Privacy Policy
We respect your privacy and are committed to protecting your personal data. This policy explains what we collect, why, and your rights under European and United States law.
Effective Date: May 1, 2025 · Last Updated: May 2025
1. Who We Are
1 Dollar Digitizing ("we," "us," or "our") is a professional embroidery digitizing and vector art service operating globally, with offices in the United States, United Kingdom, and Pakistan. Our principal place of business is:
1 Dollar Digitizing46494 Mission Blvd, Fremont, California 94539, USA
Email: support@1dollardigitizing.com
Phone: +1 206-312-6446
For the purposes of the General Data Protection Regulation (GDPR), we act as the Data Controller for personal data collected through this website and our services.
2. What Information We Collect
We collect information you provide directly and information generated automatically when you use our services.
2.1 Information You Provide
- Account Information: Name, email address, phone number, company name, and password when you register.
- Order Information: Design specifications, garment type, machine format, stitch preferences, and any instructions you provide with an order or quote request.
- Artwork Files: Logo files, images, and design files you upload for digitizing or vector conversion.
- Billing Information: Billing address and payment method details. Card numbers are handled exclusively by our payment processors (Stripe and 2Checkout) and are never stored on our servers.
- Communications: Messages, emails, and support requests you send us.
2.2 Information Collected Automatically
- Usage Data: Pages visited, orders placed, files downloaded, login timestamps, and in-app activity.
- Device and Technical Data: IP address, browser type, operating system, and referring URLs — collected for security and fraud prevention.
- Cookies and Session Tokens: See Section 8 for full details.
3. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA) or United Kingdom, we process your personal data on the following legal grounds:
- Contract Performance (Art. 6(1)(b) GDPR): Processing necessary to fulfill your orders, deliver completed files, process payments, and manage your account.
- Legitimate Interests (Art. 6(1)(f) GDPR): Fraud prevention, security monitoring, platform integrity, and improving our service — where these interests do not override your rights.
- Legal Obligation (Art. 6(1)(c) GDPR): Retaining transaction records to comply with tax, accounting, and financial regulations.
- Consent (Art. 6(1)(a) GDPR): Where we send optional marketing communications — you may withdraw consent at any time.
4. How We Use Your Information
- To process orders, deliver digitized or vector files, and manage your account.
- To communicate about quotes, order status, revisions, and support requests.
- To process payments and issue receipts or invoices.
- To detect and prevent fraud, abuse, and unauthorized access.
- To comply with legal and regulatory obligations.
- To improve our platform and service quality based on aggregate usage patterns.
- To send transactional emails (order confirmations, file delivery, revision notices). We do not send unsolicited marketing without your explicit consent.
5. Ownership of Files and Intellectual Property
This section is important. Please read it carefully.
5.1 Your Files Remain Your Property
All artwork files you upload, and all digitized or vector files we produce for you, remain your exclusive property. We claim no ownership, license, or intellectual property rights over your designs, logos, or the finished files we deliver to you. Uploading artwork to our platform does not transfer any rights to us.
5.2 We Do Not Reproduce or Resell Your Files
We will never reproduce, resell, redistribute, sublicense, or share your files with any third party for any commercial or non-commercial purpose. Your completed digitizing and vector files are created exclusively for your use. No file you upload or receive from us will be used in any sample library, portfolio (without your written consent), training dataset, or any other secondary use.
5.3 Limited Internal Use Only
We retain copies of your files solely to: (a) deliver your order, (b) process revision requests, (c) fulfill reorder requests, and (d) provide customer support. Files are stored securely and are accessible only to team members directly working on your account.
5.4 Your Responsibility for Artwork Rights
By submitting artwork to us for digitizing or vector conversion, you represent and warrant that:
- You are the owner of the artwork, or you have the lawful right, license, or authorization from the rights holder to reproduce and use the artwork for embroidery or printing purposes.
- The artwork does not infringe any third-party copyright, trademark, or other intellectual property right.
- You are legally permitted to use any logos, brand marks, or trademarked designs included in the artwork in the jurisdiction where the embroidered goods will be produced and sold.
We are a digitizing service provider. We process files as instructed. We are not responsible for determining whether a submitted logo is licensed for use, and we cannot be held liable for infringement arising from artwork submitted by you. If you are unsure whether you have the right to use a particular logo or design, please consult the rights holder or a legal professional before submitting.
6. Payments and Financial Data
Payments are processed by Stripe and 2Checkout (Verifone). These processors are PCI-DSS compliant. We never receive, store, or transmit full credit card numbers. We retain transaction records (order amount, date, payment method type, last four digits if provided by the processor) for accounting and dispute resolution purposes, in accordance with applicable financial regulations.
7. How We Share Your Information
We do not sell your personal data. We share data only in limited circumstances:
- Payment Processors: Stripe and 2Checkout receive billing information necessary to process your payment.
- Email Service Providers: We use SMTP email services to deliver transactional messages. These providers process your email address only to deliver messages on our behalf.
