1. About this policy
Summary
Everyone gets the same GDPR-level privacy protections, wherever you live. We do not sell your data. We do use what you upload and what the AI makes for you to improve our AI models. You can opt out any time in settings.
This Privacy Policy explains how Snowcone collects, uses, shares, and protects personal information when you use our consumer marketplace at snowcone.app, our developer platform at developers.snowcone.app, our API, and any related services (collectively, the "Service"). It applies to information we process as a controller. Where we process information on behalf of a business customer (for example, when you use our developer API to operate your own product), the business customer is the controller and our role is described in our B2B Data Processing Addendum.
One global standard. The rights in this policy apply to every Snowcone user, regardless of where you live. We give every user the same data-protection guarantees the European Union's GDPR gives EU residents β access, deletion, portability, rectification, objection to processing, withdrawal of consent, transparency about who processes your data and why, and a 30-day default response window on rights requests. Where the law of your country gives you additional rights or sets a stricter rule, those rights apply too. Region-specific rights and pointers to country-mandated parallel documents (including our Mexican Aviso de Privacidad) are listed in section 18 below.
2. Who we are
- Controller: Art Shop AI LLC d/b/a Snowcone, a Delaware limited liability company (file number 7347980), 611 South DuPont Highway, Suite 102, Dover, Delaware 19901, USA.
- Privacy contact: privacy@snowcone.app.
- EU representative (GDPR Art 27): we will appoint a representative established in the European Union before directing services to the European Economic Area; until then, EEA-resident users may contact us directly at the privacy address above and we will respond on the same timetable as we would through a representative.
- UK representative (UK GDPR Art 27): we will appoint a UK-resident representative before directing services to the United Kingdom; until then, UK users may contact us directly at the privacy address above.
For region-specific designations (Quebec person responsible under Law 25; Mexican "responsable" under LFPDPPP), see section 18 below.
3. The personal information we process
We process the following categories of personal information:
- Account information. Name, email address, password hash (we never store passwords in plaintext), country, language preference, and any profile information you choose to provide.
- Design uploads. Images, vector files, and other artwork you upload to create custom merchandise.
- Reviews and review media. The text, photos, videos, and ratings you submit when reviewing products. Photos and videos may include images of identifiable individuals; we treat such media as sensitive personal information and ask for separate explicit consent before processing it (see section 6).
- Order and payment metadata. Shipping address, billing address, order line items, transaction amount, the last four digits and brand of the payment method, tax-jurisdiction information. We do not store full payment-card numbers β those go directly to Stripe under PCI DSS.
- Communications. Email correspondence, support tickets, feedback you submit, review-solicitation responses, content you send to the chat assistant.
- AI prompts and generated content. When you use AI features, we process your prompts and any reference images you provide, and we store the AI-generated outputs you save. We also use these inputs and outputs to improve our AI models β see section 5 for the legal basis and section 11 for the opt-out.
- Device, technical, and usage information. IP address, browser type, operating system, referring URL, pages viewed, actions taken, timestamps. Detail in our Cookie Policy.
- Cookies and similar technologies. See our Cookie Policy for a category-by-category disclosure.
- Approximate location. Derived from your IP address (country / region) for tax, currency, language, and shipping options. We do not collect precise device-level geolocation.
- Inferences. We may infer product or design preferences from your activity to personalize the marketplace (e.g. recommended designs, similar items). We do not build a profile to predict your characteristics outside of these product-suggestion features.
4. Where we get it from
We collect most personal information directly from you when you use the Service. We also receive information from:
- Payment and tax processors β Stripe returns billing-identity, fraud signals, and tax-jurisdiction information when you complete a purchase.
- Single sign-on providers β if you sign in with Apple, Google, or another provider, we receive the email address, display name, and provider-specific identifier you authorize.
- Shipping carriers and aggregators β we receive tracking events (scan locations, delivery status) from carriers and from Ship24.
- Fulfillment partners β when an order is fulfilled by a decorator (for example, SanMar or FM Expressions), we receive shipment confirmations and exception reports.
