← Back

Privacy Policy

Effective date: March 24, 2026

1. Introduction

This Privacy Policy explains how Arts-Forms (“we”, “us”, or “our”), operating at https://arts-forms.com, collects, uses, and protects information when you use our commission form builder platform (the “Service”).

The Service is used by two types of people: Artists who create and manage commission request forms, and Clients who submit commission requests through those forms. This policy applies to both.

By using the Service, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the Service.

Our Promise to You

  • We never collect data beyond what is strictly needed to operate your account and provide the Service.
  • We never share or sell your personal data to any third party, for any reason.
  • All data you provide is kept private and protected with industry-standard security measures.

2. Information We Collect

2.1 Artist Account Information

When you create an artist account, we collect:

  • Your display name (artist slug / username)
  • Your email address
  • A bcrypt hash of your password — we never store your password in plain text
  • Optional branding preferences (colors, profile image, banner)

2.2 Payment Information

Subscription payments are processed by Stripe. We never receive or store your full card number, CVV, or banking details. Stripe provides us with a customer identifier and a tokenised payment method reference only. For details on how Stripe handles your payment data, see stripe.com/privacy.

2.3 Form Submissions from Clients

When a Client submits a commission request form created by an Artist, we collect and store the data entered into that form. The specific fields depend on what the Artist configured — common examples include name, email address, commission description, and reference file uploads. This data is stored on behalf of the Artist and is subject to the data retention rules described in Section 4.

2.4 Usage Data

We automatically collect limited technical data when you interact with the Service, including:

  • IP address (used for rate limiting and abuse prevention)
  • Browser type and version
  • Pages visited and features used
  • Timestamps of actions (e.g. form creation, submission)
  • Monthly usage metrics such as submission counts and storage consumed

This data is used solely to operate and improve the Service.

2.5 Cookies and Local Storage

We use the following browser storage mechanisms:

  • Session cookies — used to keep you logged in to your artist dashboard during a session. These expire when you close your browser or log out.
  • Persistent cookies / localStorage — used to remember user preferences (such as “remember me” login state and UI settings).
  • Cookie consent — we display a consent banner and record your choice in localStorage so we do not show the banner again.

We do not use third-party advertising or tracking cookies.


3. How We Use Your Information

We use the information we collect to:

  • Provide the Service — create and manage artist accounts, store and display commission forms, and record client submissions.
  • Process payments — pass billing information to Stripe and manage subscription status.
  • Send billing notifications — email receipts, renewal reminders, and notices about upcoming data deletion due to subscription lapse.
  • Enforce our Terms of Service — detect and prevent abuse, spam, and policy violations.
  • Improve the Service — analyse aggregated usage patterns to identify bugs and prioritise new features.
  • Respond to support requests — when you contact us, we use the information you provide solely to answer your query.

We do not use your data for targeted advertising, and we do not build personal profiles beyond what is strictly necessary to operate the Service. We collect only what we need — nothing more.


4. Data Retention

Commission submission data is automatically deleted based on your artist subscription plan:

  • Starter plan: submissions are deleted 30 days after the submission date.
  • Pro plan: submissions are deleted 90 days after the submission date.
  • Inactive accounts: all submissions and associated files are deleted 14 days after an account's subscription lapses or is cancelled.

We will send warning emails to the registered artist email address 7 days and 24 hours before scheduled deletion. Artists are responsible for exporting any data they wish to keep.

Artist account information (name, email, password hash) is retained for as long as the account is active. Upon account deletion, all associated data is permanently removed within 14 days.


5. Third-Party Services

5.1 Stripe (Payments)

All subscription billing is handled by Stripe, Inc. When you enter payment details, those details go directly to Stripe and are never transmitted to or stored on our servers. Stripe is PCI-DSS Level 1 certified. You can review their privacy practices at stripe.com/privacy.

5.2 Supabase (Database and File Storage)

Artist account data, form configurations, client submissions, and uploaded reference files are stored using Supabase, a hosted PostgreSQL database and object storage platform. Data is stored in secure, access-controlled environments with Row Level Security (RLS) policies. You can review Supabase's privacy practices at supabase.com/privacy.

5.3 No Data Shared or Sold

We never share, sell, rent, or trade your personal information to any third party for any purpose — including marketing, advertising, analytics, or any other commercial use. The only third parties we interact with are Stripe (to process your payment) and Supabase (to store your data), both of which are listed above. Your data is never passed to anyone else.


6. Cookies and Tracking Technologies

We use only the cookies and localStorage entries necessary to operate the Service. A summary:

Name / TypePurposeExpires
Session cookieKeep artist logged in during browser sessionBrowser close / logout
localStorage — auth preference“Remember me” login persistence30 days or manual logout
localStorage — cookie consentRecord your consent banner responsePersistent
localStorage — UI preferencesStore UI settings (e.g. dark mode)Persistent

You can clear cookies and localStorage at any time through your browser settings. Doing so will log you out and reset any saved preferences.


7. Your Rights

You have the following rights with respect to your personal data:

  • Access — you may request a copy of the personal data we hold about you.
  • Correction — you may ask us to correct inaccurate or incomplete data.
  • Deletion — you may request that we delete your account and all associated data. We will action this within 14 days.
  • Data portability — you may export your submission data at any time from your artist dashboard.
  • Restriction — in certain circumstances, you may ask us to restrict processing of your data while a dispute is resolved.

To exercise any of these rights, please contact us at support@arts-forms.com. We will respond within 30 days. We may ask you to verify your identity before actioning a request.


8. GDPR and CCPA

8.1 European Union (GDPR)

If you are located in the European Economic Area (EEA) or United Kingdom, the General Data Protection Regulation (GDPR) applies to our processing of your personal data. Our legal bases for processing are:

  • Contract — processing necessary to provide the Service you have subscribed to.
  • Legitimate interests — abuse prevention, rate limiting, and service improvement.
  • Consent — non-essential cookies (where applicable).

Under GDPR you also have the right to lodge a complaint with your local supervisory authority if you believe we have processed your data unlawfully.

8.2 California (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) grants you additional rights, including the right to know what personal information we collect, the right to delete it, and the right to opt out of the sale of your personal information. We do not sell personal information. To exercise your CCPA rights, contact us at support@arts-forms.com.


9. Children's Privacy

The Service is not directed to children under the age of 13, and we do not knowingly collect personal information from anyone under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at support@arts-forms.com and we will delete the information promptly.


10. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this page. Where changes are material, we will notify you by email (if you have an artist account) or by posting a prominent notice on the Service. Continued use of the Service after the revised policy takes effect constitutes your acceptance of the changes.


11. Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact us at support@arts-forms.com.

You may also review our Terms of Service for information about your contractual rights and obligations when using Arts-Forms.

© 2026 Arts-Forms. All rights reserved.