QARTA Privacy Policy
Last Updated: August 19, 2026
Introduction
QARTA (შპს მფრინავი სპილო / LLC Flying Elephant) is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our website qarta.ge and our services for creating personalized photo products (photo books, photo prints, and photo frames).
Data Controller:
შპს მფრინავი სპილო (LLC Flying Elephant)
Trading as: QARTA
Identification Number: 405681178
Address: 14 Merab Kostava St, Tbilisi, 0108, Georgia
Email: hi@qarta.ge
This Privacy Policy is based on the Law of Georgia on Personal Data Protection (No. 3144, adopted 14 June 2023, in force since 1 March 2024) and is aligned with GDPR principles.
1. Personal Information We Collect
1.1 Information You Provide Directly
When you register, place an order, or use our services, we collect:
Account Information:
- Full name
- Email address
- Phone number
- Delivery address
- Password (stored in encrypted form)
Order Information:
- Billing address
- Delivery preferences
- Order history
- Product preferences
Photos and Content:
- Photos you upload to create your photo products
- Any text, captions, or designs you add to your photo products
- Metadata embedded in your photos (which may include dates, locations, and camera information)
Communications:
- Messages you send us via email or contact forms
- Customer service correspondence via Crisp chat
- Feedback and reviews
1.2 Information Collected Automatically
When you visit our Website, we automatically collect:
Technical Information:
- IP address
- Browser type and version
- Operating system
- Device information
- Pages visited and time spent
- Referring website
- Click patterns and navigation
Cookies and Similar Technologies:
- Session cookies (essential for service function)
- Preference cookies (remember your settings)
- Analytics cookies (understand site usage)
- Marketing cookies (advertising measurement, used with consent)
1.3 Information from Third Parties
Payment Providers:
- Payment confirmation and transaction status
- We do NOT receive or store your full card details
Sign-In Providers (Google, Apple):
- If you choose to sign in with Google or Apple, we receive basic authentication data from the provider (your name and email address)
- We never receive your Google or Apple password
2. How We Use Your Personal Information
2.1 To Provide Our Services
✓ Order Processing:
- Create and print your photo products
- Process payments
- Arrange delivery
- Manage your account
✓ Customer Support:
- Respond to your inquiries via email and Crisp chat
- Resolve technical issues
- Handle returns and refunds
- Provide product support
✓ Communication:
- Send order confirmations
- Provide delivery updates via email and SMS
- Notify you of order status changes
- Send service-related announcements
2.2 To Improve Our Services
- Analyze how customers use our Website (via PostHog)
- Understand user behavior and session recordings (via PostHog)
- Improve our design tools
- Develop new features and products
- Optimize user experience
- Conduct internal research and analytics
2.3 Legal and Security
- Comply with Georgian legal obligations
- Prevent fraud and unauthorized access
- Enforce our Terms and Conditions
- Protect our rights and property
- Respond to legal requests from authorities
2.4 Marketing (With Your Consent)
- Send promotional emails about new products and offers
- Provide personalized recommendations
- Inform you about special discounts
- Measure the effectiveness of our advertising campaigns (Meta Pixel and Meta Conversions API; see Sections 10 and 18)
You can opt out of marketing communications and marketing tracking at any time.
3. Legal Basis for Processing
We process your personal data based on:
3.1 Contract Performance
Processing is necessary to fulfill our contract with you (creating and delivering your photo products).
3.2 Consent
You have given explicit consent for specific processing activities (e.g., marketing communications, marketing cookies). You may withdraw consent at any time.
3.3 Legitimate Interests
Processing is necessary for our legitimate business interests (e.g., fraud prevention, service improvement), provided your rights are not overridden.
3.4 Legal Obligation
Processing is required to comply with Georgian laws and regulations.
