Privacy Policy
legal
Privacy Policy
Last updated: 4 October 2026 · Avant.Dev · Mexico City, Mexico · office@avant.dev
What we collect
- Contact inquiries: name, email, organisation, message
- Job applications: when you apply to a position, your name, email, city, the link you give us to your work and your answers. People at the gallery read them. To help us read, an AI assistant may write a summary from your answers only (not your name, your email or your link); it scores nobody and no decision is made by a machine
- Proposals to sell a work: when you send one from Sell Art, your name, email, city and country, your telephone if you ask to be answered by a call or WhatsApp, what you tell us about each work (artist, title, year, technique, measures, condition, where it comes from, where it is, the price you have in mind) and its photographs. The photographs are stored privately, without the data a camera adds to a file (no location, no device), and only people at the gallery see them. Nothing of a proposal is published
- Photographs of exhibitions and events: we photograph our exhibitions, openings and fairs, and you may be in a picture. They are kept in a private archive that only people at the gallery see. To help us file them, an AI assistant may describe a photograph (what it shows, the works in it); it is never asked to say who a person is, and nobody is identified from their face. A photograph is published only by a person of the gallery; if you are in one and would rather it were not used, or want it removed, write to us
- Banners: when a banner is shown or clicked we add one to a counter for that day, the place on the site, the browser, the kind of device and the country. No cookie is set and nothing about you is kept. A link on a banner leaves the site with tags that tell the destination the visit came from avant.dev
- Analytics: anonymous page views via Plausible, self-hosted (no cookies, no personal data; switch it off in the cookie notice at any time)
- Cookies of our own: essential ones (your session when you sign in, your bag) and preferences (language, currency, delivery destination, text size, and your choices in the cookie notice). They need no consent; the notice at the bottom tells you once
- Your country: your IP address is looked up in memory to find the country you visit from (shown in the footer and used for the cookie rule below). The address is not stored
- Where you came from: if you arrive from a campaign link or from another site, two first-party cookies (avant_ft, 90 days; avant_lt, 30 days) keep the campaign, the referring site and the page you landed on, with no identity, while the analytics switch is on. They are read only if you become a contact (an inquiry, an account, an order), so we know which campaign brought you
- Marketing cookies: only while the "Marketing cookies" switch of the cookie notice is on. Meta’s pixel, LinkedIn’s Insight Tag and Pinterest’s tag then load and set their own cookies (Meta: _fbp and _fbc, 90 days; LinkedIn: li_fat_id on this site and its own on linkedin.com, from 1 day to 1 year; Pinterest: _pin_unauth and _derived_epik, 1 year) to measure our ads on Facebook, Instagram, LinkedIn and Pinterest: the pages you view and actions such as saving a work, adding it to the bag, sending an inquiry or buying, with the amount of a purchase but never your name, phone or address. LinkedIn also tells us, in aggregate, the kind of companies and roles of our visitors. When you send an inquiry or buy, our server also tells Meta, with your email turned into a code (a SHA-256 hash) that cannot be read back, your IP address and your browser type, so the same action is counted once
- Recordings of how the site is used: under the same switch, Microsoft Clarity may record how pages are used (clicks, scrolling, the movement of the pointer, the pages of a visit) and set its own cookies (_clck and _clsk on this site, CLID and MUID on Microsoft’s; up to 1 year), so we can see where the site is hard to use. What you type into forms is masked in those recordings. Microsoft also uses this data to improve its own products
- Purchases: payment data processed by Stripe (we never store card data)
- Delivery: the name, address, phone and email of the person receiving a work are given to the carrier you choose and to the shipping platform that books it, only to quote, deliver and clear customs for that parcel; a gift note you write travels with the work
- Art sales above AML thresholds: identity documentation (LFPIORPI compliance)
Marketing cookies: where they start on, and how to switch them off
The marketing switch starts on or off by the law of the country you visit from. In Mexico and the United States it starts on: the cookie notice says so, and you can switch it off there or at any time from "Cookie preferences" at the foot of every page. A browser that sends the Global Privacy Control signal starts off. In the European Union and the EEA, the United Kingdom, Switzerland, Brazil, Chile, Canada and everywhere else it starts off, and nothing from an advertising platform or from Microsoft Clarity loads unless you choose "Accept all" or turn the switch on. Your choice is remembered in your browser (and in the cookie avant_mc, 180 days, so our server respects it) and wins over the rule of the country. With the switch off, nothing is sent to Meta, LinkedIn, Pinterest or Microsoft Clarity, from your browser or from our server.
Your rights
Under LFPDPPP (Mexico), UK GDPR, and EU GDPR you may request access, correction, deletion, portability, or object to processing of your data. Email office@avant.dev with the subject "DSAR Request".
Data retention
Inquiry data: 3 years · Proposals to sell a work and their photographs: kept with the inquiry they open, 3 years, or deleted sooner if you ask; photographs you upload and do not send are deleted after two days · Job applications: 1 year from the day you apply, then deleted (sooner if you ask; kept if you join us) · Sales records: 7 years (legal requirement) · Analytics and banner counters: anonymous aggregates only, no retention concern.
Third parties
Stripe (payments) · Parcel carriers and our shipping platform (delivery of what you buy) · Plausible (analytics, cookieless) · Meta, LinkedIn and Pinterest (measurement of our ads) and Microsoft Clarity (recordings of how the site is used), all four only while marketing cookies are on · Cloudflare R2 (media storage) · MongoDB (database hosting) · Cal.com (call booking) · Artsy (gallery listings) · Anthropic (the AI assistant that, when a person of the gallery asks, summarises the answers of a job application or describes a photograph of our archive) · Email is sent from our own mail server, no-reply@avant.dev. We do not sell personal data. Ever. What Meta, LinkedIn and Pinterest receive while marketing cookies are on is described above; some United States state laws call that “sharing”, and the marketing switch is how you opt out of it. · Anthropic (the AI assistant that may summarise the answers of a job application for the people who read it; it receives the answers and the position, not your name or your email)
Jurisdictions
Mexico (LFPDPPP) · United Kingdom (UK GDPR + MLR 2017) · European Union / Switzerland (GDPR) · United States (state privacy laws such as California’s CCPA/CPRA; BSA awareness via Stripe)