Privacy Policy
Effective Date: August 4, 2026
1. Introduction
BeSpoke ("we," "our," or "us") is operated by Mina Logic. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our tailoring management platform, including our admin portal, customer portal, and landing page (collectively, the "Service").
By using our Service, you agree to the collection and use of information as described in this policy.
2. Information We Collect
2.1 Information You Provide
- Account Information: Phone number or email address, display name, profile photo, and linked sign-in provider when you create or connect an account. Supported sign-in methods may include phone verification, passwordless email links, Google, and Apple.
- Shop Information: Business name, logo, contact details, and branding preferences for shop owners.
- Customer Data: Names, phone numbers, email addresses, and physical measurements entered by shop administrators.
- Order Data: Order details, fabric choices, pricing, payment records, and delivery information.
- Payment Information: Transaction records processed through integrated payment providers (e.g., Paystack). We do not store credit card numbers or mobile money PINs.
2.2 Information Collected Automatically
- Usage Data: Pages visited, features used, timestamps, and session duration. On our marketing site, page-view, CTA, pricing, demo-interaction, and campaign-attribution analytics are collected only after you accept optional analytics and advertising cookies.
- Essential Operational Events: When you actively start or resume signup, authenticate, submit feedback, or encounter an error, we collect limited first-party service events needed to complete, secure, and troubleshoot that flow. These may include the step and outcome, a bounded error code, authentication route and country dial code, an ephemeral random session identifier, and account or setup identifiers needed to resume or diagnose the request. These events do not include advertising campaign identifiers without consent and expire after 30 days.
- Campaign Measurement: If you accept optional analytics and advertising cookies, Google Ads may receive a completed-signup event with an opaque, randomly generated transaction identifier. We do not send your shop name, phone number, email address, or shop identifier with that event.
- Device Information: Browser type, operating system, device type, and screen resolution.
- Error Reports: Crash reports and performance data collected via Sentry for improving service reliability. Marketing campaign values are redacted from page URLs and navigation details before these reports are transmitted.
3. How We Use Your Information
- Provide the Service: To operate the platform, manage accounts, process orders, and facilitate payments.
- Improve the Service: To analyze usage patterns, identify issues, and develop new features.
- Communicate: To send service-related notifications, updates, and support responses.
- Security: To detect and prevent fraud, abuse, and unauthorized access.
- Legal Compliance: To comply with applicable laws, regulations, and legal processes.
4. Data Sharing & Disclosure
We do not sell your personal information. We may share data with:
- Service Providers: Third-party services that help us operate, including Firebase/Google Cloud for hosting and authentication, Paystack and Stripe for payments, Sentry for error monitoring, Africa's Talking for supported messaging and phone verification, and Google Analytics and Google Ads for consented marketing measurement.
- Shop Owners: Customer data is shared with the shop owner who manages the customer's account. Each shop can only access their own data.
- Authorized Platform Operations: A limited number of role-authorized platform administrators may access shop and account information, including owner contact and login metadata, and may enter a shop-scoped support view when reasonably necessary for customer support, payment operations, security, abuse prevention, or service reliability. This access is restricted to operational purposes.
- Legal Requirements: When required by law, court order, or to protect our legal rights.
5. Data Isolation & Multi-Tenancy
BeSpoke operates a multi-tenant architecture. Each shop's data is isolated using unique identifiers and role-based rules, and ordinary shop users can access only the shops assigned to them. Tightly authorized platform administrators can access cross-shop data or a shop-scoped support view only for the operational purposes described above; they also use aggregated or de-identified information for service improvement where practical.
6. Data Security
We implement industry-standard security measures to protect your data:
- All data is encrypted in transit (TLS/SSL) and at rest.
- Authentication is handled via Firebase Authentication using supported methods such as phone verification, passwordless email links, Google, and Apple.
- Access to data is controlled by role-based permissions and Firestore security rules.
- We regularly review and update our security practices.
7. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. If you request account deletion, we will remove your personal data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., transaction records for accounting).
8. Your Rights
Depending on your location, you may have the right to:
- Access and receive a copy of your personal data.
- Correct inaccurate data.
- Delete your account and associated data.
- Object to or restrict certain data processing.
- Data portability — receive your data in a structured format.
To exercise these rights, contact us at support@bespokegh.com.
9. Cookies & Local Storage
We use browser local storage and strictly necessary technologies to save preferences, maintain signup and authentication state, protect sign-in flows, and remember your cookie choice. Before optional consent, the marketing page uses only an in-memory random identifier for limited operational events; it does not persist a returning marketing-session identifier or campaign attribution. Google Analytics and Google Ads tags load only after you accept optional analytics and advertising cookies. If consent is declined or has not been given, those tags are not loaded, page-view and CTA/pricing/demo analytics are not sent, campaign and ad-click identifiers are not stored or forwarded, and completed-signup advertising conversions are not sent. If you withdraw consent after accepting, the site immediately sends a denied consent update to Google, removes saved and outbound campaign attribution, and blocks future optional events; information already transmitted before withdrawal cannot be recalled. You can change your choice at any time with the marketing site's persistent “Privacy choices” control or by clearing the site's stored data in your browser.
10. Children's Privacy
Our Service is not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website with a new effective date. Your continued use of the Service after changes become effective constitutes acceptance of the updated policy.
12. Contact Us
If you have questions or concerns about this Privacy Policy, contact us at: