Privacy Policy

DisegnoSarto
Last updated: June 12, 2026
Effective date: June 12, 2026

1. Introduction

Welcome to DisegnoSarto. This Privacy Policy explains how Maxime Biasiol, operating as DisegnoSarto (a sole proprietorship / micro-entrepreneur under French law), referred to as “we”, “us”, or “our”, collects, uses, stores, and protects your personal information when you use the DisegnoSarto mobile application (the “App”).

We are committed to protecting your privacy and handling your data transparently. This policy applies to all users of the App, regardless of location, and is designed to comply with the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the French Data Protection Act (Loi Informatique et Libertés), and other applicable data protection laws.

By using the App, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the App.

1.1 Data Controller

The data controller responsible for your personal data is:

Maxime Biasiol
Operating as: DisegnoSarto (sole proprietorship / micro-entrepreneur)
SIRET: 97791455500015
Address: 24 rue Jeanne d’Arc, Saint-Jean-de-Bournay, France
Email: privacy@disegnosarto.com

As a micro-entrepreneur under French law, the data controller is an individual, not a separate legal entity. For all privacy-related inquiries, please use the contact email above.

1.2 Data Protection Officer

Under Article 37 GDPR, we are not required to appoint a Data Protection Officer (DPO), as we are a small-scale operator that does not carry out large-scale processing of special categories of data or systematic monitoring of individuals. If this changes, we will update this policy. For all privacy inquiries, contact us using the email in Section 1.1.

2. Information We Collect

We collect and process the minimum amount of personal data necessary to provide and improve the App, in accordance with the GDPR data-minimisation principle (Article 5(1)(c)).

2.1 Account Information

When you create an account, we collect:

  • Email address — used for authentication, account management, and essential service communications.
  • Display name — used within the App to identify your account. You may use a pseudonym.
  • Authentication identifiers — account tokens generated by Google Sign-In or Apple Sign-In if you choose these methods. We never receive or store your password for these services.

2.2 User-Created Content

When you use the App, you may create and store the following data, tied to your account:

  • Clothing designs and customisation choices (fabrics, buttons, style selections, construction details)
  • Wardrobe items and saved garments
  • Outfit combinations, favourite pairings, and wishlists
  • Travel plans with associated outfit selections
  • Body measurements (entered voluntarily by you)
  • Style preferences and metadata (season, formality level, colour families)

This content is stored solely to provide the App’s core functionality. We do not access, review, or use your wardrobe data for any purpose other than delivering the service to you.

2.3 Usage Data and Analytics

We collect usage data through Firebase Analytics to understand how the App is used and to improve it. This data is pseudonymised (it is linked to a Firebase-generated app-instance identifier rather than directly to your name), and is processed under our legitimate interest (Article 6(1)(f) GDPR). It may include:

  • App feature usage patterns and interactions (screens visited, features used)
  • Session duration and frequency
  • App performance metrics (crash reports, load times, error logs)
  • General device information (device model, operating system version, app version)

Privacy-protective configuration: We have configured Firebase Analytics to truncate / anonymise IP addresses and we do not enable Google Signals, advertising identifiers, or ads-personalisation features. Analytics data is never used for advertising or cross-app tracking.

How to opt out: You can disable analytics collection at any time, with immediate effect, directly in the App via Settings → Privacy → Usage Analytics. No analytics events are sent while this setting is off. This implements your right to object under Article 21 GDPR.

2.4 Device Information

We may automatically collect: device type and model; operating system and version; unique device identifiers generated by Firebase for analytics and crash reporting; language and locale settings; and app version.

2.5 Payment Information

The App offers in-app purchases managed through RevenueCat, Inc. We do not collect or store your payment card details, banking information, or billing address. Payment processing is handled entirely by the platform store (Google Play or Apple App Store) and by RevenueCat. We receive only:

  • Purchase status and subscription entitlements (whether you have an active premium subscription)
  • Transaction identifiers (anonymous references; no card or banking details)
  • Subscription plan type (monthly or yearly) and renewal status

2.6 Firebase App Check

We use Firebase App Check to verify that requests to our backend originate from the authentic DisegnoSarto app. This service processes device-attestation tokens to prevent abuse and unauthorized access. No personal data is collected through App Check beyond anonymous device-attestation signals.

2.7 Location Data

We do not collect precise or GPS-based geolocation, and the App does not request location permissions. However, like virtually all internet services, our analytics and security providers (Firebase, RevenueCat) automatically process your IP address, from which an approximate, coarse location (typically country and city level) may be derived for analytics aggregation, fraud prevention, and abuse detection. We do not use this to track or identify your movements.

