Privacy policy
Privacy Policy
Last updated: August 11, 2026
This policy describes how Tishmash handles personal information when you use our website and AI-powered print-on-demand service. It matches how the product works today, including the privacy choices you can manage in the app.
Who we are
Tishmash is operated by Liat Boyko Ovadia, a sole trader (עוסק מורשה) registered in Israel under number 037340031, of House 119, Shoval 85300, Israel. She is the data controller for the information described here.
We operate an online service that lets you discover, customize, and order custom apparel through a conversational workspace. Orders are fulfilled by print partners after checkout. We currently sell and ship within the United States.
Contact: support@tishmash.com
Your privacy choices
When you first visit, we may show a cookie banner where your region requires explicit consent. You can open Privacy settings from your profile at any time.
- Essential — always on. Required for sign-in, your workspace, cart, checkout handoff, and security. There is no off switch, because the service cannot work without them.
- Analytics — optional. Helps us understand product usage (browsing, pinning, creating designs, checkout starts). When off, we don't send analytics events to our warehouse for your account.
- Marketing & affiliates — optional. Lets us remember campaign parameters (UTM tags, referrer) on your session for attribution. When off, we don't persist those parameters.
Your choices are stored on your account and applied to new sessions. Changes take effect going forward; they don't delete records we already collected lawfully before you opted out.
Information we collect
Account & identity. We assign you a Firebase user ID when you use the site. You may browse anonymously and later link a Google account (the same user ID is preserved). If you sign in with Google, we receive basic profile information such as your name and email, according to your Google settings.
Workspace & creative activity. We store your collections, chat messages, pinned designs, AI generations, and curated designs. This includes prompts, assistant responses, and the design metadata needed to run the service.
Photos you upload. If you attach reference images — a person, a pet, or style inspiration — we store the file in secure cloud storage and its metadata in our database. We do not use your uploads to train AI models. See "Designs made from your uploads" below.
People you tell us about. When you shop for someone else, our assistant may record a short profile of that person so it can make better suggestions — typically a first name or nickname, your relationship to them, and a description of their taste. We keep this deliberately minimal. Please don't tell the assistant anything about another person that they wouldn't want stored — we neither need nor want contact details, addresses, dates of birth, or information about anyone's health, religion, or political views. You can view and delete these profiles in your account, and deleting one removes it from our systems.
Commerce. When you add items to cart or check out, we work with Shopify for cart, payment, and tax, and with Airwallex for payment processing. We store design snapshots and product selections on your orders. We never see or store full card numbers — those are handled by our payment providers.
Fulfillment. To produce and ship your order we share what's needed with our print partner (currently Gelato): print-ready artwork, garment variant, and your shipping address.
Content screening. We run automated checks on prompts, uploaded images, and generated designs to detect content that breaks our Terms & Conditions — copyright and trademark infringement, sexual content, hate content, and illegal material. We retain copies of screened content for moderation, safety, and dispute handling. Where the law requires it, we report illegal material to the relevant authorities.
Support and abuse records. If you open a return request we store it, along with your description and the outcome. If an account repeatedly sends hostile or abusive messages, we record a count of those incidents on the account. This count doesn't automatically restrict anything — it surfaces on an internal review screen and a person decides what, if anything, to do. If you believe your account has been flagged unfairly, email us and we'll look at it.
Analytics (with consent). If you allow analytics, we collect session ID, coarse device type, browser user agent, a country or region code we derive for consent purposes, and interaction events such as pin, focus, remix, search, and add-to-cart. We use Google BigQuery as our analytics warehouse.
Marketing attribution (with consent). If you allow marketing cookies, we may store UTM parameters and referrer information on your session.
Technical logs. Our cloud infrastructure logs operational data — errors, latency, security events. These logs may include IP addresses and are used to keep the service reliable and secure.
How we use information
- Provide the workspace, AI assistant, design tools, and feed.
- Generate and refine artwork using AI models (see processors below).
- Process orders, payments, manufacturing, and delivery.
- Remember your preferences, pins, and session context.
- Screen content and prevent abuse, fraud, and security incidents.
