Privacy Policy
Last updated September 16, 2026
1. Who we are and what this covers
Dibsy (“Dibsy,” “we,” “us”) is a service operated by Merchy LLC, a South Carolina limited liability company, 6650 Rivers Ave, STE 100, Charleston, SC 29406, United States. This policy explains what personal information we collect, why, who we share it with, and the choices and rights you have. It covers dibsy.bio, app.dibsy.bio, every creator storefront hosted on dibsy.bio, and the Dibsy mobile app.
Three groups of people interact with Dibsy, and different parts of this policy apply to each:
- Creators — people who open and run a store. For creator data, Dibsy is the data controller.
- Buyers — people who purchase from a creator’s storefront. Each storefront is operated by its creator; for order data the creator is the controller and Dibsy processes that data on the creator’s behalf (as a service provider / processor) to produce, ship, and support the order. Because creators don’t publish their own privacy notices, this policy also serves as the buyer notice for every Dibsy storefront.
- Visitors — anyone browsing dibsy.bio or a storefront without an account.
2. Information we collect
From creators
- Account: name, email, password (hashed by our auth provider) or Google sign-in identity, timezone, notification preferences, and the terms you accepted (with version and timestamp).
- Store content: your store name, handle, logo, description, theme, product designs, uploaded images and photos, product titles and prices, and your social links.
- Conversations with Dibsy: your chat and voice messages to the Dibsy assistant, images you attach, and the assistant’s replies and actions. Voice dictation is transcribed on your device by your browser; we receive the text.
- Connected Instagram account (optional): if you connect Instagram, we read your profile (username, name, bio, profile photo, website, follower and post counts) and your own recent posts (captions, media, permalinks). See section 6.
- Website you give us (optional): the public text of the site URL you enter during onboarding.
- Payouts and identity verification: to pay you, Stripe collects identity, tax, and bank details directly (which may include date of birth, government ID, SSN/EIN, or VAT number). Dibsy stores your Stripe account ID and payout status, never those documents or numbers.
- Billing: if you subscribe to a paid plan, Stripe processes your card; we keep your plan, status, and renewal date.
- Usage: pages and features used, generation and message counts (for plan limits), device and browser type, IP address, approximate location derived from IP, and error logs.
From buyers
- Order details: name, email, shipping address, phone number (if you give one), the items you bought, the ship-to country you chose, and your order history. Payment card details are entered on Stripe’s checkout page and never reach our servers.
- Support: anything you send when you reply to an order email.
- Storefront analytics: page views with the page, referring site’s host name, and device type. We do not build advertising profiles of buyers.
From visitors
- Standard server logs (IP address, browser, pages requested, timestamps) and product analytics events (section 8).
Sources
We get this information from you directly, from your device and browser, from Google (if you sign in with Google), from Instagram (if you connect it), from Stripe (payment and payout status), and from our print and shipping partners (production and tracking events). We do not buy data from data brokers. Providing account and order information is required to use the service; optional items are marked above.
3. How we use information
For each purpose we note the legal basis we rely on where GDPR or UK GDPR applies.
- Providing the service — creating your account and store, generating designs at your request, publishing products, processing orders, producing and shipping items, paying creators, and answering support (performance of a contract).
- Running the Dibsy assistant — sending your messages, images, and store context to our AI providers so the assistant can reply and act on your instructions (performance of a contract).
- Building your brand profile — analyzing the Instagram posts and website you connect to suggest a store theme, tagline, and starter designs (consent — you can disconnect at any time).
- Safety and integrity — screening prompts and images for unsafe content and for third-party trademarks, characters, and logos; detecting fraud and abuse; enforcing plan limits (legitimate interests and legal obligations).
- Communications — order confirmations, shipping updates, payout notices, and account notifications by email; product news only if you opt in (contract / consent).
- Improving Dibsy — aggregated usage analytics and error diagnostics (legitimate interests).
