Glimors

Privacy Policy

Your privacy is fundamental to how we build and operate Glimors

Last updated: January 1, 2025 · Effective: January 1, 2025

Privacy at a Glance

  • We never access or view your photos without explicit permission
  • Your Google Drive files remain in your Drive - we only read them to display in galleries
  • We use industry-standard encryption for all sensitive data
  • You can delete your account and all associated data at any time
  • We never sell your personal information to third parties

Information We Collect

Account Information

When you create an account, we collect:

  • Your name and email address from Google OAuth
  • Google account ID for authentication
  • Profile picture URL from your Google account
  • Business name (if provided)

Google Drive Access

To provide our service, we request permission to:

  • View and download files from folders you explicitly select
  • View basic metadata (file names, sizes, modification dates)
  • We NEVER modify, delete, or move your Drive files
  • We ONLY access folders you specifically link to galleries

Gallery and Usage Data

We collect information about how galleries are used:

  • Gallery settings (name, password hash, watermark preferences)
  • View counts and download statistics
  • Client favorites (stored anonymously with session IDs)
  • Bandwidth usage for billing purposes

Payment Information

For paid subscriptions:

  • Payment processing is handled entirely by Stripe
  • We never store credit card numbers or banking information
  • We only store your Stripe customer ID and subscription status

How We Use Your Information

To Provide Our Service

  • Display your photos in galleries for your clients
  • Generate ZIP downloads when requested
  • Apply watermarks and gallery settings you configure
  • Sync changes from your Google Drive folders

To Improve Our Service

  • Analyze usage patterns to improve features
  • Monitor performance and fix technical issues
  • Understand which features are most valuable

To Communicate With You

  • Send important service updates and security alerts
  • Respond to support requests
  • Send billing and subscription notifications

Data Security

We take security seriously and implement multiple layers of protection:

  • Encryption at Rest: Google Drive tokens are encrypted using libsodium sealed box encryption
  • Encryption in Transit: All data transmitted uses HTTPS/TLS encryption
  • Password Protection: Gallery passwords are hashed using bcrypt
  • Access Controls: Strict database access controls and API rate limiting
  • Infrastructure: Hosted on secure cloud infrastructure with regular security updates
  • Signed URLs: Time-limited signed URLs for secure downloads

Data Sharing and Third Parties

We never sell your personal information. Period.

We share data only in these limited circumstances:

  • Service Providers: With tools that help us operate (Stripe for payments, Postmark for emails, Cloudflare for CDN)
  • Your Clients: Photos and gallery content you explicitly share via gallery links
  • Legal Requirements: If required by law, court order, or to protect rights and safety
  • Business Transfers: In the event of a merger or acquisition (with continued privacy protection)

All third-party services we use are carefully selected for their privacy practices and security standards.

Your Rights and Controls

You have full control over your data:

  • Access Your Data: Download a copy of all your data from your account settings
  • Update Information: Edit your profile and gallery settings at any time
  • Delete Galleries: Remove individual galleries and their associated data
  • Revoke Drive Access: Disconnect Google Drive access from your Google account settings
  • Delete Account: Permanently delete your account and all associated data
  • Export Data: Export your gallery settings and analytics data

Data Retention

  • Active Account Data: Retained as long as your account is active
  • Gallery Analytics: Retained for 90 days after gallery deletion
  • Cached Images: Automatically purged within 24 hours of Drive sync
  • Deleted Accounts: All data permanently deleted within 30 days
  • Backups: Backup data retained for 30 days for disaster recovery
  • Legal Holds: Data may be retained longer if required by legal obligations

Cookies and Tracking

We use cookies and similar technologies for:

  • Authentication: Keeping you logged in securely
  • Gallery Sessions: Remembering client passwords for galleries
  • Preferences: Saving your display and gallery settings
  • Analytics: Understanding how our service is used (anonymized)

We do not use tracking cookies for advertising purposes. You can control cookie settings in your browser.

International Data Transfers

Glimors operates globally. Your data may be processed in the United States and other countries where our service providers operate. We ensure appropriate safeguards are in place for international data transfers, including:

  • Standard contractual clauses with service providers
  • Ensuring providers maintain adequate security measures
  • Compliance with applicable data protection laws

Children's Privacy

Glimors is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us immediately for deletion.

Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any material changes by:

  • Sending an email to your registered email address
  • Displaying a prominent notice in your dashboard
  • Updating the "Last Updated" date at the top of this policy

Continued use of Glimors after changes indicates acceptance of the updated policy.

Contact Us

If you have any questions, concerns, or requests regarding this privacy policy or how we handle your data, please contact us:

Email: [email protected]

Support: [email protected]

Company: A Holdings Company LLC
dba Glimors
[Your Address]
[City, State ZIP]

Data Protection Officer: For privacy-specific concerns, you can reach our Data Protection Officer directly at [email protected]

Trademarks and Third-Party Services

Google Drive™ is a trademark of Google LLC. Glimors is not affiliated with, endorsed by, or sponsored by Google LLC. We are an independent service that integrates with Google Drive through publicly available APIs.

Stripe™ is a trademark of Stripe, Inc. We use Stripe for secure payment processing.

Supabase™ is a trademark of Supabase, Inc. We use Supabase for database services.

All other trademarks, service marks, and company names mentioned in this Privacy Policy are the property of their respective owners and are used for identification purposes only.

© 2025 A Holdings Company LLC. All rights reserved.

·