- Legal Requirements: We may disclose information if required by law, court order, or government authority, or to protect the rights, property, or safety of our users or the public.
- Business Transfers: If 1 Dollar Digitizing is involved in a merger, acquisition, or asset sale, your data may be transferred. We will notify you before this occurs and before your data becomes subject to a different privacy policy.
We do not share your data with advertising networks, data brokers, or any third party for marketing purposes.
8. Cookies and Tracking
We use the following types of cookies:
- Strictly Necessary Cookies: Session cookies that keep you logged in, protect form submissions from cross-site request forgery (CSRF), and enable core platform functionality. These cannot be disabled without breaking the site.
- Persistent Login Cookies: If you select "Remember Me," a longer-lived authentication token is stored in your browser. You can clear this at any time through your browser settings or by logging out.
- Security Cookies: Short-lived tokens used for two-factor authentication and device trust verification.
We do not use advertising cookies, third-party tracking pixels, or behavioral profiling tools. You may clear all cookies at any time through your browser settings; doing so will log you out of the platform.
9. Data Retention
- Account Data: Retained for the lifetime of your account plus 3 years after closure, or as required by applicable law.
- Order and Transaction Records: Retained for 7 years to comply with tax, accounting, and financial reporting obligations in the US, UK, and EU.
- Uploaded Artwork and Completed Files: Retained for a minimum of 12 months to support revision requests and reorders. You may request earlier deletion (subject to active order obligations) by contacting us.
- Security Logs: Login and access logs are retained for 12 months for fraud detection and incident response.
- Support Communications: Retained for 3 years to maintain a complete account history.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- HTTPS/TLS encryption for all data in transit.
- Access controls limiting file and account access to authorized team members only.
- Login rate limiting, brute-force detection, and IP-based blocking.
- Optional two-factor authentication (TOTP) for all accounts.
- Security event logging and anomaly detection.
No method of transmission over the internet is 100% secure. In the event of a data breach that affects your personal data, we will notify you as required under applicable law (within 72 hours to supervisory authorities under GDPR, and as required by applicable US state breach notification laws).
11. Your Rights — European Users (GDPR)
If you are located in the EEA or United Kingdom, you have the following rights under the GDPR and UK GDPR:
- Right of Access (Art. 15): Request a copy of the personal data we hold about you.
- Right to Rectification (Art. 16): Request correction of inaccurate or incomplete data.
- Right to Erasure / "Right to be Forgotten" (Art. 17): Request deletion of your personal data, subject to our legal retention obligations.
- Right to Restriction of Processing (Art. 18): Request that we limit how we use your data in certain circumstances.
- Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format and transfer it to another controller.
- Right to Object (Art. 21): Object to processing based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
- Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection authority. In the UK: the Information Commissioner's Office (ICO) at ico.org.uk. In the EU: your national supervisory authority.
12. Your Rights — California and US Users (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) grant you the following rights:
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, the business purpose, and the categories of third parties with whom we share it.
- Right to Delete: Request deletion of personal information we have collected, subject to certain exceptions (e.g., completing transactions, legal obligations).
- Right to Correct: Request correction of inaccurate personal information.
- Right to Opt-Out of Sale or Sharing: We do not sell or share personal information for cross-context behavioral advertising. No opt-out is required, but you may contact us to confirm.
- Right to Limit Use of Sensitive Personal Information: We do not use sensitive personal information beyond what is necessary to provide our services.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.
Residents of other US states with applicable privacy laws (Virginia CDPA, Colorado CPA, Connecticut CTDPA, etc.) may exercise equivalent rights by contacting us directly.
13. International Data Transfers
1 Dollar Digitizing operates across the United States, United Kingdom, and Pakistan. If you are located in the EEA or UK, your personal data may be transferred to and processed in countries outside the EEA/UK, including the United States and Pakistan, which may not have equivalent data protection laws. When we transfer data internationally, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission, where applicable.
- The UK International Data Transfer Agreement (IDTA), where applicable.
- Appropriate organizational safeguards with our team members and processors.
14. Children's Privacy
Our services are intended for business and commercial users. We do not knowingly collect personal data from anyone under the age of 16. If we become aware that a minor has provided us with personal information, we will delete it promptly. If you believe a child has submitted data to us, please contact us immediately.
15. How to Exercise Your Rights
To exercise any of the rights described in this policy, or to ask questions about how your data is handled, contact us by any of the following methods:
- Email: support@1dollardigitizing.com
- Phone: +1 206-312-6446
- Mail: 1 Dollar Digitizing, 46494 Mission Blvd, Fremont, California 94539, USA
- Online: Contact Form
We will respond to verifiable requests within 30 days (or within the timeframe required by applicable law). We may need to verify your identity before processing a request.
16. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this page and notify registered users by email. Continued use of our services after the effective date of any update constitutes acceptance of the revised policy. We encourage you to review this page periodically.