Vasari Privacy Policy
1. Who we are
Vasari is operated by Filetrack Inc., a Delaware corporation trading as Vasari, at 11870 Santa Monica Blvd Suite 106-660, Los Angeles, CA 90025. In this policy "Vasari", "we" and "us" mean Filetrack Inc., and we are the controller of the personal information described here.
Questions, requests and complaints go to support@vasari.art. If your request concerns something published on a Codex page, the content concern form reaches the same people with the page attached, which is faster.
2. What this policy covers
It covers codex.vasari.art and what you reach through it: public Codex pages, your Vasari account, memberships and reports, work you upload, monitors and digests, the Vasari API, and messages you send us. Other Vasari services are dealt with in section 16.
It does not cover other companies' sites. Codex links out to museums, galleries, auction houses and news publishers, and what those sites do with your visit is governed by their own policies.
3. The short version
The detail is below, but in summary:
- Signing in needs an email address and nothing else. There is no password on Codex, so we hold none.
- We run no advertising, no ad networks, no third-party analytics and no cross-site tracking. Codex sets no advertising cookies because there are none to set.
- We do not sell personal information and we do not share it for cross-context behavioral advertising.
- Card numbers go to Stripe, never to us.
- Our page counts store a salted hash of your IP address rather than the address, and the underlying rows are deleted after 60 days.
- The Codex records public market activity. Private relationships - collectors, donors, trustees, private owners - are never published on a public page or sent in an alert.
- You can delete your account yourself, from your account page.
4. Information you give us
Your account. An account needs an email address. We send a six-digit code to it and you sign in with the code, so there is no password to choose, forget or for us to store. We keep your email address, when the account was created, when you last signed in, an unsubscribe token, and - if you tell us - what brought you to Vasari. If you buy something we also keep the identifiers our payment processor gives us for you.
Each time you sign in we record the session with the IP address and browser it came from, so that you and we can tell your sessions apart and so a sign-in you did not make can be recognized. Where you agree to terms, we record the same two things with the agreement, because a record of consent that cannot say where it came from is not much of a record.
Payment. Card details are typed into fields hosted by Stripe and go straight to Stripe. Vasari never receives your card number. We keep the Stripe customer reference, a reference to the payment method (of the kind that identifies a card without being one), and the record of what you bought and when, which we are required to keep for tax and accounting.
What you upload. If you upload work, we hold what you enter about it - title, artist, year, medium, dimensions, description, provenance, credit line, edition, price and sale contact where you provide one - and the image files themselves, which are stored on Amazon S3 in the United States. You choose whether a work is private, shown on your page, or listed for sale.
What you submit to a page you have claimed. Material you add to an artist or gallery page is screened before it publishes, and the screening reads what you submitted for personal contact details, unsafe links, and text that reads as an accusation about a named person. Material we cannot confirm against an independent source publishes in a labelled section as supplied by you, and you can hide any of it yourself at any time.
Messages, support and requests. When you write to support, ask to claim a page, submit a content concern, or message a claimed page through Vasari, we keep the message, your email address, and the name you gave. Messages sent through a Vasari page also record a hashed IP address and browser user agent, which exist to catch abuse of the form. Where a message reaches us as email, a copy of the original message including its attachments is stored.
5. Information we collect automatically
Page counts. We count views of Codex pages. Each view records a hash of your IP address, your browser's user agent, the page you came from, the country and network the request came from, and a session identifier. These records never hold your IP address itself. It is hashed with a secret salt that changes every month, which lets us count the same visitor twice in a month without being able to work out who that visitor is or connect them to the month before. The individual rows are deleted after 60 days and only day-level totals survive. (Sign-in sessions and consent records are the exception and do keep an address, as section 4 says.)
Most of that machinery exists to tell people from crawlers. A large share of traffic to a public database is automated, and our own counts are worthless if we cannot subtract it.
Cookies. Codex uses a small, fixed set, and none of them are advertising cookies:
- codex_user keeps you signed in. It holds a random session token, not your identity, and it is signed so it cannot be edited and marked so scripts on the page cannot read it.
- vasari_sid groups the pages you look at into one visit for the counts described above. It lasts 30 days.
- csrfToken and its equivalents protect forms from being submitted by another site on your behalf.
- news_topic, news_sort and news_range remember how you last chose to filter the news page, for 180 days.
Blocking or clearing them costs you the sign-in and the saved preference, and nothing else. Staff pages set a separate sign-in cookie which does not apply to visitors.
API keys. If you take a key for the Vasari API we store it hashed, alongside a short non-secret prefix so you can tell your keys apart, and the time the key was last used. We record request counts against the key to enforce rate limits.