4. How We Share Your Information
4.1 Service Providers
We share information with trusted third-party service providers who help us operate our business:
Cloud Storage:
- Cloudflare R2 - stores your uploaded photos securely
- Photos are encrypted and access is restricted
Payment Processors:
- Card payments are processed by our payment gateway partners; Google Pay is available as a payment option through the same gateways
- Installment and split payments are provided by Bank of Georgia and TBC Bank under their own credit terms; the bank processes your data as an independent controller for the credit relationship
- We do not store your card details; processors handle this securely
Delivery Services:
- Courier companies receive your name, phone number, and delivery address
- This information is used solely for delivering your order
SMS Delivery Provider:
- Receives your phone number and the text of order status messages
- Used solely to deliver order-related SMS notifications
Advertising (Meta Platforms):
- We use Meta Pixel and the server-side Meta Conversions API to measure the effectiveness of our advertising on Facebook and Instagram
- Meta receives event data (such as pages viewed and purchases) together with hashed identifiers (such as a hashed email address)
- You can opt out of marketing cookies and tracking (see Section 10)
Sign-In Providers:
- Google and Apple, if you choose to sign in with them; they process your authentication, and we receive only basic profile data (name, email address)
Technical Services:
- Website hosting providers
- IT security and maintenance services
- PostHog - analytics and session recording platform for understanding user behavior
- Crisp - customer support chat platform
All service providers are contractually obligated to protect your data and use it only for specified purposes.
4.2 Legal Requirements
We may disclose your information if required to:
- Comply with Georgian laws and regulations
- Respond to legal processes (court orders, subpoenas)
- Protect our rights, property, or safety
- Protect the rights, property, or safety of others
- Prevent fraud or security threats
4.3 Business Transfers
If QARTA is involved in a merger, acquisition, or sale of assets, your personal data may be transferred. You will be notified of any such change.
4.4 With Your Consent
We may share your information with third parties if you give us explicit consent to do so.
We do NOT:
- Sell your personal data to third parties
- Share your data for third-party marketing without your consent
- Transfer your data except as described in this Policy (see Section 14 on international transfers)
5. Photo Storage and Retention
5.1 Photo Storage Duration
Important: Your uploaded photos are stored for 90 days from the date of upload.
- After 90 days, photos are automatically and permanently deleted
- Once deleted, photos cannot be recovered
- We recommend downloading or backing up your photos before expiration; our platform is not a backup service
5.2 Why We Store Photos
- To allow you to edit and reorder your photo products
- To create your printed photo products
- To fulfill reprint requests within the 90-day period
5.3 How Photos Are Stored
- Stored on Cloudflare R2 secure cloud storage
- Encrypted in transit and at rest
- Access restricted to authorized personnel only
- Regular security audits conducted
5.4 Manual Deletion
You can delete your photos at any time by:
- Logging into your account
- Selecting photos to delete
- Confirming deletion
Deleted photos are permanently removed within 24 hours.
5.5 Completed Orders
Photos used in completed orders are deleted after 90 days from upload, regardless of order completion date.
5.6 Account Closure
When you close your account, all stored photos are deleted immediately.
6. Our Promises About Your Photos
Your photos are yours. We make the following commitments, and our processors are contractually prohibited from acting otherwise:
- Your photos are never sold to anyone
- Your photos are never used for advertising or marketing, and we build no marketing profiles from photo content
- We do not apply facial recognition to your photos
- Your photos are not used to train AI or machine-learning models, and our processors are contractually prohibited from doing so
- We do not routinely view your photos. Staff access them only for production quality control, for support you request, or where content-moderation checks are triggered
- Location data embedded in your photos (EXIF metadata) is not used or retained for any purpose beyond producing your printed product
7. Photos of Children and Other People
- Photos of children that you upload are processed solely to produce the product you ordered, under your authority as the customer
- You are responsible for having the consent of identifiable persons appearing in your photos and, for children, the consent of a parent or guardian
- We are committed to acting in the best interests of the child: we never use images of minors for any purpose beyond producing your ordered product, and the promises in Section 6 apply in full
8. Data Retention Periods
8.1 Account Information
- Retained while your account is active
- Deleted within 30 days of account closure (unless legal retention required)
8.2 Order Information
- Order and invoice records are retained for 6 years, as required for accounting and tax purposes under Article 43 of the Tax Code of Georgia
- Retained longer if required for legal disputes or investigations
8.3 Marketing Communications
- Retained until you unsubscribe
- Unsubscribed contacts kept on a suppression list to honor your opt-out
- Records of your marketing consent and its withdrawal are kept for the duration of the direct marketing and for 1 additional year after it stops
8.4 Technical Logs
- Website access logs retained for 12 months
- Security logs retained for 24 months
- PostHog analytics data retained for 12 months
- Crisp chat logs retained for 24 months
8.5 Retention Schedule
Summary of our retention periods:
- Uploaded photos: 90 days from upload
- Manually deleted photos: removed within 24 hours
- Photos on account closure: deleted immediately
- Account data: 30 days after account closure
- Order and invoice records: 6 years (Tax Code of Georgia, Article 43)
- Website access logs: 12 months
- Security logs: 24 months
- PostHog analytics data: 12 months
- Crisp chat logs: 24 months
- Marketing consent and withdrawal records: duration of direct marketing plus 1 year
8.6 Backups
Deleted data may persist in encrypted backups for up to 30 days before being overwritten as part of the normal backup cycle.
