Privacy Policy
How Shirt Bazaar collects, protects, processes, and respects your personal data across our global marketplace.
Overview & Data Controller
- This policy details what personal data we collect, why we need it, and how we protect it under global privacy standards (including GDPR and CCPA/CPRA).
- Shirt Bazaar, Inc. acts as the primary Data Controller for your information.
- We never sell your personal data or uploaded art to third-party data brokers.
Shirt Bazaar, Inc. ("Shirt Bazaar", "we", "us") is committed to safeguarding your fundamental right to privacy. This Privacy Policy details our practices concerning the collection, storage, processing, transfer, and disclosure of personal data when you interact with our platform, website, APIs, generation studio, and physical commerce services.
For individuals residing within the European Economic Area (EEA), United Kingdom, or Switzerland, Shirt Bazaar, Inc. serves as the designated Data Controller responsible for your personal information.
Categories of Information We Collect
- Account data: email, display name, handle, and avatar.
- Art & Prompts: prompts, reference images, and generated/claimed designs.
- Commerce data: shipping destination, garment sizing, and order fulfillment history. (Payment cards are tokenized directly via Bolt).
- Technical telemetry: IP address, device fingerprints, and security event logs.
We collect personal information across the following categories:
- Account & Identity Data: Email address, hashed authentication credentials, chosen public handle (
/creator/yourhandle), display name, profile avatar, and communication preferences. - Generative Prompts & Reference Media: Text prompt strings, style parameters, and reference images you upload to the studio to guide AI generation.
- Order & Shipping Data: Recipient name, physical delivery address, phone number (for carrier dispatch), garment size, and color selections.Note: Full payment card details are collected directly by our PCI-DSS Level 1 payment gateway (Bolt) and are never stored on Shirt Bazaar servers.
- Platform Messages: In-app messages exchanged between creators and buyers via the messaging system.
- Technical & Telemetry Data: IP address, device type, operating system, browser configuration, request timestamps, and security anomaly logs.
Purposes & Legal Bases for Processing
- We only process data when we have a valid lawful basis under GDPR Article 6.
- Primary legal bases include: Performing our contract with you (fulfilling shirts & claims), Legitimate Interests (fraud prevention & platform security), and Legal Compliance.
Under GDPR and international privacy frameworks, we process your information under the following lawful bases:
| Processing Purpose | Data Category | Lawful Basis (GDPR) |
|---|---|---|
| Generating designs from your prompts and reference media | Prompts, Uploads | Performance of Contract |
| Operating 1-of-1 claims, storefront provisioning, and physical apparel fulfillment | Account, Shipping, Order Details | Performance of Contract |
| Accounting, tracking, and distributing creator resale royalties | Claim Records, Ledger Data | Performance of Contract & Legal Obligation |
| Fraud detection, bot prevention, and content moderation | IP, Telemetry, Prompts | Legitimate Interest & Public Safety |
| Tax calculation, financial auditing, and regulatory reporting | Transaction Logs, Invoices | Legal Obligation |
Third-Party Sub-Processors & Data Sharing
- We share data only with verified sub-processors necessary to run the service.
- Sub-processors include Bolt (payments), Print-on-Demand facilities (garment manufacturing), Supabase/AWS (cloud database & auth), and Cloudflare (security).
- We do NOT sell, rent, or monetize your personal data to ad networks.
We do not sell personal data. To execute the Services, we share limited data with the following vetted third-party sub-processors:
- Payment Processing: Bolt Financial, Inc. processes card payments, fraud mitigation, and buyer checkout flows under strict PCI-DSS compliance.
- Print & Fulfillment Facilities: Certified print-on-demand manufacturing networks receive shipping names, delivery addresses, and high-resolution print files to manufacture and deliver your garment.
- Cloud Infrastructure & Database: Supabase, Inc. and Amazon Web Services (AWS) provide encrypted database storage, authentication, and secure backups.
- Edge Network & DDoS Mitigation: Cloudflare, Inc. provides web application firewall (WAF), caching, and edge routing.