Text messages. If you text the Vasari artist-lookup number, we keep the message, the number it came from, and our reply. Delivery is handled by Twilio.
6. Information about people recorded in the Codex
The Codex is a record of public art-market activity, built from auction results, museum collections and exhibitions, gallery programmes, prizes, press coverage and academic sources. It therefore contains information about people - mostly artists, and people acting in a professional capacity - who have no account with us and never gave us anything directly. This section is for them.
What we publish is professional and public. Sales at public auction, exhibitions, museum acquisitions, representation, prizes and press. These are truthful records of events that happened in public, and keeping them is the point of the thing: a record that can be edited by whoever complains about it is not a record.
What we deliberately do not publish. Private relationships are held internally and never appear on a public page, in any alert or digest, or in any API response: collectors, donors, patrons, sponsors, trustees and board members, private owners, and people named in provenance. Museum acquisition credit lines are suppressed publicly for the same reason, because they routinely identify a donor or a previous owner. Personal contact details are not published.
Material supplied by artists is separated from material we verified. What a claimed account tells us about itself publishes in a labelled section, marked as supplied by the artist and not independently verified, and it does not affect any ranking. It moves into the main record only if an independent source confirms it.
Asking us to change or remove something. Use the content concern form or write to support@vasari.art. How we answer depends on what you are asking about:
- Personal contact details - removed, promptly, in every case. There is no public interest in our holding your phone number.
- Anything involving your safety - tell us that is what it is and we will act on it immediately.
- Images of works - handled as a rights question. Tell us what you own and we will remove the image or reduce it to a reference-sized thumbnail.
- Records of public market activity - we will always correct what is wrong, and we ask for the source that shows it. We will not usually remove an accurate record of a public sale or exhibition, and if we decline we will tell you why rather than ignore you. Where someone's presence in the record is marginal, we will simply take them out.
Correcting is nearly always available where removing is not, and claiming your page gives you more control over what it says than removal ever would.
7. Why we use it, and our legal bases
We use the information above to run the service: to sign you in, to show and store what you upload, to take payment and give you what you paid for, to send the monitors and digests you asked for, to answer you when you write to us, to keep the service secure and within its limits, and to keep the accounting and consent records the law requires. Where the law asks us to name a legal basis, ours are these:
- Performing our contract with you - your account, your uploads, your membership, your reports, the alerts you configured.
- Our legitimate interests - keeping the service secure and unabused, telling people from crawlers, understanding which pages are used, and compiling and publishing the Codex record of public market activity. That last one also rests on the freedom of expression and information, which the data protection laws expressly preserve.
- Your consent - marketing email where consent is required, and anything you have specifically opted into. You can withdraw it at any time, and those messages carry a working unsubscribe link. Messages that are part of the service itself, such as a sign-in code or a receipt, are not marketing and do not stop.
- Legal obligation - tax and accounting records, and responding to lawful requests.
We do not use your uploads or your messages to train Vasari's ranking or estimate models. Those are built from public market records.
8. Who we share it with
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We share it with the companies that operate parts of the service for us, under contracts that limit them to doing what we ask:
- Stripe - payments.
- Amazon Web Services - hosting, file storage and the email we send.
- Twilio - text messages.
- Google - maps where a location is shown, and a safe-browsing check on links people submit to us.
- AI model providers - see section 9.
Vasari also operates a streaming service, and if you send your own work to a screen, what you sent moves between those two parts of Vasari. That is the same company, not a third party.
Beyond that we share personal information only where we are required to by law or valid legal process, where it is necessary to investigate abuse or protect someone, or as part of a merger or sale of the business, in which case this policy travels with the information.
9. AI model providers
Some features send text to an AI provider to produce a result: composing a reply to an artist lookup sent by text message, turning a caption you send into catalogue fields, summarizing news articles, drafting descriptive copy about works and market records, and classifying records in our internal research database. When you write to support, your message and the thread it belongs to are also sent this way, to summarize the ticket and draft a reply - which a person then reads, edits and sends. The provider we use for this is Google, and it processes the text in the United States. If we add or change providers we will say so here.
We do not send payment details or account credentials to any of them, and none of this content is used to train Vasari's own models. Where something you sent us is processed this way, it is to produce the result you asked for or the answer you are waiting on.
10. Where information is processed
Vasari is based in the United States and your information is processed there, including by the providers named above.