9. Your Rights
Under the Law of Georgia on Personal Data Protection, you have the following rights:
9.1 Right of Access
Request confirmation of what personal data we hold about you and receive a copy.
9.2 Right to Rectification
Request correction of inaccurate or incomplete personal data.
9.3 Right to Erasure (Right to be Forgotten)
Request deletion of your personal data in certain circumstances:
- Data no longer necessary for the purpose collected
- You withdraw consent and no other legal basis exists
- You object to processing and no overriding legitimate grounds exist
- Data processed unlawfully
Note: We may refuse if we need the data for legal obligations or legitimate interests.
9.4 Right to Restriction (Blocking)
Request blocking (temporary restriction of processing) of your data in certain situations:
- You contest the accuracy of the data
- Processing is unlawful but you don't want deletion
- We no longer need the data but you need it for legal claims
- You've objected to processing pending verification
Where grounds exist, we will block the data within 3 working days of your request.
9.5 Right to Data Portability
Receive your personal data in a structured, machine-readable format and transmit it to another controller, where the processing is automated and the transfer is technically feasible.
9.6 Right to Object
Object to processing based on legitimate interests or for direct marketing purposes.
For direct marketing: We will stop immediately, and at the latest within 7 working days of your request.
9.7 Right to Withdraw Consent
Withdraw consent at any time where processing is based on consent (this doesn't affect past processing).
9.8 How to Exercise Your Rights
Email us at: hi@qarta.ge
Include:
- Your full name
- Email address associated with your account
- Specific request
- Proof of identity (copy of ID document)
Response Time: We will respond within 10 working days of receiving your request. Where a request is complex, this period may be extended once by up to 10 additional working days; we will inform you of the extension and its reasons. Exercising your rights is free of charge.
If you are not satisfied with our response, you may lodge a complaint with the State Audit Office of Georgia or apply to the courts (see Section 17).
10. Cookies and Tracking Technologies
10.1 What Are Cookies?
Cookies are small text files stored on your device when you visit our Website.
10.2 Types of Cookies We Use
Essential Cookies (Required)
- Enable core Website functionality
- Manage your login session
- Remember items in your cart
- Cannot be disabled without breaking the site
Functional Cookies (Optional)
- Remember your preferences (language, region)
- Personalize your experience
- Can be disabled in browser settings
Analytics Cookies (Optional, consent-based)
- PostHog - Help us understand how visitors use our Website
- Record session replays to improve user experience
- Measure effectiveness of our services
- Can be disabled in browser settings or by contacting us
Marketing Cookies (Optional, consent-based)
- Meta Pixel - measures the effectiveness of our advertising on Facebook and Instagram
- Deliver relevant advertisements and track campaign effectiveness
- Used only with your consent; you can opt out at any time
10.3 Managing Cookies
Browser Settings: You can control cookies through your browser settings:
- Block all cookies
- Delete existing cookies
- Accept/reject cookies on a case-by-case basis
Note: Disabling essential cookies may prevent you from using certain features of our Website.
