These documents are provisional while our legal counsel finalises them. This translation is provided for your convenience. In case of any discrepancy in interpretation, the French version prevails.
COOKIES
Consent Mode v2 . GDPR + Swiss FADP
Cookie policy
The complete inventory of cookies and browser storage Galerly uses, what each one is for, how long it lives, and how to change your mind at any time.
Last updated May 2026. Questions? Reach us through the contact form.
For a translation question, reach us through the contact form.
COOKIE POLICY
Each cookie and storage entry we set, organised by purpose and retention.
Categories we use
Essential
Always onThese are required for the platform to function. They keep you signed in, remember your cookie choices, and let photographer-operated surfaces (galleries, portfolio pages) attribute interaction events to the right photographer's dashboard. They are exempt from prior consent under ePrivacy Article 5(3) and the revFADP because they are strictly necessary to deliver a service you have explicitly requested.
- cookie_consent (localStorage, 12 months) - your cookie-banner choices, so we do not nag you on every visit.
- galerly_session (cookie, 7 days) - HttpOnly authentication cookie. Set on login, cleared on logout. Without this you cannot reach your dashboard.
- galerly_sid (sessionStorage, tab session) - short-lived session identifier used to deduplicate interaction events inside one tab.
- galerly_journey (localStorage, up to 30 days) - the Galerly pages you visited before creating an account. Sent when you submit the registration form, then counted per page with nothing attached that identifies you or your account, and cleared from your device. We keep no record linking a person to the pages they read.
- galerly_vid (localStorage, persistent until cleared) - anonymous visitor identifier on photographer-operated client galleries and portfolio pages. The photographer is the data controller for that surface; Galerly is the processor. Disclosure is rendered inline on each gallery surface.
- galerly_viewer_id (sessionStorage, tab session) - live-presence identifier so a photographer can see who is actively viewing their gallery in real time.
Analytics
Always activeAnalytics cookies help us understand how visitors find and use Galerly's public marketing pages so we can improve them. They are part of the strictly necessary category and run on every visit. The provider is Google (gtag.js, Google Analytics 4 property G-NGQF46QXD5).
Google processes this data on infrastructure that may include the United States. The legal basis for that transfer is the EU-US Data Privacy Framework, with Standard Contractual Clauses as a fallback for any data that touches a region outside the framework (Schrems II compliance).
- _ga (cookie, 2 years) - distinguishes unique visitors.
- _ga_NGQF46QXD5 (cookie, 2 years) - GA4 session state, paired with the property ID.
- _gid (cookie, 24 hours) - legacy daily-visitor identifier.
- _gat (cookie, 1 minute) - request-rate throttle.
- _gcl_au (cookie, 90 days) - emitted by gtag.js for conversion linking.
Marketing
Not in useWe do not currently use any marketing, advertising, retargeting, or session-replay cookies. The category exists in the cookie banner so the consent state can be honoured if and when we ever add a specific tool. Should that change, account holders will be notified at least 30 days in advance, this policy will be updated to list each new cookie before it is ever set, and the consent banner will re-prompt every visitor for a fresh choice.
Per-cookie inventory
The full table of every cookie and storage entry Galerly can set in your browser, with provider, purpose, retention, and the consent category it belongs to.
| Name | Type | Provider | Purpose | Retention | Category |
|---|---|---|---|---|---|
| cookie_consent | localStorage | Galerly | Stores your cookie-banner choices (analytics on/off, marketing on/off) so the banner does not re-prompt on every visit. | 12 months, then re-prompt | Essential |
| galerly_session | Cookie | Galerly | Keeps you signed in to your photographer or client dashboard. HttpOnly, Secure, SameSite=Lax. | 7 days | Essential |
| galerly_sid | sessionStorage | Galerly | Short-lived session identifier used inside gallery and portfolio surfaces to deduplicate interaction events. Cleared when you close the tab. | Tab session only | Essential |
| galerly_vid | localStorage | Galerly | Anonymous visitor identifier on photographer-operated gallery and portfolio surfaces. Used only on client galleries to give the photographer engagement statistics on their own delivered work. | Persistent until you clear browser storage | Essential |
| galerly_journey | localStorage | Galerly | The Galerly pages you visited before creating an account, kept on your own device so we can count which pages lead people to sign up. It is sent to us when you submit the registration form, and only counted per page, with nothing attached that identifies you or your account. Cleared as soon as your account is created. | Up to 30 days, or until your account is created | Analytics |
| galerly_viewer_id | sessionStorage | Galerly | Live-presence identifier so a photographer can see who is currently viewing their gallery. Cleared when you close the tab. | Tab session only | Essential |
| _ga | Cookie | Distinguishes unique visitors for Google Analytics 4 (property G-NGQF46QXD5). | 2 years | Analytics | |
| _ga_NGQF46QXD5 | Cookie | GA4 session-state cookie, paired with the property ID. Holds session counter and session-start timestamp. | 2 years | Analytics | |
| _gid | Cookie | Distinguishes unique visitors over a 24-hour window. Legacy GA identifier still emitted by gtag.js. | 24 hours | Analytics | |
| _gat | Cookie | Throttles Google Analytics request rate so we do not flood the endpoint when you load many pages quickly. | 1 minute | Analytics | |
| _gcl_au | Cookie | Used by Google for conversion linking and to store and track conversions. Emitted by gtag.js even when no ad campaigns are running. | 90 days | Analytics | |
