PetStitch

Privacy Policy

Last updated: March 6, 2026

1. Data Controller

The data controller responsible for your personal data is:

Quantum Research Lab Kft.

9700 Szombathely, Vaci Mihaly utca 28/4, Hungary

EU VAT: HU32123564

Email: privacy@petstitch.art

2. Data We Collect

We collect the following categories of personal data:

  • Account Information: Email address, name (if provided), authentication data via third-party providers (Google, Facebook, Apple).
  • Pet Photos: Images you upload for embroidery design generation. These are processed by our AI pipeline and stored to deliver your designs.
  • Payment Data: We do not store credit card numbers. All payment processing is handled by Stripe, Inc. We receive only transaction identifiers, amounts, and your email for order fulfillment.
  • Usage Data: IP address, browser type, pages visited, device information, and interaction logs collected automatically for service improvement and security.
  • Onboarding Preferences: Pet details (name, breed, age, personality) and style preferences you provide during the design process.

3. Legal Basis for Processing (GDPR Art. 6)

  • Contract Performance (Art. 6(1)(b)): Processing your pet photos and delivering embroidery designs is necessary to fulfill our contract with you.
  • Consent (Art. 6(1)(a)): Where you have given explicit consent, such as agreeing to our terms at sign-up or opting into marketing communications.
  • Legitimate Interest (Art. 6(1)(f)): Service improvement, fraud prevention, and security monitoring.
  • Legal Obligation (Art. 6(1)(c)): Retaining transaction records as required by Hungarian tax law.

4. How We Use Your Data

  • To generate AI-powered embroidery designs from your pet photos
  • To process payments and deliver digital files to your email
  • To create product mockups through our partner services
  • To communicate with you about your orders and account
  • To improve our service, algorithms, and user experience
  • To comply with legal obligations under Hungarian and EU law

5. Third-Party Data Processors

We share your data with the following processors, all of which maintain adequate data protection standards:

OpenAI, Inc.

AI image generation (DALL-E). Pet photos are sent for design generation. OpenAI does not use API inputs for training.

USA (EU-US Data Privacy Framework)

Stripe, Inc.

Payment processing. Handles all credit card data.

USA (EU-US Data Privacy Framework)

Vercel, Inc.

Website hosting and content delivery.

USA (EU-US Data Privacy Framework)

Printful, Inc.

Product mockup generation and physical product fulfillment (if ordered).

USA/Latvia (EU-US Data Privacy Framework)

Resend, Inc.

Transactional email delivery.

USA (EU-US Data Privacy Framework)

Cloudflare, Inc. (R2)

Cloud storage for uploaded images and generated designs. We use jurisdiction-specific endpoints to keep EU data within the EU.

EU jurisdiction (Cloudflare R2)

6. International Data Transfers

Some of our processors are located in the United States. These transfers are protected by the EU-US Data Privacy Framework, Standard Contractual Clauses (SCCs), or other approved safeguards under GDPR Chapter V.

7. Data Retention

  • Account data: Retained while your account is active, and for up to 12 months after deletion request.
  • Pet photos and designs: Stored for 90 days after generation to allow re-downloads, then automatically deleted.
  • Transaction records: Retained for 8 years as required by Hungarian accounting law (2000. évi C. törvény).
  • Usage logs: Retained for up to 12 months, then anonymized or deleted.

8. Cookies and Tracking

We use the following types of cookies:

  • Essential cookies: Required for authentication, session management, and security. Cannot be disabled.
  • Analytics cookies: Help us understand how visitors use our site. We use privacy-friendly analytics that do not track individuals across sites.

We do not use advertising cookies or sell your data to advertisers.

9. Your Rights Under GDPR

As an EU/EEA resident, you have the following rights:

  • Right of Access (Art. 15): Request a copy of your personal data.
  • Right to Rectification (Art. 16): Request correction of inaccurate data.
  • Right to Erasure (Art. 17): Request deletion of your data ("right to be forgotten").
  • Right to Data Portability (Art. 20): Receive your data in a machine-readable format.
  • Right to Restrict Processing (Art. 18): Request limitation of data processing.
  • Right to Object (Art. 21): Object to processing based on legitimate interests.
  • Right to Withdraw Consent (Art. 7): Withdraw previously given consent at any time.

To exercise any of these rights, contact us at privacy@petstitch.art. We will respond within 30 days.

10. US Privacy Rights

If you are a resident of California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), or other US states with privacy legislation, you have additional rights:

  • Right to Know: What personal information we collect and how it is used.
  • Right to Delete: Request deletion of your personal information.
  • Right to Opt-Out: We do not sell or share your personal information for cross-context behavioral advertising.
  • Non-Discrimination: We will not discriminate against you for exercising your privacy rights.

To make a request, email privacy@petstitch.art.

11. Children's Privacy

Our service is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

12. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including encryption in transit (TLS/HTTPS), secure cloud infrastructure, access controls, and regular security reviews.

13. Supervisory Authority

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Hungarian data protection authority:

Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)

1055 Budapest, Falk Miksa utca 9-11, Hungary

Phone: +36 (1) 391-1400

Website: naih.hu

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Continued use of our service after changes constitutes acceptance of the updated policy.

15. Contact Us

For any questions about this Privacy Policy or your personal data, contact us at:

privacy@petstitch.art