- Public sources β for marketplace listings of public-domain or Creative Commons-licensed designs, we may pull metadata from public catalogs. We do not enrich your account from public sources.
5. Why we process your information
| Purpose | Lawful basis (EU/UK GDPR Art 6) |
|---|---|
| Provide the Service: account creation, design tools, checkout, order fulfillment, customer support. | Contract performance (Art 6(1)(b)). |
| Process payments and prevent fraud. | Contract (Art 6(1)(b)) + legal obligation (Art 6(1)(c)) for tax records + legitimate interests (Art 6(1)(f)) for fraud. |
| Send transactional emails (order confirmation, shipping, account changes, security alerts). | Contract performance (Art 6(1)(b)). |
| Send marketing emails about new products and features. | Consent (Art 6(1)(a)) for first-time recipients; soft opt-in for existing customers under PECR Reg 22(3)(b) and ePrivacy. |
| Solicit reviews after a purchase. | Legitimate interests (Art 6(1)(f)) β operating an authentic marketplace is a recognised legitimate interest; balanced against your right to object. |
| Publish reviews you submit. | Consent (Art 6(1)(a)) β publication is opt-in at submission. |
| Use AI features (image generation, background removal, upscaling, video synthesis). | Contract performance (Art 6(1)(b)) for the feature itself. |
| Improve our AI models β including using your inputs (prompts, reference images) and the outputs we generate for you to train and refine the models that power our generative-AI features. | Legitimate interests (Art 6(1)(f)) β operating and improving a generative-AI product is a recognised legitimate interest, balanced against your right to object under Art 21. You can opt out at any time (see section 11). |
| Detect abuse, prevent platform misuse, enforce our Acceptable Use Policy, respond to intellectual-property notices. | Legitimate interests (Art 6(1)(f)) and legal obligation (Art 6(1)(c)) where applicable. |
| Comply with Digital Services Act notice-and-action obligations and similar laws. | Legal obligation (Art 6(1)(c)). |
| Improve the Service through aggregated, de-identified analytics. | Legitimate interests (Art 6(1)(f)). |
| Respond to lawful requests, exercise legal rights, defend against legal claims. | Legal obligation (Art 6(1)(c)) and legitimate interests (Art 6(1)(f)). |
6. Sensitive personal information
- Photos and videos in reviews. When you upload images or video to a review, those files may contain identifiable likenesses. We treat such media as sensitive personal information for every user β regardless of where you live β and we do not process it without your separate, explicit consent collected at the point of submission.
- Account-recovery information. Email and any passkey or recovery factor you set up are used to recover your account; we do not use them for advertising or sale.
- Sensitive-PI use limit. Where the law of your country gives you a right to limit our use of sensitive personal information to what is necessary to provide the Service, you can exercise that right at /privacy-requests.
- No biometric identification β hard rule. We do not extract face embeddings, scan-of-face geometry, voiceprints, fingerprint templates, or any other biometric identifier from review media or any other content you submit. We do not perform 1:1 matching, 1:N identification, or biometric-based content moderation. This rule is absolute and applies regardless of opt-in. If we ever change this posture we will obtain separate explicit consent under Illinois BIPA, Texas CUBI, Washington biometric law, GDPR Art 9, and LFPDPPP Art 9 before processing any biometric data.
8. International transfers
Snowcone is operated from the United States. We process personal information in the United States and in other countries where our sub-processors operate (including the European Economic Area, the United Kingdom, Estonia, France, Ireland, and the United States).
For transfers from the European Economic Area, the United Kingdom, or Switzerland to a country that does not benefit from a European Commission adequacy decision, we rely on the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914, as updated for the UK by the UK Addendum) as the safeguard under GDPR Art 46(2)(c) and UK GDPR Art 46(2)(c). We complete a Transfer Impact Assessment for each such transfer in line with the European Court of Justice's Schrems II ruling (Case C-311/18, 16 July 2020).
Where the recipient operates under an applicable adequacy decision (for example, transfers to recipients within the EEA, the United Kingdom, or other adequacy-listed jurisdictions), we rely on that adequacy decision under GDPR Art 45.
