What SEWN holds, why, who else touches it and how to make it go away. This covers founders — the people who make stores — and the buyers who order from them. It is the platform-level document; each store also shows its buyers a shorter notice in its own chrome, and the two say the same thing.
| About whom | What | Why |
|---|---|---|
| Founder | Email address, brand name, site URL, logo file, store settings and prices | To build the store, sign you in, and email you about orders |
| Founder | Plan, subscription state, Stripe customer id | To bill a paid plan |
| Buyer | Name, email, shipping address, optional phone, what they ordered | To make the piece and post it |
| Buyer | Order value, tax, status, carrier tracking | Fulfilment, support and the tax record |
| Either | Card details | Never. Cards are entered on Stripe's own pages and never reach our servers. |
We do not run advertising trackers, analytics pixels or third-party marketing tags on any SEWN
page or on any store we build. There is nothing to opt out of because there is nothing there. The
only cookie we set is sewn_owner, the HttpOnly session cookie that keeps a founder
signed in; a buyer's cart lives in their own browser and never reaches us until they check out.
| Who | What they get | Why they must |
|---|---|---|
| Cloudflare (D1, Pages), United States | Everything above | It is our database and our hosting |
| Stripe | Buyer name, email, shipping address, order value; founder billing details | Taking payment and calculating sales tax |
| OpenAI | The founder's logo file only | Generating the four product photographs. Nothing about a buyer is ever sent |
| Our embroidery and fulfilment partner, United States | Buyer name and address, and what to make | Somebody has to sew it and post it |
| The carrier | Buyer name and address | Delivery |
| Google (Gmail) | The contents of the mail we send you | Our outbound email runs through a Google mailbox |
That is the complete list. We do not sell personal information, we do not share it for advertising, and we do not train any model on it. Under California law that means we have no "sale" or "sharing" to opt out of — and if that ever changed, it would change on this page first.
Data is stored in the United States. If you are in the UK or the EU, that is a transfer, and it is the transfer you are consenting to by using a US service.
Whoever you are and wherever you live, you can ask us to show you what we hold, correct it, or delete it. Founders can do most of it without asking anyone: your orders export as CSV from the dashboard, and closing a store or deleting an account are buttons.
Email hello@yoursewn.store from the address on the store. Closing a store takes it offline but leaves those files in the database; this is the request that removes them. We do it within seven days and confirm when it is done.
Same address, within seven days.
Buyers: email hello@yoursewn.store with the order number. We delete everything not legally required — the order line itself stays for the seven-year tax record, but the address and contact details do not have to.
We send founders order notifications and account mail, and buyers mail about their own order. There is no marketing list to leave. If we ever start one it will be opt-in.
We will not charge you for any of this and we will not make you create an account to ask. If you are in the EU or UK and think we have got it wrong, you can complain to your data protection authority; we would rather you emailed us first.
Sessions are HttpOnly, Secure, SameSite cookies. Admin routes require a token. Card data never reaches us. Database access is limited to the people running SEWN.
We hold no security certification. Not SOC 2, not ISO 27001, not HIPAA. We have not been audited by anybody. We would rather tell you that than imply a badge we do not have — the same position as the trust page.
SEWN is not for under-16s and we do not knowingly hold their data. If a child's details reached us, email hello@yoursewn.store and we will delete them.
If this notice changes materially, founders get an email — not a silent edit and a new date at the bottom.
Privacy notice — version 1, 5 September 2026. Questions: hello@yoursewn.store. See also the founder terms and the trust page.