gallerylink

Privacy Policy

Last updated: July 30, 2026

This Privacy Policy explains what GalleryLink collects when you use the Service at gallerylink.live, how we use it, and the choices you have. We’ve tried to keep it short and honest.

What we don’t store

We do not store, host, or re-upload your photos or videos. Your media stays in your own Google Drive; GalleryLink reads the folder live to display a gallery and never keeps copies of the files.

What we collect

  • Account data — your email address, optional name, and a securely hashed password (we never store plain-text passwords).
  • Gallery metadata — the Google Drive folder ID, gallery title, theme, layout, a hashed gallery password (if set), and any website/social links you add.
  • Client interactions — when a visitor favorites photos or submits an album selection, we store their picks and any name/note they provide, associated with an anonymous per-browser identifier (a cookie). Clients do not need an account.
  • Gallery activity — so a photographer can see how their delivery is doing, we record when a gallery is viewed, unlocked with its password, or a photo’s download button is clicked, tied to the same anonymous visitor identifier. No name, email, precise location, or device fingerprint is collected, and the photographer’s own visits are excluded.
  • Hosted media (optional) — if you upload photos or videos to a GalleryLink-hosted gallery (or guests add photos via the Event Suite), those files are stored on Cloudflare R2 and served by us. They are deleted when you delete the photo or the gallery. Drive-linked galleries store no media with us at all.
  • Download leads (optional) — if a photographer turns on the email-before-download option, we store the email and optional name a visitor enters, visible to that photographer.
  • Payment data — handled by Dodo Payments (see below). We store your plan, subscription status, and a customer reference, but not your card details.
  • Usage analytics — aggregate, cookieless page-view metrics via Cloudflare Web Analytics. No persistent identifier is assigned and no device fingerprinting is used.

Who is responsible for what

For your account — your email, password, plan, and the galleries you create — GalleryLink is the controller.

For the personal data of your clients — the people in your photographs, and the names and notes they leave when they submit an album selection — you are the controller and GalleryLink acts as your processor, handling that data only to provide the Service to you. If you need a data processing agreement under Article 28 GDPR, email us and we will provide one. Our sub-processor list sets out every provider involved.

Cookies

We set four cookies, all strictly necessary: cs_session (keeps you signed in), gl_auth (a flag so the header renders correctly before paint), cs_gallery_<gallery> (records that a client entered the right gallery password), and cs_visitor (an anonymous id so a client’s favorites persist without an account). We use no advertising or cross-site tracking cookies, which is why there is no cookie banner. Full detail, including lifetimes, is in our Cookie Policy.

How we use your data, and our legal basis

PurposeLegal basis (GDPR Art. 6)
Providing the Service — creating your account, rendering galleries, remembering client favorites and selectionsPerformance of a contract, Art. 6(1)(b). For client data, we act on your instructions as processor.
Processing subscriptions and answering support requestsPerformance of a contract, Art. 6(1)(b)
Keeping the Service secure, preventing abuse, and staying within Google Drive API limitsLegitimate interests, Art. 6(1)(f)
Understanding aggregate usage to improve the productLegitimate interests, Art. 6(1)(f) — measured without cookies or identifiers
Keeping invoices and tax recordsLegal obligation, Art. 6(1)(c)

Third parties we rely on

  • Google Drive API — to read the files in folders you’ve shared “Anyone with the link.” Thumbnails and downloads are served from Google’s CDN.
  • Dodo Payments — our merchant of record for subscriptions; they process payments and handle card data and tax.
  • Supabase — our database host for the metadata described above.
  • Cloudflare — application hosting, CDN, and cookieless analytics.

The full list, with what each provider processes and where, is on our sub-processor page.

Where your data is stored, and international transfers

Account and gallery metadata is stored in a database hosted in Mumbai, India. Our application runs on Cloudflare’s global edge network, which includes locations in the EU. Media is never transferred to us at all — it is served from Google directly to the viewer.

Where personal data of people in the EEA or UK leaves that area, the transfer is made under our providers’ data processing terms, which incorporate the European Commission’s Standard Contractual Clauses. If EU data residency matters to your studio, tell us — it helps us prioritise an EU-hosted region.

Data retention

  • Account data — kept while your account is active, and deleted when you delete your account or ask us to.
  • Gallery metadata — kept until you delete the gallery, which removes it along with its favorites and selections.
  • Client favorites and album selections — kept for as long as the gallery exists, so a client can return to their picks. If you want them cleared sooner, ask us and we will delete them for that gallery.
  • Gallery activity events — automatically deleted after 180 days, and immediately when the gallery is deleted.
  • Invoices and tax records — retained as long as tax law requires, typically several years, even after account deletion.

Deleting anything in GalleryLink never touches your Google Drive files.

Your rights

You have the right to access your personal data, to have it corrected or deleted, to receive a copy in a portable format, to restrict or object to certain processing, and to withdraw consent where processing relies on it. Email hello@gallerylink.live and we will action it — we aim to respond within 30 days, as the GDPR requires.

If your clients contact us directly about their data, we will refer them to you as the controller and help you respond.

If you are in the EEA or UK and think we have handled your data improperly, you can lodge a complaint with your national data protection authority. In the EEA, that is the supervisory authority of the country where you live or work; in the UK, it is the Information Commissioner’s Office. You may also have rights under other laws, such as the CCPA.

Security

Connections are encrypted over HTTPS, passwords are bcrypt-hashed, and gallery access uses short-lived signed tokens. No system is perfectly secure, but we take reasonable measures to protect your data.

Children

The Service is not directed to children under 16, and we do not knowingly collect their personal data.

Changes

We may update this policy; the “Last updated” date reflects the latest version. Material changes will be made clear.

Contact

Questions about your privacy? Email hello@gallerylink.live or visit our contact page.