Where the law of the country where you live imposes additional or different transfer requirements, we comply with those requirements as well. Country-specific transfer obligations are described in section 18.
9. How long we keep it
| Category | Retention |
|---|---|
| Account profile | For as long as your account is active, plus 30 days after you delete the account (grace period for accidental deletion per ADR-0063 Β§5). |
| Designs and design history | For as long as you keep them; deleted when you delete the design or the account. |
| Order records (line items, shipping, fulfillment events) | Retained for the period required by tax, accounting, and consumer-protection law in the relevant jurisdiction (typically 7 years in the US; 10 years in Germany; statutory equivalents elsewhere). Retention for these purposes survives account deletion. |
| Reviews you have submitted | Pseudonymised on account deletion (display name removed, content preserved) so review aggregates remain accurate. We do not destroy review aggregates β pseudonymisation, not deletion, per GDPR Art 17 + ADR-0062 Β§14. |
| Consent log | 3 years from last consent change (ADR-0065 Β§4.5). |
| DSAR records | 3 years from request closure for audit/regulator. |
| Transactional and security logs | Up to 18 months in primary stores; longer when required by security incident review or legal hold. |
| Backups | Encrypted backups roll over on a 35-day cycle. Deletion requests are honored in primary stores immediately and in backups by overwrite within the 35-day cycle. |
10. Your rights
Summary
You can ask to see, delete, export, or correct your data. You can object to how we use it, withdraw consent, opt out of sale, and opt out of AI training. Make any request at /privacy-requests. We answer within 30 days, or faster where the law requires.
You may have the following rights, depending on where you live:
- Access to the personal information we hold about you, including a portable export.
- Correction of inaccurate or incomplete information.
- Deletion of your information, subject to exceptions (we keep certain order records for tax purposes; we pseudonymise rather than destroy review aggregates).
- Portability in a structured, commonly used, machine-readable format (EU/UK only by GDPR Art 20).
- Restriction or objection to specific kinds of processing, including review-solicitation emails.
- Opt out of AI-model training. Our default posture is to use your inputs and the outputs we generate for you to improve our AI models, on the legitimate- interests basis described in section 5. You can object to this processing at any time and we will exclude your content from future training runs. See section 11 for the mechanism. We do not train on review media that depicts identifiable individuals β that is a hard rule, not an opt-out (LFPDPPP Art 3-VI / CPRA sensitive PI / future EU AI Act biometric tier).
- Withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
- Opt out of "sale" or "sharing" as defined under California, Colorado, Connecticut, Virginia, and similar US laws. We do not currently engage in either; this right is preserved as a floor.
- Limit use of sensitive personal information (California CPRA Β§1798.121).
- Non-discrimination β we will not deny, charge differently, or provide a different quality of service because you exercise a privacy right.
- Authorised agent β California, Colorado, and other jurisdictions allow you to designate an authorised agent to submit requests on your behalf.
- Complain to a regulator. See section 17 for the relevant authorities in your jurisdiction.
11. How to exercise your rights
Summary
One portal at /privacy-requests. It works whether or not you are signed in. You can also opt out of AI training with one click in account settings.
Submit a request through our unified portal at /privacy-requests. If you are not signed in, you will receive a magic link to verify the email address associated with your account; we use this only to confirm we are responding to the right person.
AI-training opt-out, specifically: submit a request through /privacy-requests and select "Object to AI-model training." Once we process the request, your existing content is excluded from future training runs and any future inputs you submit will be tagged at submission time. The change takes effect immediately for prospective use; we do not delete model weights derived from prior training (technically not reversible without retraining the entire model β Art 21 objection is to future processing, not historical model outputs).
We respond within 30 days of receipt as our global default. Where the law of the country where you live requires a faster response or permits an extension for complex requests, we honor that timing.
You will not be charged for routine requests. We may charge a reasonable fee or refuse a request that is manifestly unfounded or excessive (in particular, repetitive); in that case we will explain our reasoning in the response.
