Privacy Policy

Last updated: July 20, 2026

This Privacy Policy explains how TidyArchive ("we", "us") collects, uses, and protects information when you use Vitrine, our digital collections catalog platform. We are committed to being transparent about data practices because we serve libraries, museums, and archives that care deeply about information stewardship.

1. Information We Collect

Account Information

  • Organization name (e.g., "Riverbend County Historical Society")
  • Your name (the person creating the account)
  • Email address (used for login and notifications)
  • Password (stored as a hashed value, never in plain text)

Collection Content

  • Item metadata: titles, descriptions, dates, creator names, subject keywords, physical descriptions, provenance notes
  • Images: photographs, documents, maps, and other digitized materials you upload
  • Custom fields and tags you define for your collections
  • Organization settings: logo, brand colors, public gallery preferences

Usage Data

  • Login timestamps and IP addresses (for security and audit purposes)
  • Audit log entries (who created, edited, or deleted items and when)
  • Aggregate analytics (page views on public galleries, search queries)

Payment Information

Payment is processed by Stripe. We receive your email address, plan tier, and payment status from Stripe. We never see or store your credit card number, CVV, or full payment details.

2. How We Use Your Information

  • To operate your Vitrine account and display your public gallery
  • To send you service notifications (password resets, plan changes, security alerts)
  • To process payments through Stripe and manage your subscription
  • To diagnose technical issues and improve the platform
  • To comply with legal obligations if required

We do not sell your data. We do not use your collection content to train AI models. We do not share your information with third parties for advertising.

3. Who Can See Your Data

Your Organization's Users

Users you invite to your organization can see and manage items based on their role (admin, editor, viewer). You control this access from your settings page.

Public Gallery Visitors

Items you mark as "public" and "published" are visible to anyone who visits your public gallery URL. This includes item titles, descriptions, images, and metadata. Unlisted and draft items are not visible publicly.

Internet Archive

If you enable Internet Archive backup, your items and images are uploaded to archive.org. This is optional and off by default. Once uploaded, they are subject to the Internet Archive's privacy policy and terms.

TidyArchive Staff

We (Alan, the operator) can access your data for support, debugging, and maintenance. We access account data only when needed to resolve a support issue or fix a technical problem.

Service Providers

  • Cloudflare R2 — stores your uploaded images. Cloudflare has their own privacy policy.
  • Stripe — processes payments. Stripe has their own privacy policy.
  • Internet Archive — receives your content only if you opt in.

We do not share your data with any other third parties.

4. Data Storage

  • Your images are stored on Cloudflare R2, a cloud object storage service.
  • Your metadata and account data are stored in a database on our server in the United States.
  • Nightly backups of your database are stored on Cloudflare R2.
  • Passwords are hashed using industry-standard algorithms and cannot be read in plain text.

5. Data Retention

  • Your data is kept as long as your account is active.
  • If you cancel your account, your data is retained for 30 days, then permanently deleted (database records and R2 images).
  • If you request immediate deletion, we will remove your data within 7 days.
  • Audit logs are retained for 24 months, then automatically purged.
  • If you uploaded content to the Internet Archive, that content remains on archive.org subject to their retention policies. We cannot delete content from the Internet Archive on your behalf.

6. Your Privacy Rights

Depending on your location, you may have the following rights:

  • Access — request a copy of your data. You can also export all items via CSV at any time.
  • Correction — update your account information or item metadata directly in Vitrine.
  • Deletion — request deletion of your account and all associated data.
  • Portability — export your collection data in CSV format.
  • Opt-out of IA — the Internet Archive backup is always optional. You can disable it at any time.

To exercise any of these rights, email [email protected].

California Residents (CCPA)

If you are a California resident, you have the right to know what personal information we collect, request deletion, and opt out of the sale of your information. We do not sell personal information. To submit a request, email us at the address above.

European Residents (GDPR)

If you are located in the European Economic Area, you have the right to access, rectify, erase, restrict processing, and port your data. You also have the right to object to processing and to lodge a complaint with your local data protection authority. Our lawful basis for processing is your consent (account creation) and contract performance (providing the service you signed up for).

7. Security

  • Passwords are hashed using Werkzeug's password hashing (PBKDF2 with salt).
  • All traffic between your browser and Vitrine is encrypted via HTTPS (TLS).
  • Stripe handles payment security. We never touch raw credit card data.
  • Database access is restricted to the server itself.
  • We use CSRF tokens on all forms to prevent cross-site request forgery.

No system is 100% secure. If we discover a data breach, we will notify affected users by email within 72 hours of confirming the breach.

8. Children's Privacy

Vitrine is designed for cultural heritage organizations, not individuals under 18. We do not knowingly collect information from children. If you believe a child has created an account, contact us and we will delete it.

9. Cookies

Vitrine uses essential cookies only:

  • Session cookie — keeps you logged in. Deleted when you close your browser or log out.
  • CSRF token cookie — protects forms from cross-site request forgery.
  • Flash message cookie — temporary, used for showing success/error messages.

We do not use tracking cookies, advertising cookies, or third-party analytics cookies. We do not use Google Analytics or similar tracking services.

10. Changes to This Policy

We may update this Privacy Policy as Vitrine evolves. If we make material changes, we will notify you by email at least 14 days before the changes take effect. The "last updated" date at the top of this page reflects the most recent revision.

11. Contact

Questions about your privacy or this policy? Email [email protected]. We take privacy seriously and will respond promptly.