Privacy Policy

We're committed to protecting your privacy and being transparent about how we handle your data.

1. Introduction

Welcome to Pacco ("we," "our," or "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service at pacco.studio.

This policy applies to all information collected through our website, application, and related services (collectively, the "Service").

2. Data Controller Information

Pacco is operated by:

Gui Rodrigues Cruz Pereira
Avenue des Criquets 17
1170 Watermael-Boitsfort
Brussels, Belgium
VAT: BE1004915644

For privacy-related inquiries, please contact us at: privacy@pacco.studio

3. Information We Collect

3.1 Information You Provide to Us

Account Information:

  • Full name
  • Email address
  • Business/company name and information
  • Profile photo
  • Username and password

Payment Information:

  • Billing address
  • Payment details processed through Stripe (we do not store card numbers)

Content Information:

  • Photos uploaded to galleries
  • Gallery names and descriptions
  • Client email addresses (for gallery sharing)

3.2 Information Automatically Collected

Technical Data:

  • IP address
  • Browser type and version
  • Device information
  • Usage data through Pirsch Analytics
  • Interaction data through Meta Pixel

Cookies and Tracking:

  • Essential/functional cookies
  • Analytics cookies
  • Marketing/advertising cookies
  • Third-party cookies (Meta Pixel)

4. How We Use Your Information

We use your personal information for the following purposes:

  • Service Provision: To create and manage user accounts
  • Payment Processing: To process payments and transactions
  • Communications: To send transactional emails (password resets, receipts, gallery shares)
  • Marketing: To send marketing communications (with your consent)
  • Support: To provide customer support
  • Improvement: To improve our service through analytics
  • Legal Compliance: To comply with legal obligations
  • Security: To prevent fraud and ensure platform security
  • Features: To enable sharing features (galleries with clients)

5. Legal Basis for Processing (GDPR)

We process your personal data under the following legal bases:

  • Consent: For marketing communications and analytics
  • Contract Performance: To provide our services and process payments
  • Legal Obligations: To comply with applicable laws and regulations
  • Legitimate Interests: For security, fraud prevention, and service improvement

6. How We Share Your Information

We may share your information with:

6.1 Service Providers

  • Stripe: Payment processing
  • AWS (Amazon Web Services): Data storage
  • Vercel: Platform hosting
  • Resend: Email communications
  • Bunny.net: Content delivery network
  • Pirsch Analytics: Usage analytics
  • Meta: Analytics and advertising

6.2 Legal Requirements

We may disclose your information where required by law, court order, or governmental authority.

6.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.

7. Data Retention

We retain your personal information for the following periods:

  • Account Data: Deleted immediately upon account deletion request
  • Photos/Galleries: Deleted immediately upon deletion request
  • Payment Records: Retained for up to 20 years for legal and tax compliance
  • Analytics Data: Retained according to Pirsch Analytics' terms
  • Client Email Addresses: Deleted when photographer deletes their account

8. Data Security

We implement appropriate technical and organizational measures to protect your personal information:

  • SSL/TLS encryption for data in transit
  • Encryption at rest for sensitive data
  • Access controls and authentication systems
  • Regular security reviews

While we strive to protect your personal information, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.

9. Your Rights Under GDPR

As an EU resident, you have the following rights:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your personal data
  • Portability: Receive your data in a portable format
  • Object: Object to processing of your personal data
  • Restriction: Request restricted processing of your data
  • Withdraw Consent: Withdraw consent at any time
  • Complaint: File a complaint with your local supervisory authority

To exercise any of these rights, please contact us at privacy@pacco.studio

10. International Data Transfers

We only serve customers within the European Union. However, some of our service providers may process data outside the EU. Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.

11. Age Restrictions

Our Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from anyone under 18. If we become aware that we have collected personal data from someone under 18, we will take steps to delete that information.

12. Cookies Policy

We use cookies and similar tracking technologies to track activity on our Service. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service.

Types of cookies we use:

  • Essential Cookies: Required for the Service to function properly
  • Analytics Cookies: Help us understand how users interact with our Service
  • Marketing Cookies: Used to track visitors across websites for advertising purposes

13. Gallery-Specific Information

13.1 Public Galleries

Galleries are public by default. Public galleries may be used for marketing and demonstration purposes with the photographer's consent.

13.2 Client Access

Gallery viewers (your clients) can access galleries without creating accounts. When you share a gallery, we collect the client's email address solely to send them the gallery link.

13.3 Photo Rights

We do not claim any ownership rights to photos you upload. You retain all rights to your content.

14. Data Breach Notification

In the event of a data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by:

  • Sending an email to your registered email address
  • Posting the new Privacy Policy on this page

You are advised to review this Privacy Policy periodically for any changes.

16. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at:

Email: privacy@pacco.studio
Address:
Gui Rodrigues Cruz Pereira
Avenue des Criquets 17
1170 Watermael-Boitsfort
Brussels, Belgium

17. Supervisory Authority

If you are not satisfied with our response to your privacy concerns, you have the right to lodge a complaint with your local data protection authority. For Belgium, this is:

Belgian Data Protection Authority (APD/GBA)
Rue de la Presse 35
1000 Brussels
Belgium
contact@apd-gba.be


By using Pacco, you acknowledge that you have read and understood this Privacy Policy.

Questions about your privacy?

We're here to help you understand how we protect your data.