Image processing
Images selected in the pattern maker are processed locally by code running in your browser. The application does not upload source images or generated pattern data to our server or to the payment provider. Temporary browser object URLs display local files and stop working when released, refreshed, or closed.
To limit paid downloads to the source image purchased, the browser combines the image bytes with a random value stored in that browser and creates a one-way SHA-256 identifier. Only this browser-scoped identifier is sent to our server and stored in short-lived payment-access cookies; the source image, file name, and generated pattern are not sent. The identifier is used only to match export access to that image and is not designed to identify a person or compare photos across different browsers.
Checkout and payment data
When you choose a paid export, our server creates a checkout with Waffo Pancake. Waffo may receive the checkout product, price, currency, request identifiers, contact and billing details you provide, payment method data, IP address, browser information, and other information needed to process the transaction, prevent fraud, calculate tax, provide receipts, and meet legal obligations. Payment details are entered directly with Waffo; this site does not receive or store your full card number.
After checkout, our server retrieves the order from Waffo and verifies its store, product, environment, price, currency, and payment status before granting export access. Waffo may also send a signed payment-status webhook to our server. Checkout and order identifiers do not contain your image or generated chart.
Essential cookies
The paid export flow uses short-lived, HttpOnly cookies. A pending-payment cookie binds the browser and browser-scoped image identifier to the checkout it started, and a separate export-access cookie records the verified temporary entitlement for each paid image. These cookies are required to prevent an unverified browser response or payment for a different image from unlocking downloads. They are not used for advertising or cross-site profiling and expire automatically.
Ordinary web requests
As with most websites, the hosting provider may receive technical request data such as IP address, browser user agent, requested path, timestamp, and security logs. This data supports delivery, abuse prevention, and debugging and is governed by the selected hosting provider's terms.
Optional analytics
Google Analytics 4 loads only after you accept analytics in the consent panel. It helps us understand page visits and a limited set of product actions, including image selection, pattern preview creation, checkout start, confirmed purchase, and PNG or PDF download. The data may include the page path and title, referrer, event time, approximate location derived from an IP address, and browser or device information.
Analytics events do not include your selected image, file name, generated chart, contact message, full payment details, or raw Waffo checkout and order identifiers. A confirmed purchase uses an irreversible, shortened transaction reference so Google Analytics can deduplicate the event.
When you accept, Google Analytics may set first-party cookies such as _ga and a property-specific _ga_* cookie. These identifiers can remain for up to two years unless you clear them or withdraw consent. Your analytics choice is stored locally in your browser. Choose Cookie settings in the footer to change that choice; declining or withdrawing prevents further analytics events and removes accessible Google Analytics cookies for this site.
Downloads
PNG and PDF pattern files are generated in your browser and downloaded to the location controlled by your browser or operating system. The site and Waffo do not receive copies of those files.
Contact
If you send an email, the message and address are handled by the configured mail provider and retained as needed to answer the request, prevent abuse, or meet legal obligations. Do not send sensitive images unless they are necessary for support.
User Data Rights
Depending on the law where you live, you may have rights to be informed about processing; access, correct, or delete your personal data; restrict or object to processing; receive portable data; and withdraw consent. To exercise a right, email support@stitchfromphoto.com. Include enough information to identify the relevant support message or purchase, but do not send full payment-card details or identity documents unless we specifically request them through a secure process. We may ask for reasonable verification before acting on a request and normally respond within 30 calendar days, or within another period required by applicable law.
Source images and generated patterns processed only in your browser are not held by StitchFromPhoto, so there is no server copy for us to access or delete. Some transaction, tax, fraud-prevention, accounting, or security records may need to be retained despite a deletion request. Where Waffo, Google Analytics, the hosting provider, or another provider controls the relevant data, we will explain how to contact that provider or forward the request when appropriate.
You may also complain to the data protection authority responsible for your location. Withdrawing analytics consent through Cookie settings stops future optional analytics collection but does not affect processing that occurred before withdrawal.
Changes
The effective date above will change when this policy is revised. Material changes to image handling, accounts, payment providers, analytics, advertising, or storage will be reflected here before release.