We use cookies

Cookies help this site function, measure usage, and support marketing. anytime. Learn more about our cookie policy.

These documents are provisional while our legal counsel finalises them. This translation is provided for your convenience. In case of any discrepancy in interpretation, the French version prevails.

Privacy

Data Protection • GDPR Compliant

Your data, protected.

How we collect, use, and protect your personal information on Galerly.

Last updated December 2025. GDPR compliant. Questions? Reach us through the contact form.

For a translation question, reach us through the contact form.

01

Information We Collect

Account Information: When you register, we collect your email address and password. You may optionally provide profile information such as name, phone number, bio, location, website, and social media links.

Content You Upload: Photographs, gallery titles, descriptions, client information (names, emails), and file metadata.

Payment Information: Payment details are processed by Stripe. We do not store credit card numbers. We retain subscription status and transaction records.

Usage Information: We collect data about how you interact with Galerly, including pages visited, features used, and session information to improve our service.

Compliance Audit Records: When you exercise a data-protection right (e.g. requesting a data export, deletion, or rectification) we generate a pseudonymised audit record so we can demonstrate compliance with GDPR Article 12’s response-time obligation. These records contain your user identifier, the type and timestamp of the request, the outcome, and a salted hash of your IP address — never your raw email or raw IP. Retained for three years and then automatically deleted.

02

How We Use Your Information

We use your information to:

  • ·Provide and maintain gallery hosting services
  • ·Process payments and manage subscriptions
  • ·Send account notifications, password resets, and gallery updates
  • ·Improve platform usability and identify technical issues
  • ·Analyze usage patterns to improve features
  • ·Prevent fraud and ensure security

We send automated emails for account activities. You can manage notification preferences in your account settings.

03

Data Sharing & Third Parties

We do NOT sell your data. We share information only with:

  • ·Service Providers: Cloud hosting, email delivery, payment processing (Stripe), and analytics services that help us operate Galerly.
  • ·Legal Requirements: When required by law, court order, or to protect our rights.
  • ·Your Clients: Galleries you create are accessible to clients via links you generate or via email invitations. You control privacy settings for each gallery.

Third-party service providers are contractually obligated to protect your data and use it only for services they provide to us. The complete, up-to-date list of our subprocessors is maintained below — each is bound by a Data Processing Agreement, with Standard Contractual Clauses or an applicable adequacy decision for any transfer outside the EEA / Switzerland.

Current subprocessors

  • Amazon Web Services EMEA SARL — object storage, database, queue, video transcoding, transactional email. Processed in AWS eu-central-1 (Frankfurt, Germany).
  • Stripe Payments Europe Ltd — subscription billing, card processing (we never see full card numbers). Processed in Ireland; US fallback under the EU–US Data Privacy Framework.
  • Cloudflare, Inc. — CDN, DNS, edge TLS, static hosting (Pages), API proxy (Workers). Global anycast; EU-US DPF + SCCs in place.
  • Hetzner Online GmbH — primary compute. Processed in Germany (Nuremberg / Falkenstein).
  • Sentry (Functional Software, Inc.) — application error monitoring. Processed in the EU region; PII scrubbing applied.
  • GitHub, Inc. / Microsoft Corporation — source code hosting. US; adequacy via EU-US DPF.
  • Google LLC (Google Analytics 4 + Google Ads) : site analytics (measurement ID G-NGQF46QXD5) and conversion measurement for our own ads (account AW-18162535340). Both are loaded under Google's Consent Mode v2: all consent signals default to denied; no cookies are set and no conversion data is sent until you accept via the cookie banner. Analytics are limited to the public marketing pages. Data is processed by Google in the US under the EU-US Data Privacy Framework and Standard Contractual Clauses. The full per-cookie inventory is on the Cookie policy page.

Galerly does not run retargeting, remarketing, or session-replay tools. We do not sell personal data to third parties. We notify account owners at least 30 days before adding a new subprocessor that will process personal data.

Optional: cross-gallery benchmarks (opt-in)

Pro and Business photographers can opt in — at Settings → Privacy → Industry benchmarks — to have their client-engagement metrics (dwell, scroll depth, favorite rate, return rate) contribute to anonymized industry-wide aggregates. The lawful basis is your explicit consent under Art. 6(1)(a) GDPR; you can withdraw at any time from the same toggle, and we never sell, share, or expose this data to third parties.

