Legal

Privacy Policy

Last updated: 11 May 2025 · GDPR compliant

The short version: We only collect what we need to process your order. Your photo is deleted 72 hours after delivery. We never sell your data. We use Stripe for payments so we never see your card details. That's it.

Contents

  1. Who we are
  2. What data we collect
  3. How we use your data
  4. Legal basis for processing
  5. Your photo — special notice
  6. Who we share data with
  7. How long we keep data
  8. Your rights
  9. Security
  10. Children
  11. Changes to this policy
  12. Contact & DPO

1. Who we are

Caricature.online is an AI-powered caricature e-commerce service. When this policy refers to "we", "us" or "our", it means the operator of caricature.online, who acts as the data controller for the personal data described in this policy.

Contact: privacy@caricature.online

2. What data we collect

Data you provide directly

DataWhen collectedWhy
Email addressCheckoutTo deliver your caricature and send your receipt
Full nameCheckoutTo personalise your delivery email
Photo(s) of peopleOrder flowTo generate your caricature — deleted 72h after delivery
Personalisation answersOrder flowHair colour, occasion details, etc. — to improve the caricature result
Free-text notesOrder flowAny extra instructions you provide

Data collected automatically

DataSourceWhy
IP address (truncated)Server logsSecurity and fraud prevention — not stored in full
Browser & device typeServer logsTo ensure the site displays correctly
Pages visited, time on siteGoogle Analytics (anonymised)To improve the website — only with your consent
Referral sourceURL parametersTo understand which channels bring visitors — only with your consent
Cookie preferenceslocalStorageTo remember your consent choices

Payment data

We use Stripe to process payments. We never see, receive or store your card number, CVV or banking details. Stripe is PCI-DSS Level 1 certified. The only payment-related data we store is the Stripe payment intent ID (a reference number) and the amount charged.

3. How we use your data

We do not use your data for: advertising profiling, automated decision-making that affects you legally, selling to third parties, or any purpose other than those listed above.

5. Your photo — special notice

Your photo is the most sensitive data we handle. Here is exactly what happens to it:

  1. You upload your photo securely (TLS encryption) to Google Cloud Storage
  2. The photo is sent to our AI processing services (fal.ai and/or Anthropic) to generate the caricature
  3. The resulting caricature is saved to Google Cloud Storage and sent to your email
  4. Your original photo is permanently deleted within 72 hours of delivery
  5. The generated caricature download link also expires after 72 hours

We do not use your photo to train AI models. We do not share your photo with anyone except the AI processing services strictly necessary to generate your caricature. fal.ai and Anthropic process your photo as data processors under our instructions and are contractually prohibited from using it for any other purpose.

6. Who we share data with

We use the following data processors. All are bound by data processing agreements and GDPR-compliant contractual clauses:

ProcessorRoleData sharedLocation
StripePayment processingEmail, name, order amountUS / EU
Google Cloud PlatformHosting, database, file storageAll order data, photos (temporarily)EU (us-central1)
SendGrid / TwilioTransactional emailEmail address, name, download linksUS (SCCs)
fal.aiAI image generation (face swap)Your photo (temporarily, for generation)US (SCCs)
AnthropicAI prompt enhancementYour photo (temporarily, for analysis)US (SCCs)
Google AnalyticsAnonymised analyticsAnonymised usage data (consent only)US (SCCs)

SCCs = EU Standard Contractual Clauses, which provide adequate protection for transfers outside the EEA.

We will disclose data to law enforcement or regulatory authorities if required by law. We will notify you where legally permitted to do so.

7. How long we keep your data

Data typeRetention periodReason
Your photo (original upload)72 hours after deliveryAutomatically deleted — no longer needed
Generated caricature file72 hours after deliveryDownload link expires, file deleted
Order record (email, name, template, amount)7 yearsLegal / accounting obligation
Personalisation answers & notes90 daysCustomer support window
Analytics data26 monthsGoogle Analytics default (anonymised)
Cookie consent record1 yearTo avoid showing banner repeatedly

8. Your rights

Under GDPR, you have the following rights. To exercise any of them, email privacy@caricature.online. We will respond within 30 days.

In Greece: Hellenic Data Protection Authority (HDPA) — www.dpa.gr

9. Security

We implement appropriate technical and organisational measures to protect your personal data:

No system is 100% secure. In the event of a data breach affecting your rights, we will notify you and the relevant supervisory authority within 72 hours as required by GDPR.

10. Children

Our service is not directed at children under 16 years of age. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at privacy@caricature.online and we will delete it promptly.

Caricatures featuring children may be ordered by adults (parents, guardians) on behalf of children — in this context, the adult ordering is the data subject for purposes of this policy.

11. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will notify you of significant changes by displaying a notice on our website for at least 30 days before the change takes effect.

The "Last updated" date at the top of this page indicates when the policy was last revised. We encourage you to review it periodically.

12. Contact & DPO

For any privacy-related questions, data subject requests, or concerns:

Last updated: 11 May 2025