We use cookies

Cookies help this site function, measure usage, and support marketing. anytime. Learn more about our cookie policy.

These documents are provisional while our legal counsel finalises them. This translation is provided for your convenience. In case of any discrepancy in interpretation, the French version prevails.

COOKIES

Consent Mode v2 . GDPR + Swiss FADP

Cookie policy

The complete inventory of cookies and browser storage Galerly uses, what each one is for, how long it lives, and how to change your mind at any time.

Last updated May 2026. Questions? Reach us through the contact form.

For a translation question, reach us through the contact form.

Privacy policyLegal notice
01

What cookies are

A cookie is a small piece of text that a website stores in your browser. Each time you come back to the same site, your browser sends the cookie back so the site can remember things about you, like the fact you are signed in or the language you picked.

Modern browsers also expose two related stores that are not, strictly speaking, cookies, but behave similarly: localStorage (persists across tabs and sessions until cleared) and sessionStorage (cleared when you close the tab). Some of what Galerly stores in your browser sits in those two stores rather than in cookies, and we treat them all under the same rules in this policy.

Galerly is a Swiss company. We follow the Swiss Federal Act on Data Protection (revFADP), the EU General Data Protection Regulation (GDPR), and the EU ePrivacy Directive's cookie rules. In practice that means: anything that is not strictly necessary for the service to work is off by default until you choose to turn it on.

02

Categories we use

Essential

Always on

These are required for the platform to function. They keep you signed in, remember your cookie choices, and let photographer-operated surfaces (galleries, portfolio pages) attribute interaction events to the right photographer's dashboard. They are exempt from prior consent under ePrivacy Article 5(3) and the revFADP because they are strictly necessary to deliver a service you have explicitly requested.

  • cookie_consent (localStorage, 12 months) - your cookie-banner choices, so we do not nag you on every visit.
  • galerly_session (cookie, 7 days) - HttpOnly authentication cookie. Set on login, cleared on logout. Without this you cannot reach your dashboard.
  • galerly_sid (sessionStorage, tab session) - short-lived session identifier used to deduplicate interaction events inside one tab.
  • galerly_journey (localStorage, up to 30 days) - the Galerly pages you visited before creating an account. Sent when you submit the registration form, then counted per page with nothing attached that identifies you or your account, and cleared from your device. We keep no record linking a person to the pages they read.
  • galerly_vid (localStorage, persistent until cleared) - anonymous visitor identifier on photographer-operated client galleries and portfolio pages. The photographer is the data controller for that surface; Galerly is the processor. Disclosure is rendered inline on each gallery surface.
  • galerly_viewer_id (sessionStorage, tab session) - live-presence identifier so a photographer can see who is actively viewing their gallery in real time.

Analytics

Always active

Analytics cookies help us understand how visitors find and use Galerly's public marketing pages so we can improve them. They are part of the strictly necessary category and run on every visit. The provider is Google (gtag.js, Google Analytics 4 property G-NGQF46QXD5).

Google processes this data on infrastructure that may include the United States. The legal basis for that transfer is the EU-US Data Privacy Framework, with Standard Contractual Clauses as a fallback for any data that touches a region outside the framework (Schrems II compliance).

  • _ga (cookie, 2 years) - distinguishes unique visitors.
  • _ga_NGQF46QXD5 (cookie, 2 years) - GA4 session state, paired with the property ID.
  • _gid (cookie, 24 hours) - legacy daily-visitor identifier.
  • _gat (cookie, 1 minute) - request-rate throttle.
  • _gcl_au (cookie, 90 days) - emitted by gtag.js for conversion linking.

Marketing

Not in use

We do not currently use any marketing, advertising, retargeting, or session-replay cookies. The category exists in the cookie banner so the consent state can be honoured if and when we ever add a specific tool. Should that change, account holders will be notified at least 30 days in advance, this policy will be updated to list each new cookie before it is ever set, and the consent banner will re-prompt every visitor for a fresh choice.

03

Per-cookie inventory

The full table of every cookie and storage entry Galerly can set in your browser, with provider, purpose, retention, and the consent category it belongs to.