Before any aggregate is computed for a (gallery-type, metric) cohort, we require a minimum of 50 opted-in photographers in that cohort. Below the floor, no aggregate is written — your single studio cannot be reverse-identified from a small sample. Once enough photographers opt in, you'll see your numbers compared against the platform average inside your analytics dashboard.

04

Data Security

We implement industry-standard security measures to protect your data, including encrypted storage, secure transmission (HTTPS), and password hashing.

Authentication tokens expire after 7 days. We regularly review security practices to protect against unauthorized access.

While we take reasonable precautions, no system is completely secure. You accept the inherent risks of transmitting data online.

05

Your Privacy Rights

Access: Download your data from your dashboard.

Correction: Update your profile information anytime.

Deletion: Delete your account or content anytime. When you manually delete content (photos, galleries, or your account), it is immediately and permanently removed from our database. We do not retain deleted content.

Portability: Self-serve bulk export of every gallery, contract, invoice, and client record as JSON + CSV from Settings → Data.

Objection: Opt out of optional analytics and marketing cookies.

Right to complain: if you believe we've mishandled your data, you may lodge a complaint with your supervisory authority. For residents of Switzerland that is the FDPIC; for residents of the EU, with the data protection authority in your EU member state.

Transparency on enforcement: Exercising any of the rights above (e.g. requesting an export) is itself logged in a pseudonymised compliance audit record — described in “Information We Collect” above — so we can prove we responded within the GDPR Article 12 one-month window. The record is visible to you in Settings → Data.

Access, deletion, rectification, and objection requests not covered by the self-serve export above can be raised via our contact form with “Privacy / GDPR” as the topic. Submissions categorised as privacy requests are routed to our DPO mailbox. We respond within 30 days. Swiss data protection laws (revFADP) and EU GDPR apply.

06

Cookies & Local Storage

We use cookies and browser storage to improve your experience:

Necessary: Authentication and session management. Required for the service to function.

Analytics: Optional. Aggregate statistics about platform usage.

Marketing: Optional. Consent-gated Google Ads conversion measurement only. No cross-site ad targeting or remarketing.

Manage cookie preferences via the popup or browser settings. Disabling necessary cookies may limit functionality.

07

Data Retention

Active Account Data: Retained while your account is active.

Canceled Subscriptions: After cancellation, data remains accessible for 30 days for export, then permanently deleted.

Manual Deletions: Content you manually delete (photos, galleries, account) is immediately and permanently removed. No retention period applies.

Usage Analytics: Aggregated, anonymized data retained to improve service quality.

Bank Transfer Receipts: If you attach a receipt to a bank-transfer order, we store that file for 180 days and then delete it automatically. It is visible only to the buyer and the photographer on that order. Attaching one is optional, and we do not verify it against any bank.

Payment Records: Retained for 10 years as required by Swiss tax and accounting regulations.

08

International Data Transfers

Galerly is a Swiss company. Your data is stored on secure cloud servers that may be located outside Switzerland.

For EU/EEA users, we ensure adequate safeguards through Standard Contractual Clauses and compliance with Swiss-EU data adequacy decisions. Your data is protected under Swiss Federal Act on Data Protection (FADP) and EU GDPR where applicable.

09

Children's Privacy

Galerly is not intended for users under 16. We do not knowingly collect information from children.

If we discover an account belongs to a child, we will delete it immediately. Parents or guardians should contact us if they believe their child has created an account.

10

Policy Updates & Contact

We may update this Privacy Policy to reflect changes in our practices or legal requirements. Material changes will be notified via email and posted here.

Your continued use after updates constitutes acceptance. We recommend reviewing this page periodically.

Privacy Questions?

Use our contact form and select “Privacy / GDPR” as the topic.

For Swiss FADP or EU GDPR requests, data access, or deletion inquiries — submissions categorised as privacy requests are routed to our data protection officer.

Jurisdiction: Swiss law governs this Privacy Policy. Disputes subject to Swiss courts jurisdiction.

Last updated: December 2025