- Legal — tax and accounting records, responding to intellectual property notices, and complying with law (legal obligation).
4. Artificial intelligence
- What goes to AI providers. To generate designs and run the assistant we send your prompts, chat messages, attached images, uploaded designs, connected Instagram content, and relevant store data (products, orders, theme) to the providers in section 7. Each provider processes it only to deliver the service to us under contracts that prohibit other uses.
- We never use your content to train AI models. Your designs, images, conversations, and store data are not used by Dibsy to create, train, or improve machine-learning or AI models, and our contracts with providers do not permit them to train on it either.
- Automated screening. Every prompt, upload, and generated design is screened automatically for safety and for possible third-party intellectual property. A screening result can prevent a design from being generated or published. These decisions do not have legal effects on you and you can ask a person to review any screening decision at ip@dibsy.bio.
- Nothing irreversible is automated. Activating a product, approving an order for production, refunding, and going live are actions only you take.
5. Google sign-in
If you sign in with Google we receive your Google account email, name, and profile photo to create and identify your account. Dibsy’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not request access to your Gmail, Drive, or other Google data.
6. Instagram
Connecting Instagram is optional and uses Instagram’s official login. We ask only for permission to read your own profile and media. We use it to understand your brand and suggest designs, a theme, a store name, and a description; to let you import your own posts as design references; and to show you your posts inside Dibsy. We never post on your behalf, read your messages, or access other people’s accounts.
We store the access token Instagram issues (encrypted, server-side only), your Instagram user ID and username, and any posts you choose to import. Tokens expire after 60 days unless you keep using the connection. To delete this data: open Profile & socials → Instagram → Disconnect in the app, which deletes the token and profile data immediately, or email privacy@dibsy.bio. Removing Dibsy from your Instagram account settings (Apps and Websites) also triggers deletion on our side. Posts you imported into your design library remain until you delete them.
7. Who we share information with
We share personal information only with the parties below, and never sell it.
- Print and shipping partners — Printify and the print providers and carriers it routes orders to receive the buyer’s name, shipping address, phone number (if provided), and email, solely to produce, ship, and deliver the order. Partners may not use it for marketing.
- Stripe — payments, refunds, subscriptions, and creator payouts (Stripe Connect). Stripe is an independent controller of the identity and financial data it collects; see Stripe’s privacy policy.
- Creators — the creator whose store you buy from sees your order details (name, email, address, items) to support you, and receives your replies to order emails.
- Hosting and infrastructure — Supabase (database, authentication, file storage), Railway (application hosting), and Resend (transactional email delivery).
- AI and screening providers — Google Cloud (Vertex AI for image generation; Cloud Vision for logo and image screening; Google Identity for sign-in), OpenRouter (routes assistant conversations and screening prompts to large language models from providers such as OpenAI, Google, and Meta), fal.ai (image background removal and upscaling), Hive (image likeness screening, when enabled), and Firecrawl (reading the website you give us).
- Analytics — PostHog (product analytics, section 8). Creator-app product images may be resized through the wsrv.nl image proxy.
- Rights holders — if a rights holder submits a valid infringement notice about a design, we may disclose the responsible creator’s name and contact details to them or to a court, as the law allows.
- Legal, safety, and corporate — to comply with law or valid legal process, to enforce our terms, to protect the rights and safety of users and the public, and to a successor in a merger, acquisition, or asset sale (we’ll notify you before your data becomes subject to a different privacy policy).
8. Cookies and analytics
- Essential: session cookies and local storage that keep you signed in, remember your bag on a storefront, and hold preferences. These are required for the service.
- Analytics: we use PostHog to understand how the product is used (pages, features, errors). On dibsy.bio and storefronts it runs without identifying you; in the creator app it is tied to your account. PostHog sets a first-party cookie/local-storage identifier. We do not use advertising cookies, cross-site tracking, or ad networks.