If you are in the European Economic Area, the United Kingdom or Switzerland, transferring your information to the United States means it goes somewhere whose laws differ from your own. Where those laws require a transfer mechanism, we rely on the European Commission's standard contractual clauses and the equivalent UK and Swiss provisions, together with the terms our providers offer for international transfers. We do not rely on the Privacy Shield frameworks, which have been invalid since 2020.
11. How long we keep it
- Your account - until you delete it, or you ask us to.
- What you uploaded - until you delete it or close your account, apart from copies in backups for a reasonable period.
- Page-view rows - 60 days, after which only day-level totals remain and nothing in them relates to a person.
- Sign-in session records - until the session expires or you sign out.
- Purchased reports - available to re-download for 30 days.
- Payment and accounting records - as long as tax law requires.
- Records of terms you agreed to - kept for as long as they may be needed as evidence of the agreement. These records are append-only by design and are not edited.
- Messages and support correspondence - for the life of the account and a reasonable period after, so we can answer a question about what was said.
- Records in the Codex about public market activity - kept as part of the record, subject to section 6.
12. Security
Everything runs over encrypted connections. There is no password to steal because Codex does not use one. Session cookies carry a random token rather than your identity, are signed so they cannot be forged, and are not readable by scripts on the page. API keys are stored hashed, never in a form we could read back to you. IP addresses in our analytics are hashed before they are stored. Access to member information is limited to the people who need it to do their jobs.
None of that is a guarantee, and anyone who tells you otherwise is selling something. If we ever learn of a breach affecting your information we will tell you and the relevant regulator as the law requires. If you think your account has been used by someone else, write to support@vasari.art and we will help.
13. Your choices and your rights
Everyone can do these things, wherever they live. You can see your account information and change what you have added to it from your account page. You can unsubscribe from any email we send using the link in it. You can delete your account yourself from your account page: that removes what you created - your uploads, lists, monitors, claims and sync settings - while the public record of artists, galleries, sales and museum holdings stays, with any link to you detached. If you have a paid membership you will need to cancel it first, because deleting the account does not stop the billing.
If you are in the EEA, the UK or Switzerland, you have the right to ask for a copy of your personal information, to have it corrected, to have it erased, to restrict or object to how we use it (including our legitimate interests), and to receive what you gave us in a portable form. Where we rely on consent you can withdraw it without affecting what we did before. You can complain to your national data protection authority; we would rather you told us first at support@vasari.art, but that right does not depend on our agreement.
If you are in California, you have the right to know what we collect, use, disclose and retain, to a copy of it, to correct it, to delete it, and to limit the use of sensitive personal information. The categories we collect are: identifiers (your email address), commercial information (what you bought), internet activity (the page-view information described in section 5), geolocation at the level of country only, and the content you choose to upload or send us. We collect it for the purposes in section 7, from you and from public sources, and we disclose it to the service providers in section 8. We do not sell personal information and we do not share it for cross-context behavioral advertising, and we have not done so in the preceding twelve months. We will not treat you differently for exercising any of these rights, and an authorized agent may act for you with proof that you asked them to.
If you are in another US state with a privacy law - Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and the rest - you have the equivalent rights that law gives you, including the right to appeal if we turn a request down. Tell us the state you are in and we will apply its rules.
How to make a request. Write to support@vasari.art from the email address on the account, which is how we verify it is you. If you have no account with us and your request is about a Codex page, use the content concern form and include the page. We answer within the time the applicable law allows, and where we need longer we will say so before that time runs out.
14. Children
Vasari is a professional art-market service and it is not directed to anyone under 16. We do not knowingly collect personal information from anyone under 16, and if we find that we have, we delete it. If you believe a child has given us information, write to support@vasari.art.
15. Rankings, estimates and automated decisions
Vasari produces rankings, gallery tiers and vEstimates by computation from the records described in section 6. They are our opinion drawn from disclosed data. They are reference figures, not appraisals, quotes or advice, and they must not be presented as a formal valuation.
They are also not decisions about you in the sense the data protection laws use. Nothing at Vasari makes an automated decision that produces a legal effect on a person or anything similarly significant. Our methodology is published at /about/methodology, and if you think a number about you is wrong, the route in section 6 applies to it.
16. Other Vasari services
Vasari also runs a streaming art service - the viewer, the mobile apps and the television apps - which is a different product with a different shape, and the policy for it is at info.vasari.art/privacy-policy. Where the two overlap, because one Vasari account works across both, this policy is the one that describes what happens on codex.vasari.art.
17. Changes to this policy
We will change this policy when the service changes, and every version is kept with the date it took effect. The version and date at the top of this page are the ones in force. Where a change materially affects you we will tell you rather than rely on you noticing. Earlier versions are available on request from support@vasari.art.
