Security
How we protect galleries' data.
Last updated: 7 October 2026
Draft under legal review. These documents will be finalised before the service is sold.
Separation between galleries
Every record belongs to one gallery. Database rules check, for every request, that the person is a member of that gallery and has the right role. One gallery can never read another's data, even through a programming error in the application.
Roles
Owners and admins manage the team; staff edit records; read-only members can look but not change anything. Purchase prices, insurance values and contacts are never shown on public pages.
Encryption and hosting
Connections use HTTPS. Data is encrypted at rest by our hosting providers. The database runs in the Paris region.
Backups
The database is backed up daily. Customers can export their records at any time.
Public pages
Public websites and private view links only show what a gallery has chosen to publish. Private view links can expire and can show or hide prices.
Reporting a vulnerability
If you find a security issue, write to [to be completed]. Please give us reasonable time to fix it before making it public. We will not take action against good-faith research that respects other customers' data.