12. Automated decision-making
We use automated systems for limited purposes β fraud screening at checkout, bot-detection during sign-up and account access, IP moderation of design uploads, and content moderation of reviews. These systems can result in your account being limited, your design being blocked, or your review being held for human review.
These decisions are not fully automated for outcomes that significantly affect you: a human reviewer confirms account suspensions, IP moderation hide-actions, and review take-downs before the action takes effect, except in narrow safety-driven cases (active fraud or active rule violations) where reversal is offered.
You have the right to human review and to contest these decisions. For Digital Services Act decisions on user-generated content (review take-downs, listing removals, account restrictions), you receive a statement of reasons explaining the decision and the appeal route per Articles 17 and 20 of the DSA. Submit appeals through the contact route in the statement-of-reasons email, or through /privacy-requests.
14. Children
Snowcone is not directed to children. The minimum age to create an account is whatever age the law of your country sets for digital-services consent; if your country does not specify one, the minimum age is 16. Where your country's law requires verifiable parental consent below a higher contract-capacity age, we obtain that consent before creating the account.
The age threshold for some markets we serve:
- United States: 13 (we apply COPPA β we do not knowingly collect personal information from children under 13). California residents under 16 receive an additional opt-in for any "sale" or "sharing" of personal information (CA Civ. Code Β§1798.120(c)) β we do not sell or share, but the right is preserved.
- European Economic Area: 16 by default; the digital-services-consent age varies by member state under GDPR Art 8(1) (some states set it as low as 13). We apply 16 unless the user's registered country sets a different age.
- United Kingdom: 13 (per ICO Age Appropriate Design Code).
- Mexico, Quebec, and other markets where the age of contractual capacity is 18: 18, with conditional registration for users between the digital-services-consent age and 18 only with verifiable parental consent.
We do not knowingly collect personal information from children below the applicable age. If you believe a child has provided us with personal information, contact us at privacy@snowcone.app and we will promptly delete it.
15. Security
We implement technical and organisational measures designed to protect personal information against unauthorised access, disclosure, alteration, and destruction, taking into account the state of the art, the cost of implementation, and the nature, scope, context, and purposes of processing. Our measures include:
- Encryption. Data in transit is protected by TLS 1.2 or higher; data at rest is encrypted using industry-standard algorithms.
- Access control. Role-based access with least-privilege defaults; multi-factor authentication for personnel access to production systems; written confidentiality obligations for all personnel.
- Audit and monitoring. Administrative and access events are logged and retained for at least 18 months. Production systems are monitored for security events on a 24/7 basis.
- Vendor due-diligence. Sub-processors are assessed before onboarding and bound by written data-processing agreements with flow-down obligations. See /legal/sub-processors for the current list.
- Vulnerability management. Regular security review, dependency scanning, and patch management for systems handling personal information; an internal incident-response runbook with on-call coverage.
- Payment card data. We never store full payment-card numbers on our systems. Card data is transmitted directly to Stripe under PCI DSS controls.
No system is perfectly secure. If we become aware of a personal-data breach that is likely to result in risk to you, we will notify you and the appropriate regulator within the timeframes required by applicable law (in the EU and UK, that means notice to the supervisory authority within 72 hours under GDPR Art 33 / UK GDPR Art 33; notice to affected individuals "without undue delay" where the breach is likely to result in a high risk under GDPR Art 34). For security disclosures, write to security@snowcone.app.
16. Changes to this policy
We may revise this policy from time to time. The version number and effective date appear at the top of this page. Historical versions remain reachable at /legal/privacy/v<version>.
For material changes β those that expand the categories of personal information we collect, change the purposes of processing, or introduce a new sub-processor that meaningfully changes who receives your information β we will post the change at least 30 days before it takes effect, send notice to your account email, surface a banner on the site, and re-prompt you to review your cookie preferences.
17. Contact us and how to complain
Designated contacts:
- Privacy questions and rights requests: privacy@snowcone.app or /privacy-requests.
- Security disclosures (responsible disclosure): security@snowcone.app.
- Copyright / IP notices (DMCA agent): copyright@snowcone.app β see the Intellectual Property Policy for the Β§512(c) elements.
