# Privacy Policy

> This policy explains what MTTenterprise Inc. collects through Clothing Tech Pack, why it is used, when it is shared, and the choices available to you.

Effective date: September 3, 2026

Operator: MTTenterprise Inc.

Address: 201-1525 Alta Vista Drive, Ottawa, Ontario K1G 0G1, Canada

Contact: [support@clothingtechpack.com](mailto:support@clothingtechpack.com)

## Highlights

- Garment files use private storage and authorization-checked access.
- Selected data is sent to OpenAI only after consent for that assisted feature.
- We do not sell personal information or use uploaded designs for advertising profiles.

## Scope and privacy controller

This Privacy Policy covers the Clothing Tech Pack website, guest workspaces, registered accounts, garment-documentation tools, uploads, previews, exports, billing, product analytics, and support interactions.

MTTenterprise Inc. is the organization responsible for personal information processed for these services. If you submit information about employees, suppliers, factories, models, customers, or other people, you are responsible for having authority to provide it and for giving any notice required by law.

## Information we collect

The information we collect depends on whether you browse the website, use a guest workspace, create an account, upload files, request a suggestion, or purchase a paid service.

- Account and security data, including name, email address, password hash, email-verification status, passkeys, two-factor settings, recovery information, and active sessions.
- Workspace and production data, including brands, style names, garment choices, materials, components, construction, measurements, colorways, artwork, labels, packaging, sample reviews, readiness findings, revisions, and notes.
- Private files and file metadata, including references, sketches, photographs, technical flats, artwork, PDFs, SVGs, filenames, file type, size, checksum, image dimensions, safety status, and relationships to a tech pack.
- Generated records, including snapshots, watermarked previews, clean PDF and XLSX files, readiness results, suggestion decisions, and export history.
- Billing data, including Stripe customer and transaction identifiers, checkout status, product purchased, subscriptions, entitlements, cancellations, refunds, disputes, and audit records. Stripe, not Clothing Tech Pack, handles complete card details.
- Device and usage data, including IP address, browser and device information, timestamps, referrer category, pages or features used, error and security events, and a pseudonymous analytics identifier stored in your browser.
- Communications you send to us, including support messages, feedback, and records needed to investigate a request or dispute.

## How information is collected

We collect information directly from you, automatically when you use the website, and from service providers that report the outcome of an operation. For example, Stripe reports payment and subscription events, and an assisted-feature provider returns a structured suggestion or status after you request processing.

We do not obtain consumer data from data brokers for advertising profiles.

## How and why we use information

We use information to create and secure workspaces, authenticate accounts, store production records, process private files, generate previews and exports, run Factory Readiness, provide requested suggestions, manage billing, enforce limits, prevent abuse, diagnose failures, communicate with you, improve reliability, comply with law, and enforce our agreements.

Depending on your location and the activity, our legal basis may be performance of a contract, your consent, our legitimate interests in operating and protecting the Service, or a legal obligation. Where processing depends on consent, you may withdraw it for future processing.

## Private files and automated safety checks

Uploads and generated documents are stored outside the public web root. The Service uses authorization checks and short-lived signed links where appropriate. Download responses are marked private and are not intended for shared browser caches.

Files may be re-encoded, stripped of unnecessary metadata, rasterized, scanned, quarantined, rejected, or deleted to reduce security risk. PDFs may remain unavailable while a malware check is pending. These controls reduce risk but cannot guarantee that every harmful or corrupted file will be detected.

## Consent-based assisted features

Assisted features are optional and require an affirmative request. For reference analysis, only the private images you select are sent to OpenAI. For readiness advice, the current rule-based score and named findings are sent, without uploaded files or undisclosed production data.

Provider storage is disabled for these requests. Clothing Tech Pack stores the resulting review suggestions, your accept or dismiss decisions, consent version, model and schema identifiers, timestamps, status, and operational hashes. The application does not store the prompt or raw provider response.

