Your photo stays private by design.
This notice explains what ClassicPetArt collects, why it is used, which service providers receive it, how long it is kept, and the controls available to you.
1. Information we process
We process the photo you choose, a normalized copy with metadata removed, optional pet name, generated preview and master, artwork and generation identifiers, model and prompt version, account email and profile name, authentication records, Portrait Credit activity, and technical security information such as timestamps, request limits, and error categories. We also receive page and conversion measurements such as route, referrer, campaign tags, device category, approximate country, selected portrait style, and funnel stage.
For an order we also process product choice, price, payment and fulfilment status, email, and—only for a physical item—recipient name and delivery address. We do not receive or store full card details; Stripe handles payment information.
2. Why we use it
We use this information to provide the requested preview and account, perform a purchase and delivery, calculate shipping, issue secure downloads, manage credits, answer support requests, prevent abuse, investigate failures, keep accounting records, and comply with legal obligations.
The intended legal bases are performance of a contract or steps you request before a contract, legitimate interests in securing and operating the service, and compliance with legal obligations. Consent is used only where the law specifically requires it.
3. Portrait generation and private storage
The server verifies the upload, fixes orientation, removes embedded metadata such as GPS information, and re-encodes it before sending the normalized image and portrait instructions to Google’s Gemini API. The Gemini credential stays server-side. Google applies SynthID to model-generated images.
Sources, watermarked previews, unwatermarked masters, and production files are stored in separate private Supabase buckets. The free-preview page receives only an access-controlled watermarked derivative, not a public URL for the unwatermarked master.
4. Service providers and disclosures
Vercel hosts the application and provides aggregated, cookieless Web Analytics; Supabase provides authentication, database, and private storage; Google provides Gemini image generation and, only after analytics consent, Google Analytics; Stripe provides payment tooling; Resend sends transactional email; Printful will provide production and delivery only after physical fulfilment is enabled.
Each provider receives only information needed for its role. We may also disclose information where legally required, to protect customers and the service, or as part of a properly managed business transfer. We do not sell customer photos or use them for third-party advertising.
5. International transfers
Some providers or their subprocessors may process information outside Sweden or the European Economic Area. ClassicPetArt relies on the transfer mechanisms and safeguards applicable to the selected provider services, including adequacy decisions or standard contractual clauses where required.
We will not claim that providers never retain data or never use it for model improvement until the selected product terms, account settings, contracts, and deletion procedures support that statement.
6. Retention
Unpaid anonymous creation sessions and their source, preview, and master assets expire after seven days. Signed-in gallery artwork is retained until you delete or archive it, request account deletion, or a documented legal or security reason requires limited continued retention. Expiring download links last seven days and can be replaced after order access is verified.
Paid transaction, tax, consent, and order records are separated from optional gallery content and may need to be retained for up to seven years or another period required by applicable accounting, tax, consumer, or dispute law. Data no longer required is deleted or anonymised.
7. Your choices and rights
Signed-in customers can export account, gallery, order, and Portrait Credit data; archive or delete unpurchased portraits; renew eligible paid download links; and request account deletion. Contact hello@classicpetart.com to request access, correction, deletion, restriction, portability, or objection, or to withdraw consent where processing is based on consent.
A request may require identity verification. Some information cannot be deleted immediately when retention is legally required, but it will be restricted to that purpose. You may complain to the competent data-protection authority; in Sweden this is Integritetsskyddsmyndigheten (IMY).
8. Cookies and security
ClassicPetArt uses necessary cookies or equivalent browser storage for authentication, private creation ownership, request recovery, and security. Vercel Web Analytics measures aggregated traffic and conversion events without third-party cookies or persistent cross-site identifiers. During a visit, we may keep short, sanitized campaign labels such as source, campaign, and ad content in session storage and attach them to aggregated funnel events; click identifiers and customer details are not included. Optional Google Analytics remains off unless you select Allow analytics. If allowed, Google may set _ga cookies and process page, referrer, campaign, device, approximate-location, and funnel-event data. Advertising storage, Google Signals, and ads personalization remain disabled. You can decline initially or change your choice at any time through Cookie choices in the footer.
Account and callback pages are excluded from analytics, private portrait routes are normalized, and analytics events do not include names, email addresses, artwork or order identifiers, payment-session values, photo URLs, or uploaded content. Declining optional analytics does not limit the shop.
Controls include server-side secrets, private storage, short-lived signed access, hashed bearer download tokens, origin checks, rate limits, verified webhooks, metadata stripping, access checks, and scheduled retention. No online service can promise absolute security; suspected incidents are investigated under the incident runbook.
9. Contact and changes
Privacy questions and requests can be sent to hello@classicpetart.com. Material changes will be dated and, where required, communicated before they take effect.
Privacy notice · Google Analytics update 15 July 2026
