Policy MGLS-105-PP-v5

Privacy Policy

Effective September 8, 2026.

Payments are not active yet. No payment information is collected, and no member will be charged automatically.

1. Information MGLS handles

2. What becomes public

An approved Studio can make the member’s Studio name, profile title, biography, category and specialties, links, approved artwork and captions, event information, and selected design choices public. The private account email, password hash, consent records, security records, visitor contact messages, and reporter email addresses are not displayed on the public Studio.

3. How information is used

MGLS uses information to create and secure accounts; verify email addresses; process password resets; operate, display, search, and moderate Studios; record required consent and upload-rights confirmations; provide member/Admin messaging; receive visitor contact messages and reports; deliver Contact This Artist messages to the selected artist’s private registered email; deliver Contact Us messages to MGLS support; apply trial eligibility and prevent repeated trial resets; measure aggregate site traffic and Studio views for the private Admin dashboard; prevent fraud, spam, and abuse; troubleshoot the service; respond to privacy, account, and legal requests; and comply with law.

MGLS does not sell personal information and does not use personal information for targeted advertising.

4. Cookies and similar technology

MGLS uses essential cookies for member and Admin sessions. These cookies are used for login, security, and access control. They are HttpOnly and SameSite protected when set by the service, and secure transport is used on HTTPS deployments. When an Admin uses the Admin Dashboard, MGLS also sets an Admin-only first-party exclusion cookie so that browser’s public-site testing is not counted in MGLS traffic totals. Ordinary visitors are not given an analytics cookie by this traffic feature. MGLS measures aggregate traffic using first-party server records and one-way visitor hashes rather than advertising or third-party analytics cookies, so this build does not add a cookie-consent banner. If nonessential advertising or other tracking technology is added later, this policy and any required consent controls must be updated first.

5. Service providers and third-party requests

MGLS is built on Cloudflare Pages and Workers, with Cloudflare D1 used for database records and Cloudflare R2 used for media storage. Cloudflare processes technical and stored information as needed to provide those services. MGLS uses Cloudflare Email Service to send account-verification and password-reset messages, deliver Contact This Artist messages to the artist’s private registered email address, and deliver Contact Us messages to MGLS support. Cloudflare processes the sender and recipient addresses and message contents as needed to provide email delivery.

The Artist Parade still includes several sample images requested from Pexels, which means a visitor’s browser may contact Pexels to load those images. Social shortcut icons are requested from the version-pinned jsDelivr-hosted Bootstrap Icons package, which means a visitor’s browser may contact jsDelivr for those SVG icon files. Member-selected external links are operated by third parties under their own privacy practices.

6. Retention

Active account, Studio, media, and moderation data are generally kept while an account is active or while reasonably needed to operate the service. Member login sessions are created with a seven-day expiration and are also removed on sign-out, password reset, or account deletion as applicable. Email-verification links expire after 24 hours, and password-reset links expire after 60 minutes; used verification/reset tokens are cleared. Rate-limit records are short-lived and are eligible for cleanup after roughly twice their applicable rate-limit window.

Deleted active media is removed from active storage when the deletion operation succeeds. MGLS may retain a one-way hashed version of the registered email address, together with limited trial-start and deletion timestamps, so deleting and re-registering with the same email does not restart the same free trial. This retained trial-eligibility record does not contain the readable email address. Temporary infrastructure backups and records reasonably needed for security, fraud prevention, legal compliance, rights complaints, or disputes may also remain for a reasonable period. This build does not set an automatic purge date for consent records, upload-rights confirmations, moderation records, visitor contact messages, reports, member/Admin messages, or privacy-preserving traffic records. Those records may remain until they are manually removed or a later retention schedule is adopted, subject to legitimate legal, safety, and dispute needs.

7. Access, correction, and deletion

Members can correct many public Studio details through their dashboard. A member may request access, correction, or deletion through the official privacy/contact method below. The service also includes a member-facing account-deletion option when the deployed environment supports the required account protections. Reasonable identity verification may be required before acting on a request.

8. Security

MGLS uses salted password hashing, session-token hashing, secure/HttpOnly/SameSite session cookies, same-origin checks for state-changing requests, hashed IP records rather than readable IP addresses for consent and security evidence, rate limiting, and a Content Security Policy in this build. Public bot protection and outbound email-dependent account features remain unavailable unless the required Cloudflare configuration and secrets are actually present. No system can guarantee absolute security.

9. Adults only

MGLS is intended for adults age 18 and older and is not directed to children. If MGLS learns that a person under 18 created an account or submitted personal information, the service may remove the account or information as appropriate.

10. Contact

Contact: Email: support@mardigraslinks.com

Use the same contact method for privacy requests, account deletion help, support, and copyright/legal notices unless MGLS later publishes separate addresses.

Return home · Terms of Use · Privacy Policy · Content & Linking Rules