2.8 Information We Do Not Collect

For transparency, we confirm that we do not collect:

  • Precise location data — no GPS or fine-grained geolocation.
  • Contacts or address book — we do not access your contacts.
  • Biometric data — no fingerprint, face, or voice data.
  • Photos or camera data — the App does not access your camera or photo library.
  • Health data — body measurements you enter are treated as general user content for styling purposes, not as health data.

3. How We Use Your Information

  • Providing the service — to create and manage your account, save your designs, manage your wardrobe, and deliver core features.
  • Authentication — to verify your identity and secure your account via Firebase Authentication.
  • In-app purchases — to manage subscription status and unlock premium features through RevenueCat.
  • Improving the App — to analyze pseudonymized usage patterns, identify bugs, and enhance the experience.
  • Security and abuse prevention — to detect and prevent fraud, abuse, or unauthorized access, including via Firebase App Check.
  • Customer support — to respond to your inquiries and resolve issues.

We do not use your data for: selling to third parties; behavioral advertising or ad targeting; automated decision-making or profiling producing legal effects (Article 22 GDPR); or training artificial-intelligence or machine-learning models.

4. Legal Bases for Processing (GDPR)

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, we process your personal data on the following grounds:

Purpose Legal Basis
Account creation and service delivery Performance of a contract — necessary to provide the service you signed up for (Art. 6(1)(b) GDPR)
In-app purchases and subscription management Performance of a contract — necessary to fulfil your purchase (Art. 6(1)(b) GDPR)
Usage analytics and app improvement Legitimate interest — to understand and improve how the App is used, using pseudonymized data with IP truncation and no advertising features. You may opt out in-app at any time (Art. 6(1)(f) GDPR; see Section 2.3)
Security and fraud prevention Legitimate interest — to protect our users and our service (Art. 6(1)(f) GDPR)
Compliance with legal obligations Legal obligation — where required by applicable law, e.g. retention of transaction records (Art. 6(1)(c) GDPR)

Legitimate-interest assessment: Where we rely on legitimate interest, we have conducted a balancing test confirming that our interests do not override your fundamental rights and freedoms. The analytics data is pseudonymized, IP-truncated, free of advertising identifiers, proportionate, and you can opt out at any time in-app.

5. Data Sharing and Disclosure

We do not sell your personal data, and we do not share it with any party for marketing or advertising. We share data only with the following service providers (“sub-processors”), strictly as necessary to operate the App:

Service Provider Purpose Data Shared Location
Google Firebase (Authentication) User login and account management Email, authentication tokens EU / US (SCCs)
Google Firebase (Cloud Firestore) Storing designs, wardrobe, app data User-created content, account IDs EU / US (SCCs)
Google Firebase (Analytics) Usage analysis and crash reporting Pseudonymized usage and device data EU / US (SCCs)
Google Firebase (App Check) Preventing abuse and unauthorized access Device-attestation tokens EU / US (SCCs)
RevenueCat, Inc. Subscription and in-app purchase management User identifiers, subscription status US (SCCs)
Google (Google Sign-In) Third-party authentication (if chosen) Email, name (as authorized by you) EU / US (SCCs)
Apple (Sign in with Apple) Third-party authentication (if chosen) Email or relay email, name (as authorized) US / Ireland (SCCs)

Each provider acts as a data processor on our behalf and is bound by data-processing agreements compliant with Article 28 GDPR.

5.1 SDK Transparency

The App integrates the following third-party SDKs: Firebase Authentication, Cloud Firestore, Firebase Analytics, Firebase App Check, RevenueCat Purchases, Google Sign-In, and (on iOS) Apple Authentication Services. Each may collect and transmit data as described in their respective privacy policies (see Section 13).

5.2 Mandatory Disclosures

We may disclose your information where required by law, regulation, legal process, or governmental request; to enforce our Terms of Service; to protect the rights, property, or safety of our users or the public; or in connection with legal proceedings.

6. International Data Transfers

Your data is processed and stored using Google Cloud infrastructure, which may process data outside the EEA, including in the United States. RevenueCat processes subscription data in the United States. Where data is transferred outside the EEA, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, as incorporated into Google’s and RevenueCat’s data-processing agreements.
  • Adequacy decisions where the European Commission has determined a third country provides adequate protection.

Learn more at policies.google.com/privacy and revenuecat.com/privacy.

