ArtStandards
GDPR (EU) 2016/679 & CCPA compliant · Updated: April 2026
The data controller is ArtStandards LLC, a Delaware limited liability company (USA). DPO contact: privacy@artstandards.org
| Category | Data | Legal basis |
|---|---|---|
| Artist account | Name, email, photo, legal information | Contract |
| Transactions | Buyer name, email, address, amount, currency | Contract |
| Artworks | Title, medium, dimensions, HD photos, SHA-256 fingerprint | Contract |
| Payments | Stripe token (no card data stored) | Contract |
| Navigation | Technical logs, anonymised IP, session cookies | Legitimate interest |
| Social media | OAuth tokens (Instagram, LinkedIn, TikTok, Facebook) | Consent |
| Blockchain | Ethereum/Polygon wallet (optional), transaction hash | Consent |
| Sub-processor | Role | Location |
|---|---|---|
| Stripe | Online payments | USA (DPA, SCCs) |
| Neon.tech | PostgreSQL database | EU (Frankfurt) |
| Upstash | Redis cache | EU |
| Cloudflare R2 | File storage | Global (edge) |
| Resend | Transactional emails | USA (DPA) |
| Mistral AI | AI text generation | France (EU) |
| Vercel | Hosting | USA (DPA, SCCs) |
| Prodigi | Fine art printing | UK / EU |
| Pinata | IPFS storage | USA (DPA) |
All transfers outside the EU/EEA are governed by Standard Contractual Clauses (SCCs) in compliance with GDPR.
Under GDPR, EU/EEA residents have the following rights:
To exercise your rights: privacy@artstandards.org. You may also lodge a complaint with your national supervisory authority (CNIL in France, ICO in the UK, etc.).
California residents have the following rights under the California Consumer Privacy Act (CCPA):
To exercise your CCPA rights: privacy@artstandards.org
The Platform uses only strictly necessary cookies:
No advertising or third-party tracking cookies. No data is sold to third parties.
Data is encrypted in transit (TLS 1.3) and at rest. Passwords are not stored — authentication via OAuth only. API keys are stored in secure environment variables, never exposed client-side.