Legal
We built AARM to connect artists and collectors — not to collect or sell your data. This policy explains what we collect, why we collect it, and how it is used. Last updated: April 2026.
When you create an account we collect your email address and a password (hashed — we never store it in plain text). This is used solely to authenticate you and to associate your activity with your account.
If you sign up as an artist, we also collect your display name and, optionally, a bio, location, and links to your social profiles. This information is displayed publicly on your artist profile.
When you purchase an artwork we collect the following in order to complete and record the transaction:
This information is stored in our database and shared with the selling artist solely for the purpose of fulfilling your order and arranging shipping. It is never used for advertising or sold to third parties.
All payments are processed by Stripe. Your full card details (card number, CVV, expiry) are entered directly into Stripe's secure payment interface and are never transmitted to or stored on AARM's servers.
Artists receive payouts via Stripe Connect. To enable payouts, artists are directed to complete Stripe's identity verification process. The information collected during that process (legal name, bank account details, government ID where required) is collected and held by Stripe, not by AARM.
Stripe's privacy policy is available at stripe.com/privacy.
AARM requests access to your device's photo library when you upload artwork images or a profile photo. This permission is used only to let you select images to upload. We do not access, scan, or store any photos beyond the specific image you choose to upload.
You can revoke photo library access at any time in your device's Settings. Revoking access will prevent you from uploading new images but will not affect your existing listings.
AARM uses Supabase to store application data including artist profiles, artwork listings, and order records. Supabase stores data in hosted PostgreSQL databases on infrastructure provided by AWS in the United States.
Artwork images and profile photos are stored in Supabase Storage, which uses AWS S3-compatible object storage. Uploaded images are accessible via public URLs for display in the app and on artist profiles.
Supabase's privacy policy is available at supabase.com/privacy.
We do not sell, rent, trade, or otherwise transfer your personal information to third parties for advertising, marketing, or any commercial purpose unrelated to operating AARM.
The only third-party services that receive any user data are Stripe (payment processing) and Supabase (data storage), as described above. Both are used solely to provide the core functionality of the app.
You may request deletion of your account and associated data at any time by contacting us at the address below. Upon request we will delete your account, profile, and any personally identifiable information from our systems within 30 days, except where retention is required by law (for example, transaction records for tax purposes).
Artwork listings and order records may be retained in anonymised form for platform integrity purposes after account deletion.
If we make material changes to this policy we will update the date at the top of this page. Continued use of the app after changes are posted constitutes acceptance of the revised policy.
Questions & requests
For any questions about this privacy policy, to request access to your data, or to request deletion of your account, contact us at:
hello@aarm.app