7. Data Retention

Data Type Retention Period
Account information Until you delete your account
User-created content (designs, wardrobe, outfits) Until you delete your account or remove the content
Analytics data Retained in pseudonymized/aggregated form per Firebase default retention (up to 14 months for user-level data)
Payment / subscription records 10 years after the transaction, as required by French law (Art. L123-22 Code de commerce)
Firebase App Check attestation tokens Transient — not retained beyond the verification request

When you delete your account, we delete or anonymize your personal data within 30 days, except where retention is required by law (e.g. transaction records above).

8. Security

  • Authentication security — managed through Firebase Authentication using industry-standard protocols (OAuth 2.0, OpenID Connect).
  • Encryption — data in transit is encrypted via TLS/SSL; data at rest in Cloud Firestore is encrypted by Google using AES-256.
  • Access controls — Firestore Security Rules restrict access so users can only read and write their own data. Administrative access is limited to the data controller.
  • App integrity — Firebase App Check verifies that requests originate from the authentic app.
  • Minimal data collection — we collect only what is necessary for the App to function.

While we take reasonable technical and organizational measures, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.

9. Data Breach Notification

In the event of a personal-data breach likely to result in a risk to your rights and freedoms, we will:

  • Notify the CNIL within 72 hours of becoming aware of the breach (Article 33 GDPR).
  • Notify affected users without undue delay where the breach is likely to result in a high risk (Article 34 GDPR), via the email associated with your account.
  • Document the breach internally, including its nature, the categories and approximate number of individuals affected, likely consequences, and remedial measures.

10. Your Rights (GDPR)

If you are located in the EEA, UK, or Switzerland, you have the following rights:

  • Right of access (Art. 15) — request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16) — correct inaccurate or incomplete data; you can also edit profile information directly in the App.
  • Right to erasure (Art. 17) — delete your account directly in the App via Settings → Profile → Delete Account, permanently removing your account and associated data within 30 days.
  • Right to restriction (Art. 18) — ask us to limit how we use your data in certain circumstances.
  • Right to data portability (Art. 20) — request your data in a structured, commonly used, machine-readable format. Where in-app export is unavailable, contact us and we will provide it.
  • Right to object (Art. 21) — object to processing based on legitimate interests, including analytics; see Section 2.3 for the in-app opt-out.
  • Right to withdraw consent (Art. 7(3)) — where processing is based on consent, withdraw it at any time without affecting prior lawful processing.
  • Right to lodge a complaint — with your local data-protection authority.

To exercise any right, contact us at the email in Section 1.1. We respond within 30 days, extendable by up to 60 days for complex requests, in which case we will inform you within the initial period.

Supervisory authority: the lead authority for our processing is the CNIL: www.cnil.fr — Tel: +33 (0)1 53 73 22 22. You may also contact the authority in your EU/EEA member state of residence.

11. Cookies and Tracking

The DisegnoSarto App is a mobile application and does not use cookies. Firebase Analytics may use device identifiers to collect pseudonymized usage data; this is not used for advertising or cross-app tracking, and you can disable it in-app (Section 2.3). If we launch a website in future, we will provide cookie information and obtain consent as required.

12. Children’s Privacy

DisegnoSarto is intended for adults and is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected such data without verified parental consent, we will delete it within 72 hours. If you believe a child under 16 has provided us with personal data, contact us immediately at the email in Section 1.1.

13. Third-Party Services

The App integrates with third-party services that have their own privacy policies, which we encourage you to review:

We are not responsible for the privacy practices of these services.

14. Automated Decision-Making

We do not engage in automated decision-making or profiling producing legal effects concerning you or similarly significantly affecting you, within the meaning of Article 22 GDPR. No decisions about your access, pricing, or service level are made by automated means without human involvement.

15. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the “Last updated” date and notify you through the App or via the email associated with your account. Your continued use of the App after changes constitutes acceptance of the updated policy.

16. Governing Law and Jurisdiction

This Privacy Policy is governed by the laws of France, without regard to conflict-of-law principles, and in compliance with the GDPR.

Any disputes that cannot be resolved amicably shall be submitted to the competent French courts of Vienne, without prejudice to your right to lodge a complaint with a supervisory authority or, as a consumer, to bring proceedings before the courts of the EU/EEA member state in which you are habitually resident.

17. Contact Information

Maxime Biasiol — DisegnoSarto
Email: privacy@disegnosarto.com
Address: 24 rue Jeanne d’Arc, Saint-Jean-de-Bournay, France

For complaints about data handling, you may also contact the CNIL: www.cnil.fr — Tel: +33 (0)1 53 73 22 22.