Privacy policy
0. When you use Curate via a merchant's branded URL
You may have arrived on a curatewalls.com subdomain (e.g. acme.curatewalls.com) or on a merchantâs own vanity domain (e.g. curate.acme.com). In both cases the merchant is using Curateâs white-label gallery-wall planner. Curate is a service operated by Curate Walls Ltd, a company registered in England and Wales, and provides the planner, the database that holds your account, and the AI / hosting / email infrastructure behind it. See âWho we areâ below for our full contact details. The merchant operates the catalogue, the prices, the branding you see, and (where they handle checkout themselves) the order. The address bar shows the merchant; the platform is Curate.
| Controlled by Curate | Controlled by the merchant |
|---|---|
| Your account, walls, frames, favourites, room photos, feedback, support tickets, AI-companion conversations, lifecycle-email log, analytics events, cookies. | Catalogue rows, prices, stock, branding (logo / colours / fonts you see), sample rooms, and, where the merchant uses their own checkout, the order and payment data. |
Curate handles all data-subject requests (access, deletion, rectification, portability) for the consumer-side data above. The merchant has no obligation to action your DSAR. Contact team@curatewalls.com and Curate will respond within statutory timelines. If a payment dispute or refund question arises, thatâs a relationship between you and the merchant (or their payment processor).
Service signals to the merchant. When you use a merchantâs branded planner, that merchant can receive service signals about activity in their planner (for example, that a wall was saved or shared there). These signals carry a pseudonymous reference, never your email address or account ID. What the merchant does with them in their own systems is governed by their privacy notice.
Section 0 added 2026-05-18, pending counsel review.
1. What we collect
When you use Curate we may collect the following categories of personal data:
- Account data: email address, display name, avatar.
- Content you create: uploaded room photos, wall designs, frame arrangements, favourited artwork, uploaded artwork.
- Commerce data: orders, affiliate click history, payment metadata (we never see full card numbers; Stripe handles those).
- Product telemetry: pages visited, features used, device class, locale (only if you grant analytics consent).
- Support correspondence: messages you send us and our replies.
- Technical data: IP address (used for rate-limiting and audit logs; not sold or used for ads).
2. How we use it
- To run the service: letting you save walls, browse art, and complete purchases.
- To keep your account secure and prevent abuse.
- To understand how Curate is used so we can improve it (analytics, only with consent).
- To process payments and pay retailer partners.
- To respond to support requests.
3. Processors we use
We rely on a small number of vetted third parties to run Curate. Your account, your saved walls and any room photos you upload are stored in the United Kingdom. Where a processor is outside the UK, that transfer is covered by the UK International Data Transfer Agreement (IDTA) or the European Commissionâs Standard Contractual Clauses (SCCs), as applicable.
| Processor | What we send | Region | Safeguard |
|---|---|---|---|
| Supabase | Auth, database, object storage | United Kingdom (London) | Stored in the UK |
| Stripe | Payments, subscriptions, billing | EU / US | SCCs (EUâUS) |
| Resend | Transactional and lifecycle email | US | SCCs |
| PostHog | Product analytics (consent-gated) | EU | Within EEA |
| Anthropic | AI room-photo analysis, AI Print Companion suggestions, support triage. Photo / message content only; no account identifiers. | US | SCCs. Retained 30 days for safety and security, then deleted. Not used to train models. |
| Vercel | Hosting, CDN, edge runtime | United Kingdom (London) | SCCs. Functions run in London; Vercel is a US company and may access data to provide support. |
| Upstash | Distributed rate limiting (per-IP counters; IP only, no payload) | Global | SCCs |
| Twilio | WhatsApp/SMS alerts for P0/P1 support to admin contact only | US | SCCs |
| Crisp | Live chat inside the merchant dashboard: merchant email, store name, and the chat transcript. Not loaded on consumer surfaces. | EU (Netherlands) | Within EEA |
| Shopify | Only for merchants who connect a Shopify store: catalogue sync, and where that merchant sells the hanging kit through their own checkout, the shopper's order reference and shipping address. | Global (Ireland / Canada) | SCCs and UK IDTA Addendum |
