Free shipping worldwide · 30×40cm · Fits standard frames

Privacy Policy

Last updated: 23 June 2026

Who controls your data

Pictor is the data controller for the personal data you provide through this website. If you have any questions about how your data is handled, email [email protected].

What data we collect and why

When you place an order

We collect your name, email address, shipping address, and payment details.

  • Lawful basis: Contract (Article 6(1)(b) UK GDPR). We need this information to fulfil your order, process payment, and arrange delivery.
  • Retention: Order data is kept for six years after the order is fulfilled, as required by UK tax law. After that, it is deleted or anonymised.

When you sign up for the newsletter

We collect your email address only.

  • Lawful basis: Consent (Article 6(1)(a) UK GDPR). You actively opt in and can unsubscribe at any time.
  • Retention: Until you unsubscribe. If you unsubscribe, your email is removed from the active list within 48 hours.

When you browse the website

We use Google Analytics 4 to understand how visitors use the site. GA4 collects anonymised data about pages visited, time spent, and browser type. It does not identify you personally. Your IP address is anonymised before it is stored.

  • Lawful basis: Consent (for non-essential cookies). GA4 cookies are only set after you accept cookies through the cookie banner. You can decline or withdraw consent at any time.
  • Retention: 14 months (GA4 default).

Who we share data with

We do not sell your personal data. We share data only with the services necessary to process and fulfil your order:

  • Stripe (payment processing) - receives your name, card details, and billing address. Stripe operates under UK GDPR and uses Standard Contractual Clauses for US data transfers. Stripe Privacy Policy
  • Gelato (print fulfilment) - receives your name, shipping address, and order details to print and deliver your poster. Gelato operates from Europe. Gelato Privacy Policy
  • Google (analytics) - receives anonymised browsing data via GA4. Google operates under UK GDPR and uses Standard Contractual Clauses for US data transfers. Google Privacy Policy
  • Netlify (hosting) - receives your IP address as part of normal web server operation. Netlify Privacy Policy
  • Mailchimp or Klaviyo (email marketing) - receives your email address if you subscribe to the newsletter.

International data transfers

Stripe and Google may transfer data to the United States. Both rely on Standard Contractual Clauses approved by the UK Information Commissioner to ensure your data receives adequate protection. Gelato operates within Europe. The UK has an adequacy decision from the European Commission (renewed December 2025, valid until December 2031), so data flows between the UK and EEA are unrestricted.

Your rights under UK GDPR

You have the following rights regarding your personal data:

  • Right of access - request a copy of the data we hold about you
  • Right to rectification - correct inaccurate data
  • Right to erasure - request deletion of your data
  • Right to data portability - receive your data in a machine-readable format
  • Right to object - object to processing based on legitimate interests or direct marketing
  • Right to restriction - restrict how we process your data

To exercise any of these rights, email [email protected]. We will respond within 30 days.

How to make a complaint

If you believe we have handled your data incorrectly, please email us first at [email protected]. We will investigate and respond within 30 days.

If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO), the UK regulator for data protection:

Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
ico.org.uk | 0303 123 1113

From 19 June 2026, UK law requires you to raise your complaint with us first before contacting the ICO.

Cart (0)

Your cart is empty

Browse posters