GALLERYLAB · 2026-10-03
Privacy notice
Varga István Bertalan, a sole proprietor registered in Hungary, operating as MacoLabs.
1078 Budapest, District VII, Murányi utca 38., ground floor, door 9, Hungary.
Full provider details
Pre-launch draft. Provider and processor details must be completed and legally reviewed before live subscription sales.
Connected store data
We store the connected store address, public product details, optimized product images and a hash of the connection credential. The raw credential remains in the WordPress plugin’s local settings. The plugin does not send orders, customer addresses or payment details to GalleryLab. The cart uses the store’s own session; the merchant’s privacy and cookie notices cover it. Revoking the connection stops further imports; previously saved content remains.
Artwork inquiries
Submitting an inquiry sends the visitor’s name, email, message, selected artwork details and confirmation timestamp to the named gallery’s private inbox. The form displays the gallery’s identity and privacy notice. Its owner can view, annotate, export and delete the inquiry. After 180 days it is removed on the next store update or inbox load. Inquiries and private notes are excluded from public exhibitions and project backups. Contact the receiving gallery for a reply or deletion of inquiry data. GalleryLab sends no automatic replies or marketing messages.
Who controls your data?
The provider named in the Legal notice controls account and service data. If you include other people’s personal data in an exhibition, you are responsible for lawful publication; organizational processing requirements require a separate agreement.
What data and why?
Email, name and Google identifier: sign-in and account management, performance of a contract. Gallery documents and media: editing, storage and publication initiated by you, performance of a contract. Hashed session and single-use tokens, expiry times and request counters: access security and abuse prevention, legitimate interests. Terms acceptance time and version: evidence of the contract. Payment customer and subscription IDs: billing and entitlement management, contract and legal obligations. We do not store card numbers.
Who can access data?
Published exhibitions and their optimized media are public. Drafts and original files are accessible only through the owner’s account. The hosted service runs on Cloudflare Workers; account and exhibition data is stored in an EU-jurisdiction Cloudflare D1 database, and uploads in separate private EU-jurisdiction R2 buckets. Workers processes requests on a global network: EU storage does not mean all processing takes place exclusively in the EU. Google handles authentication when you choose Google sign-in. Email sign-in and paid subscriptions are not currently enabled. Local development files remain on your own computer. Provider agreements and safeguards for any transfers outside the EEA still require legal review.
Retention
Galleries and media remain while the account exists or until an erasure request is fulfilled; cancelling a plan does not delete the account. Sign-in links are valid for 15 minutes, OAuth flows for 10 minutes and sessions for 7 days. Used sign-in tokens are removed; expired authentication records are cleaned on the next store mutation. Statutory billing retention and backup deletion cycles must be finalized for the provider’s jurisdiction and production infrastructure.
Your rights
Subject to applicable conditions, you may request access, rectification, erasure, restriction and portability, and object to processing based on legitimate interests. Download account data on the Account page and gallery backups through Export. Use the Legal notice email for requests and complaints. You may complain to the competent data protection authority, including NAIH in Hungary. There is no marketing profiling or automated decision-making with legal effects.