- California "Shine the Light" requests (Cal. Civ. Code Β§1798.83): California residents may request, once per year, a disclosure of personal information we shared with third parties for those third parties' direct marketing purposes during the prior calendar year. We do not share personal information for that purpose, but you can request written confirmation by writing to privacy@snowcone.app with the subject line "Shine the Light Request" and including your California postal address. We will respond within 30 days.
- Postal address: Art Shop AI LLC d/b/a Snowcone, Attn: Privacy, 611 South DuPont Highway, Suite 102, Dover, Delaware 19901, USA.
If you are not satisfied with our response, you have the right to lodge a complaint with the data-protection supervisory authority in the country where you live. For users in the European Economic Area, a list of national authorities is at edpb.europa.eu/about-edpb/members; for UK users, the Information Commissioner's Office at ico.org.uk; for California users, the California Privacy Protection Agency at cppa.ca.gov.
18. Region-specific rights
The body of this Privacy Policy gives every user the same GDPR-level rights. The dedicated subsections below list additional rights and country-mandated parallel notices for users in specific jurisdictions.
18.1 California (and other US states with comprehensive privacy laws)
California residents have the rights set out in the body above plus, under CCPA / CPRA: the right to know the categories and specific pieces of personal information collected; the right to delete; the right to correct; the right to opt out of sale or sharing for cross-context behavioral advertising; the right to limit use of sensitive personal information; and the right to non-discrimination for exercising these rights. We do not sell or share personal information for cross-context behavioral advertising. The Global Privacy Control signal is honored on each browser where it is sent. To exercise California rights, use /privacy-requests.
Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Iowa, Tennessee, Indiana, Delaware, New Hampshire, New Jersey, Minnesota, Maryland, and Kentucky have analogous rights under their respective state comprehensive privacy laws and may exercise them through the same portal.
18.2 European Economic Area, United Kingdom, and Switzerland
Where this Privacy Policy refers to GDPR, the equivalent provisions of the UK GDPR + UK Data Protection Act 2018 apply to UK residents, and the equivalent provisions of the Swiss Federal Act on Data Protection apply to Swiss residents.
Our designated representatives under GDPR Article 27 (for EEA residents) and UK GDPR Article 27 (for UK residents) will be appointed before we direct services to those markets. Until then, EEA and UK users can reach us directly at privacy@snowcone.app and we will respond on the same timetable as we would through a representative.
Cross-border transfers from the EEA, UK, or Switzerland to the United States and other non-adequate jurisdictions rely on the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914) and the UK Addendum, with Transfer Impact Assessments completed in line with Schrems II (CJEU C-311/18, 16 July 2020).
18.3 Mexico
Mexican residents β see our parallel Aviso de Privacidad, which is required by LFPDPPP Article 17 in addition to (not in place of) this Privacy Policy. The Aviso contains the identity and address of the responsable, the integral enumeration of personal data we collect, primary and secondary purposes, the ARCO-rights mechanism, the cross-border transfer provisions under LFPDPPP Articles 36 and 37, and the contact for the competent authority.
18.4 Quebec
Quebec residents have the rights set out in the body above plus, under Quebec's Act respecting the protection of personal information in the private sector ("Law 25"): the right to access, the right to rectification, the right to withdraw consent, the right to data portability (since September 2024), and the right to know about the use of any automated decision-making that produces effects on you. To exercise these rights, use /privacy-requests.
The person responsible for the protection of personal information at Snowcone, designated under section 3.1 of Law 25, is Kevin Sproles, Chief Executive Officer. You may contact the person responsible at privacy@snowcone.app (subject line: "Quebec Law 25 β Person Responsible") or by mail to the postal address in section 17.
If you are dissatisfied with our handling of your request, you may lodge a complaint with the Commission d'accès à l'information du Québec at cai.gouv.qc.ca.
19. Document version
The current version and effective date appear at the top of this page. Sub-processor changes are tracked separately at /legal/sub-processors.
Last updated . Previous versions available on request.
Read the Cookie Policy β
