Last updated: September 2026

Privacy Policy

1. Introduction

Sartorium is a members-only directory and showcase for classic menswear houses. This Privacy Policy explains how DIRO s.r.o. ("we", "us", "our") collects, uses, and protects your personal data in compliance with the General Data Protection Regulation (GDPR).

It covers both sides of the platform: individuals who hold an account to browse the directory, and houses that publish a page on it.

2. Data Controller

We are the controller for the personal data we collect about the users of Sartorium: we decide what is collected, and why.

The Data Controller for your personal information is:

DIRO s.r.o.

Roháčova 145/14, Žižkov, 130 00 Prague 3, Czech Republic.

Email: hello@sartorium.net

3. What Data We Collect

We collect only what a given feature needs, and most of the list below depends on what you actually do — opting into location alerts, claiming a house, requesting an appointment.

  • Account: your name, your email address, a hashed password (the password itself is never stored), the account type you chose at signup (individual or house), and your language preference.
  • Session and technical data: signing in creates a session record holding your IP address, your browser's user-agent string, and timestamps. It keeps you signed in and helps us detect abuse. Requests to our sign-in and account endpoints are separately counted against the calling IP address, in our database, so that a password cannot be guessed at speed. That counter holds nothing but the address, which endpoint was called, a number and a timestamp — never who you are.
  • Watched city (optional, individuals): if you opt in to proximity alerts, the single city you ask to be notified about, with coordinates deliberately rounded to two decimal places — roughly one kilometre. There is one, not a list: choosing another replaces it. We do not store a precise position, and turning the option off erases these fields.
  • Fit data (individuals): none, yet. Your preferred cut, your body measurements and the digital wardrobe all belong to a feature that has not shipped: the columns exist in the database, holding nothing but a default value nobody chose, and nothing ever asks you for them. This policy will be updated before any of them collects anything.
  • House page (houses): everything you choose to publish — house name, description, tagline, founding year, website, Instagram handle, logo, photographs, and shop addresses. This content is by design visible to every signed-in member.
  • Contact address (houses): the address a house gives so that members can write to it. We send a link there to check that the house reads that inbox, and we keep the confirmed address, one that is pending while it is being changed, and the date of the confirmation. This address is not published: a house page shows only that the house can be written to, and a member's message is relayed to the address by our email provider.
  • Claim records (houses): when you claim a shop that is already on the map, we keep which shop you claimed, how the claim was made, whether it is pending, accepted or refused, and the dates. A claim made from a verified address on a domain belonging to the house itself — never a shared mailbox provider — is accepted on that match; every other claim is read by a person before the page goes live. Either way, this record is what the decision rests on.
  • Images: photographs you upload are re-encoded on our servers, which strips all embedded metadata — including EXIF GPS coordinates — before the file is stored.
  • Appointment requests: which trunk-show slot you requested, on what date, and its status.
  • Billing (houses): references issued by our payment provider — a customer identifier and a subscription identifier. We never see, receive, or store card details.
  • Usage analytics: cookieless measurement of page views and interactions. No identifier is written to your device, and no analytics profile is built about you. On the public pages and on the sign-in, sign-up and forgotten-password screens, we may also record how a visit unfolds, to see where visitors get stuck: the page as it appears, the scrolling and the clicks, the messages the browser writes to its console, and the timing of each request the page makes, never the content of those requests. Everything typed into a field is masked before it leaves your browser. How a visit unfolds is never recorded on the map, on a house page or in your account, nor on a page opened from a personal link we emailed you, such as a confirmation or password-reset link. These recordings are deleted after thirty days. This is separate from the reach records described next, which are held on our servers and are tied to your account.
  • Reach records (signed-in members): when you open a house page, open a pin on the map, follow a link from a house page to that house's website or Instagram, or write to a house from its page, we record on our servers that your account reached that house on that calendar day — your account identifier, which house, which kind of reach, and the date. Nothing else: no time of day, no duration, no page you came from, no IP address, no device. The record exists so that a house can be told how many different members reached it, and so that one member opening a page eleven times counts once. These records are deleted after seven days; the daily counts they produce carry no identifier and are kept.
  • Waitlist: if you joined our pre-launch waitlist, the name and email address you gave at the time.
  • The curated directory (businesses): Sartorium publishes a directory of houses and shops that is compiled by hand — the name of a shop, its street address, and where the business publishes them, a telephone number and a contact address. This is business contact information rather than data about a member, though for a one-person atelier the two can be the same. We did not obtain it from you: it comes from public sources, not from the business it describes. We publish it so that members can find you, and because a curated directory is the service Sartorium provides; write to us and we will correct or remove your entry.

