Privacy
Last updated: [DATE]
You are about to hand us a photograph that matters to you. This page explains exactly what we do with it, who else touches it, and when we delete it. We have tried to write it the way we would explain it to you in the studio.
Who we are
[COMPANY LEGAL NAME], NIF [NIF], registered at [REGISTERED ADDRESS], Barcelona, Spain. We trade as VELLO.
We are the data controller for everything described here. You can reach us at hello@madebyvello.art. Our data protection contact is [DPO OR PRIVACY CONTACT].
What we collect
Your photograph. The image file you upload, and any crop or note you add with it.
Your order. Name, email address, delivery address, phone number if you give us one, the format and size you chose, your gift message if there is one, and your Vello ID.
Your payment. Stripe handles the card. We never see or store your card number or any part of it. We keep Stripe's reference for the payment, so we can find your order and issue a refund.
Your IP address. We keep a short record of the network address a request came from, only to stop abuse such as repeated failed studio sign ins or a form being submitted too many times. These records are cleared after two days. Our own sign in log for the studio keeps this for as long as that log entry exists.
How you used the site. No cookies are set for this. A short random code lives in your browser's session storage under the name vello-session-ref while your tab is open, and it disappears the moment you close it. We use Vercel Web Analytics for aggregated page views, and only on our marketing pages and the order configurator, never on an order page or in the studio panel. We also record a small set of first party events in our own database, for example that someone reached the upload step, using no third party advertising or tracking pixel. Each event carries an HMAC, a one way hash, of your order number rather than the number itself, so we can count events against the same order without being able to work back to which order it was. These events are kept for 400 days and then deleted.
What we do with it, and why
| What | Why we are allowed to | How long |
|---|---|---|
| Create your artwork from your photograph, QA it, print it, ship it | To perform our contract with you, GDPR art. 6(1)(b) | Your original photograph is deleted 30 days after delivery, 30 days after a cancellation, a refund or a failed payment, whichever applies, or after at most one year with no movement on the order at all |
| Keep the finished artwork file and your Vello ID | Our legitimate interest in being able to reprint a faulty artwork, and your legal guarantee, GDPR art. 6(1)(f) | 3 years from delivery |
| Keep the artwork longer so you can reorder it or add a second copy | Your consent, GDPR art. 6(1)(a) | 5 years, renewable, and you can delete it at any time |
| Send you order and delivery emails | To perform our contract | For the life of the order |
| Send you occasional emails about VELLO | Your consent | Until you unsubscribe |
| Show your artwork in our gallery, social posts or advertising | Your separate, explicit consent | Until you withdraw it |
| Keep invoices and accounting records | Legal obligation, GDPR art. 6(1)(c) | 6 years, Spanish Código de Comercio art. 30 |
| Understand how the site is used | Our legitimate interest in improving it | 400 days, then deleted |
About the people in your photograph
Photographs of people are personal data about those people, not only about you. We take that seriously.
We do not run facial recognition. We never measure, match or index anyone's face. We do not compare faces across orders and we do not build a face database. Our system interprets an image into a painting. It does not identify anybody. That is a deliberate design decision and it is why your photograph is not treated as biometric data under GDPR art. 9.
We do not read your photograph for anything else. We do not tag it, categorise it, infer anything about health, beliefs, origin or relationships, or use it to train anything beyond making your own artwork.
If you are in a photograph someone sent us, and you did not agree to it, write to hello@madebyvello.art with anything that helps us find the order. We will delete the photograph and, unless the artwork has already shipped, stop the work. If it has shipped we will still delete our copies and remove it from anything public.
When you upload, you tell us that you have the right to give us the photograph, and that the people in it are content for it to be made into an artwork. For children, that means a parent or guardian. If someone in the photograph has died, it means you are close family or you have their family's blessing. We do not verify this, so please be honest with us. It matters.
Who else handles your data
We keep the list short on purpose.
| Who | What they do | Where |
|---|---|---|
| Vercel | Hosts the website and stores your uploaded file | EU and United States |
| Neon | Database for your order record | [REGION, EU PREFERRED] |
| Stripe | Takes the payment and screens for fraud | EU and United States |
| Resend | Sends your order and delivery emails | EU and United States |
| [PRODUCTION PARTNER] | Prints, frames and packs your artwork | [COUNTRY] |
| [CARRIER] | Delivers it to you | [COUNTRIES] |
Each of them is bound by a written data processing agreement. The production partner may not reuse your artwork or your photograph for anything, including their own portfolio.
Some of these companies are based in the United States. Where that is the case we rely on the European Commission's adequacy decision for the EU US Data Privacy Framework, and on standard contractual clauses as a backup. You can ask us for a copy of the safeguards at hello@madebyvello.art.
We do not sell your data. We do not share it with advertising networks.
Cookies
We do not use tracking cookies and we do not show a cookie banner, because we do not need one.
Your unfinished order lives in your own browser's session storage, not in a cookie. While you are filling it in it holds your name, delivery address, email and gift message, it is never sent to us until you place the order, and it disappears the moment you close the tab.
The cookies we do set are all strictly necessary, and none of them tracks you across other websites:
| Cookie | What it does | How long |
|---|---|---|
A cookie named for your order, for example vello_order_... | Keeps your order, preview or upload page open without the signed link showing in your address bar or your browser history | 12 hours |
vello_csrf | Confirms that a form was submitted from our own page | 12 hours |
vello_admin | Keeps a member of the studio signed in to the studio panel | 12 hours |
Payment happens entirely on Stripe's own pages. We never load Stripe's checkout on madebyvello.art, so we never set or read a cookie of theirs ourselves. Any cookie Stripe sets while you are on their page belongs to Stripe, on Stripe's own domain, and is covered by Stripe's own privacy notice.
Our analytics is described above: no cookie, a session identifier kept in your browser that dies with the tab, and events tied to your order only by a one way hash.
If we ever add advertising or third party tracking, we will ask you first, in a banner where refusing is exactly as easy as accepting.
Your rights
You can ask us to show you your data, correct it, delete it, restrict what we do with it, send it to you in a portable file, or object to processing we base on legitimate interest. Where we rely on your consent, you can withdraw it at any time, and that does not affect what we did before you withdrew it.
Write to hello@madebyvello.art, or use the link in one of your order emails. We will answer within 30 days. A deletion request is never completed by an automated process on its own. A member of the studio checks that the request really is yours before anything is destroyed, which is also why forwarding somebody else's order email cannot be used to delete their photograph.
If we have got something wrong, please tell us first. You also have the right to complain to the Spanish data protection authority, the Agencia Española de Protección de Datos, at www.aepd.es.
If something goes wrong
If your data is ever exposed in a way that puts you at risk, we will tell the AEPD within 72 hours of finding out, and we will tell you directly and plainly if the risk to you is high. We will say what happened, what we know, and what we are doing about it.
Changes
If we change this page in a way that matters, we will email everyone with an active order. The date at the top always tells you which version you are reading.