Privacy Policy
Effective date: May 8, 2026
This Privacy Policy describes how Re Embroidery ("Re Embroidery," "we," "us," or "our"), collects, uses, discloses, and protects personal information when you visit reembroidery.com (the "Site") or purchase digital embroidery design files from us. By using the Site, you agree to this Privacy Policy. If you do not agree, do not use the Site.
1. Who we are and how to contact us
The data controller responsible for your personal information is:
Re Embroidery
Email for privacy inquiries: privacy@reembroidery.com
2. Information we collect
2.1 Information you provide
- Account information: name, email address, password (hashed), shipping/billing address (where applicable), phone number
- Order information: products purchased, order amount, payment confirmation (we do not store full card numbers, see Section 4)
- Communications: messages sent through our contact form, chat tool, support emails, or social channels
- Marketing preferences: email subscription status, opt-in selections
2.2 Information collected automatically
- Device and browser information: IP address, device type, operating system, browser type and version, language preference, referring URL
- Usage data: pages viewed, time spent, products browsed, search terms, click paths
- Cookies and similar technologies: see our Cookie Policy for full details
- Download logs: timestamps and IP addresses of digital file downloads, retained for license enforcement and fraud prevention
2.3 Information from third parties
- Payment processors (Shopify Payments, PayPal, Apple Pay, Google Pay, Shop Pay) confirm transaction status and may share fraud risk indicators
- Authentication providers when you sign in via third-party services (e.g., Shop Pay, Google)
- Marketing partners may share aggregated audience data
3. Legal bases for processing (EU/UK residents)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we process your personal information under the following legal bases under the General Data Protection Regulation (GDPR) and UK GDPR:
- Contract performance: to fulfill orders, deliver downloads, manage your account, and provide customer support
- Legitimate interests: to operate, secure, and improve the Site; prevent fraud; enforce our terms and licenses; pursue marketing where allowed
- Consent: for non-essential cookies, marketing emails (where consent is required), and any processing requiring explicit opt-in
- Legal obligation: to comply with tax, accounting, and law-enforcement requirements
4. How we use your information
- Process and deliver your orders, including digital file delivery and download access
- Maintain your account and order history
- Provide customer support and respond to inquiries
- Send transactional communications (order confirmations, download links, account notices)
- Send marketing communications where permitted, which you may unsubscribe from at any time
- Detect, prevent, and investigate fraud, abuse, license violations, and unauthorized redistribution of our designs
- Improve the Site, our products, and customer experience through analytics
- Comply with legal obligations, court orders, and lawful government requests
- Enforce our Terms of Service, License, and Acceptable Use Policy
5. How we share your information
We do not sell your personal information for monetary consideration. We share information only as described below:
- Service providers who process information on our behalf under written agreements: Shopify (hosting, payments, fulfillment), Pendora (digital downloads delivery and license tokens), Google Analytics (traffic analysis), Meta (advertising), email service providers, customer-support tools, fraud-prevention services
- Payment processors for transaction processing
- Legal and safety: when required by law, court order, subpoena, or to protect rights, property, or safety of Re Embroidery, our customers, or others
- Business transfers: in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our assets, with notice to you where required
- With your consent: for any other purpose disclosed at the time of collection
5.1 Sale or sharing for cross-context behavioral advertising (CCPA)
We may share certain information (cookies, device identifiers, browsing activity) with advertising partners (Meta, Google) to deliver targeted advertising. Under California law (CCPA/CPRA), this may be considered a "sale" or "sharing." California residents may opt out at Your Privacy Choices.
6. International data transfers
We are based in Bangladesh. If you access the Site from outside the US, your information will be transferred to, stored, and processed in the US. For transfers from the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses or other lawful transfer mechanisms with our service providers.
7. Data retention
- Account and order information: retained for the life of your account plus 7 years for tax and accounting compliance
- Download logs: 5 years for license enforcement
- Marketing preferences: until you unsubscribe or request deletion
- Cookies: see Cookie Policy for retention periods by category
- Support communications: 3 years from last contact
8. Your rights
8.1 General rights (where applicable)
- Access: request a copy of personal information we hold about you
- Correction: request correction of inaccurate or incomplete information
- Deletion: request deletion of your information, subject to legal retention requirements
- Portability: receive your information in a structured, commonly used format
- Restriction: request that we limit processing in certain circumstances
- Objection: object to processing based on legitimate interests, including direct marketing
- Withdraw consent: withdraw consent for processing based on consent at any time
- Lodge a complaint: with your local data-protection authority
8.2 California residents (CCPA/CPRA)
California residents have the right to know what personal information we collect, the right to delete it, the right to correct it, the right to opt out of sale or sharing for cross-context behavioral advertising, the right to limit use of sensitive personal information, and the right to non-discrimination for exercising these rights. Submit requests via privacy@reembroidery.com or Your Privacy Choices. We verify identity before fulfilling requests.
8.3 How to exercise your rights
Email privacy@reembroidery.com with the subject "Privacy Rights Request." Include your full name, email associated with your account, and a clear description of the request. We respond within 30 days (45 days under CCPA, extendable by an additional 45 days when reasonably necessary, with notice).
9. Children's privacy
The Site is not directed to children under 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected such information, we will delete it. Parents or guardians who believe a child has provided us with information should contact privacy@reembroidery.com.
10. Security
We use commercially reasonable technical and organizational measures to protect personal information, including encryption in transit (TLS), access controls, and vendor due diligence. No method of transmission or storage is fully secure, however. You are responsible for maintaining the confidentiality of your account password.
11. Third-party links
The Site may contain links to third-party websites and services. Their privacy practices are governed by their own policies, which we do not control. Review their policies before sharing personal information.
12. Automated decision-making
We do not engage in automated decision-making with legal or similarly significant effects on you. Some fraud-prevention scoring is automated but reviewed by a human before action is taken on an account.
13. Changes to this policy
We may update this Privacy Policy from time to time. The "Effective date" at the top reflects the latest revision. Material changes will be communicated by email (where we have a verified address) or by prominent notice on the Site. Continued use of the Site after changes take effect constitutes acceptance of the revised policy.
14. Contact
Questions about this Privacy Policy or our handling of your personal information:
Email: privacy@reembroidery.com
Mailing address: Re Embroidery, Prottasha Housing (4B), Namajgor, Bogura Sadar, Bogura - 5800, Bangladesh.
This policy is provided for informational use. It is not legal advice. Consult a qualified attorney in your jurisdiction before relying on it for compliance.