Privacy Policy

Effective [Effective date]

This policy explains how [Registered business name] ("STLmint", "we") handles personal data when you use https://stlmint.app and the studio. We are the data controller (the "Data Fiduciary" under India's Digital Personal Data Protection Act, 2023). It is written to meet that Act and, for people in the EU and UK, the GDPR.

What we collect

  • Account details: your email address, and your name and profile picture if you sign in with a provider that shares them. Sign-in is handled by Clerk.
  • Orders and membership: what you bought, when, the amount, your STLmint Seller plan status, and the reference our payment processor gives us. We do not receive or store your full card or bank details; our payment processor handles them.
  • What you enter in the studio: the text and options you put on a design, often your customers' names. We use it to make the picture and the file, and we store it with your purchases so you can download them again.
  • Technical data: IP address, browser and device type, pages requested and error logs. We use these to run the site, keep it secure and stop abuse (for example rate limits).
  • Messages: what you send us when you contact us.

We do not use advertising trackers, sell personal data or use it to build advertising profiles.

Why we use it and on what basis

Purpose Basis
Creating your account, making and delivering files, running the STLmint Seller plan Performing our contract with you; under the DPDP Act, the purpose you gave the data for
Taking payments, issuing receipts, keeping tax and accounting records Contract and legal obligation
Security, fraud prevention, rate limits, fixing errors Legitimate interests; under the DPDP Act, legitimate uses and your consent
Service emails (receipts, renewal and price-change notices, account security) Contract
Product news or marketing emails, if we send any Your consent, which you can withdraw at any time

Where we rely on consent, you can withdraw it at any time by emailing [Privacy contact email address]. This does not affect what we did before.

Your customers' details

When you enter a customer's name or other details in the studio, you decide what to enter and why; we process it only to make your picture and file and to let you download it again. Please enter only what the design needs and only with your customer's permission. Take particular care with children's names (for example school tags): enter only what is needed.

Who processes data for us

We use these service providers ("sub-processors"). Each gets only the data it needs for its job, under a contract that requires them to protect it.

Provider What it does Where
Clerk Sign-in and account management United States
Vercel Hosts the studio web app Global network, United States based
Cloudflare DNS, network delivery and protection against attacks and bots Global network, United States based
Hetzner Hosts our application server and database European Union (Germany / Finland)
[Razorpay or Stripe] Processes payments and subscriptions See the provider's privacy policy
[Transactional email provider] Sends service emails such as receipts See the provider's privacy policy

We may also share data when the law requires it, to protect our rights or users' safety, or with a buyer if the business is sold (under the same protections).

Transfers abroad

We are based in [Country of registration], our servers are in the EU, and some providers are in the United States and elsewhere. When data leaves the EU or UK, we rely on adequacy decisions or the European Commission's Standard Contractual Clauses (and the UK equivalent). Transfers from India follow the DPDP Act and any restrictions the Indian government sets under it.

How long we keep it

  • Account data: while your account is open. When you close it, we delete or anonymise it within 30 days, except as below.
  • Orders, payments and invoices: as long as tax and accounting law requires, currently up to 8 years.
  • Studio text and options: with the purchase they belong to; text that is only previewed and not bought is not linked to your account and is kept only briefly in temporary caches.
  • Server and security logs: up to 30 days, longer only when needed to investigate abuse.
  • Support messages: up to 2 years after the conversation ends.

Cookies and similar technologies

We use only cookies needed for the service to work, so we do not show a cookie banner for them:

  • Clerk sign-in cookies (such as __session and __client_uat on our domain, and Clerk's own cookies on its sign-in domain) keep you signed in and protect your account.
  • Cloudflare security cookies (such as __cf_bm, and cf_clearance if you are shown a check) tell people apart from bots.
  • Payment processor cookies are set by [Razorpay or Stripe] on its checkout pages to process the payment and prevent fraud.
  • Local storage in your browser remembers small preferences, such as whether the studio shows all options and the inputs of the price calculator on our blog. It stays on your device.

We do not use analytics or advertising cookies. If we add any, we will update this policy and ask for your consent first where the law requires.

Your rights

Depending on where you live, you can ask to:

  • see the personal data we hold about you and how we use it, and get a copy;
  • correct or update it;
  • delete it, or close your account;
  • object to or restrict some uses, and withdraw consent;
  • receive your data in a portable format (EU and UK);
  • nominate someone to exercise your rights if you die or become unable to (India).

Email [Privacy contact email address]. We may need to confirm your identity. We reply within one month, or sooner where the law requires.

If you are not satisfied, contact our Grievance Officer (see Contact and Grievances). You can also complain to the Data Protection Board of India, or, in the EU or UK, to your local data protection authority (in the UK, the ICO). Our representative in the EU/UK: [EU/UK representative under GDPR Article 27, or 'Not appointed'].

Security

Data is encrypted in transit (HTTPS). Access to systems and data is limited to people who need it. Our design templates and your files are generated on our servers. No system is perfectly secure; if a breach affects your personal data, we will tell you and the authorities as the law requires.

Children

STLmint is for adults buying for themselves or their business. We do not knowingly create accounts for anyone under 18. If you believe a child has an account, contact us and we will delete it.

Changes

We will post changes here with a new effective date and email account holders about significant ones.

Contact

Privacy questions: [Privacy contact email address]. Grievance Officer: [Grievance officer name], [Grievance officer email address]. Postal address: [Registered business name], [Registered business address].