100% to women artists

Legal

Privacy Policy

§ 01

Who we are

Women In Art ("we", "us", "our") operates the marketplace at womeninart.com. We are the data controller for personal data collected through the site. You can reach our data protection contact at hello@womeninart.com. This policy was last updated in February 2026.

§ 02

Personal data we collect

Account data — name, email address, hashed password, account role (buyer / artist / admin), preferred language and currency. Artist data — biography, profile image, portfolio, business name, tax / VAT number (optional), Stripe Connect account ID, identity verification status (from Didit), commission preferences. Buyer data — shipping and billing address, order history, returns history. Transaction metadata — Stripe customer ID, subscription status, payment intents, payout history. We never see or store full card numbers. Content you upload — artwork images, descriptions, forum posts, journal entries, application records, exhibition outfits, AI chat prompts. Technical data — IP address, browser type, device, language, timestamps, basic interaction logs needed to operate and secure the service.

§ 03

Why we process your data (legal basis)

Contract (Art. 6(1)(b) GDPR) — to operate your account, process orders and subscriptions, deliver artworks, manage returns, run artist payouts. Legal obligation (Art. 6(1)(c)) — anti-fraud, tax records (we retain order metadata in pseudonymised form for 6 years to comply with HMRC), accounting, identity verification for sellers. Legitimate interest (Art. 6(1)(f)) — keeping the platform secure, preventing abuse, basic analytics on our own server logs, replying to your support requests. Consent (Art. 6(1)(a)) — optional marketing email, optional cookies beyond strictly-necessary, and any future tracking pixels. You can withdraw consent at any time without affecting prior processing.

§ 04

Cookies and tracking

We use a small number of strictly-necessary cookies (login session, language, currency, MVP gate). We do not currently run advertising trackers, Google Analytics, Meta Pixel, or any cross-site profiling. If we add analytics in the future, we will request explicit consent through the cookie banner before any non-essential script loads.

§ 05

Sub-processors and third parties

We share the minimum personal data required with the following vetted providers, all of which are GDPR-compliant: Stripe Payments Europe Ltd (Ireland) — payments, subscriptions, Connect Express payouts. Stripe receives card details, billing address, email, payout details. Didit (Estonia / EU) — identity and age verification for artists. Didit receives name, government ID image, selfie, and returns a pass/fail. We do not store the ID document itself. Cloudinary Ltd (Israel / EU) — hosting of uploaded images. Personal data: image content, filenames. Resend (USA, EU data residency option enabled) — transactional email delivery. Personal data: recipient email and email content. Google LLC (USA) — provides the Gemini large language model used by our AI Marketing Guru, Shop Assistant and Art Advisory chats. Personal data: only what you type into the chat. Prompts are not used to train external models. MongoDB Atlas (EU region) — primary database. We sign a Data Processing Agreement with every sub-processor and only transfer data outside the UK / EEA under Standard Contractual Clauses or an adequacy decision. Other third-party services (no personal data transmitted): Shippo Inc. (USA) — carrier rate lookups for shipping estimates using postal code and country only.

§ 06

International transfers

Some sub-processors (e.g. Resend, Google) are based in the United States. Transfers rely on the EU Standard Contractual Clauses plus the UK Addendum, and on the EU-US / UK-US Data Privacy Framework where applicable.

§ 07

How long we keep your data

Account: until you delete it. Orders & invoices: retained for 6 years in pseudonymised form (no name, no shipping address) for HMRC. Identity verification record: 5 years after artist account closure for anti-fraud compliance. Marketing email opt-in: until you unsubscribe. Server logs: 30 days. Backups roll off after 35 days.

§ 08

Your rights under UK GDPR / EU GDPR

You have the right to: access the personal data we hold about you; correct it; delete it ("right to be forgotten"); restrict or object to processing; data portability (machine-readable export); withdraw consent at any time; lodge a complaint with the UK Information Commissioner's Office (ico.org.uk) or your local EU supervisory authority. You can self-serve access and deletion from your Account page (Data → Export / Delete), which is also available via API at /api/me/data-export and /api/me/delete. We respond to all formal requests within 30 days.

§ 09

Security

Passwords are hashed with bcrypt. All traffic is encrypted in transit (TLS 1.2+). Strict CORS, HSTS, content-type and frame-ancestors headers are enforced. Sensitive endpoints (login, signup, AI chat, identity start) are rate-limited. We never store full payment card numbers — these go directly to Stripe.

§ 10

Children

The platform is restricted to users aged 18 or over. Artist identity verification confirms age. We do not knowingly collect data from minors.

§ 11

Changes & contact

If we make material changes we will notify you by email and through a banner on the site before they take effect. Questions, complaints, or DSAR requests: hello@womeninart.com.

Last updated: 21 February 2026.

Cookies

We use cookies to keep the site working and improve your experience. See our Cookie Policy.