1. Who We Are
JoshuaSunforged.com is operated by Joshua Gallagher ("we," "us," "our"). We are a fine art photography studio and print shop based in New York State. This Privacy Policy explains how we collect, use, disclose, and protect information about you when you visit our website or purchase from our store.
Contact: joshuasunforged.com/contact
2. Information We Collect
Information you provide directly
- Name, email address, and shipping address when you place an order
- Payment information (processed securely by our payment processor — we do not store card numbers)
- Messages sent through our contact form
Information collected automatically
- IP address and browser type
- Pages visited and time spent on site (via analytics — see Cookie Policy)
- Referring URLs
3. How We Use Your Information
- To process and fulfill your orders
- To communicate with you about your order status
- To respond to inquiries
- To improve our website and services
- To comply with legal obligations
We do not sell, rent, or trade your personal information to third parties.
4. Legal Basis for Processing (GDPR)
For visitors in the European Economic Area, our legal bases for processing are: contract performance (for orders), legitimate interests (for analytics), and consent (for marketing, where applicable).
5. Data Retention
We retain order records for seven years for tax and legal compliance. Contact form messages are retained for one year. Analytics data is anonymized after 26 months.
6. Your Rights
You have the right to access, correct, or delete your personal data. To exercise these rights, contact us. EU/UK residents may also lodge a complaint with their local data protection authority.
7. Third-Party Services
We use the following third-party services that may process your data under their own privacy policies:
- Stripe — payment processing
- Vercel — website hosting
- Google Analytics — anonymized site usage analytics
- Printful or similar — print fulfillment (receives shipping address)
8. Security
We use HTTPS encryption for all data transmission. Payment processing uses PCI-compliant third-party processors. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security.
9. Children's Privacy
Our site is not directed at children under 13. We do not knowingly collect data from children.
10. Changes to This Policy
We may update this policy periodically. Material changes will be noted at the top of this page with the updated date.