10.4 Third-Party Cookies
Some cookies are placed by third-party services that operate on our Website:
Crisp (Website Chat)
- Privacy Policy: https://crisp.chat/en/privacy/
- Purpose: Provide customer support chat functionality
- Data Collected: Chat messages, name, email, browsing context
- Retention: 24 months
PostHog (Analytics & Session Recording)
- Privacy Policy: https://posthog.com/privacy
- Purpose: Understand user behavior, improve user experience
- Data Collected: Page views, clicks, session recordings, device info
- Retention: 12 months
- Session Recording: PostHog may record your interactions with our Website (mouse movements, clicks, scrolling) to help us identify and fix issues and improve user experience
- You can opt out of session recording in your browser settings or by contacting us
Meta Platforms (Advertising Measurement)
- Privacy Policy: https://www.facebook.com/privacy/policy/
- Purpose: Measure the effectiveness of our advertising on Facebook and Instagram
- Data Collected: Event data (pages viewed, purchases) with hashed identifiers; in addition to the Meta Pixel cookie, we send certain events server-side via the Meta Conversions API
- You can opt out of marketing cookies and tracking at any time
Payment Providers
- Secure transaction processing
- Payment confirmation status
These third-party cookies are governed by the respective third parties' privacy policies.
10.5 Do Not Track
Our Website does not currently respond to "Do Not Track" signals. You can opt out of analytics and marketing tracking by:
- Disabling cookies in your browser
- Contacting us at hi@qarta.ge to opt out of PostHog and Meta tracking
- Using browser extensions that block tracking
11. Security Measures
11.1 How We Protect Your Data
Technical Measures:
- SSL/TLS encryption for all data transmission
- Encrypted storage of photos and sensitive data
- Secure password hashing
- Regular security audits and vulnerability assessments
- Firewall and intrusion detection systems
- Secure backup systems
Organizational Measures:
- Access controls and authentication
- Staff training on data protection
- Confidentiality agreements with employees and contractors
- Regular policy reviews and updates
11.2 Your Responsibilities
- Use a strong, unique password
- Do not share your account credentials
- Log out after using shared devices
- Keep your email account secure
- Notify us immediately of suspected unauthorized access
11.3 Data Breach Notification
While we implement industry-standard security measures, no system is 100% secure. If a personal data breach occurs:
- We will notify the State Audit Office of Georgia within 72 hours of becoming aware of the breach, as required by Articles 29 and 30 of the Law of Georgia on Personal Data Protection
- Where the breach is likely to create a high risk to your rights, we will also inform you promptly and describe the measures taken
12. Third-Party Links
Our Website may contain links to third-party websites, social media platforms, or services.
We are NOT responsible for:
- Privacy practices of third-party sites
- Content on external websites
- Data collection by third parties
We recommend: Review the privacy policies of any third-party sites you visit.
13. Children's Privacy
Our services are not intended for individuals under 18 years of age.
- We do not knowingly collect personal data from minors
- If we discover we have collected data from someone under 18, we will delete it promptly
- If you believe we have inadvertently collected data from a minor, please contact us at hi@qarta.ge
- Photos of your children that you upload for printing are addressed in Section 7
14. International Data Transfers
14.1 Where Your Data Is Stored
Your personal data is stored in data centers located in the European Union and Georgia where available. States of the European Union and the European Economic Area benefit from adequacy recognition under the Law of Georgia on Personal Data Protection.
14.2 Service Providers in the United States
Some of our service providers (including Cloudflare, PostHog, Crisp, and our transactional email provider) are companies headquartered in the United States, and some processing may occur in the United States under data-processing agreements and contractual safeguards. We are consolidating personal data storage into European Union data center regions.
14.3 Advertising Data
Advertising measurement data shared with Meta Platforms (see Sections 4 and 10) is processed by Meta under its data processing terms.
15. Marketing Communications
15.1 Consent
We send marketing communications only with your consent, given by your active action (for example, subscribing or ticking an unticked box). We do not treat a purchase by itself as consent to marketing.
15.2 What We Send
- New product announcements
- Special offers and promotions
- Seasonal campaigns
- Personalized recommendations
15.3 Opt-Out
You can unsubscribe at any time and free of charge:
- Click "Unsubscribe" link in any marketing email
- Log into your account and update preferences
- Email hi@qarta.ge with "Unsubscribe" request
You can always opt out in the same channel in which you received the message. We will honor your opt-out immediately, and at the latest within 7 working days.
15.4 Service Communications
You cannot opt out of essential service communications (order confirmations, delivery updates, account notifications).
