Back to Home

Privacy Policy

Last updated: February 2026

1. What We Collect

  • Account data — if you sign in, we store your email and profile details via Firebase Authentication; guest checkout uses an anonymous session.
  • Images — photos you upload or artwork you generate, stored in Cloudinary.
  • Order data — shipping address, order details, and payment confirmation stored in Firestore.
  • Payment data — processed entirely by Stripe. We never see or store full card numbers.
  • Usage data — anonymous page-view and feature-usage analytics.

2. How We Use Your Data

  • Fulfil and deliver your print orders via Gelato's global print network.
  • Send order-status and shipping-tracking updates.
  • Improve print-quality checks and site reliability.
  • Respond to support requests.

3. Third-Party Services

We share the minimum data needed with each provider:

  • Firebase / Google Cloud — authentication and database.
  • Stripe — payment processing.
  • Gelato — print fulfillment and shipping.
  • Cloudinary — image storage and transformation.
  • OpenAI — creative-art image generation (prompts only, no personal data).

4. Data Retention

We retain account and order data for as long as your account is active, plus any period required by law. You may request deletion of your account and associated data at any time by contacting us.

5. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, or delete your personal data, or to object to or restrict certain processing. Contact us at the email below to exercise these rights.

6. Security

All connections use TLS encryption. Payments are handled by Stripe (PCI-DSS compliant). Firebase authentication tokens are short-lived and refreshed automatically. We perform rate limiting and input validation on all API endpoints.

7. Contact

For privacy-related questions, email [email protected].