4. How We Use Your Data

We use your data to:

  • Operate your account: signing in, session security, language, password reset.
  • Deliver the service: showing the directory and house pages to signed-in members, letting a house publish and edit its page, and handling house claims and appointment requests.
  • Notify you when a trunk show is announced near a city you asked to watch. This only ever happens if you opted in.
  • Bill houses for their subscription and issue the corresponding receipts.
  • Protect the platform: rate limits, abuse detection, and protection of the directory against bulk extraction.
  • Understand in aggregate how the directory is used, so we can improve it.
  • Show each house the reach its listing received — how many different members opened its page, opened its pin, and left for its website or Instagram — and state a platform-wide total in public. A house is never shown who reached it, and a public total is never broken down to a single house.
  • Relay a message you choose to write to a house, with your name and your e-mail address, so that the house can answer you directly. We keep no copy of what you wrote.
  • Send you updates and newsletters, if you asked for them. Every such email carries an unsubscribe link.

5. Legal Basis for Processing

Under Article 6 of the GDPR, we process your personal data on the following legal bases:

  • Performance of a contract (Art. 6(1)(b)): creating and running your account, giving you access to the directory, publishing a house page, handling appointment requests, and administering a house subscription.
  • Consent (Art. 6(1)(a)): proximity alerts and the watched city they require, newsletters and marketing communications, and the pre-launch waitlist. You may withdraw your consent at any time, without affecting the lawfulness of what came before.
  • Legitimate interest (Art. 6(1)(f)): keeping the platform secure and available, preventing abuse, protecting the curated directory against bulk extraction, measuring the reach a house receives so that it can be shown what its subscription delivers, analysing usage in aggregate, and seeing where a visit to the public pages or the sign-in and sign-up screens gets stuck. You may object to processing on this basis at any time. For reach measurement we have written down the assessment that weighed this interest against your rights, and we redo it if the design changes.
  • Legal obligation (Art. 6(1)(c)): retaining accounting records relating to paid subscriptions for the period required by law.

6. Third-Party Services & Data Processors

To operate the platform we rely on the providers below. Each acts on our instructions under a data processing agreement, and we choose an EU-hosted option wherever one exists.

  • Neon: our database, hosted in the European Union (Frankfurt). Account, profile, house and booking data are stored there.
  • Vercel: our hosting and application platform, which processes technical request data such as IP addresses and browser information in order to serve the site.
  • Vercel Blob: object storage for the images houses upload — logos, hero images and gallery photographs.
  • Brevo: a European provider used for transactional email (account emails, proximity alerts, booking notices), for relaying a message you write to a house, and for our contact lists.
  • Geoapify: a geocoding provider hosted in Austria, which turns a place name into coordinates. It is called only from our servers — your browser never contacts it — and every result is cached so the same place is looked up once.
  • OpenFreeMap: the interactive map loads its tiles from OpenFreeMap. When the map is displayed, your IP address is transmitted to their servers as part of the standard tile request.
  • PostHog (Cloud EU): product analytics and the visit recordings described in section 3, run without cookies and without a persistent identifier.
  • Sentry: error monitoring, on its European data region. When something breaks, a report of the failure is sent so we can fix it. Reports are filtered before they leave our servers: no session cookie, no email address, no measurement, and an account is identified by its internal id rather than by name.
  • Paddle: our Merchant of Record for house subscriptions. Paddle collects and processes payment and billing information directly and securely, as its own controller, and handles subscription management, tax compliance and invoicing. We never see, receive or store card details.
  • Upstash: short-lived rate-limit counters, keyed on an account identifier or an IP address. No message content or personal profile is stored there.
  • Professional advisers: our accountants, auditors and lawyers, where they need access to do their work for us, and under a duty of confidentiality.
  • Authorities: a public authority, a court or a regulator, where the law requires disclosure or where it is necessary to establish, exercise or defend a legal claim, or to protect someone's rights or safety.

7. What a House Can See About You

Sartorium has two sides, so a small amount of data reaches a house. Once it does, that house is a separate controller for what it goes on to do with it.

  • If you request a trunk-show appointment, the house sees your name, your language, and the slot you asked for — and nothing else.
  • A house never receives your postal address, your watched city, or any measurement, through Sartorium.
  • If you write to a house from its page, that house receives your name, your e-mail address and your message. Your address is the reply path, so it can answer you directly. Nothing is sent to a house you did not write to, and we keep no copy of the message.
  • A house is never told which members viewed its page. Reading a house page does not reveal your identity to it.
  • A house is shown how many different members reached its page and its pin over a period — a count, and nothing else. Never which members, never a list, and never a figure narrow enough to point at one person.
  • Of the members who wrote to it, a house is also shown how many chose each of the four reasons the form offers — counts again, and never who chose what. Each of those reasons already reached the house in the subject line of the message it received.

If instead you contact a house directly using the website, Instagram or address shown on its page, you leave Sartorium and that exchange is between you and them, under their own privacy practices.