Data Retention & Ledger Permanence
- Active account data is kept while your account remains in good standing.
- Financial, order, and tax records are retained for 7 years as required by statutory law.
- 1-of-1 Genesis Claim records and royalty provenance are retained permanently on our platform ledger to safeguard creator royalty rights.
5.1 Retention Standard: We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including servicing your account, fulfilling warranty guarantees, resolving disputes, and adhering to statutory tax and financial reporting mandates (typically 7 years).
5.2 1-of-1 Claim & Provenance Permanence: Because a 1-of-1 Genesis Claim conveys permanent commercial IP assignment and perpetual royalty rights, immutable records of the claim timestamp, creator handle, and design hash are maintained permanently in our platform ledger to protect future royalty distribution.
International Data Transfers
- Your data may be processed in the United States and other global cloud regions.
- All cross-border data transfers are protected under Standard Contractual Clauses (SCCs) approved by the European Commission.
Shirt Bazaar operates globally with primary cloud infrastructure hosted in the United States. If you access our platform from the European Economic Area (EEA), United Kingdom, or other regions with data transfer laws, your personal data will be transferred to and processed in the United States.
We ensure adequate data protection safeguards through Standard Contractual Clauses (SCCs) adopted by the European Commission and relevant International Data Transfer Addenda.
Your Rights (GDPR, CCPA/CPRA & Global)
- You have the right to access, download (data portability), correct, or delete your personal data.
- California residents may submit CCPA requests; we do not sell or share personal information.
- To submit a Data Subject Request (DSR), email privacy@shirtbazaar.com with your verified account handle.
Depending on your geographic jurisdiction, you possess the following statutory privacy rights:
- Right of Access & Portability: Obtain confirmation of processing and receive a machine-readable copy of your personal data.
- Right to Rectification: Request correction of inaccurate or incomplete information.
- Right to Erasure ("Right to be Forgotten"): Request deletion of your account and personal data, subject to legal and tax retention exemptions.
- Right to Restrict or Object to Processing: Object to processing based on legitimate interests or direct communications.
- CCPA Non-Discrimination: California residents have the right not to receive discriminatory treatment for exercising privacy rights.
To submit a verified Data Subject Request, email our privacy desk at privacy@shirtbazaar.com. We respond to all verified requests within thirty (30) calendar days.
Security Architecture & Encryption
- All data in transit is encrypted using modern TLS 1.3.
- Data at rest is secured using AES-256 encryption.
- We employ strict role-based access control (RBAC), multi-factor authentication, and continuous automated vulnerability monitoring.
We implement industry-leading technical and organizational security controls designed to protect personal data against accidental loss, unauthorized access, destruction, or disclosure. These controls include:
- Full encryption in transit via TLS 1.3 and strong cryptographic cipher suites.
- Full database encryption at rest using AES-256.
- Least-privilege role-based access controls (RBAC) and hardware-backed multi-factor administrative authentication.
- Automated security log auditing, anomaly detection, and regular vulnerability assessments.
Children's Privacy Protection
- Shirt Bazaar is strictly intended for individuals aged 18 and older.
- We do not knowingly collect personal data from children under 13 (or under 16 in certain EU jurisdictions).
Shirt Bazaar is not directed to children under the age of 13 (or under 16 within applicable European jurisdictions). We do not knowingly solicit or collect personal data from minors. If you believe a child has provided us with personal information without parental consent, please contact privacy@shirtbazaar.com so we can promptly delete the account and associated records.
Privacy Inquiries & Data Protection Contact
- Direct all privacy questions, data export requests, and compliance notices to privacy@shirtbazaar.com.
- EU/UK residents have the right to lodge a complaint with their local supervisory data authority.
For questions regarding this Privacy Policy or to exercise your statutory rights, please contact our Data Protection Team:
Shirt Bazaar, Inc. — Privacy & Compliance Office
Attention: Data Protection Officer
1209 Orange Street, Wilmington, DE 19801, United States
Direct Inquiries: privacy@shirtbazaar.com
Explore Other Policies
Our complete legal framework is composed of complementary, binding policies.