Your information & your choices
Privacy Policy
Last updated October 1, 2026.
DecorMotif is operated by DecorMotif.
Privacy, order support, and legal notices: hello@decormotif.com.
This policy explains how DecorMotif handles personal information when you browse, create artwork, open an account, or order prints. We do not sell personal information for money. Private customer photos, prompts, and artwork are not offered to advertisers or used as source images for our retail collection.
Information we collect
- Account and contact information: your name, email, account identifier, authentication information, and information provided by a sign-in provider you choose. Our authentication provider processes credentials and security factors.
- Your creative project: room and reference photos you upload, written instructions, art preferences, room observations produced by AI, generated images, selections, proof approvals, and project history. Room photos are optional. Avoid including faces, private documents, precise location details, or other sensitive information you do not need us to process.
- Orders: items, quantities, shipping names and addresses, payment status, transaction identifiers, credits, and shipment details. Stripe collects payment card details in its checkout; our application does not store full card numbers or security codes.
- Service and security records: requests, device/browser information and IP addresses processed by our hosting and service providers, authentication activity, consent records, support correspondence, and abuse-prevention records.
- Analytics: account-linked art impressions and selections, and an age range and region only if you choose to provide them. Separately, for U.S. visitors who have not opted out, Google Analytics 4 measures public-page views and Microsoft Clarity measures public-page interactions. We do not infer demographic attributes from room photos or use shipping addresses to populate these optional fields.
We receive information from you, your browser, your chosen sign-in provider, and providers confirming payments, delivery, or service operations.
How we use it
We use necessary information to secure accounts, save projects, analyze the visible design of a room, generate and refine artwork, prepare print proofs, calculate prices and shipping, fulfill orders, provide support, prevent fraud, and meet legal obligations. Transactional emails about sign-in, security, and orders are separate from optional studio marketing messages.
With your optional analytics permission, we study account-linked activity before combining it into art preference reports. Consented design choices and paid activity can inform new retail art directions. We use structured preferences and aggregate signals for this purpose, not your private photos, written prompts, or generated artwork as retail source material. Analytics permission is not required to create or buy art. Turning it off removes account-linked behavior events and optional demographic fields; previously aggregated reports and independently created retail art may remain.
Providers and other disclosures
We disclose information needed to operate the service to our hosting providers, Supabase for accounts, databases and storage, OpenAI for requested AI processing, fal.ai and Topaz Labs for paid print file enlargement, Stripe for payments and tax calculations, Printful and delivery providers for production and shipping, and our email provider for service messages. Room photos may be sent to OpenAI to analyze room design; references, prompts, and artwork may be sent for generation or refinement. After payment, the selected artwork crop is sent to fal.ai and Topaz Labs to prepare the high-resolution print file. Printful receives the approved print file and order/delivery information needed for fulfillment, rather than your room photos or private creative history.
Authorized personnel may access relevant information for support, security, legal compliance, or order operations. We may disclose necessary records to professional advisers, authorities when legally required, or parties to a business transfer subject to applicable law and appropriate confidentiality protections. Information may be processed in the United States and other countries where these providers operate. Providers apply their own contractual retention, security, and legal obligations; we do not promise zero provider retention or end-to-end encryption.
Cookies, browser storage, and site analytics
Necessary cookies support authentication. Browser storage remembers creative drafts, room previews, bag contents, saved pieces, and interface choices. Shared devices may retain this information until it is cleared; signing out clears the private draft keys used by this app. You can also clear site data in your browser, which may sign you out or remove unsaved work.
For U.S. visitors, Google Analytics 4 (GA4) and Microsoft Clarity may run on public pages unless you turn off site tracking in this browser. We do not load either tool for visitors outside the U.S. or when your browser sends a Global Privacy Control signal. Earlier choices to decline either tool remain in effect. This site tracking is separate from the account setting for art-preference analytics and from email marketing.
- GA4: measures approved public-page views. It may use analytics cookies and receive browser and device information, a shortened public page address without query parameters, and page title. We do not send names, emails, addresses, private project identifiers, photos, prompts, or URL query parameters as analytics events.
- Microsoft Clarity: measures public-page interactions such as clicks and scrolling and may create session recordings and heatmaps. It may use cookies and receive browser, device, and public-page URL information. Page content and images are masked in recordings; interaction locations may remain visible. We do not identify you to Clarity or deliberately send private account, artwork, or order content.
- Page limits: both tools are restricted to approved public pages. Private studio, account, authentication, admin, upload, bag, privacy, and checkout pages are excluded. Navigation into a private page ends active tracking by loading the page separately.
- Meta/Facebook Conversions API or Pixel (not enabled): optional advertising measurement would require a separate advertising choice. If introduced, limited conversion and matching information may be transmitted, including hashed identifiers where disclosed and permitted. Hashing does not make personal information anonymous. No private creative content will be sent.
Advertising disclosures can constitute “sale” or “sharing” under privacy laws even when no money changes hands. We will not enable advertising tracking without the required notice and choices. Email marketing permission does not authorize advertising tracking. We honor Global Privacy Control by keeping GA4 and Clarity off and by stopping browser behavior-event collection through our events API. Legacy Do Not Track signals do not change essential service processing.
Retention and protection
We retain account and project records while needed to provide your saved studio and orders. We retain payment, tax, fraud-prevention, consent, and dispute records as needed for their purpose and applicable legal obligations. Retention depends on account status, outstanding orders, disputes, and legal requirements. A deletion request is reviewed for these exceptions; it is not an immediate erasure of every record or backup. Backups and provider records may remain until their retention cycles end or legal holds are resolved.
Our safeguards include account access controls, private storage, administrator multifactor authentication, limited production-file delivery, encrypted shipping-address records, request limits, and signed provider notifications. No service can guarantee absolute security. Do not share sign-in codes, passwords, or authentication factors.
Your choices and privacy rights
In Account & privacy, you can change internal analytics and email-marketing choices and submit export or deletion requests. These requests are queued for review, and the service does not claim that submission completes deletion. Contact the operator above for corrections, access problems, other rights requests, authorized-agent requests, or to appeal a decision. We may verify identity proportionately before releasing or deleting account information.
Depending on your location and applicable law, you may have rights to access, obtain a portable copy, correct or delete information, withdraw consent, object to or restrict processing, opt out of targeted advertising or sale/sharing, and complain to a regulator. California residents may also request information about categories, sources, purposes and disclosures of personal information, and limit qualifying uses of sensitive information. We do not discriminate against people exercising applicable privacy rights. We will respond within the period required by applicable law and explain any permitted exception or extension.
If EEA or UK data-protection law applies, necessary service processing relies on performance of a contract, legal obligations, or legitimate interests such as security and fraud prevention; optional tracking and marketing rely on consent where required. Any applicable international-transfer safeguards and regional contact requirements must be in place before we expand service to those markets.
Children and updates
The service is intended for adults aged 18 and over. We do not knowingly collect personal information from children under 13. Contact us if you believe a child has provided information so we can investigate and take appropriate action.
We may update this policy as the service changes. The date above identifies the latest version. Material changes will receive an appropriate notice, and we will seek new permission where required before using information for a new optional purpose.