Legal

Privacy Policy

Last updated May 26, 2026

Overview

StitchGrid (“StitchGrid,” “we,” “us”) provides a curated sourcing network for product brands and manufacturers. This Privacy Policy explains what we collect, why we collect it, and the choices you have.

Information we collect

  • Account information. Name, email, password hash, company name, country, role, and membership information.
  • Brand briefs and orders. Tech packs, sketches, photos, quantities, target costs, timelines, attachments, milestone updates, and message threads you create on the Service.
  • Factory profile data. Capabilities, certifications, capacity, references, photos, vetting notes, and quotes submitted to brand briefs.
  • Payments. Order amounts, payout configuration, and Stripe IDs. StitchGrid does not store full card numbers; payment data is processed by Stripe.
  • Usage data. Log data, device and browser type, IP address, pages viewed, and product-analytics events (PostHog).
  • Cookies. Session cookies for authentication and analytics cookies to understand product usage.

How we use information

  • Operate the marketplace: matching, messaging, quote workflow, order tracking, payouts, digests.
  • Vetting and trust & safety: verify factory credentials, detect off-platform circumvention.
  • Customer support and account communication.
  • Product analytics and feature improvement.
  • Legal compliance, fraud prevention, and enforcing our Terms.

How we share information

We share information only as needed to run the Service:

  • Between Brands and Factories. When you post a brief, the matched Factories see what you choose to share with them. When you submit a quote, the Brand sees it.
  • Service providers. Infrastructure (Vercel, Neon), email (Resend), payments (Stripe), file storage (Vercel Blob), analytics (PostHog), error reporting (Sentry), AI gateway (Vercel AI Gateway).
  • Legal. When required by law or to protect the rights, property, or safety of StitchGrid, our users, or others.
  • Business transfers. In connection with a merger, acquisition, or asset sale, with notice where required by law.

We do not sell personal information.

Data retention

We retain account, order, and audit data for as long as your account is active and for a reasonable period afterward to meet legal, accounting, or reporting obligations. You may request deletion of your account by emailing hello@stitchgrid.com. We may retain a limited record of completed transactions for tax and fraud-prevention purposes.

Security

We use industry-standard measures including TLS in transit, encrypted storage, password hashing (bcrypt), audit logging, and least-privilege access for staff. No system is perfectly secure; please use a strong, unique password.

International transfers

StitchGrid is operated from the United States. If you access the Service from outside the US, your information may be processed in the US and other countries where our service providers operate.

Your rights

Depending on your jurisdiction (EEA, UK, California, and others), you may have rights to access, correct, delete, or restrict processing of your personal information, and to object to certain processing. To exercise these rights, email hello@stitchgrid.com. We will respond within the time required by applicable law.

Children

The Service is not directed to children under 16, and we do not knowingly collect personal information from them.

Changes

We may update this Policy from time to time. Material changes will be announced via the Service or by email.

Contact

Privacy questions? Email hello@stitchgrid.com or use our contact form.