Legal
Privacy Policy
Last updated: October 8, 2026
We collect as little personal data as we can. This page explains what we collect when you browse statue001.com, buy a piece or bid on the Heart, what we do with it, and what your rights are.
1. Who is responsible
The controller of your personal data is:
STATUE
E-mail: contact@statue001.com
2. What we collect and why
- When you buy a piece: your name (or the name you want shown), e-mail address, the piece number, price, date, and the optional text, link and image you add. Why: to perform the sale, show your piece in the monument, send your receipt and keep accounting records. Legal basis: contract (GDPR art. 6(1)(b)) and legal obligation (6(1)(c)).
- When you register to bid on the Heart: name, e-mail address, and your bids. Why: to verify your e-mail, run the auction and contact the winner. Basis: contract / steps requested by you.
- Notifications: if you own a piece we e-mail you about your purchase and about the Heart auction (it starts when all pieces are sold). Basis: contract and our legitimate interest (6(1)(f)) in telling owners about the project they joined. These are service messages, not advertising.
- Payments: handled by Stripe. We receive a payment reference, the amount and the status — never your full card number. Stripe is an independent controller for its own fraud and compliance processing; see stripe.com/privacy.
- Technical data: your IP address and basic request data are processed briefly to keep the Site secure and to rate-limit abuse, and appear in server logs. Basis: legitimate interest in security.
Information you put on a piece (name, text, link, image) is public on the Site. Your e-mail address is never shown publicly.
3. Cookies
We use only strictly necessary cookies: a signed session cookie when you confirm your e-mail to bid on the Heart, and a session cookie for the administrator login. We do not use advertising or analytics cookies and do not track you across sites, so no cookie banner is required. Your browser may also cache the 3D model file so the Site loads faster.
4. Who receives your data
- Stripe — payment processing and refunds.
- Resend — sending e-mails (receipts, confirmations, auction notices).
- Render — hosting of the Site, database and uploaded images.
- Cloudflare — domain name (DNS) services.
- Accountants, advisers, courts or authorities where the law requires or allows it.
We do not sell your data. Some of these providers process data in the United States; where that applies they rely on safeguards such as the EU–US Data Privacy Framework or standard contractual clauses.
5. How long we keep it
- Piece, owner and public content: for as long as the piece is part of the monument, since permanence is the point of the project. If a piece is cancelled, the owner details, text, link and image are deleted from it; a record of the cancellation (without the content) is kept in an internal log.
- Order and payment records: as long as accounting and tax law requires (typically several years).
- Bidder registrations and bids: for the auction and a reasonable time afterwards for disputes.
- Uploaded images that were never attached to a completed purchase are deleted automatically after a short time.
- Server logs and rate-limit data: short-term, normally days.
6. Your rights
Subject to the law that applies to you (including the GDPR), you may ask us to access, correct or delete your personal data, restrict or object to its processing, or receive a copy of it, and you may withdraw consent where we rely on it. Because pieces are meant to be permanent and public, we may not be able to delete data we must keep for legal reasons or that is needed to honour a completed sale, but we will tell you what we can do. Write to the e-mail address in section 1; we reply within one month.
You can also complain to the data-protection authority of the country where you live or work.
7. Children
The Site is not meant for people under 18 and purchases require a payment method belonging to an adult. If you think a child gave us data, contact us and we will delete it.
8. Security
We use HTTPS, hashed admin credentials, signed sessions and access controls, and leave payment data with Stripe. No system is perfectly secure; if a breach affects you we will notify you and the authorities as the law requires.
9. Changes
We will update this page when our practices change and show the date at the top. Related: Terms of Service and Refunds & Cancellations.