Last updated: 24 August 2026
1. Who we are
Desby OS (“Desby”, “we”, “us”) is a digital operating system for the fashion industry, connecting tailors, clients, apprentices and fabric sellers. We provide tools for order management, client and measurement records, AI-powered body scanning and virtual try-on, a public marketplace of tailor-listed designs, apprenticeship learning, and delivery coordination. This policy explains how we handle personal data when you use our website at desby.app, our web and mobile applications, and related services (together, the “Services”).
We act as the data controller for the personal data described here. Where a tailor, fabric seller or apprenticeship master uses the Services to manage their own client or learner records, they act as a separate data controller for those records and we act as a processor on their instructions.
2. Data we collect
2.1 Account data
- Identity and contact details: full name, email address, phone number.
- Authentication data: hashed passwords (we never store plain passwords) and session tokens.
- Role information: tailor, client, apprentice or fabric seller, and your onboarding details such as business name, business address, service area (state/LGA), working hours and service list.
2.2 Content you create
- Designs and products you publish: photos, titles, categories, prices, descriptions.
- Orders, bookings, price estimates, invoices and order status history.
- Messages and attachments you send through in-app chat.
- Apprenticeship records: lesson progress, task submissions, grades and feedback.
2.3 Measurement and AI data
- Body measurements you enter manually or capture with the AI Body Scan.
- Photos you upload for body scanning or virtual try-on, and the AI-generated try-on results, where you choose to save them.
2.4 Technical data
- Device and browser information, IP address, app version and diagnostic logs used to keep the Services secure and working.
3. How we use your data
- To provide the Services: accounts, orders, chat, measurement ledgers, AI features, the public shop, apprenticeship tools and delivery coordination.
- To personalise your experience and show you relevant designs, tailors and marketplace listings.
- To process payments through our payment partners and prevent fraud.
- To provide customer support and respond to your requests.
- To improve the Services: aggregated analytics on feature usage, performance and reliability.
- To send service communications (order updates, security notices) and — only with your consent — marketing messages you can opt out of at any time.
4. Legal bases
Where the Nigeria Data Protection Act 2023 (“NDPA”) applies, we process your data on one or more of the following bases:
- Contract: to deliver the Services you signed up for.
- Consent: for marketing messages, optional AI photo features and non-essential cookies. You can withdraw consent at any time.
- Legitimate interests: to secure the platform, prevent fraud and improve our Services, balanced against your rights.
- Legal obligation: where Nigerian law requires it.
5. AI features & your photos
The AI Body Scan and Virtual Try-On process photos you choose to upload. Please note:
- Photos are processed only to produce your measurements or try-on result.
- Try-on results are saved to your account history only when you choose to save them, and can be deleted by you at any time.
- Your scan photos and measurements are never published, never sold, and are shared only with a tailor when you explicitly book with that tailor.
- We do not use your body scan photos or measurements to train third-party AI models.
AI-generated measurements are estimates intended to assist with garment fitting. They are not medical or health advice. For critical fittings, your tailor may confirm key measurements manually.
6. Sharing & disclosure
We share personal data only as follows:
- With counterparties you choose: your name, measurements (when relevant) and order details with a tailor you book; your business profile with clients who view your listings.
- With service providers: hosting (Supabase), payment processing (Flutterwave/Paystack), delivery partners, AI processing providers and email delivery — each bound to process data only on our instructions.
- For legal reasons: where required by law, court order or to protect the rights, property or safety of Desby, our users or the public.
- Business transfers: if we are involved in a merger or acquisition, data may be transferred subject to this policy.
We never sell your personal data.
7. Storage & security
Your data is stored on infrastructure provided by our hosting partners with encryption in transit (TLS) and at rest. Access to personal data inside Desby is limited to personnel who need it to run the Services, under confidentiality obligations. Passwords are stored only as modern salted hashes, and sensitive session tokens are protected. No system is perfectly secure; if a breach affecting your data occurs, we will notify you and the Nigeria Data Protection Commission as required by law.
8. Retention
We keep personal data for as long as your account is active, or as needed to provide the Services. If you delete your account, we delete or anonymise your personal data within 90 days, except where we must retain it for legal, accounting or dispute-resolution purposes (for example, transaction records required by tax rules). Measurement ledgers a tailor holds about their clients are controlled by that tailor; deleting your Desby account does not automatically delete records a tailor separately maintains.
9. Your rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your data (“right to erasure”).
- Object to or restrict certain processing, and withdraw consent at any time.
- Data portability — receive your data in a structured, commonly used format.
- Lodge a complaint with the Nigeria Data Protection Commission (NDPC).
To exercise any right, use in-app Settings or email privacy@desby.app. We respond within 30 days.
10. Children
The Services are not directed at children under 13, and apprentices under 18 may only use the Services with the involvement and consent of a parent or guardian and their apprenticeship master. If we learn we have collected data from a child without proper consent, we will delete it.
11. International transfers
Our hosting and service providers may process data outside Nigeria. Where that happens, we rely on appropriate safeguards — such as the provider’s security certifications and contractual data protection commitments — to protect your data to a standard consistent with this policy and the NDPA.
12. Cookies
We use a small number of cookies and similar storage: strictly necessary storage to keep you signed in (session tokens), and optional analytics to understand how the Services are used. We do not use third-party advertising cookies. You can clear or block storage in your browser settings; blocking strictly necessary storage may prevent sign-in from working.
13. Changes to this policy
We may update this policy as the Services evolve. Material changes will be announced in-app or by email at least 7 days before they take effect. The “Last updated” date above always shows the current version.