Privacy

Last updated 4 September 2026

Ecrino is a workshop tool for jewellery studios, operated by Dounsky Group L.L.C-FZ of Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates. It holds a studio’s clients, stones, designs and offers, and it shows some of that to the client on a private link. This page says what is held, why, who else touches it, and how to make all of it go away.

Two kinds of people, two different roles

The studio. When a jeweller opens an account, Ecrino decides what to hold about them and is the controller of it.

The studio’s clients. Everything a studio files about their own customers — names, briefs, budgets, what a client said about a stone — belongs to the studio. Ecrino only holds it on their instructions, as their processor. If you are a client of a studio using Ecrino and you want your record changed or removed, ask the studio; they can do it themselves, and we will pass on any request that reaches us first.

What is held

About a studio account

  • Name and email address.
  • The password, stored only as a bcrypt hash. Nobody at Ecrino can read it and we cannot tell you what it is.
  • The studio’s brand: its name, accent colour and logo, which appear on client pages.
  • Notification preferences, and the role each colleague holds.
  • A device token for each phone signed in with notifications allowed, so Apple can deliver a push. It is deleted when the phone is signed out, when notifications are turned off, and the first time Apple reports the token dead.
  • A log of consequential changes inside the studio — who moved a price, who deleted a stone, who let a colleague in — visible to that studio only.

What a studio files

  • Customers: name, email, phone, and whatever notes the studio keeps.
  • Projects, stones, suppliers, designs, offers, and the photographs and film attached to them.

This is the studio’s working material. Ecrino does not read it, mine it, or use it to train anything.

About someone who opens a share link

A client needs no account and no password unless the studio sets a passcode. What is recorded is:

  • The name and email they type in, if they type one. It is optional, and it is what lets the studio tell one visitor from another.
  • Which stones and designs they opened, how many times, and how long the page was in front of them — because a designer needs to know which stone held someone’s attention.
  • Their reaction and comment on each stone or design.

Technical

  • A SHA-256 hash of the requesting IP address, kept to throttle sign-in, signup and passcode attempts. The address itself is never written down, and the hash is discarded once the window has passed.
  • Ordinary server logs at our hosting provider, which include IP addresses and are kept briefly for security and debugging.

Cookies

Four of our own, all first-party, all set by Ecrino itself, none of them for advertising. There are no trackers and no third-party tags inside a studio’s account or on a client page. The one third-party tag on this site is on the public pages, and has its own heading below.

  • Session — keeps a signed-in studio user signed in. It ends when they sign out or change their password.
  • Sign-in code — set only where two-factor authentication is on, between a correct password and the code that follows it. It lasts ten minutes, says nothing but which account is halfway through signing in, and is not a sign-in on its own.
  • Passcode unlock — remembers, for thirty days, that a passcode was entered correctly for one share link. Changing the passcode invalidates it.
  • Visitor — recognises a returning client on one studio’s links for a year, so that the same person answering on Monday and Friday reads as one client rather than two strangers. It is scoped to that one studio and says nothing about any other. Clearing it means the next visit starts fresh.

Measurement, on the public pages only

The marketing pages, these legal pages, and the sign-in and sign-up screens load Google Analytics, so that we can tell whether anybody reads them. It sets cookies of its own and reports the page that was opened, the campaign tag that brought somebody to it, and the ordinary things a browser gives away: approximate location, device and referring site.

It is loaded on those pages and nowhere else. Not on a share link, not on an offer, not on any page inside an account — and because signing in never reloads the page, the tag is also switched off by name the moment anybody leaves the public pages, rather than merely left unattended. It is never told a studio’s clients, stones, designs or prices, and the address of a share link is never reported: that address is the key to the link. Any browser setting or extension that blocks it works normally here.

Why we are allowed to hold it

  • To perform the contract with the studio: an account they asked for cannot run without their account details, and neither can the work they put in it.
  • Legitimate interests: keeping the service secure — the hashed address that stops somebody working through a list of passwords — and the studio’s own interest in knowing how their clients responded to what they sent.
  • Consent, where you gave it: push notifications, which iOS asks about separately and which you can withdraw in Settings on the phone or in Ecrino.

Who else touches it

As few as possible, and none of them is sold anything. Each is a processor under contract, and each is used for one job:

  • Vercel — hosting, and the private store the photographs and film live in. Media is never public: every image link is signed and expires after a quarter of an hour.
  • Our database host — the Postgres instance the records sit in.
  • Resend — the transactional email: an invitation, a password reset, a note that a client answered. No marketing email is sent through it or anywhere else.
  • Apple — push notifications, which reach a phone through Apple’s servers by design.
  • Google — Analytics on the public pages, as described under Cookies. It sees visits to those pages and nothing else: no share link, no offer, no page inside an account.
  • metals.dev — today’s gold and platinum price. It receives no personal data at all; it is asked what a gram costs.

Ecrino is run from the United Arab Emirates, and some of these providers operate elsewhere again. So when a studio in the European Economic Area or the United Kingdom files a client’s details here, that is a transfer out of it. Those transfers rest on the European Commission’s standard contractual clauses, which form part of our processing terms with the studio and are available on request.

Nothing here is sold, rented, or handed to advertisers. We would disclose data to an authority only where the law actually requires it.

How long it is kept

A studio’s data is kept for as long as the account is open, and goes when the account closes. The hashed rate-limit records last hours. Server logs at the hosting provider roll off on their schedule. Deleted records can survive briefly in encrypted backups before those expire.

Deleting it

You do not have to ask us, and there is no form to fill in. Either the app or the website will do it:

  • In the iPhone app — Studio, then Settings, then Delete my account at the bottom.
  • On the website — Settings, then Close your account at the bottom.

Both ask for your password again and then act immediately. What goes depends on whose account it is. An owner’s account is the studio’s: closing it deletes the whole atelier — every client, project, stone, design, offer, share link, colleague sign-in, and every photograph and film in the private store. A colleague’s account is a seat: closing it removes their sign-in and takes their name off what they added, and the studio’s work stays with the studio.

There is no undo, no archive, and no support ticket that puts a studio back. The full path is written out on the support page.

Your rights

If you are in the EEA or the UK you may ask for a copy of what we hold about you, have it corrected, have it deleted, ask us to restrict or stop a particular use, and receive it in a portable form. Write to support@ecrino.com and we will answer within a month.

If you think we have handled your data badly, you can complain to the data protection supervisory authority where you live — and, in the United Arab Emirates, to the UAE Data Office. We would rather you told us first: write to us and we will answer.

Children

Ecrino is a tool for a business and is not directed at children. Do not open an account if you are under 16.

Security

Passwords are hashed with bcrypt. Sign-in tokens carry a version that a password change increments, so changing it signs every other device out at once. Media is stored privately and served through links that expire. Each studio’s data is scoped to that studio at every query. No system is perfect; if you find a weakness, please write to us before you write about it.

Changes

If this page changes materially we will say so by email to account holders before the change takes effect. The date at the top always says when it last moved.

Contact

Ecrino is operated by Dounsky Group L.L.C-FZ.
Meydan Grandstand, 6th floor
Meydan Road, Nad Al Sheba
Dubai, United Arab Emirates
support@ecrino.com