16. Changes to This Privacy Policy
16.1 Updates
We may update this Privacy Policy from time to time to reflect:
- Changes in our services
- Changes in data protection laws
- Improvements to our practices
- Addition or removal of third-party services
16.2 Notification
Material Changes: We will notify you by:
- Email to your registered address
- Prominent notice on our Website
- At least 30 days before changes take effect
Minor Changes: Posted on this page with updated "Last Updated" date.
16.3 Your Acceptance
Continued use of our services after changes take effect constitutes acknowledgment of the updated Privacy Policy. Where a change requires your consent under applicable law, we will ask for it separately.
17. Contact Us and Complaints
17.1 Privacy Contact
For privacy-related questions or concerns:
Email: hi@qarta.ge
Subject Line: "Privacy Inquiry" or "Data Protection Request"
Postal Address:
QARTA Data Protection
14 Merab Kostava St, Tbilisi, 0108, Georgia
17.2 Response Time
We will respond to your inquiry within 10 working days.
17.3 Complaints
If you believe we have mishandled your personal data:
- First, contact us at hi@qarta.ge so we can try to resolve the matter
- You may lodge a complaint with the supervisory authority for personal data protection, the State Audit Office of Georgia (website: https://sao.ge)
- You also have the right to seek judicial remedy through the Georgian courts at any time
18. Third-Party Service Providers
18.1 Complete List
Cloudflare R2
- Purpose: Photo storage
- Data: Photos uploaded by users
- Privacy Policy: https://www.cloudflare.com/privacypolicy/
Payment Gateway Providers
- Purpose: Process card and Google Pay payments
- Data: Payment transaction data (card details handled by provider, not QARTA)
- PCI-DSS compliant
Bank of Georgia and TBC Bank
- Purpose: Installment and split payments, provided under the banks' own credit terms
- Data: Data required to arrange the credit; each bank acts as an independent controller for the credit relationship
Courier Services
- Purpose: Deliver your orders
- Data: Name, phone number, delivery address
- Used solely for delivery purposes
SMS Delivery Provider
- Purpose: Deliver order status SMS notifications
- Data: Phone number and the message text
PostHog
- Purpose: Analytics and session recording
- Data: Usage patterns, session recordings, device info
- Privacy Policy: https://posthog.com/privacy
- Opt-out: Contact hi@qarta.ge
Crisp
- Purpose: Customer support chat
- Data: Chat messages, name, email
- Privacy Policy: https://crisp.chat/en/privacy/
Meta Platforms
- Purpose: Advertising measurement (Meta Pixel and server-side Meta Conversions API)
- Data: Event data with hashed identifiers
- Privacy Policy: https://www.facebook.com/privacy/policy/
- Opt-out: Disable marketing cookies/tracking or contact hi@qarta.ge
Google and Apple (Sign-In)
- Purpose: Optional sign-in providers
- Data: We receive basic authentication data only (name, email address)
- Privacy Policies: https://policies.google.com/privacy and https://www.apple.com/legal/privacy/
19. Acknowledgment
This Privacy Policy is a notice about how we process personal data, not a contract. By using QARTA's services, you acknowledge that:
- You have read and understood this Privacy Policy
- You understand your rights regarding your personal data
- You understand our photo storage and retention policies
Where processing requires your consent (marketing communications, analytics and marketing cookies, session recording), we collect that consent separately through your active action, and you can withdraw it at any time by contacting hi@qarta.ge or using the controls described in this Policy. Processing that does not require consent is based on contract performance, legal obligation, or legitimate interests, as described in Section 3.
20. Definitions
Personal Data: Any information relating to an identified or identifiable natural person.
Processing: Any operation performed on personal data (collection, storage, use, disclosure, deletion).
Data Controller: The entity that determines the purposes and means of processing personal data (QARTA).
Data Processor: A third party that processes personal data on behalf of the data controller.
Consent: Freely given, specific, informed, and unambiguous indication of agreement to processing, expressed by an active action.
Data Subject: The individual whose personal data is being processed (you).
Session Recording: Recording of user interactions on a website, including mouse movements, clicks, and scrolling, for analysis purposes.
- The Georgian version of this Privacy Policy is available on our website. In case of any discrepancy, the Georgian version prevails.
- Last Updated: August 19, 2026
- Version: 2.0