| galerly_user_data | localStorage | Galerly | Signed-in account state. Required to keep you signed in across page reloads on app routes. | Until you sign out | Essential |
| galerly_lang | localStorage | Galerly | Remembers your chosen interface language (English / French / German) so the right translation loads on every page. | 1 year | Essential |
| guest_email / guest_name | localStorage | Galerly | Remembers a gallery viewer's name + email when they leave a comment or send feedback, so they don't have to re-type it on later visits to the same gallery. | 12 months | Essential |
| galerly_visited_{gallery_id} | localStorage | Galerly | Counter that distinguishes a gallery's first-visit from a return visit (one key per gallery). Drives the photographer's "return-visitor" engagement metric. | 12 months | Essential |
| galerly_connect_banner_dismissed_at | localStorage | Galerly | Remembers that you dismissed the "Connect your Stripe account" banner so we don't re-show it on every login. | 90 days | Essential |
| tour_completed_{tour_id} | localStorage | Galerly | Tracks which in-product onboarding tours you've already finished so we don't replay them. | Indefinite | Essential |
| video_quality_preference | localStorage | Galerly | Remembers your video playback quality preference (auto / 720p / 1080p) across sessions. | Indefinite | Essential |
| last_seen_changelog_version | localStorage | Galerly | Tracks the changelog version you've already viewed, so the "What's new" dot only lights up after a new release. | Indefinite | Essential |
| gallery_password_verified | sessionStorage | Galerly | Per-tab token issued by Galerly after you enter a password-protected gallery's password, so you don't re-enter the password on every action in that tab. | Until tab closes | Essential |
Google Consent Mode v2
Before any third-party script loads on Galerly, our HTML calls gtag('consent', 'default', ...) with every non-essential category set to 'denied'. That is the Google-documented Consent Mode v2 fallback for GDPR jurisdictions.
What that means in practice:
- .Until you click Accept, gtag.js sends only cookie-less, anonymised pings. No
_gais set, no identifier ships, and Google models traffic from these pings without per-user data. - .If you accept analytics, the next page view fires a normal gtag event with full cookies.
- .If you later change your mind and reject analytics, Galerly also sweeps the
_ga/_gid/_gat/_gcl_aucookies from your browser. Consent Mode v2 alone stops the next hit but leaves existing 2-year cookies in place; we wipe them on the same call so the device is actually clean.
Galerly's Google Analytics property is configured with IP-address truncation, no Google Signals, no demographic enrichment, and no advertising features. The data we receive is aggregate page-view counts and high-level traffic source breakdowns - not individual identification.
Your choices
The consent banner appears on your first visit. Each category has its own toggle, and the Reject Non-Essential button is rendered in the exact same size and prominence as Accept All - in line with the French CNIL's binding 2022 guidance.
Your choice is stored for 12 months. After that we re-prompt, because GDPR considers stale consent invalid.
To change your mind at any time, click the Cookie settings link in the footer (or use the button at the top of this page). The banner re-opens in detail-view mode with your current preferences pre-loaded so you can adjust each category and save.
If your browser sends a Global Privacy Control signal or a legacy Do Not Track header, Galerly treats that as an automatic rejection of non-essential cookies and skips the banner. You can still open Cookie settings from the footer to opt in if you change your mind.
Browser-level controls
You can also clear or block cookies directly in your browser. Quick paths:
- .Chrome - Settings -> Privacy and security -> Cookies and other site data -> See all site data and permissions.
- .Safari - Settings -> Privacy -> Manage Website Data.
- .Firefox - Settings -> Privacy & Security -> Cookies and Site Data -> Manage Data.
- .Edge - Settings -> Cookies and site permissions -> Manage and delete cookies and site data.
Blocking essential cookies will break sign-in and gallery delivery. Blocking analytics cookies has no effect on functionality.
Third-party processors
Only two third parties can set cookies through galerly.com:
- Google LLC / Google Ireland Ltd - sets the GA4 cookies listed above when, and only when, you have accepted the Analytics category. Subject to a Data Processing Addendum and the EU-US Data Privacy Framework. See Google's policy at policies.google.com/privacy.
- Cloudflare, Inc. - operates Galerly's CDN, edge TLS, and the Pages frontend host. Cloudflare may set a strictly necessary cookie named
__cf_bmfor bot management at the edge. It is a session-lifetime cookie scoped to Cloudflare's infrastructure, contains no cross-site identifier, and is exempt from consent under ePrivacy as a security cookie. See Cloudflare's policy at cloudflare.com/privacypolicy.
The full list of Galerly subprocessors (storage, billing, transactional email, error monitoring, etc.) is in the Privacy policy - the entries here are limited to the ones that can write cookies or storage in your browser from Galerly's domains.
Contact and updates
We will update this page whenever we add, remove, or change a cookie. Material changes (a new third-party processor, a new category becoming active, a change in retention) are announced at least 30 days before they take effect, by email to account holders and via a notice on the homepage. Once a material change goes live, the cookie banner re-prompts every visitor for a fresh choice.
Cookie or privacy questions?
Use our contact form and select “Privacy / GDPR” as the topic — submissions categorised as privacy requests are routed to our data protection officer.
For data-access, export, or deletion requests under revFADP / GDPR, see the Privacy policy.
Jurisdiction: Swiss law governs this Cookie policy. Disputes are subject to Swiss courts jurisdiction.
Last updated: May 2026
For the broader data-handling story, the privacy policy and legal notice are alongside this page.