session records: until they expire or you sign out.
- Newsletter records: until you unsubscribe, after which the unsubscribed record is kept so we can keep honoring it.
- Billing records: for as long as tax and accounting rules require, which can outlast the account.
- Mail you send us: while it is useful to the conversation and to any dispute it concerns.
Deletion, and what it cannot reach
You can delete individual Projects and uploads, and you can delete the whole account from Account. Deleting the account removes the account record and the records attached to it, including your Projects, your uploaded designs, and your Export Job history.
Three limits are worth stating plainly. Stored files are removed by a scheduled sweep rather than at the instant you press delete, so we do not promise a deletion window. A stored file is addressed by the digest of its contents and can be referenced by more than one record, so a file that another record still needs stays until nothing references it. Deleting the whole account removes the records first, which can leave stored files behind that the sweep no longer has a record to work from. Copies can also survive for a time in our providers' backups, which we do not control.
If you need a particular file removed, or want to know whether it is gone, write to hello@embroiderydesignmaker.com and we will deal with it by hand.
Your rights
Under Chilean Law 19.628 and any other data protection law that applies to you, you can ask us what we hold about you, ask us to correct it, ask us to delete it, ask us to stop a particular use, and withdraw a consent you gave. Withdrawing consent does not undo what was done while it was in force.
Most of this you can do yourself in Account. For anything else, write to hello@embroiderydesignmaker.com from the address on the account. We may have to confirm who you are before acting, and we answer within the time the applicable law allows.
Children
Stitchly is not intended for children. An account requires you to be 18, or the age of majority where you live, and we do not knowingly collect data from anyone younger. If you believe a child has an account, write to us and we will remove it.
Changes to this policy
When this policy changes we publish the new text here and move the effective date at the top. Where a change materially affects you we will say so on the site. Continuing to use Stitchly after a change means the current version applies.
Contact
Nymbo SpA, DBA Stitchly. Questions, requests, and complaints about this policy go to hello@embroiderydesignmaker.com.