Selling digital products in the EU comes with certain privacy rules. The good news is that Stitchonomy handles almost all GDPR compliance on your behalf. As a vendor, your responsibilities are minimal, but it’s important to understand how data is handled.
What Stitchonomy handles for you #
Stitchonomy is the seller of record. This means we are responsible for collecting and processing all customer data. We take care of:
- Collecting customer information like name, email, IP address, and payment details
- Storing digital downloads securely
- Managing GDPR compliance, including cookie notices, privacy policies, data removal, and customer access requests
You do not receive or control any personal customer data. As a result, you are not responsible for handling GDPR requirements related to buyers.
What you should do as a vendor #
Even though Stitchonomy covers most of the GDPR work, there are still a few best practices you should follow.
Do not collect customer data yourself
Please do not ask us to send you buyer information. You may not use purchases to build your own email list or contact customers directly.
Create and maintain your own privacy policy
If you sell your patterns on other platforms, like Etsy or your own website, you need a privacy policy there. This shows how you handle data across platforms, including Stitchonomy.
Store your files securely
Make sure your original designs and PDFs are stored in a secure place. Do not use public links or open folders. A password-protected cloud storage or external drive is a safer choice.
Additional advice for EU-based vendors #
If you are located in the EU and receive payouts from Stitchonomy, we may share certain data with our payment processor. This includes your name, email address, and commission amounts. GDPR views you as a “data recipient” in this case. This is normal and legal.
To stay compliant, we recommend:
- Keeping payout records in a secure location
- Using password protection for sensitive files
- Avoiding the sharing of payout reports with others