| BrandFetch | Optional onboarding-time merchant brand auto-import. Domain string only, no personal data sent. | UK | Within UK |
| Sign in with Google (OAuth) and the optional Google Photos picker. Triggered explicitly when you choose those options. | US | SCCs | |
| Awin / CJ | Affiliate commission attribution. Receives a click ID when you click out to a partner retailer. | EU / US | SCCs where applicable |
| Public museum APIs | Read-only artwork catalogue from Art Institute of Chicago, Met, Cleveland Museum of Art. We fetch their public catalogue; no personal data leaves Curate. | US | No personal data transferred |
4. Legal bases (UK GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Running your account and saving walls | Contract (Art. 6(1)(b)) |
| AI room-photo analysis and print suggestions (Section 8) | Contract (Art. 6(1)(b)): delivering the analysis you request when you upload a photo |
| Fulfilling orders and paying partners | Contract (Art. 6(1)(b)) |
| Product analytics | Consent (Art. 6(1)(a)) |
| Marketing communications | Consent (Art. 6(1)(a)) |
| Fraud prevention and security | Legitimate interests (Art. 6(1)(f)) |
| Tax and accounting records | Legal obligation (Art. 6(1)(c)) |
| Responding to support requests | Legitimate interests / contract |
5. Retention
- Account data: until you request deletion. Deletion is immediate and self-serve via Account settings. Records we are legally required to keep (order and invoice records, and the email dispatch log) are not deleted on request; they are de-linked from your identity and kept for the periods set out below.
- Wall designs, uploads, favourites: until you delete them or your account.
- Guest walls and rooms (no account): stored on our servers, tied to a browser cookie, and deleted by a daily job, photos included. A wall goes 60 days after the last change you save to it, and a room goes 60 days after the last time we read its photo. Opening a wall or a room again does not restart either clock. The identity cookie itself lasts 90 days, renewed each time you save. Signing in moves them onto your account instead.
- Room photo AI analysis: there can be two copies of the result, each with its own clock. The shared results cache, keyed on the photo itself, is deleted by a daily job 90 days after it was written. The copy kept on the room, which is what lets a room you own still open once the cache has gone, is deleted with the room itself: on the 60-day guest clock above, or when you delete your account.
- Analytics events: retained per PostHogâs default (up to 12 months); revoke via Cookie preferences.
- Support correspondence: kept while your account is open. Stale resolved tickets auto-close after 30 days of inactivity, and your tickets and their full message history are deleted outright when you delete your account.
- Email dispatch log (recipient address, subject, delivery status): retained for 12 months from sending, for delivery audit and bounce tracking. On account deletion the link to your user ID is anonymised; the dispatch record remains for the retention window.
- Merchant attribution and pixel events (pseudonymised purchase signals used for commission reconciliation): retained for 12 months, then automatically pruned. This applies after a merchant uninstalls too, so the data ages out rather than persisting.
- Order and invoice records: 7 years (legal obligation). On account deletion the orderâs link to your user ID is anonymised; the financial record remains for tax purposes.
6. Your rights
Under UK GDPR and EU GDPR you have the right to access, rectify, export, and delete your personal data, and to object to or restrict certain processing.
- Access / Portability (Art. 15 & 20): use âDownload my dataâ in Account settings to get a JSON export.
- Erasure (Art. 17): use âDelete accountâ in Account settings. This is immediate, not a 30-day grace period. Deletion also propagates to our processors: your PostHog person profile and its event history are deleted, your Stripe customer record is stripped of identifying details (the underlying invoice/tax record is retained as required by law, but no longer linked to your identity), and, for merchant accounts, your Crisp live-chat contact is deleted. A few records are kept because the law requires it, but de-linked from your identity: order and invoice records (about 7 years, for tax) and the email dispatch log (about 12 months, for delivery audit). One exception is not ours to speed up: if a room photo of yours was analysed by AI, Anthropicâs own copy is deleted on their 30-day cycle rather than the moment you press delete. See the Retention section above for the full list.