NameTypeProviderPurposeRetentionCategory
cookie_consentlocalStorageGalerlyStores your cookie-banner choices (analytics on/off, marketing on/off) so the banner does not re-prompt on every visit.12 months, then re-promptEssential
galerly_sessionCookieGalerlyKeeps you signed in to your photographer or client dashboard. HttpOnly, Secure, SameSite=Lax.7 daysEssential
galerly_sidsessionStorageGalerlyShort-lived session identifier used inside gallery and portfolio surfaces to deduplicate interaction events. Cleared when you close the tab.Tab session onlyEssential
galerly_vidlocalStorageGalerlyAnonymous visitor identifier on photographer-operated gallery and portfolio surfaces. Used only on client galleries to give the photographer engagement statistics on their own delivered work.Persistent until you clear browser storageEssential
galerly_journeylocalStorageGalerlyThe Galerly pages you visited before creating an account, kept on your own device so we can count which pages lead people to sign up. It is sent to us when you submit the registration form, and only counted per page, with nothing attached that identifies you or your account. Cleared as soon as your account is created.Up to 30 days, or until your account is createdAnalytics
galerly_viewer_idsessionStorageGalerlyLive-presence identifier so a photographer can see who is currently viewing their gallery. Cleared when you close the tab.Tab session onlyEssential
_gaCookieGoogleDistinguishes unique visitors for Google Analytics 4 (property G-NGQF46QXD5).2 yearsAnalytics
_ga_NGQF46QXD5CookieGoogleGA4 session-state cookie, paired with the property ID. Holds session counter and session-start timestamp.2 yearsAnalytics
_gidCookieGoogleDistinguishes unique visitors over a 24-hour window. Legacy GA identifier still emitted by gtag.js.24 hoursAnalytics
_gatCookieGoogleThrottles Google Analytics request rate so we do not flood the endpoint when you load many pages quickly.1 minuteAnalytics
_gcl_auCookieGoogleUsed by Google for conversion linking and to store and track conversions. Emitted by gtag.js even when no ad campaigns are running.90 daysAnalytics
galerly_user_datalocalStorageGalerlySigned-in account state. Required to keep you signed in across page reloads on app routes.Until you sign outEssential
galerly_langlocalStorageGalerlyRemembers your chosen interface language (English / French / German) so the right translation loads on every page.1 yearEssential
guest_email / guest_namelocalStorageGalerlyRemembers a gallery viewer's name + email when they leave a comment or send feedback, so they don't have to re-type it on later visits to the same gallery.12 monthsEssential
galerly_visited_{gallery_id}localStorageGalerlyCounter that distinguishes a gallery's first-visit from a return visit (one key per gallery). Drives the photographer's "return-visitor" engagement metric.12 monthsEssential
galerly_connect_banner_dismissed_atlocalStorageGalerlyRemembers that you dismissed the "Connect your Stripe account" banner so we don't re-show it on every login.90 daysEssential
tour_completed_{tour_id}localStorageGalerlyTracks which in-product onboarding tours you've already finished so we don't replay them.IndefiniteEssential
video_quality_preferencelocalStorageGalerlyRemembers your video playback quality preference (auto / 720p / 1080p) across sessions.IndefiniteEssential
last_seen_changelog_versionlocalStorageGalerlyTracks the changelog version you've already viewed, so the "What's new" dot only lights up after a new release.IndefiniteEssential
gallery_password_verifiedsessionStorageGalerlyPer-tab token issued by Galerly after you enter a password-protected gallery's password, so you don't re-enter the password on every action in that tab.Until tab closesEssential
05

Your choices

The consent banner appears on your first visit. Each category has its own toggle, and the Reject Non-Essential button is rendered in the exact same size and prominence as Accept All - in line with the French CNIL's binding 2022 guidance.

Your choice is stored for 12 months. After that we re-prompt, because GDPR considers stale consent invalid.

To change your mind at any time, click the Cookie settings link in the footer (or use the button at the top of this page). The banner re-opens in detail-view mode with your current preferences pre-loaded so you can adjust each category and save.

If your browser sends a Global Privacy Control signal or a legacy Do Not Track header, Galerly treats that as an automatic rejection of non-essential cookies and skips the banner. You can still open Cookie settings from the footer to opt in if you change your mind.

06

Browser-level controls

You can also clear or block cookies directly in your browser. Quick paths:

  • .Chrome - Settings -> Privacy and security -> Cookies and other site data -> See all site data and permissions.
  • .Safari - Settings -> Privacy -> Manage Website Data.
  • .Firefox - Settings -> Privacy & Security -> Cookies and Site Data -> Manage Data.
  • .Edge - Settings -> Cookies and site permissions -> Manage and delete cookies and site data.

Blocking essential cookies will break sign-in and gallery delivery. Blocking analytics cookies has no effect on functionality.

07

Third-party processors

Only two third parties can set cookies through galerly.com:

  • Google LLC / Google Ireland Ltd - sets the GA4 cookies listed above when, and only when, you have accepted the Analytics category. Subject to a Data Processing Addendum and the EU-US Data Privacy Framework. See Google's policy at policies.google.com/privacy.
  • Cloudflare, Inc. - operates Galerly's CDN, edge TLS, and the Pages frontend host. Cloudflare may set a strictly necessary cookie named __cf_bm for bot management at the edge. It is a session-lifetime cookie scoped to Cloudflare's infrastructure, contains no cross-site identifier, and is exempt from consent under ePrivacy as a security cookie. See Cloudflare's policy at cloudflare.com/privacypolicy.

The full list of Galerly subprocessors (storage, billing, transactional email, error monitoring, etc.) is in the Privacy policy - the entries here are limited to the ones that can write cookies or storage in your browser from Galerly's domains.

08

Contact and updates

We will update this page whenever we add, remove, or change a cookie. Material changes (a new third-party processor, a new category becoming active, a change in retention) are announced at least 30 days before they take effect, by email to account holders and via a notice on the homepage. Once a material change goes live, the cookie banner re-prompts every visitor for a fresh choice.

Cookie or privacy questions?

Use our contact form and select “Privacy / GDPR” as the topic — submissions categorised as privacy requests are routed to our data protection officer.

For data-access, export, or deletion requests under revFADP / GDPR, see the Privacy policy.

Jurisdiction: Swiss law governs this Cookie policy. Disputes are subject to Swiss courts jurisdiction.

Last updated: May 2026

For the broader data-handling story, the privacy policy and legal notice are alongside this page.