8. Cookies

We set only strictly necessary cookies, and each one exists for one of these reasons: to keep you signed in; to hold a short-lived copy of your session, so that an ordinary page does not have to re-read the database to know who you are; and to remember the language you chose. None of them requires consent under the ePrivacy rules.

Our analytics run without cookies and without any persistent identifier, which is why you are not shown a cookie banner. We use no advertising and no cross-site tracking cookies. Should this ever change, we will update this policy and ask for your consent first.

9. International Transfers

Our database, our email provider, our analytics and our geocoder all process data within the European Union. Some providers — notably our hosting platform and our payment provider — are established outside the EEA or may process data there. In those cases the transfer relies on the European Commission's Standard Contractual Clauses or on an adequacy decision.

10. Data Retention

We keep your account data for as long as your account exists. Deleting your account erases it — your profile, your watched city, your appointment history and, for a house, its page and its photographs — immediately and by cascade. The only exception is records we are legally required to keep, such as accounting records for a paid subscription.

Your session record — the one described in section 3 — lasts as long as the session does. Signing out deletes it at once. A session you simply abandon expires on its own, and the daily job that clears the reach records then deletes the expired record, with the IP address and the user-agent string it held. A session that is still valid keeps its record, because that record is what keeps you signed in. Deleting your account removes all of them together, by the cascade described above.

Reach records are deleted seven days after they are written, by a job that runs every day. Seven days is what deduplication needs — one day of usefulness, plus margin for a late write or a missed run — and nothing shown to anyone is computed from them after the day they are written. The daily counts they produce carry no identifier and are kept: the deletion removes who reached a house, never how many, and no history is lost.

The rate-limit counters described in section 3 are keyed on an IP address rather than on an account, so an erasure request cannot find them and they are not tied to anyone. A counter's window is short — fifteen minutes for the sign-in and password endpoints — and once it has passed the row has no effect; it is removed as later requests come in.

The visit recordings described in section 3 are tied to no account, so an erasure request cannot find them and account deletion does not reach them. They are deleted after thirty days.

You can delete your account yourself at any time from your account settings; you do not need to write to us. Deleting your account also removes you from our contact lists. To stop our newsletters without deleting your account, turn them off in your account settings, or use the unsubscribe link carried in every one of them. To leave the waitlist, use that link.

11. Security

We protect your personal data with technical and organisational measures appropriate to the risk, and we revisit them whenever the system changes.

  • Encryption in transit: the whole site, and every call between it and our providers, runs over HTTPS. There is no unencrypted route into the platform.
  • Encryption at rest: our database and our object storage encrypt what they hold on disk.
  • Passwords: your password is never stored. What we keep is a scrypt hash, deliberately slow to attack, and neither we nor anyone else can read your password back out of it.
  • Access control: no account can read another account's data through the application, and there is no administrative interface that could browse member data casually. A few features work across accounts by design — a trunk-show alert finds the members who live near a show and writes to them — but they return a result, never another member's record. Direct access to the database is limited to those who need it, over authenticated connections.
  • Metadata stripping: photographs are re-encoded on our servers before storage, which removes embedded EXIF data, including GPS coordinates.
  • Abuse limits: rate limits on reads and writes protect accounts against brute force and the directory against bulk extraction.
  • Secrets: the credentials for our database and our providers live in our hosting platform's encrypted environment and are never written into our source code.
  • Error reports: failures are reported to our monitoring provider with session cookies, e-mail addresses and measurements removed before the report leaves our servers.

No system is perfectly secure. If a personal data breach occurs and is likely to result in a risk to your rights and freedoms, we notify the Czech Office for Personal Data Protection within 72 hours of becoming aware of it, and we tell you directly where the law requires it.

12. Your GDPR Rights

Under the GDPR, you have the right to:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Request correction of inaccurate or incomplete data.
  • Erasure (Right to be Forgotten): Request the deletion of your personal data.
  • Restriction: Request that we limit the processing of your data.
  • Data Portability: Receive your data in a structured, commonly used format.
  • Objection: Object at any time to the processing of your data based on our legitimate interests, and to direct marketing. This includes reach counting: if you object, your visits stop being counted for any house from that moment, and no house is ever told that anyone objected.
  • Withdrawal of Consent: Withdraw your consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.
  • Complaint: Lodge a complaint with a supervisory authority — in our case the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů, www.uoou.cz) — or with the authority of your country of residence.

Erasure and your objection to reach counting are both available to you directly in your account settings. For anything else, contact us at hello@sartorium.net.

We answer within one month of receiving your request. If it is complex, or if you have made several, we may extend that by up to two further months, and we tell you within the first month if we do.

13. Changes to This Policy

We update this policy whenever we add a feature that processes new data, and we do it before that feature ships rather than after. Significant changes are announced by email or by updating the date at the top of this document.