- Rectification (Art. 16): you can change your display name and profile photo directly in Account settings. For any other correction, email team@curatewalls.com and we will update it for you.
- Objection / Restriction (Art. 21 & 18): email team@curatewalls.com.
- Using Curate without an account? These rights donât depend on having one. Guest walls and rooms are tied to a cookie in the browser that made them, and can be exported or erased from that browser; they also age out on their own 60 days after the last change you save to a wall, or 60 days after we last read a roomâs photo (see Retention). If you need help, or no longer have that browser, email team@curatewalls.com.
- Complaints: you can lodge a complaint with the UK ICO (ico.org.uk) or your local EU supervisory authority.
7. Cookies
We use a small number of cookies. See our Cookie policy for the full list, or open cookie preferences to change your choices.
8. Automated processing (AI)
When you upload a room photo, Curate sends the photo to one AI processor: Anthropicâs Claude model (US, covered by Standard Contractual Clauses), to suggest a style and estimate wall scale, and to generate AI Print Companion suggestions when you ask for them.
What Anthropic does with it. Your photo is not used to train any AI model. Anthropic retains it for 30 days, where it may be accessed for safety and security purposes, and deletes it after that. Curate itself keeps the photo until you delete the wall or your account, and stores it in the United Kingdom.
No account identifiers are sent with the photo. No legal or similarly significant decisions are made about you automatically (Art. 22). You can opt out by using a template room instead of uploading a photo.
8a. Camera and sensors (AR)
When you tap âView on your wallâ on a phone, Curate hands the wall design off to your deviceâs native AR launcher: Apple Quick Look on iOS, Google Scene Viewer on Android, or a WebXR fallback on capable desktop browsers. Those launchers request access to your camera. Curate does not record, transmit, or store any camera frames. The camera feed is rendered locally by the launcher and discarded as soon as you exit AR.
8b. Checkout
When you tap âGet this wallâ, Curate either opens the print retailerâs site in a new tab or, where the retailer has configured an embedded checkout integration, renders the retailerâs own checkout inside an iframe on our page. Card details and payment data are never seen by Curate. Payment processing happens entirely on the retailerâs domain (or via Stripe for our merchant subscription billing).
9. Children
Curate is not directed at children under 13 and we do not knowingly collect personal data from anyone under 13. If you believe a child has provided us personal data, contact us at team@curatewalls.com and we will delete it.
10. International transfers
Some processors are outside the UK/EEA (see Section 3). Transfers are covered by the European Commissionâs Standard Contractual Clauses and, for transfers from the UK, the UK International Data Transfer Addendum.
11. UK / EU representative
Curate is operated by Curate Walls Ltd, a company established in the United Kingdom. Art. 27 UK GDPR applies to controllers outside the UK, so no UK representative is required.
Curate is aimed at the UK market: prices are in pounds sterling, the hanging kit ships to the United Kingdom only, and we do not market the service in the European Union. On that basis we do not consider ourselves to be offering services to data subjects in the EU under Art. 3(2) EU GDPR, and we have not appointed an EU representative. If that changes we will appoint one and update this policy first.
Direct all data-protection enquiries to team@curatewalls.com.
12. Who we are and how to contact us
Curate is operated by Curate Walls Ltd, a company registered in England and Wales (company number 17412020) with its registered office at 167-169 Great Portland Street, Fifth Floor, London W1W 5PF. Curate Walls Ltd is the data controller for the personal data described in this policy, and is registered with the Information Commissionerâs Office under registration number ZC229040.
For anything to do with this policy, your data, or your rights, email team@curatewalls.com. That address reaches a person, and it is the right address for access, deletion, rectification, portability, objection and restriction requests.