Privacy Policy
Last updated: June 10, 2026 Version: 2026-06-10
1. Who we are
So You Sew ("So You Sew", "we", "us") operates a mobile application that lets sewing hobbyists share projects, save inspiration, manage their personal fabric stash, and buy and sell sewing-related physical goods from each other (the "Service").
You can reach our privacy team at chambersjohn310@gmail.com.
2. Data we collect
From you, directly
- Account data: email address, username, display name, bio, optional location string, skill level, profile photo, password hash (stored by Supabase Auth).
- Content you create: posts, images, captions, tags, comments, boards, pins, messages, listings, project journals, project attachments, stash items, shipping addresses you save, dispute submissions, evidence attachments, reports of other content.
- Marketplace data: order records (buyer/seller IDs, listing snapshot, amounts, currencies, shipping address provided at purchase, tracking numbers, status transitions), agreement-acceptance timestamps and versions.
From your device
- Device data: device type, OS version, app version, Expo push token (so we can send you notifications), approximate IP address (in Supabase server logs) for security and abuse detection.
From third parties
- Payment data: handled by Stripe, Inc. as a separate data controller. We do not see or store full card numbers, bank account numbers, or government IDs. We retain limited Stripe references (Stripe Customer ID, Stripe Account ID, PaymentIntent ID, Charge ID, last four digits and brand of the card as shown on receipts) for transaction operation, dispute handling, and audit. Sellers' identity information for KYC is collected by Stripe under Stripe's Privacy Policy.
- Analytics: we use PostHog for product analytics (events, screen views, basic device attributes). We do not transmit personally identifying free-text to PostHog. PostHog is configured with EU/US region routing per its Privacy Policy.
We do not sell personal data, and we do not share personal data with third parties for their own advertising purposes.
3. How we use data
- Operate the Service: render your feed, deliver messages, process orders, send transactional and trust-and-safety push notifications, support search and discovery.
- Trust and safety: investigate reports, prevent and detect fraud and abuse, enforce our Terms and Community Rules, calculate seller risk tiers, hold or release seller payouts.
- Customer support: respond to your inquiries; investigate disputes; cooperate with law enforcement only under valid legal process.
- Communications: send transactional messages (order receipts, password resets, dispute status, critical account notices) and, with your consent, optional product updates. You can opt out of optional communications.
- Improve the Service: aggregate, anonymized analytics; debugging.
- Comply with law: respond to lawful requests; preserve evidence; tax/finance recordkeeping.
- Legitimate interests: protecting the platform from fraud and abuse, defending our legal rights.
4. Legal bases (GDPR / UK GDPR)
Where the GDPR applies, we rely on: contract (operating the Service for you), legitimate interests (security, trust & safety, fraud prevention, analytics, defending claims), legal obligation (tax, accounting, law enforcement), and consent where required (e.g., push notifications, optional marketing emails).
5. Sharing
We share personal data with the following categories of recipients, each contractually bound to process it only on our instructions:
- Supabase (database, file storage, authentication, edge functions) — primary platform infrastructure.
- Stripe (payments, payouts, KYC, fraud detection via Stripe Radar) — separate data controller for payment data.
- Apple Push Notification service / Google Firebase Cloud Messaging (push notification delivery).
- Expo Application Services (build delivery, push token routing).
- PostHog (product analytics).
- Email and customer support tooling (transactional email; trust & safety inboxes).
- Other users: the username, display name, bio, profile photo, posts, comments, boards, listings, and order interactions you direct toward another user are visible to that user; marketplace counterparties see your shipping address, name, and order contents on confirmed orders.
- In a corporate transaction: if we are acquired or merge, your data may be transferred subject to this Privacy Policy.
- Legal: under valid legal process, to protect our rights, or to prevent imminent harm.
6. Storage and security
We store data on infrastructure operated by Supabase (primarily in the United States) and Stripe. Data is encrypted in transit (TLS) and at rest. Access is restricted via role-based access control and audit logging. Despite reasonable controls, no system is perfectly secure; please notify chambersjohn310@gmail.com immediately if you suspect a compromise.
7. Retention
We keep your data while your account is active. When you delete your account from Settings → Delete account, we delete or anonymize your profile, posts, comments, boards, pins, project entries, stash items, draft listings, messages you sent, and reports you filed within 30 days.
We retain order records (including buyer/seller IDs and amounts) for at least 7 years to comply with tax, accounting, and consumer-protection laws and to defend chargebacks; personal identifiers within those records (such as shipping address line) are anonymized after the retention window expires. We retain dispute records and trust-and-safety enforcement records for as long as necessary to investigate, defend, or prevent recurrence.
8. Your rights
Depending on your jurisdiction, you may have rights to: access, correct, delete, restrict or object to processing, port your data, or withdraw consent. To exercise these rights, email chambersjohn310@gmail.com. We will verify your identity (e.g., by confirming control of the account email) and respond within 30 days (or sooner where required by law).
If you are a California resident, the CCPA/CPRA gives you the right to know, delete, and correct, and to opt out of "sales" or "sharing" of personal information — we do not "sell" or "share" personal information as defined by the CCPA/CPRA. You may exercise these rights via chambersjohn310@gmail.com; we will not discriminate against you for doing so.
If you are in the EU/UK, you also have the right to lodge a complaint with a supervisory authority.
9. Children
The Service is not directed to children under 13. We do not knowingly collect data from anyone under 13; if we learn we have, we will delete the account and its data. Users between 13 and the age of majority must have a parent or guardian agree to the Terms on their behalf.
10. International transfers
Our primary infrastructure is in the United States. If you use the Service from outside the United States (including the EU, UK, EEA, or Switzerland), your data will be transferred to and processed in the United States. We rely on EU Standard Contractual Clauses (and the UK addendum where applicable) with our sub-processors and, where relevant, supplementary measures, to legitimize these transfers.
11. Cookies and similar technologies
Because the Service is a mobile app and not a website, we do not use traditional browser cookies. We use platform-provided identifiers and our own client-side storage (Async Storage, Secure Store) to keep you logged in, cache content, and remember preferences. PostHog uses anonymous installation identifiers for analytics.
12. Push notifications
If you enable notifications, we use your Expo push token to deliver transactional and trust-and-safety messages (orders, disputes, mentions). You can disable notifications in your device settings; transactional emails are also sent for critical events.
13. Changes to this Policy
We may update this Privacy Policy. We will notify you of material changes via an in-app banner at least 14 days before they take effect.
14. Contact
For privacy questions or to exercise your rights: chambersjohn310@gmail.com.
Designated agent for copyright (DMCA): chambersjohn310@gmail.com — see the DMCA Policy.