StitchPress

Home / Docs / Privacy

Privacy

This page lists what StitchPress stores about your customers, why, for how long and who can see it. It also covers how StitchPress takes part in WordPress's personal data export and erasure tools, and the retention setting.

StitchPress does not send designs, artwork or proof decisions to any outside service. Everything stays in your WordPress database and your uploads folder. What WooCommerce itself shares to process an order (for example with your payment provider) is unchanged and is covered by WooCommerce's own privacy text.

What StitchPress stores

Data Where Why How long Who sees it
The design on an order line: decoration areas, sizes, colors, text, typeface, the name of any uploaded artwork file, the customer's note Order item meta (_stp_spec) It is the product you sell and produce As long as you keep the order Shop staff; the customer on their order and proof pages
Uploaded artwork files wp-content/uploads/stp-artwork/ under random file names To show the design to the customer and produce it Files that never reach an order are removed by the artwork clean-up (30 days by default) or sooner by the retention setting; files on an order are kept with the order Shop staff through a download link; image files can be opened by anyone who has their random address
Proof rounds and decisions: the decision, when it was made, the customer's comment and the IP address it came from Order meta (_stp_proofs) and the order notes Evidence of what the customer approved As long as you keep the order Shop staff; the customer sees their own proof history
Saved designs ("Save design") A temporary record in the options table, stored under a hash of the link So a customer can come back to a design without ordering 14 days, or sooner with the retention setting Anyone holding the link
The link between a logged-in customer and their saved designs User meta (_stp_saved_designs), hashes only So export and erasure can find those saved designs Until the designs expire or are erased Nobody in the admin; used by the privacy tools
An unfinished design The customer's own browser (local storage) So a customer can leave the page and come back 7 days after the last change Only that browser

Rate limiting for uploads, saves and proof decisions uses short-lived counters keyed by a salted hash of the visitor's IP address. They expire within the hour and do not store the address.

A design saved by a guest carries nothing that identifies the person who saved it. StitchPress cannot find it from an email address, so it does not appear in an export or erasure. It is deleted when its 14 days run out.

Suggested privacy policy text

StitchPress adds two sections to Settings > Privacy > Policy Guide: "StitchPress" (what the designer stores) and "StitchPress: your design data" (export, erasure and retention). Review both and copy what applies into your policy. The second section reads:

If you are logged in when you press "Save design", the saved design is linked to your account so that it can be included when you ask for a copy of your data or ask us to erase it. A design saved without logging in is not linked to you, so we cannot find it from your email address; it is deleted automatically when its link expires.

You can ask for a copy of the personal data we hold about you. For StitchPress this includes the designs on your orders (decoration areas, sizes, colors, text, typeface, the name of any artwork file and your note), the proofs we sent you with your decisions on them (the decision, when it was made, your comment and the IP address it came from), and any designs you saved while logged in.

You can ask us to erase your personal data. We then delete your saved designs and replace the IP address and comment on your proof decisions. If our shop removes personal data from orders on request, we also delete the artwork files on your finished orders, unless the same file is used by another order. The design itself stays on the order, including any text, because it describes the product we made and sold; order totals and prices also stay, because we are required to keep accounting records.

Saved designs, and artwork that never became part of an order, are deleted N days after they were saved or uploaded. (Only shown when the retention setting is above 0; N is your setting.)

StitchPress does not send your design or your artwork to any other service. What WooCommerce itself shares to process your order (for example with a payment provider) is described in the WooCommerce section of this policy.

Exporting a customer's data

Go to Tools > Export Personal Data, enter the customer's email address and send the request as usual. StitchPress adds three groups to the export file:

  • StitchPress designs: one entry per decorated order line, with the order number, product, decoration method, each placement (area, size, text, typeface, colors, artwork file name and, for JPG and PNG files, its address), the customer's note and whether a proof was requested.
  • StitchPress proofs: one entry per proof round, with the proof file name, when it was sent, the decision, when and by whom it was made (the customer from the proof link, or staff on their behalf), the comment and the IP address.
  • StitchPress saved designs: designs the customer saved while logged in that have not expired.

The orders included are the ones whose billing email is that address, plus the orders of the user account with that email. This is the same set WooCommerce's own order export uses.

Erasing a customer's data

Go to Tools > Erase Personal Data, enter the email address and run the erasure. StitchPress runs before WooCommerce's order eraser, because WooCommerce replaces the billing email on each order it anonymises.

What StitchPress always does:

  • Replaces the IP address on every proof decision with its anonymised form (the last part set to zero) and replaces the customer's comment with "This content was deleted by the author." The same values are replaced in the order notes StitchPress wrote. The decision and its time stay, so the order still shows that a proof was approved or changed.
  • Deletes the customer's saved designs (those saved while logged in) and the artwork they used, unless an order, a cart or another saved design uses the same file.

What StitchPress does only when you remove order data on request (WooCommerce > Settings > Accounts & Privacy, "Remove personal data from orders on request"):

  • Deletes the artwork files on the customer's orders. Orders that are still pending, on hold, waiting for proof approval or processing keep their artwork, because you still need it to produce them; the erasure reports this as data retained. A file that another customer's order also uses is kept.

What StitchPress never changes:

  • Order totals, line totals and prices.
  • The design record on the order line, including its text. The text is part of the product that was made and sold, and the production sheet needs the placement data. If a design's text itself identifies a person, edit or remove it by hand.
  • Proof images. They are files your shop made, not customer uploads.

When you keep order data, the erasure response says so with the message "Kept the design artwork for order N because the shop keeps order data on erasure requests." Emails that were already sent (proof emails, the shop's notification of a decision) cannot be recalled.

Retention setting

StitchPress > Settings, Privacy section, Delete unordered designs after (days). The default is 0, which turns it off.

When it is above 0, a daily task deletes:

  • saved designs older than that many days;
  • artwork files older than that many days that are not used by any order, any cart, any saved cart of a logged-in customer, or any saved design that still exists.

A file used by any order is never deleted by this setting, whatever the order's status. The task checks up to 500 old files per run and carries on from where it stopped the next day. It writes one line per run to WooCommerce > Status > Logs (source "stitchpress"), with counts only.

Two limits to know about:

  • A customer's unfinished design lives in their browser and may point at artwork they uploaded earlier. A setting below 7 days can remove that artwork before the browser copy expires; the customer then sees the design refused when they add it to the cart and has to upload the file again.
  • With a persistent object cache (Redis, Memcached), saved designs are not kept in the options table and cannot be listed. The retention task then only reaches designs saved by logged-in customers; guests' saved designs still expire after 14 days.

Developers can override the number of days with the stp_retention_days filter, and keep individual files with the stp_artwork_gc_delete filter, which also guards the regular artwork clean-up.

Uninstall

Deleting the plugin always removes saved designs, the saved-design links on user accounts and the retention task. The retention setting is removed when "Remove all StitchPress data when the plugin is deleted" is on. Artwork files are removed only when the separate switch for uploaded files is also on. Design records and proof history on orders are never removed, because orders are your business records. See Install.

Source: the plugin's docs/site/privacy.md, rendered for StitchPress 1.0.0-rc4. Found an error? Tell support.