Privacy Policy
Last updated: 2025-09-22
This Privacy Policy explains how Visioneria (we, us) collects and processes personal data when you use our website and services to generate AI images and order premium canvas prints. We comply with the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (nFADP).
Data Controller & Contact
Visioneria, 1022 Chavannes (VD) - CH
Email: support@visioneria.art
What Data We Process
- Account data: email address, name, credentials (managed via Supabase).
- Service data: prompts and images you generate, image metadata (aspect, format), and visibility settings.
- Order data: selected product (canvas size/thickness), shipping details (name, address, city, postal code, country, email), price, order identifiers.
- Payment data: handled by Stripe. We receive payment status and references but not your full card details.
- Technical data: basic device and page view information for privacy-friendly analytics (no cookies; we respect Do Not Track and anonymize IPs).
- Authentication data: session token stored in a short‑lived cookie for secure login.
- Localization data: language preference (cookie) to display the site in your chosen language.
Purposes and Legal Bases
- Provide the service (generate images, manage accounts, place orders, deliver prints) — Art. 6(1)(b) GDPR (contract) / nFADP Art. 31.
- Payments via Stripe — Art. 6(1)(b) GDPR.
- Customer support and communications — Art. 6(1)(b) and 6(1)(f) GDPR; legitimate interest to operate and improve our services.
- Privacy‑friendly analytics (no cookies, DNT honored, IP anonymized) — Art. 6(1)(f) GDPR.
- Compliance with tax/accounting and legal obligations — Art. 6(1)(c) GDPR.
- Marketing with Google Ads (if enabled) — Art. 6(1)(a) GDPR (consent). We do not use Google Analytics or Usercentrics.
Cookies and Local Storage
We use a small number of necessary cookies to run the website. See our Cookies & Data Protection page for details and retention. Cookies & Data Protection.
Analytics
We use an in‑house, privacy‑friendly analytics endpoint that does not set cookies and respects your browser’s Do Not Track setting. IP addresses are anonymized before hashing; we store an ephemeral local session ID in localStorage to de‑duplicate page views during a visit.
Sharing and Processors
- Hosting/Runtime: Vercel (EU/Global).
- Authentication & Database: Supabase (EU region, with session cookie).
- Object storage: Backblaze B2 for images/assets.
- Payments: Stripe (card processing; no full card details on our servers).
- Email: Resend (transactional emails).
- AI generation: various public models for image/prompt processing.
- Advertising: Google Ads (Ads/Conversion tags) — only if enabled and, in the EU/CH, only with consent.
All providers are engaged under appropriate data processing terms and, where applicable, Standard Contractual Clauses (SCCs).
International Transfers
When personal data is transferred outside Switzerland or the EEA, we rely on adequacy decisions or safeguards such as SCCs. We take reasonable steps to ensure an equivalent level of protection.
Retention
- Account data: kept while your account is active; deleted upon request unless retention is required by law.
- Orders and invoices: retained according to Swiss accounting/tax laws (generally up to 10 years).
- Analytics events: stored without identifiers; aggregated for trends and deleted when no longer needed.
- Session cookies and checkout cookies: short‑lived and cleared automatically or when you sign out.
Your Rights
Under GDPR and Swiss nFADP, you have rights to access, rectification, erasure, restriction, data portability, and objection. For consent‑based processing (e.g., Google Ads cookies), you may withdraw consent at any time. To exercise your rights, contact us at support@visioneria.art.
Children
Our services are not directed to children under 16. We do not knowingly collect data from children.
Changes to This Policy
We may update this policy to reflect changes in our services or laws. We will indicate the latest update date above.
Contact
If you have questions or requests about this policy or your data, contact support@visioneria.art.