Legal

Privacy Policy

Effective August 14, 2026

Galerin does not sell personal data. We collect what is needed to run an art platform: accounts, orders, commissions, and a discovery feed. Nothing we collect is designed to follow you around the internet. This policy explains exactly what that means.

1

Who is responsible for your data

The data controller is Galerin Limited Liability Company, 5900 Balcones Drive, STE 100, Austin, TX, 78731, US. For any privacy question or to exercise your rights, write to [email protected].

2

What we collect

You provide it

  • Account and profile — email address, handle, display name, avatar, bio, and role (artist, collector, or both). If you sign in with Google, we receive your email and basic profile from them; we never see your password.
  • Artwork and content — images you upload, titles, descriptions, tags, commission briefs, open-call entries, and messages in commission threads.
  • Orders and commissions — what you bought or commissioned, prices, and the shipping name and address you enter for physical delivery.
  • Reports — anything you tell us when you report content or contact support.
  • Launch notifications and enquiries — if you ask to be told when Wall-Space or Art Opens goes live, we keep the email address and name you give us, whether you told us you are an artist or a collector, and which page you signed up from. We use it to write to you when that feature launches, and nothing else. The gallery itself needs no invitation: you can browse it, and buy a print, without an account or an email address.

Generated by use

  • Activity events — views, saves, commission requests, and drop interest, tied to your account. These power your saved collection and, if you are signed in, personalise the discovery feed toward mediums and tags you have saved.
  • Technical data — IP address, browser type, and logs kept for security, rate-limiting, and debugging. Rate limiting records a short-lived counter against your IP address so a single source cannot flood sign-in, upload, or checkout endpoints.
  • Aggregate usage measurement — page views and page loading performance, collected without cookies and without building a profile of you, by two providers: Vercel (Web Analytics and Speed Insights) and Cloudflare (Web Analytics). We use it to see which pages are used and which are slow, not to identify you.
  • Network error reports — when your browser fails to reach the site, it reports the failed request to Cloudflare so we can see outages we would otherwise never hear about. Only failures are reported, never successful visits.
  • Invite attribution— if you arrive through an artist’s invite link, the invite code and a random visitor identifier (see Section 8), so we can credit the artist who brought you and show them how many clicks became signups. Artists see counts, never who you are.
  • Content-integrity signals — automated analysis of uploaded images (resolution, colour profile, and indicators of AI generation) used to enforce print quality and the human-made policy.

From payment processing

Payments are handled by Stripe. We never receive or store your full card number.We receive transaction outcomes and limited metadata (amounts, last four digits, payout status). Artists who enable payouts provide identity and bank details directly to Stripe under Stripe’s own privacy policy; Galerin sees verification status, not the underlying documents.

3

Why we use it, and the legal bases

  • Running the platform (accounts, galleries, orders, commissions, escrow, payouts, transactional email such as order confirmations) — necessary to perform our contract with you.
  • Personalising discovery for signed-in users based on your saves — our legitimate interest in showing you relevant art; signed-out visitors see a non-personalised feed, and you can influence yours simply by what you save.
  • Safety and integrity (AI-generation detection, anti-fraud, rate-limiting, moderation, vote integrity in open calls) — our legitimate interest in keeping the platform honest.
  • Measuring and improving the site (aggregate page views and loading performance, crediting artist invites) — our legitimate interest in knowing what works and in giving artists honest numbers on the invites they share.
  • Telling you when a feature launches if you asked to be notified about Wall-Space or Art Opens — your consent, given when you submitted the form, which you can withdraw at any time by replying to any message or writing to [email protected].
  • Legal compliance (tax, accounting, responding to lawful requests) — legal obligation.
  • Anything we would ever do beyond these purposes would be based on your consent, which you could withdraw at any time.
4

Who we share it with

We do not sell personal data and we do not share it with advertisers or data brokers. We share it only with the processors and parties needed to deliver the service:

  • Stripe (payments and artist payouts) — receives transaction data and, for artists, onboarding identity data it collects itself.
  • Artelo(print production and shipping) — receives the artwork file to print and your recipient name, shipping address, and order details. Artelo’s carriers receive what is needed to deliver.
  • Supabase (our infrastructure provider) — hosts our database, authentication, and file storage.
  • Vercel(hosting and delivery) — serves the site and processes request metadata such as your IP address and browser. We also run Vercel’s Web Analytics and Speed Insights, which measure page views and loading performance in aggregate. They set no cookies, do not use device fingerprinting, and do not build a profile of you or follow you to other sites.
  • Cloudflare(network, image storage, and delivery) — sits in front of the whole site, so every request you make reaches us through Cloudflare and it processes the request metadata (including your IP address and browser) needed to route, cache, and protect it. It also stores and serves artwork images and other static assets, runs Web Analytics on the same cookieless, no-profile basis as Vercel’s, and receives the network error reports described in Section 2.
  • Resend (email delivery) — sends sign-in links, sign-in codes, and transactional email to your address. We may use Amazon SES as an alternate provider for the same purpose.
  • Other users, to the minimum degree the product requires — your public profile and published works are visible to everyone; commission threads are visible to the two parties involved; artists see the details of commissions addressed to them but collectors’ shipping addresses for prints go to Artelo, not to the artist.
  • Authorities or successors— where the law requires it, or as part of a merger or acquisition under this policy’s protections.
5

International transfers

Our infrastructure and processors may store or process data in the United States and other countries outside the EEA/UK. Where data of EEA or UK residents is transferred to such countries, we rely on adequacy decisions (including the EU–US Data Privacy Framework where the recipient is certified) or the European Commission’s Standard Contractual Clauses, alongside each processor’s own safeguards.

6

How long we keep it

  • Account and profile data — for as long as your account exists, then deleted or anonymised within 30 days of account closure.
  • Published artwork — until you remove it or close your account, except copies needed to complete orders already in production.
  • Order, commission, escrow, and payout records — retained for the period required by tax and accounting law (typically 6–10 years depending on jurisdiction), even after account closure.
  • Commission message threads — retained while either party keeps an account, as they document the agreed scope of a paid contract; retained with the transaction record thereafter.
  • Security logs and rate-limit data — short rolling windows, typically 90 days or less; rate-limit counters expire within minutes.
  • Launch notification entries — until you ask us to remove you, or until the feature you asked about has launched and we have written to tell you.
  • Invite attribution — the cookies expire after 30 days; once a signup is credited, only the link between the artist and the account they referred is kept.
  • Aggregate usage measurement and network error reports — retained by our analytics providers in aggregate form and not linked to your account.
  • Moderation and strike records — for as long as needed to enforce our policies, including preventing banned users from returning.
7

Your rights

Everyone can access, correct, or delete their data through their account or by writing to [email protected]. If you are in the EEA or UK, you additionally have the rights under the GDPR to:

  • access a copy of your personal data (portability in a machine-readable format where processing is based on contract or consent);
  • rectify inaccurate data and erase data we no longer have grounds to keep;
  • restrict or object to processing based on legitimate interests, including the discovery-feed personalisation described above;
  • withdraw any consent at any time, without affecting prior processing;
  • complain to your local supervisory authority.

We respond within one month. We do not use automated decision-making that produces legal or similarly significant effects; content moderation signals (including AI-generation detection) are reviewed by a human before an account is suspended.

8

Cookies

Galerin sets first-party cookies only, and only these:

  • Session — keeps you signed in. Strictly necessary.
  • Entry gate — a signed cookie recording that you entered a site access password. Galerin is open to the public and this cookie is not currently set; it is listed because the same gate is used if we ever put an unreleased build behind a password. Strictly necessary when it applies.
  • Invite attribution— if you arrive through an artist’s invite link, we store that invite code and a random visitor identifier for 30 days so the invite can be credited if you go on to sign up. The identifier is a random value tied to nothing else: it carries no IP address, no fingerprint, and no meaning outside Galerin.

There are no advertising, analytics, or cross-site tracking cookies and no third-party cookies at all, which is why you don’t see a cookie banner. Our analytics (see Section 4) are cookieless.

9

Security

Data is encrypted in transit, access to production data is restricted and role-based, payment credentials never touch our servers, and payout-affecting records are protected by database-level constraints and audit trails. No system is perfectly secure; if a breach affects your personal data we will notify you and the competent authority as the law requires.

10

Children

Galerin is not directed at children. You must be at least 16 to hold an account and 18 to transact. We delete accounts we discover to be under these ages.

11

Changes and contact

If we change this policy materially we will notify you by email or in-product notice before the change takes effect. Continued use after that date means the new policy applies. Privacy questions and rights requests: [email protected]. See also our Terms of Service.