- Opt out: block cookies in your browser, or send a Global Privacy Control (GPC) signal — we treat GPC as an opt-out of analytics and of any sale or sharing. We do not respond to the older Do Not Track header. Creators can also email us to turn off analytics for their account.
9. Email
Transactional emails (order confirmations, shipping and delivery updates, payout and account notices, sign-in codes) are sent because you placed an order or hold an account and can’t be fully disabled. Creators can turn off each notification category in the app. Marketing email is sent only with your consent and always includes an unsubscribe link and our postal address.
10. How long we keep information
- Account and store data: for as long as your account is open.
- After you close your account: we begin deletion within 30 days and complete it within 90, except for records we must keep.
- Orders, payments, payouts, and tax records: 7 years, as required for accounting and tax law.
- Assistant conversations: for the life of your account, so the assistant keeps context; you can delete individual threads in the app.
- Intellectual property notices, moderation and screening records, fraud and dispute records: up to 7 years after the event, to defend claims and enforce repeat-infringer rules.
- Server logs and analytics events: up to 13 months.
- Buyer order data is retained on the creator’s behalf for the same periods; buyers can ask the creator or us to delete non-required data at any time.
11. Security
Data is encrypted in transit (TLS) and at rest, database access is restricted per account with row-level security, secrets live in managed vaults, and access by our team is limited and logged. No system is perfectly secure; if a breach affects your personal information we will notify you and any required regulators without undue delay and as the law requires.
12. International transfers
Dibsy is based in the United States and our providers process data in the United States and other countries. Where GDPR or UK GDPR applies, we transfer personal information under the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, or another lawful mechanism.
13. Your rights and choices
Wherever you live, you can:
- Access, correct, or delete your account information and store content in the app.
- Download a copy of your data or ask us to delete your account by emailing us.
- Turn notification categories on or off, and disconnect Instagram, in the app.
If you are in the EEA, UK, or Switzerland, you also have the rights to object to or restrict processing, to data portability, to withdraw consent at any time (without affecting earlier processing), and to lodge a complaint with your supervisory authority.
If you are a California resident (CCPA/CPRA) you have the right to know what personal information we collect, use, and disclose; to delete it; to correct it; to opt out of sale or sharing; to limit use of sensitive personal information; and not to be discriminated against for exercising these rights. We do not sell personal information and do not share it for cross-context behavioral advertising, and we honor Global Privacy Control signals. In the preceding 12 months we collected the categories listed in section 2 (identifiers, commercial information, internet activity, geolocation derived from IP, and user-generated content) from the sources in section 2, for the purposes in section 3, and disclosed them for business purposes to the service providers in section 7. Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and other states with privacy laws have similar rights, including the right to appeal a decision we make about your request.
To exercise any right, email privacy@dibsy.bio from the address on your account (or use the settings in the app). We verify requests by confirming you control the account email. An authorized agent may submit a request with your written permission. We respond within 45 days (30 days under GDPR) and will tell you if we need more time. If we deny a request you can appeal by replying to our decision.
Buyers: because the creator you bought from controls your order data, you can contact them by replying to your order email, or contact us and we will assist and pass the request on.
14. Children
Dibsy is not directed to children. Creators must be at least 18. Buyers must be at least the age of majority where they live, or have a parent or guardian place the order. We do not knowingly collect personal information from anyone under 13 (or under 16 in the EEA and UK); if we learn we have, we delete it. Parents can contact privacy@dibsy.bio.
15. Third-party sites
Creator storefronts link to creators’ own social profiles and websites, and checkout happens on Stripe. Those sites have their own privacy practices, which this policy does not cover.
16. Changes and contact
We will post any changes here with a new date, and for material changes we will notify creators in the app or by email before they take effect. Questions, requests, or complaints: privacy@dibsy.bio, or write to Merchy LLC, 6650 Rivers Ave, STE 100, Charleston, SC 29406. [If Dibsy targets EU/UK users: appoint and name an EU and a UK representative here (GDPR Art. 27).]