ArtStandards

Privacy Policy

GDPR (EU) 2016/679 & CCPA compliant · Updated: April 2026

1. Data Controller

The data controller is ArtStandards LLC, a Delaware limited liability company (USA). DPO contact: privacy@artstandards.org

2. Data We Collect

CategoryDataLegal basis
Artist accountName, email, photo, legal informationContract
TransactionsBuyer name, email, address, amount, currencyContract
ArtworksTitle, medium, dimensions, HD photos, SHA-256 fingerprintContract
PaymentsStripe token (no card data stored)Contract
NavigationTechnical logs, anonymised IP, session cookiesLegitimate interest
Social mediaOAuth tokens (Instagram, LinkedIn, TikTok, Facebook)Consent
BlockchainEthereum/Polygon wallet (optional), transaction hashConsent

3. Purposes

  • Artist account management and commercial transactions
  • Legal document generation (invoices, license agreements, certificates)
  • Artwork authenticity certification (ArtStandard ID)
  • Transactional communication (sale confirmations, shipping)
  • Social media publishing (only on explicit request)
  • Platform improvement and fraud prevention
  • Compliance with legal obligations

4. Sub-processors & Transfers

Sub-processorRoleLocation
StripeOnline paymentsUSA (DPA, SCCs)
Neon.techPostgreSQL databaseEU (Frankfurt)
UpstashRedis cacheEU
Cloudflare R2File storageGlobal (edge)
ResendTransactional emailsUSA (DPA)
Mistral AIAI text generationFrance (EU)
VercelHostingUSA (DPA, SCCs)
ProdigiFine art printingUK / EU
PinataIPFS storageUSA (DPA)

All transfers outside the EU/EEA are governed by Standard Contractual Clauses (SCCs) in compliance with GDPR.

5. Retention

  • Active account data: duration of subscription + 3 years
  • Transactions and invoices: 7 years (accounting obligations)
  • License agreements: duration of copyright protection
  • Authenticity certificates: unlimited (artwork provenance)
  • Session cookies: maximum 30 days
  • Social media OAuth tokens: until revoked by user

6. Your Rights (GDPR)

Under GDPR, EU/EEA residents have the following rights:

  • Right of access (Art. 15) — obtain a copy of your data
  • Right to rectification (Art. 16) — correct inaccurate data
  • Right to erasure (Art. 17) — deletion subject to legal obligations
  • Right to portability (Art. 20) — export your data as JSON/CSV
  • Right to object (Art. 21) — object to certain processing
  • Right to restriction (Art. 18) — temporarily restrict processing

To exercise your rights: privacy@artstandards.org. You may also lodge a complaint with your national supervisory authority (CNIL in France, ICO in the UK, etc.).

7. CCPA Rights (California, USA)

California residents have the following rights under the California Consumer Privacy Act (CCPA):

  • Right to know what personal information is collected about you
  • Right to request deletion of your personal information
  • Right to opt-out of the sale of personal information (ArtStandards does not sell data)
  • Right to non-discrimination for exercising these rights

To exercise your CCPA rights: privacy@artstandards.org

8. Cookies

The Platform uses only strictly necessary cookies:

  • next-auth.session-token authentication (httpOnly, secure, 30 days)
  • NEXT_LOCALE language preference (1 year)

No advertising or third-party tracking cookies. No data is sold to third parties.

9. Security

Data is encrypted in transit (TLS 1.3) and at rest. Passwords are not stored — authentication via OAuth only. API keys are stored in secure environment variables, never exposed client-side.

ArtStandards LLC · privacy@artstandards.org