Privacy policy
Last updated: October 7, 2026
Cross Stitch (thecrossstitch.com) is operated by A.B. DIGITAL HORIZON SYNDICATE LIMITED, which is responsible for the data described here.
In your browser
- Cropping, the preview and the pattern itself are made in your browser. Photos you only try out in the editor are not stored on our servers.
- If you sign in from the editor, your browser temporarily keeps the photo and settings to return you to the same pattern. They are deleted after it is restored.
When you download a PDF
- To create every PDF, new or repeated, we send the pattern data (grid, threads and settings, not the original photo) to our server. The PDF is not stored.
- We keep a reduced copy of your cropped photo (a JPEG of at most 1024 px, without camera or location metadata).
- We keep the pattern settings: size in stitches, number of colors, paper and language, plus the pixel size of the photo and the crop.
- We use this only to understand what people stitch and to improve our patterns and pages. We never share, sell or publish your photos.
- We keep each pattern you unlock (grid, threads and settings) and a small preview image, so you can download it again from “My patterns”.
- Repeat downloads of a pattern you already unlocked store nothing new.
Your account
- When you sign in with Google we receive your name, email, Google account ID and the address of your profile picture.
- When your account is created we store your IP address and the first page you visited in that browser session (path, referring site and UTM tags).
- We keep your credit history and which patterns you unlocked, so repeat downloads cost nothing.
Payments
- Paddle processes credit purchases as merchant of record. Payment details are entered directly in its checkout; we do not store card numbers or security codes.
- We store the transaction ID, pack, amount, currency and payment status linked to your account to fulfill purchases and prevent duplicate credits.
- Paddle checkout loads when you open a payment. Paddle handles payment and billing data as an independent controller of that data; its privacy policy is available in the checkout.
Cookies
- stitch_session: keeps you signed in for 30 days.
- stitch_oauth_state: protects Google sign-in; expires after 10 minutes.
- stitch_signed_in: only tells the page you are signed in so it can show “My account”; lasts as long as your session.
- stitch_entry: the first page of your browser session; deleted when you close the browser.
- Site analytics load only if you accept them under “Analytics preferences”.
Storage and retention
- Data is stored with Cloudflare (D1 database and R2 storage), with no public access.
- We do not delete this data on a schedule: account, credit and pattern history is kept complete.
- You can ask us to delete your account, photos or saved patterns at any time; payment records may be kept for as long as the law requires.
Your rights
- You can ask us for access to your data, to correct or delete it, to restrict its use or to receive a copy, and you can object to how it is used.
- If you believe we handle your data improperly, you can complain to the data protection authority in your country.
Contact
To find out what we store about you, ask us to remove your photos or saved patterns, exercise your rights, or ask anything else about privacy, email privacy@thecrossstitch.com.
Terms of Service · Refund Policy · Contact · Paddle privacy policy