Legal

Privacy Policy

Last updated: April 10, 2026

Who We Are

Painted Whiskers ("we," "us," "our") is a US-based e-commerce service that creates AI-generated pet portrait artwork. This policy describes how we collect, use, and protect your personal information when you visit our website at paintedwhiskers.com or use our services.

For privacy inquiries, contact us at privacy@paintedwhiskers.com.

Information We Collect

We collect the following categories of personal information:

  • Photos you upload for portrait generation. Stored securely and used solely to create your artwork.
  • Account information — email address, name (when you create an account or place an order).
  • Payment information — processed securely through Stripe. We never store credit card numbers on our servers.
  • Shipping address — when you order physical products, shared only with our fulfillment partners.
  • Device and usage data — IP address, browser type, pages visited, session duration. Collected through essential first-party cookies and analytics.
  • Communications — emails you send us for customer support.

How We Use Your Information

We use your information for the following purposes and legal bases:

  • To generate portraits from your uploaded photos (contractual necessity / consent)
  • To process payments and fulfill orders (contractual necessity)
  • To send order confirmations, shipping updates, and delivery notifications (contractual necessity)
  • To respond to customer support inquiries (legitimate interest)
  • To improve our service through aggregate analytics (legitimate interest)
  • To prevent fraud and abuse (legitimate interest)

Your Photos

Your uploaded photos are stored in encrypted cloud storage (Supabase). We use them exclusively to generate your portraits via OpenAI's image generation API. We do not sell, share, or use your photos for training AI models. Generated portraits are stored for your access and order fulfillment. You may request deletion of all your data at any time.

Third-Party Service Providers

We share limited information with trusted partners to operate our service. Each partner is bound by a data processing agreement:

  • OpenAI (San Francisco, CA) — processes your photo to generate portraits. Receives image data only.
  • Stripe (San Francisco, CA) — securely processes payments. Receives name, email, and payment card details.
  • Prodigi (Manchester, UK) — prints and ships physical products for European orders. Receives shipping address and print file.
  • Printful (Charlotte, NC) — prints and ships physical products for US/CA/AU orders. Receives shipping address and print file.
  • Supabase (San Francisco, CA) — hosts our database and file storage.
  • Vercel (San Francisco, CA) — hosts our website.
  • Resend — delivers transactional emails (order confirmations, shipping updates).
  • Claid.ai — upscales images for print-quality resolution.

We do not sell or share your personal information with data brokers, identity resolution vendors, or advertising networks. We do not use third-party tracking pixels for cross-site behavioral advertising.

Cookies and Tracking

We use essential first-party cookies to maintain your session, remember your login state, and process orders. These are strictly necessary for the service to function.

We do not use advertising cookies, cross-site tracking pixels, device fingerprinting, or third-party identity resolution technologies. We honor Global Privacy Control (GPC) signals automatically as a valid opt-out of any sale or sharing of personal information.

International Data Transfers

Our services are hosted in the United States. If you are visiting from the European Economic Area (EEA) or United Kingdom, your personal data will be transferred to and processed in the United States. We rely on the European Commission's Standard Contractual Clauses (SCCs) executed within our processors' Data Processing Agreements to ensure adequate protection for international transfers.

Data Retention

  • Uploaded photos and generated portraits: Retained while your account is active or for 365 days for anonymous sessions.
  • Order records: Retained for 7 years for legal/tax compliance.
  • Account data: Retained until you request deletion.
  • Server logs: Automatically expire within 30 days.

Your Rights

All users:

  • Right to access your personal data
  • Right to correct inaccurate data
  • Right to delete your data
  • Right to data portability (receive a copy in machine-readable format)

California residents (CCPA/CPRA):

  • Right to know what personal information we collect, use, and disclose
  • Right to delete your personal information
  • Right to opt out of the sale or sharing of your personal information
  • Right to limit use of sensitive personal information
  • Right to non-discrimination for exercising your rights

European residents (GDPR):

  • Right to withdraw consent at any time
  • Right to restrict processing
  • Right to object to processing based on legitimate interest
  • Right to lodge a complaint with your local Data Protection Authority

To exercise any of these rights, email privacy@paintedwhiskers.com. We will respond within 30 days.

California Disclosure: Categories of Personal Information

In the preceding 12 months, we have collected the following categories of personal information as defined by the CCPA:

  • Identifiers: name, email address, IP address, account ID
  • Commercial information: order history, products purchased
  • Internet activity: pages visited, session data
  • Geolocation data: approximate location derived from IP address
  • Audio/visual: photos you upload for portrait generation

We have not sold or shared personal information for cross-context behavioral advertising in the preceding 12 months.

Children's Privacy

Our services are not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email to registered users and posted on this page with an updated date. Your continued use of the service after changes constitutes acceptance.

Contact

For privacy-related questions, data requests, or complaints, email us at privacy@paintedwhiskers.com.

Privacy Policy — Painted Whiskers