Picarm Logo

AI-smart pricing. Pro-level editors. Limited early-access now open.

Try now!

Privacy & Cookies

Last updated: 6 May 2026

This page explains what Picarm collects, why, and how to control it. Plain English, no dark patterns.

Who we are

Picarm is operated by Picarm Ltd, a company registered in England & Wales. You can reach us at hello@picarm.com. We’re the data controller for the personal information described on this page.

What we collect on www.picarm.com (the marketing site)

If you don’t sign up, the only personal data we’d have about you comes from analytics – and only if you click Accept on the consent banner.

  • Microsoft Clarity – behavioural analytics including session replay (mouse movement, clicks, scrolls, page interactions), browser/device info, and an approximate location based on IP. Microsoft acts as our processor; some of their processing happens outside the UK and is covered by the UK extension to the EU–US Data Privacy Framework or the UK International Data Transfer Agreement.
  • Google Analytics 4 – aggregated traffic and engagement metrics. Google acts as our processor under the same kind of transfer mechanism.

What we collect on app.picarm.com (the customer app)

You can use the editor without creating an account. Anything you do while you’re “trying it out” stays in your browser; nothing is sent to our servers until you decide to check out.

If you check out and place an order, we collect:

  • Account and authentication – your business email, a password (hashed), and authentication tokens. Handled via Microsoft Entra (formerly Azure AD).
  • Order details – your business email, the short note you give us about why you’re using Picarm, the photos you upload, the editing options you choose, order metadata, and the processed images we deliver back. Stored on Microsoft Azure for as long as your account is open plus a short retention window for support and accounting.
  • Payments – we use Stripe to take payment. Stripe handles your card details directly; we receive an order reference and the amount. Stripe is the controller for the card data itself; see Stripe’s privacy notice.
  • Operational telemetry – server-side logs (request paths, response codes, error stacks, IP addresses) so we can keep the service running. Legal basis is our legitimate interest in operating a reliable service.
  • Microsoft Clarity – same as the marketing site, only loaded if you’ve consented (in the UK, EEA, or Switzerland).

We don’t sell your data, and we don’t use it to train AI models.

How long we keep things

  • Analytics signals (Clarity, GA4): up to 13 months from your last visit, then refreshed if you give consent again.
  • Account data: while your account is active, plus 6 years for tax/accounting on order records.
  • Server logs and telemetry: typically 90 days.

Your rights

Under UK GDPR and the Data Protection Act 2018 you can ask us to see, correct, delete, or export your personal data, restrict or object to how we use it, or withdraw consent at any time. Email hello@picarm.com. We aim to respond within a month.

You can also complain to the Information Commissioner’s Office at ico.org.uk or 0303 123 1113.

Cookies

We only set cookies for things that need them.

Strictly necessary (no consent required, used regardless):

  • connect.sid – your login session on app.picarm.com.
  • picarm_consent_v1 (in localStorage) – remembers your cookie choice so we don’t re-ask.

Analytics cookies (Microsoft Clarity, Google Analytics):

  • _clck, _clsk (Microsoft Clarity, first-party) and MUID, ANONCHK, SM (Microsoft, third-party) – behavioural analytics and session replay, up to 13 months.
  • _ga, _ga_<ID> (Google Analytics) – traffic statistics, up to 13 months.

If you’re visiting from the UK, EEA, or Switzerland, none of these analytics cookies are set until you opt in via the banner. Outside those regions, our analytics tools may set them by default in line with local rules; you can still opt out at any time using the Open cookie preferences button below or your browser settings. Declining clears any analytics cookies that were previously set.

We don’t use advertising or retargeting cookies.

Changes

If we change anything material we’ll update the “Last updated” date and, where appropriate, prompt you again on your next visit.