Privacy

Gallpack is a product of TentaPack LLC, which operates it. This describes exactly what the service stores and why. It is written from the actual database schema rather than from a template, so it should match what really happens.

If you just have an account

We store your email address, a hashed version of your password (never the password itself), your name, and when the account was made. Artists also have a page address, bio, location, and the links you choose to publish. If you sign in with Google we store the identifier Google gives us for your account, not your Google password.

Signing in creates a session. We store a hash of the session token, not the token, together with a rough description of the browser and a hashed IP (see Abuse prevention below) so your account page can list where you are signed in. We also remember each browser you have signed in from, as a hash, so we can email you when a sign-in comes from a device or a country we have not seen, with the city and country the network reported. A session ends after 30 days without use, or 90 days after it began; expired ones are removed automatically.

What you tell us when you join

Both sign-up flows ask a short questionnaire. Artists are asked what they make, where they are, whether they work full time, their social and shop links, and rough bands for their prices, past sales, what they have spent on selling, and how they heard of us. We use those answers to recommend a plan and to set up your page; nothing in them is shown publicly except what you put on your page yourself. Collectors are asked what kinds of work and styles they like, a budget range, a location, why they are looking, and how they heard of us. We use those to pick what Discover shows you and which artists to suggest. Every answer can be changed or cleared from your account, and all of them are deleted with the account.

Selling, and the legal details it needs

An artist who sells through Gallpack gives us a legal name, a phone number, a legal or business address, and a ship-from address, because a sale needs a shipping label and a real party to the contract. Artists who reach the reporting threshold also complete a tax form (W-9 or W-8) on their studio page. The taxpayer identification number, date of birth and foreign tax number on that form are encrypted with a key that lives only in our infrastructure and are never shown again in full, only the last four digits. Stripe handles your bank details for payouts; we never see them.

Work you upload

Images you stage are stored along with the title, medium, dimensions and description you provide. Staged work is reviewed by a person before it appears publicly, which means a member of staff sees it.

Messages

Chat between a collector and an artist about a piece is stored on Gallpack, with any photo attached. The artist sees your display name, never your email address. Gallpack staff can read every thread in full, including the collector's email address, to resolve a dispute or a report, and can post into a thread as "Gallpack". Threads are deleted with whichever account is deleted.

What we record about visits

We record what happens on the site so artists can see whether Gallpack is sending them anyone and so we can tell what works: page and piece views, where a view came from (the referring site, classified as Google, Instagram, and so on), zooms, wall-mockup and AR opens, searches and their filters, which result was clicked, favourites, cart changes, offers, checkouts, messages sent, and each step of the sign-up flow. These records contain no IP address.Each carries a random visitor id (the gp_vid cookie below) and, if you were signed in, your account id. Raw records are kept for90 days and then reduced to daily counts, which carry no visitor id at all. Deleting your account removes your account id from every record that had it.

Cloudflare, which hosts the site, also adds its Web Analyticsbeacon to every page. It is a script Cloudflare serves; it does not set cookies or use local storage, and what it reports to Cloudflare (page, referrer, browser type, country) is only ever shown to us as aggregates. It is the one third-party script on the site.

If a script on one of our tools crashes in your browser, the error message and your browser's identifying string are sent to our logs so we can fix it.

What we do with those records: the pieces people look at, favourite, put in a cart and buy are turned, once a night, into two things -- "people who looked at this also looked at" scores between pieces, and a per-visitor list of the categories, mediums, styles, price bands and artists you have shown interest in. Discover's "For you" order, the "Because you looked at" strip on a piece page and the weekly "Picked for you" email (only if you left new-work mail on) are ranked from these. The per-visitor list is keyed by the visitor id and your account, rebuilt from the last 30 days each night, and holds no page, IP or purchase detail -- just scores.

Marketing pixel. Gallpack has a slot for a marketing pixel (Meta's, and a Google Ads tag) to show Gallpack to people on other sites, and to measure it. It is off unless we have configured it, and even then it runs only with your permission. Outside the United States you are asked once, in a bar at the bottom of the page, and nothing loads until you say yes; inside the United States it may run unless you click "Do not sell or share my info" in the footer, which stops it for a year (thegp_consent cookie holds your answer). When it runs, the pixel is the provider's own script: it reports the page you are on and, for a piece you view, add to a cart, favourite or buy, the piece's id and price -- never your name or email from us. What the provider does with that is governed by their policy. You can change your answer at any time from the footer.

Abuse prevention

To stop brute-force sign-in attempts, mass account creation, coordinated false reporting, and scripts flooding the public endpoints, we keep a salted one-way hash of the IP address making those requests, together with a count. The original IP is never written down, and the hash is made with a secret held only on our servers, so a copy of the database alone cannot be turned back into addresses. Some of these counters are keyed by email address or account instead, where the abuse being prevented targets a specific account. All of them are deleted 2 days after their window closes.

If you report a piece without being signed in, that report is stored with the same hashed IP so the same person cannot file the same complaint repeatedly. If you report while signed in, the report records your account until you delete it, after which it stays as an anonymous report.

Cookies and browser storage

Cookies, all first-party, none for advertising:

If you have allowed the marketing pixel and we have one configured, its provider sets its own cookies under its own domain; see the paragraph above.

In your browser's own storage, which never leaves your device unless you act:

Who else sees your data

We do not sell your data, and we do not share it with advertisers. There are none.

Email

Emails about your account, your orders, your money and the security of all three -- confirming your address, resetting your password, a sign-in from a new device or country, a receipt, a payout, a return -- are part of using the service and cannot be turned off. Marketing email (new work from artists you follow or buy from, and their newsletters) is the opposite: off until you say yes, on the signup form or on your notifications page, with the date and place of that yes recorded; every one carries a one-click unsubscribe, and unsubscribing from any withdraws the yes. If mail to your address bounces, your account pages say so.

How long we keep things

Deleting an account is asked for from Account → Delete, confirmed by email, and carried out fourteen days later unless you cancel it from that email or that page; the delete page lists exactly what goes and what the law keeps.

A job runs once a day and removes what has aged out. Before that job existed this page said we did not yet delete old counters; now we do.

Getting your data, or getting rid of it

You can do both yourself, without asking anyone:

What deletion removes: your account row and everything that hangs off it, which for an artist is every piece and image, your questionnaire answers, tax forms, messages, sessions and known devices, the security log, sign-in challenges, reset links, the counters keyed to your email or account, your account id on every visit record and every report you filed, and your answers to the artist survey if you gave any. A support request you sent is kept as a dated, topic-only record with the name, email and message blanked, so an appeal about a piece stays in that piece's history.

What deletion keeps: orders, because they are the other party's record of a sale, with your name and shipping address redacted and the link to your account removed; and, for artists, the starter grant ledger(your account id, email and Stripe's card fingerprint, never a card number), which is how we stop one person collecting the first-sale offer by opening account after account.

If you can't sign in, or you want something corrected rather than removed, write to us and a person will action it.

What changed, and when

Every material change to this page is listed here with the date it took effect. The version at the top is the date of the current text.

If what we store changes, this page changes with it, and the entry above says what moved.

Ask us something