- Measure and improve the product where you've consented to analytics.
- Comply with law and respond to valid legal requests.
We do not sell your personal information, and we do not use your uploads or your designs to train AI models.
Designs made from your uploads
Where a design was created using any image you uploaded, it is private. We use it only to produce and deliver the orders you place. We never add it to our public catalog, never include it in our search index, never sell it to another customer, and never use it in our marketing. This is enforced in our systems by design provenance, not by manual review, and sharing a link to a design does not change it.
Designs created without an uploaded image may be listed in our public catalog under section 6 of our Terms & Conditions.
AI processing
Tishmash uses third-party AI services for chat, design generation, and image analysis. When you interact with the assistant or request a design, relevant context — messages, design references, and uploaded images where applicable — is sent to those providers to produce a response.
AI outputs can be imperfect. Don't submit sensitive personal information you're not comfortable having processed by automated systems. You are responsible for having the rights to any image you upload, including photographs of other people.
How we share information
We share data with service providers who process it on our behalf, only as needed to run Tishmash:
| Provider | Purpose |
|---|---|
| Google Cloud / Firebase | Authentication, database, file storage, hosting, cloud functions |
| Google BigQuery | Analytics warehouse |
| Google (Gemini) and other AI providers | Language and image models |
| Pinecone | Search index for public catalog designs |
| Photoroom | Background removal and print-ready asset preparation |
| Shopify | Cart, checkout, order management |
| Airwallex | Payment processing |
| Gelato | Print production and shipping |
We may also disclose information where required by law, to protect rights and safety, or in connection with a sale of the business (with notice where required).
International transfers
We are based in Israel and use providers that process data in the United States, the European Economic Area, and elsewhere. Israel holds an adequacy decision from the European Commission, and where further safeguards are required for transfers we rely on appropriate mechanisms such as Standard Contractual Clauses.
Retention
- Uploaded photos — kept while your account is active, subject to per-account limits. Deleted within 30 days of a deletion request or account closure. Uploads not used in the previous 12 months are purged automatically.
- Print files containing an uploaded photograph — deleted 90 days after delivery, once the return window has closed. The order record is kept; the image is not.
- People you tell us about — kept while your account is active, and deleted when you delete the profile or your account.
- Account & workspace — kept while your account is active, and afterwards only as needed for support, disputes, and legal compliance.
- Orders — kept for accounting and tax records as required by law.
- Screening and abuse records — kept while your account is active and for up to 24 months afterwards for fraud prevention.
- Analytics — retained in BigQuery on the order of months to a few years, unless a longer period is needed for security or legal reasons.
- Feed browsing — feed cards are session-based and not stored as a long-term personal archive; ranking uses aggregated analytics.
Security
We use industry-standard measures including encrypted transport (HTTPS), access controls, and cloud provider security features. No method of transmission or storage is completely secure — please use a strong password and keep your credentials private.
Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to certain processing, and to data portability. You may withdraw consent for analytics or marketing at any time in Privacy settings; this doesn't affect processing already performed.
To exercise any right, or to request deletion of your account or data, email support@tishmash.com. We may need to verify your identity. California residents may exercise rights under the CCPA/CPRA, including the right to know, delete, and correct, and will not be discriminated against for doing so. EEA and UK users may lodge a complaint with their local supervisory authority. Israeli users may contact the Privacy Protection Authority.
Legal bases (EEA/UK)
Where the GDPR applies we rely on: contract, to provide the service you request; consent, for non-essential analytics and marketing cookies; legitimate interests, for security, fraud prevention, content screening, and service improvement; and legal obligation, where we must retain or disclose data by law.
Children
Tishmash is not directed at children under 13, and we do not knowingly collect their personal information. You must be 18 to place an order. If you believe a child has provided us with data, contact us and we will delete it.
Changes
We may update this policy. We'll post the new version here and update the date above. Material changes may also be highlighted in the app.
Related links
Manage cookies: open the app → Profile → Privacy settings.
See also our Terms & Conditions, Shipping Policy, and Returns & Refunds Policy.