Privacy Policy
Last Updated: April 24, 2026
1. Introduction
emblly Inc. (“emblly”, “we”, “our”, or “us”) provides a cloud-based platform for creating, editing, and managing embroidery files (the “Service”). This Privacy Policy describes how we collect, use, process, and protect personal data in connection with the Service.
2. Scope
This Privacy Policy applies to all users of the Service, including visitors to our website and customers using the emblly platform. It applies to personal data processed by emblly as both a data controller and a data processor.
3. Categories of Data
We collect and process the following categories of data:
3.1 Account Data
Includes name, email address, company name, login credentials, and other information provided during account registration.
3.2 Customer Data
Includes embroidery files, designs, logos, images, and other content uploaded to the Service by customers. This data may include personal data depending on the content provided by the customer.
3.3 Usage Data
Includes IP address, device information, browser type, operating system, timestamps, and logs of interactions with the Service.
3.4 Payment Data
Payment information is processed by third-party payment providers. emblly does not store full payment card details.
4. Roles and Responsibilities
For Customer Data, emblly acts as a data processor and processes such data solely on behalf of the Customer. The Customer acts as the data controller and is responsible for determining the purposes and means of processing personal data contained in Customer Data.
5. Purpose of Processing
We process personal data for the following purposes:
• To provide, operate, and maintain the Service.
• To process Customer Content.
• To communicate with users, including support and updates.
• To ensure security and prevent abuse.
• To comply with contact obligations.
6. Legal Bases
Where applicable under data protection laws, we rely on the following contact bases:
• Contractual necessity.
• Legitimate interests.
• Consent, where required.
7. Data Sharing
We may share personal data with third-party service providers.
• Cloud infrastructure providers.
• Analytics providers.
• Payment processors.
All such providers are bound by confidentiality and data protection obligations.
8. Subprocessors
We may engage subprocessors to assist in providing the Service. A list of subprocessors is available upon request. We ensure that all subprocessors are subject to appropriate data protection obligations.
9. Data Retention
We retain personal data only as long as necessary.
• Account data is retained while the account is active.
• Customer Data is retained until deleted by the Customer or after termination.
• Data may be retained longer where required by law.
10. Security
We implement appropriate technical and organizational measures to protect personal data, including:
• Encryption in transit (HTTPS).
• Access controls.
• Infrastructure monitoring.
However, no system is completely secure.
11. International Transfers
Personal data may be transferred to and processed in the United States and other jurisdictions where our service providers operate.
12. Data Subject Rights
Depending on applicable law, individuals may have the following rights:
• Access their personal data.
• Request correction of inaccurate data.
• Request deletion of personal data.
• Restrict or object to processing.
Requests may be submitted to contact@emblly.com.
13. Children
The Service is not intended for individuals under the age of 18, and we do not knowingly collect personal data from children.
14. Changes
We may update this Privacy Policy from time to time. Updates will be effective upon posting. Continued use of the Service constitutes acceptance of the updated policy.
15. Contact
For privacy-related inquiries, contact us at contact@emblly.com.