Uploaded designs are not sold, used for advertising profiles, or used by MTTenterprise Inc. to train a public or shared artificial-intelligence model.

## Cookies and browser storage

Essential cookies support security, cross-site request forgery protection, authentication, preferences, and guest-workspace access. The secure guest-workspace cookie ordinarily lasts 30 days. A sidebar preference cookie may last up to 7 days. Login sessions follow the configured session period and may last longer when you choose a remember-me option.

Local storage holds a randomly generated analytics identifier. The identifier is pseudonymized with a keyed hash before it is stored with an event. Session storage may hold an analytics-session identifier, an unfinished editor draft, or a checkout preference so the interface can recover the current workflow.

Clearing browser storage may remove preferences, draft recovery information, analytics identifiers, checkout intent, or access to an unclaimed guest workspace. The Service does not use third-party advertising cookies or sell activity for cross-context behavioral advertising.

## When information is shared

We share only the information reasonably needed for the purpose described. Recipients may include Stripe for payments; OpenAI for an assisted feature you expressly request; hosting, database, storage, email, queue, monitoring, and security providers; contractors who support the Service under confidentiality obligations; professional advisers; and authorities where disclosure is legally required.

Information may also be disclosed to prevent fraud or harm, protect the Service or its users, enforce agreements, investigate a security event, or complete a financing, reorganization, merger, acquisition, or sale. A successor must handle personal information consistently with applicable law.

We do not sell personal information or uploaded garment files. We do not disclose them for targeted advertising.

## Retention and deletion

We keep information only as long as reasonably needed for the Service, security, disputes, accounting, and legal obligations. Current product retention is summarized below.

- Unclaimed guest workspaces and their private files are scheduled for deletion after the 30-day guest period expires.
- Watermarked preview files are scheduled to expire 24 hours after generation.
- Account workspaces, uploaded files, issued revisions, and clean exports remain while needed to provide the account until you delete a tech pack or the account, subject to production-history and legal-record requirements.
- First-party analytics events are scheduled for deletion after 13 months.
- Suggestion records and operational metadata ordinarily remain with the related workspace until that workspace is deleted, unless a longer period is needed for security or a dispute.
- Billing, fraud-prevention, security, tax, accounting, and audit records may be retained longer when required or reasonably necessary.

## Security

We use safeguards designed for the sensitivity of the information, including private storage, access controls, password hashing, optional passkeys and two-factor authentication, rate limits, signed links, file validation, malware checks, audit records, and transport encryption in production.

No internet service can guarantee absolute security. You should use a unique password, protect recovery codes, keep your browser and devices secure, and send production files only to intended recipients.

## International processing

MTTenterprise Inc. is based in Canada. Service providers may process information in Canada, the United States, or other countries where they operate. Privacy laws in those places may differ from the laws where you live.

Where required, we use contractual, organizational, and technical measures intended to protect information transferred across borders.

## Your rights and choices

Depending on your location, you may request access to personal information, correction, deletion, restriction, objection, or a portable copy. You may withdraw consent for future assisted processing and may complain to the Office of the Privacy Commissioner of Canada or another applicable regulator.

You can update profile information and delete your account in account settings. Account deletion removes the live workspace and queues deletion of private files, while limited billing, security, dispute, and legal records remain disconnected or retained as required. You may need to cancel an active subscription and resolve pending checkouts first.

We may ask for information needed to verify your identity and authority before completing a privacy request. Some requests may be limited where retention is required by law, needed for security or disputes, or permitted by another legal exception.

## Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from them. A minor who is legally permitted to use the Service must do so with any consent required from a parent or guardian. Contact us if you believe a child provided personal information without appropriate permission.

## Policy updates and contact

We may update this policy as the Service, providers, or legal requirements change. The page will show the revised effective date, and we will provide additional notice of material changes when required.

Contact us to ask a privacy question, exercise a privacy right, or report a concern. Include enough detail for us to understand the request, but do not send passwords, payment-card details, or unnecessary confidential garment files by email.
