gallerylink

Privacy Policy

Last updated: June 3, 2026

This Privacy Policy explains what GalleryLink collects when you use the Service at gallerylink.live, how we use it, and the choices you have. We’ve tried to keep it short and honest.

What we don’t store

We do not store, host, or re-upload your photos or videos. Your media stays in your own Google Drive; GalleryLink reads the folder live to display a gallery and never keeps copies of the files.

What we collect

  • Account data — your email address, optional name, and a securely hashed password (we never store plain-text passwords).
  • Gallery metadata — the Google Drive folder ID, gallery title, theme, layout, a hashed gallery password (if set), and any website/social links you add.
  • Client interactions — when a visitor favorites photos or submits an album selection, we store their picks and any name/note they provide, associated with an anonymous per-browser identifier (a cookie). Clients do not need an account.
  • Payment data — handled by Dodo Payments (see below). We store your plan, subscription status, and a customer reference, but not your card details.
  • Usage analytics — aggregate, privacy-friendly page-view metrics via Vercel Analytics.

Cookies

We use a small number of cookies: a secure, signed session cookie to keep you logged in, a readable login-hint cookie so pages render the right header, an anonymous visitor cookie to remember a client’s favorites, and a short-lived cookie granting access to a password-protected gallery. We do not use advertising or cross-site tracking cookies.

How we use your data

  • to provide and operate the Service (render galleries, auth);
  • to process subscriptions and support requests;
  • to keep the Service secure and within usage limits;
  • to understand aggregate usage and improve the product.

Third parties we rely on

  • Google Drive API — to read the files in folders you’ve shared “Anyone with the link.” Thumbnails and downloads are served from Google’s CDN.
  • Dodo Payments — our merchant of record for subscriptions; they process payments and handle card data and tax.
  • Supabase — our database host for the metadata described above.
  • Vercel — hosting and privacy-friendly analytics.

Data retention

We keep your account and gallery metadata while your account is active. Deleting a gallery removes its metadata; deleting your account removes your associated data from GalleryLink. Your Google Drive files are never affected by these actions.

Your rights

You may access, correct, export, or delete your personal data. Email gallerylinklive@gmail.com and we’ll help. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA.

Security

Connections are encrypted over HTTPS, passwords are bcrypt-hashed, and gallery access uses short-lived signed tokens. No system is perfectly secure, but we take reasonable measures to protect your data.

Children

The Service is not directed to children under 16, and we do not knowingly collect their personal data.

Changes

We may update this policy; the “Last updated” date reflects the latest version. Material changes will be made clear.

Contact

Questions about your privacy? Email gallerylinklive@gmail.com or visit our contact page.