Free shipping across the US and Europe

Privacy

What we do with the photo of your child, and with everything else you give us.

Version 1

Who we are

A Tale Called You is a sole trader based in Belgium. We are the data controller for everything on this page. Write to [email protected] and a person answers. We are not required to appoint a Data Protection Officer, and we have not. Privacy questions are handled by the founder.

What we collect, and why

PurposeDataLegal basis
Taking, making and delivering your orderYour email, delivery name and address, order details, payment outcomeContract (Art 6(1)(b) GDPR)
Making the artworkThe child's first name, age, gender, and the photo you shareLegitimate interests (Art 6(1)(f)), see the next section
Preview, approval, dispatch and tracking emailsYour email and order detailsContract (Art 6(1)(b))
Keeping invoices and order recordsInvoice dataLegal obligation (Art 6(1)(c), Belgian tax and accounting law)
Marketing emailYour emailConsent (Art 6(1)(a)), withdrawable at any time
Site statisticsAggregate page counts, no profile of youLegitimate interests (Art 6(1)(f))
Remembering the country we ship to for youOne cookie with your chosen countryLegitimate interests (Art 6(1)(f)), you asked us to remember it
Showing you our work again later (advertising)Pages you visit here, via advertising cookiesConsent (Art 6(1)(a)), nothing loads unless you allow it

Payment card details go to Stripe directly. They never reach our servers. Stripe processes payment data under its own privacy policy, because it also runs the payment network.

You do not have to give us any of this. But without an email, a photo and a delivery address, we cannot make or deliver an order.

The child in the picture

The child’s photo, first name, age and gender come from you, the parent or guardian. They do not come from the child. The child is not our customer, so we do not treat their data as “needed for a contract”. We rely on legitimate interests: yours in getting the piece you ordered, ours in making it. We weighed this against the child’s own interests. That is why the photo goes nowhere except into your artwork, is never used for marketing without your separate permission, and is deleted on a fixed schedule.

These rights belong to the child too. If they are old enough to ask, they can ask what we hold, have it corrected, or have it deleted. You can object to the processing at any time (Art 21 GDPR). Before you approve the preview, we then cancel and refund in full. After, we stop and delete everything the law does not require us to keep.

Faces and biometrics

We do not use facial recognition. We do not measure or store the geometry of your child’s face. We do not create a faceprint or face template. We do not match the photo against any database. We do not use it to train anything, and the systems that make the artwork are not allowed to either. The photo is used once, to make the artwork you ordered, and then deleted on the schedule below. A photograph on its own is not “sensitive” data under the GDPR; it only becomes biometric data when technology is used to identify a person from it, and we use none.

Who receives your data

Stripe takes your payment. Your card details go to Stripe directly and never reach our servers. Our production and delivery partners receive the finished artwork, your delivery name and address, and your card text. The photo stays inside the systems that make the artwork; every service in that chain works under our instructions and may not use anything for its own purposes. Our site statistics come from our own analytics system, which we build and operate ourselves.

With your permission, our advertising partners Meta and TikTok set cookies here so we can show you our work again later. For that data they are their own controllers, with their own privacy policies. In the EU nothing of theirs loads unless you allow it, and you can change your mind at any time.

We do not sell your data. If you send us an access request, we name the actual companies that handled your data.

Where your data goes

The site, the database and your files are hosted in Germany. Some services we rely on are American companies. Where your data reaches the United States, we rely on the EU–US Data Privacy Framework (the European Commission’s adequacy decision of 10 July 2023) for certified companies, with the Commission’s Standard Contractual Clauses as a backstop in our contracts.

How long we keep it

DataKept for
The photo you shareDeleted automatically 90 days after your print is delivered. Drafts that never become an order: deleted 30 days after their last activity.
The finished artwork filesKept so we can honour a remake and your two-year guarantee.
Invoice and order records10 years.
Emails you send us24 months.
The marketing listUntil you unsubscribe, plus a record of your consent for up to 12 months after, so we can show we never mailed you without permission.
Site statisticsAggregate only. Nothing points back to you.

Cookies

The essentials below always work. Advertising cookies are set only after you allow them in the banner, and you can change that choice at any time: Cookie settings, in the footer.

CookieFromLastsWhat it does
atcy-regionUs12 monthsYour shop region (US or EU), set on your first visit from your location or browser language. Prices and shipping depend on it.
atcy-countryUs12 monthsThe country you pick in the country switcher.
atcy-ads, atcy-ads-atUs6 monthsYour cookie choice itself, and when you made it.
Sign-in cookieUsWhile signed inUsed only by our own staff. Customers do not have accounts.
Basket draftUs (session storage, not a cookie)Until the tab session endsYour order in progress, kept in your browser.
__stripe_mid, __stripe_sidStripe12 months / 30 minutesSet during checkout for secure payment and fraud prevention.
__cf_bmOur network security providerAbout 30 minutesTells real visitors apart from bots.
_fbp, _fbc, _ttpMeta and TikTok3 months / 3 months / 13 monthsAdvertising cookies. Set only after you allow them; choosing Essentials only removes them.

Advertising

With your permission, we use the Meta Pixel and the TikTok Pixel. These tools set cookies and collect: the pages you visit here, the actions you take (for example, viewing a world or starting checkout), and device information such as your browser type and IP address. That data goes to Meta Platforms Ireland Limited and TikTok Technology Limited, who use it to show you our ads on their platforms, to measure how those ads perform, and for their own purposes described in their privacy policies: Meta · TikTok. For that use they are independent controllers.

You can withdraw your permission at any time: Cookie settings, in the footer, one click. You can also control the ads you see in your Meta ad preferences and your TikTok settings. We never share the photo, the artwork, or your delivery address with advertising partners.

Email

Order emails are part of the service: the preview, the approval, the dispatch and the tracking. Marketing email happens only if you ticked the box at checkout or joined the list in the footer. Every marketing email contains an unsubscribe link that works with one click.

How we protect it

Connections to the site are encrypted. Your files are stored in access-controlled data centres in the EU. Card details never reach us. Access to order data is limited to the people who make and deliver your order. If a breach ever puts your data at risk, we tell you and the supervisory authority without undue delay.

Your rights

You can ask for a copy of your data, have it corrected, have it deleted, restrict its use, object to its use, and take your data with you. Consent, once given, can be withdrawn at any time — withdrawal does not undo processing that already happened lawfully. Objection to marketing always works, immediately and without a reason. Write to [email protected]; we answer within one month. We make no automated decisions about you and we build no profiles.

If you think we mishandled your data, tell us first. We would rather fix it. You can also complain to the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), Drukpersstraat 35, 1000 Brussels, [email protected], or to your own country’s authority if you live elsewhere in the EU.

For customers in the United States

Every right on this page is offered to every customer, wherever you live. We do not sell your personal information. Under California law, advertising cookies count as “sharing” — you control them with Cookie settings in the footer, and we treat a Global Privacy Control browser signal as a request not to share, and honour it. This shop is sold to adults. US children’s privacy law (COPPA) covers data collected online from children under 13, not information a parent gives us about their own child, and we knowingly collect nothing from children directly. Your data is processed in Europe.

Changes

If we change something meaningful, we update this page and its date; if a change affects how we use the photo or the child’s data, we email you before it takes effect. See also our terms.