GDPR and privacy for your site
Privacy compliance is a partnership. We provide a tracker-free, secure foundation, but your site's legal readiness depends on your settings. Review this guide to configure cookie banners, process data erasure requests, redact maps, and customize compliant opt-in forms for global visitors.
Privacy compliance is a partnership. Digital privacy laws (like GDPR and CCPA) protect users worldwide—when someone from the EU or California browses your portfolio, leaves a message, or joins your newsletter, your site should handle their data transparently. ArtInStack provides a tracker-free, secure foundation; your Settings choices and public-site copy complete the picture for your studio.
Not legal advice. Work with counsel for your jurisdiction, client contracts, and final privacy policy text.
Open Settings → Privacy & security for the controls below. For a map of all three inner tabs (Privacy, Security, Site controls), start at Privacy & security overview.
The responsibility split
| What ArtInStack handles (out of the box) | 🛠️ What you configure (your responsibility) |
|---|---|
| No tracker defaults — Portfolio galleries and image layouts do not inject Meta Pixel, Google Analytics, or similar marketing scripts by default | Privacy policy link — Publish a dedicated Privacy Policy page and add it to footer Settings → Navigation |
| Secure data architecture — Contact inquiries, newsletter signups, and account data are stored on ArtInStack infrastructure with encryption in transit and at rest | Lawful basis — State your legal right to hold client information (for example contractual necessity for client shoots) in your privacy policy |
| Dashboard traffic metrics — Cloudflare zone analytics on the dashboard home (visits and unique visitors when your zone is configured), not tracking scripts dropped on your public pages | Marketing & inquiry consent copy — Customize newsletter widget title/description, contact form success copy, and policy text for clear, affirmative opt-in language |
| Geo privacy defaults — Conservative map redaction (500 m baseline fuzz; Public (redacted) default for new portfolios) on the Privacy tab | Per-portfolio geo rules — Override map visibility and review location metadata under Portfolio → Portfolio Settings |
| Cookie consent popup — Public-site banner with Accept all, Reject all, and Manage preferences; optional analytics and personalization stay off until the visitor opts in | Enable the cookie banner — Turn Show Cookie Consent Popup on under Privacy & security → Privacy when you expect EU/California visitors |
| Data export & account deletion — Request a ZIP from the Privacy tab; schedule workspace removal with a defined grace period (public site goes offline when deletion is requested) | Data-subject requests & off-platform copies — Fulfill visitor SARs using exports and portal records; keep ESP lists and local archives you control outside the dashboard |
| Subprocessor transparency — Vendor list on the Privacy tab (Stripe, Cloudflare, Resend, object storage, and related services) | Your extended stack — Email providers, CRMs, and other tools you connect beyond ArtInStack |
Configure privacy on your site
A. Privacy policy link
If you collect email addresses (contact form, newsletter, checkout), link visitors to your policy.
- Create a Privacy policy page under Pages (or start from a template under Media → Documents).
- Open Settings → Navigation and add that page to your footer menu — Header, footer, and navigation.
- Reference the policy near forms in page copy when your counsel recommends it.
B. Marketing and inquiry consent copy
Affirmative consent should be specific—say what subscribers receive and avoid vague “by emailing me you agree” language.
Newsletter signups (blog sidebar and footer):
- Enable a signup placement — Newsletter subscriptions.
- Edit the widget title and description in Settings → Blog Post (sidebar) or your footer template traits so visitors know what they are opting into.
- Link your privacy policy from the footer Navigation menu.
Contact forms:
- Add a Contact form block — Add contact form to pages.
- Turn on Spam protection (Cloudflare Turnstile) on public pages when available.
- Use your Success message and surrounding page copy to set expectations; inquiries email your account address with reply-to set to the visitor.
When you export subscribers to Mailchimp, ConvertKit, or similar, carry consent language and unsubscribe links forward in your ESP.
C. Cookie consent banner
- Open Settings → Privacy & security → Privacy.
- Turn Show Cookie Consent Popup on (recommended for EU/California traffic).
- Click Save Changes on Settings.
- On the live site, visitors see a bottom-right dialog with Accept all, Reject all, and Manage preferences for optional analytics and personalization categories. Essential cookies remain on; optional categories stay off until the visitor opts in.
Data export (your account)
Where: Settings → Privacy & security → Privacy → Data export.
| Step | Behavior |
|---|---|
| Click Export My Data | Queues a background export job |
| Refresh status / email | Notifies you when the ZIP is ready |
| Download | Secure link; export artifacts expire 7 days after the job is marked ready |
| Contents | Workspace metadata, subscriber and order references, and time-limited signed URLs for media files |
Use exports to respond to data-subject requests and to archive records before offboarding. The dashboard shows a security reminder before download—you become custodian of client data in that file. Step-by-step: Account deletion and data export.
Account deletion (your workspace)
Where: Settings → Privacy & security → Privacy or Security → Danger zone (owner only).
| Event | Timeline |
|---|---|
| Deletion scheduled | Public site goes offline immediately |
| Grace period | Data purge is scheduled for 30 days after your final billing cycle ends (confirm the date shown in the confirmation dialog) |
| Cancel | Owner can cancel before the grace deadline from Deletion pending |
| Purge | Workspace data is removed after the grace deadline |
Export anything you must retain before confirming deletion.
Geo privacy defaults (maps and EXIF)
Where: Settings → Privacy & security → Privacy → Geo privacy defaults.
| Setting | Default / behavior |
|---|---|
| Platform baseline fuzz | 500 m (read-only reference on the Privacy tab) |
| Fallback fuzz radius | Your override, clamped 50–5000 m — used when a photo has a location but no recorded accuracy |
| Default visibility for new portfolios | Public (redacted) — recommended; alternatives are Public (exact coordinates) or Private |
Per-album rules remain under Portfolio → Portfolio Settings → Visibility & SEO. Deep dive: Portfolio geo visibility and impact maps.
ArtInStack legal pages (platform vs your site)
These documents describe ArtInStack the company—not your studio’s visitor-facing policy:
| Document | URL |
|---|---|
| Privacy Policy | https://www.artinstack.com/legal/privacy |
| Data Processing Agreement (DPA) | https://www.artinstack.com/legal/dpa |
| Subprocessors | https://www.artinstack.com/legal/subprocessors |
Your dashboard Privacy tab lists subprocessors that process your account and site data, with links to vendor policies. Publish a separate privacy page on your public site for clients and visitors.
Prerequisites
- Dashboard → Settings → Privacy & security
- Owner or manager role (deletion and some cards are owner-only)
- A published privacy policy when you collect emails or run newsletters
Compliance checklist
- Publish a privacy policy and add it to footer Navigation.
- Set Geo privacy defaults if you use Impact map blocks or public location metadata.
- Enable Show Cookie Consent Popup when you expect global visitors.
- Customize newsletter and contact form copy for clear opt-in language.
- Review Subprocessors on the Privacy tab and align your policy with the vendors you use.
- Know how to run Export My Data and account deletion before you need them.
Verifying your setup
- Footer menu includes a working privacy policy link on the live site.
- Cookie popup appears on the public homepage when enabled (test in a private browser window).
- Geo defaults persist after save on the Privacy tab.
- A test Export My Data job reaches ready and download works before link expiry.
- Newsletter and contact flows match the copy on your policy and signup widgets.
