Stitchoice

Privacy Policy

Updated October 5, 2026

Information used by the shop

When you purchase a pattern, the shop stores the order reference, purchased products, prices, payment state, PayPal order and capture references, delivery email entered at checkout and email supplied through PayPal, policy acknowledgment, refunds and relevant dispute updates.

The delivery system records access-link issue and expiry times and email-job outcomes. IP addresses are used in short-lived rate-limit checks to reduce misuse. These records support payment verification, delivery, recovery and resolving order problems.

Payment processing

PayPal processes payments. The shop does not ask for or store full payment-card numbers, PayPal passwords or bank login details. PayPal's own privacy policy applies to its payment interface.

Email and service providers

Order and recovery emails are delivered through Resend when the sending service is configured. The shop sends the purchase email address and order message to that provider. Hosting, Google Drive folder delivery and the order database process information needed to operate the service. We do not publish customer order information or sell purchase email addresses.

Cookies and browser storage

The shop uses an essential session cookie for order access and request protection. Your shopping bag is stored in your browser. PayPal's checkout interface is loaded only on the checkout page after the delivery email and policy acknowledgment are provided and may use its own cookies and device information.

No advertising or behavioral analytics system is installed by this shop integration. Blocking essential cookies may prevent checkout or order access. You may clear browser storage to remove the saved bag.

Keeping and protecting records

Order and transaction records are kept for support, accounting and resolving disputes. Retention must also meet requirements applicable to the seller. Expired access capabilities and sessions are periodically removed. Paid folder links and order data are kept out of the public catalog, with restricted server access.

Do not share private order links. No network or storage system can guarantee absolute security.

Your requests

Use the contact page to ask about access, correction or deletion of your information. We may need to verify the request and retain information required for transactions, disputes or legal obligations.

Changes

This page is dated to identify its version. Changes to the shop's installed services or handling of information will be reflected here.

Customer care and email sign-in

Support messages, reply email addresses, supplied order references and staff replies are stored to resolve your request. Closed messages are removed after 180 days. Customer email fields and support-message contents are encrypted in the application database; email lookup uses keyed hashes. Email sign-in links are single-use, expire after 15 minutes and are stored hashed. Email verification is required to access the download library in another browser. The sign-in session lasts up to 24 hours; signing out ends access in that browser.

Download-link activity and order administration

When you press a purchased pattern download button, the shop records the order reference, pattern and time of the request. Google Drive button requests do not show whether you downloaded or opened a file. Google handles activity after the folder opens, and later direct folder visits are not tracked by this shop. Local ZIP responses, where used, record transferred response bytes and whether the response completed. These records help resolve delivery questions, not advertising or cross-site profiling.

The owner panel stores private order notes, invoice snapshots and an activity log of management actions. Notes and invoices containing customer information are encrypted in the application database. These records are retained with transaction and support records for accounting, delivery and dispute handling. Only authenticated management access can inspect them.