upTownArt
Privacy policy
We process only data needed for the marketplace, communication, and features you choose.
Controller
Michael König-Weichhardt, trading as upTownArt, Sporgasse 24, 8010 Graz, Austria
Privacy enquiries: michael@uptown.art
Marketplace, order and account
For carts, intermediation, orders, payments and optional accounts we process contact, delivery, order and payment-status data. The relevant seller receives the order and delivery data required for their purchase contract. Legal bases are contract performance or pre-contractual steps, legal obligations and our legitimate interest in secure marketplace operation. Stripe processes card data; we do not receive complete card details.
Artist accounts, direct payments and commissioned fulfilment
For active artist accounts we process profile, plan, product and settlement information. Stripe Connect collects and verifies identity, bank, payment and payout details directly. Buyer payments are processed as direct payments in the relevant seller's connected Stripe account; upTownArt receives the agreed commission as a Stripe application fee. upTownArt stores the Stripe account ID, connection status and amounts required for settlement and refunds. Optional manual payout destinations are encrypted at rest and displayed only in masked form.
A seller may independently pass the order and delivery data needed for production and delivery to a directly commissioned production or fulfilment service, such as a print-on-demand provider, merch-store provider, printing service, local producer, or fulfilment service. The seller is responsible for the legal basis, contractual safeguards, data security, and deletion by that service. upTownArt does not select or commission the service and receives no service-provider documents.
Statutory platform reporting under DAC7/DPMG
As an Austrian platform operator, upTownArt processes private seller identity and tax data to comply with DAC7 and the Austrian Digital Platform Reporting Obligation Act (DPMG). Depending on the seller's legal form, this includes the legal name, primary address, every Tax Identification Number actually issued and its issuing country or—where no TIN was issued to an individual—their place of birth, residence countries derived from those details, date of birth, company or other register details, VAT identification number, reported permanent establishments and, where legally required and available to upTownArt, the financial-account identifier and a different account holder. These details are not public and are not collected on the basis of consent; the legal basis is Article 6(1)(c) GDPR together with the DPMG.
For reportable sellers, upTownArt aggregates the consideration credited or paid and the number of relevant activities per quarter. Information required by law is sent to the Austrian tax office and may be exchanged automatically with competent tax authorities in other countries as provided by law. upTownArt informs each affected seller before each report about the reportable information concerning them. If a different account holder is affected, that account holder is also informed before the intended transmission of their financial-account identifier. VAT small-business treatment does not automatically exempt this data collection.
Data and evidence processed or transmitted for a DPMG report are normally deleted ten years after the end of the reporting period unless another statutory retention duty or pending proceeding requires longer retention. Sellers must correct inaccurate or changed information without delay.
Comments, reactions and artist community
Comments and reactions are linked to a signed-in account and to the relevant product and artist IDs. For comments we store the account display name and avatar, an optional title, original text, language and moderation state. Our EU-hosted translation infrastructure may translate comments for bilingual display while the original remains unchanged.
Receiving community messages from an artist is voluntary and requires separate recorded consent. A reaction or comment alone is not newsletter consent. After a product is archived, a confirmed community contact is retained only until withdrawal, unsubscribe or account deletion.
Analytics and personalization
Product views for personal suggestions and pseudonymous reach statistics are counted only after consent. Artists see aggregated counts, not individual browsing histories. Consent can be withdrawn at any time in Cookie settings; local view cookies are then removed and no new views are counted. Previously formed pseudonymous aggregate data may remain until its technical maximum lifetime of 180 days expires.
Newsletter and studio mail
The general upTownArt newsletter and studio mail from individual artists are voluntary and separate. Each is sent only after a separate registration and confirmation through a double-opt-in link. Every message contains an unsubscribe option. Registration and consent evidence is retained while consent remains valid and afterwards only where needed to establish, exercise or defend legal claims.
Voluntary online meetings through Google Meet
When an online meeting is published, we process its title, description, date and time, time zone, language, and the email addresses of registered or invited people. Mailgun sends an invitation and one reminder containing a private link to the upTownArt meeting page. The actual Google Meet link is neither displayed publicly nor exposed in the invitation email. The legal basis is fulfilling the requested registration or our legitimate interest in secure personal communication.
Participation is voluntary. Only after a participant opens the join link does Google, as a separate video-conferencing service, process information such as an account or display name, IP address, browser, device and connection details and, depending on use, audio/video data, screen shares, chat and other meeting data. Camera and microphone are used only after browser permission. The private meeting page links to Google's Privacy Policy and Terms of Service.
upTownArt normally deletes meeting, recipient and delivery records ninety days after the meeting ends unless a mandatory legal duty or a specific legal matter requires longer retention. Google credentials are not stored in meeting records or emails.
Product safety, notices and recalls
To review product listings, we process product and variant identifiers, manufacturer and responsible-person details, warnings and safety information, review state, sources, notices and immutable evidence of the product information displayed at the time of an order. Legal bases are statutory product-safety and marketplace duties, contract performance and our legitimate interest in operating a safe marketplace.
For safety warnings and recalls, upTownArt and the responsible economic operators use existing order and contact data to notify identifiable affected buyers directly. These legally required messages are sent without newsletter consent, contain no advertising and cannot be prevented through a marketing unsubscribe.
Product reviews, notices, authority orders, delivery attempts, acknowledgements and remedies are deleted only under a documented retention schedule. A hold for an active authority, recall, dispute, litigation or tax matter prevents deletion while the purpose continues. Public recall pages contain no buyer, order or private-token data.
Processors and retention
We use Cloudflare for hosting and security, Stripe for payments, Mailgun for transactional email, the general newsletter and voluntarily subscribed studio mail, and our EU-hosted AIO infrastructure for translations. Order, payment, refund and settlement records are retained for up to ten years to meet statutory documentation and evidence duties and to protect legal claims. They are then automatically deleted or anonymized unless a longer statutory duty or pending proceeding requires otherwise. Data without an ongoing purpose or legal basis is deleted or anonymized earlier.
Your rights
You may request access, correction, deletion, restriction, portability, objection and withdrawal of consent. Complaints may be lodged with the Austrian Data Protection Authority.
