Skip to content

Privacy Policy

Last updated: August 2026. This document is a generic draft prepared for the Barti platform and must be reviewed by a qualified lawyer before publication.

1. Who we are

The data controller is Chirali Bahar, registered at Strada Gualdo Centro 6, 05035 Narni (TR), Italy, VAT number IT01759710559, Italian tax code CHRBHR82D66Z211F. For any privacy request you can contact us at contact@playbarti.com.

2. Who Barti is for

Barti is an educational service designed for children aged 6 to 12. The account always belongs to a parent or legal guardian (the "guardian"), who must be an adult. Children do not create accounts themselves and are not asked for an email address.

3. What we collect

Guardian data: name, email address, password (stored hashed), language, market and currency preferences, billing details and payment history, consent records, and support correspondence.

Child profile data: a made-up nickname chosen by the guardian (we do not ask for the child's legal name and explicitly ask you not to enter it), an age band (6–7, 8–9, 10–12), preferred language, mission progress, rewards earned and notifications.

Uploaded artwork: photographs of drawings uploaded to complete a mission. On upload every image is decoded and re-encoded, which removes all technical metadata including EXIF and GPS coordinates. The raw file is not kept: it is replaced by the cleaned copy and deleted.

Technical data: the minimum needed to operate and secure the service. In particular, for each browsing session we store a session identifier, the IP address and the browser type (user agent); those rows are deleted automatically after the period given in section 10. We also keep server logs and the payment events Stripe sends us.

Public-site measurement: only if you agree, our public pages use third-party measurement and marketing tools (section 6).

4. What we do not collect

We do not collect a child's legal name, exact date of birth, email address, home address, school or precise location. There are no public profiles, chat, comments or community features, and we never ask a child for data.

No measurement, session-recording or marketing tool runs anywhere in the member area — the pages that hold the child profile, the missions and the uploaded artwork. We do not profile children, we do not build advertising audiences from their data, and we do not retarget on the basis of their activity.

5. Why we process data, and on what legal basis

  • Providing the service (accounts, missions, rewards, member area) — performance of a contract.
  • Payments and subscriptions — performance of a contract and legal accounting obligations.
  • Publishing artwork in the Gallery — the guardian's specific consent, given separately for each child in the member area and withdrawable at any time.
  • Creating a public link to an artwork — only on the guardian's explicit request, and switchable off at any time.
  • Measurement and marketing on the public site — consent, collected through the cookie banner and withdrawable at any time.
  • Security, abuse prevention and technical logs — our legitimate interest in keeping the service safe and working.
  • Service messages (email verification, receipts, subscription notices) — performance of a contract.

6. Cookies, measurement and marketing

Strictly necessary cookies (sign-in, security, payments, language, and the record of your cookie choice) are always on. Everything else is optional and does not load until you allow it from the banner: measurement (Microsoft Clarity, Google Analytics via Google Tag Manager) and marketing (Meta Pixel). You can change your mind at any time using the "Cookie settings" link in the footer. None of these tools ever runs in the member area, whatever you choose. The full detail is in the Cookie Policy.

Counting visits without cookies. Whatever you choose, we count visits to the public pages on our own server: the date, the page, the language, whether the device is a phone or a computer, and the name of the site you arrived from. Nothing is written to your device, nothing is sent to anyone else, and your IP address is not kept: it is used, together with the browser, only to compute a one-way code with a random value that changes every day, so that two visitors can be told apart within a day without anyone being identified and without one day being linked to the next. Legal basis: our legitimate interest in knowing how many people visit the site. This counting never runs in the member area either. The aggregate figures are kept for 14 months.

7. The Little Artists' Gallery

Gallery permission is off by default. The guardian turns it on, if they want to, from "Child profiles" in the member area, separately for each child; it is not part of the Terms and Conditions and it is not a condition of using the service. Even with permission on, publication is never automatic: every artwork is selected manually by our moderation team. Published artwork is anonymous: we never show names, nicknames, ages, faces, internal identifiers or personal data. A guardian can withdraw permission at any time from the member area; withdrawal immediately removes that child's published artwork from the gallery.

Private links. An artwork has no public address at all until the guardian asks us to create one. The link shows the artwork anonymously, is kept out of search engines, and can be switched off again at any time from the member area.

8. Who we share data with

We do not sell personal data. We use the following providers, acting as processors:

  • Stripe — payments and subscriptions. Receives the guardian's name and email and the transaction details. Card details are handled by Stripe and never stored by us.
  • Our transactional email provider — sending service emails. Receives the guardian's address and the message, which may include the child's nickname.
  • Our hosting provider — servers and file storage. Artwork is stored on that server in an area the web cannot reach.
  • Microsoft (Clarity) and Google (Tag Manager, Analytics) — measurement, on public pages only and only with your consent.
  • Meta — advertising pixel, on public pages only and only with your consent.

Data may be disclosed to competent authorities where the law requires it.

9. International transfers

Some providers may process data outside the European Economic Area or the United Kingdom. Where that happens, transfers rely on Standard Contractual Clauses approved by the European Commission (or the UK equivalent) or another appropriate safeguard.

10. How long we keep data

Account data is kept while the account remains active. A daily job enforces the following periods automatically:

  • Archived artwork: 24 months from archiving, after which the image files are permanently deleted.
  • Session rows (identifier, IP, browser): 30 days.
  • Payment events received from Stripe: 12 months.
  • Notifications: 24 months.
  • Administrative action log: 5 years.
  • Tax and accounting records: the period required by law.

Following a deletion request, child data and artwork are erased; only data we are legally required to retain is kept, stripped of your name and email.

11. Your rights

As a guardian you can request access, rectification, erasure or restriction of processing, data portability, and object to certain processing; you may also withdraw any consent at any time without affecting the lawfulness of earlier processing.

Two of those rights you exercise yourself, without asking anyone, from "Your data" in the member area:

  • Download a copy — a single file with your account details, each child profile, mission history and rewards, your consents, your orders, and every artwork image.
  • Request deletion — carried out after 30 days, during which you can call it off. Child profiles, artwork (files included), history, rewards, notifications, consents and active sessions are deleted; invoices and payment records remain, without your name or email.

You can also write to contact@playbarti.com. You have the right to lodge a complaint with the Garante per la protezione dei dati personali (Italy) or the Information Commissioner's Office (United Kingdom).

12. Security

We apply appropriate technical and organisational measures: encrypted traffic (HTTPS), passwords stored with strong hashing, metadata stripped from images on upload, artwork stored in an area of the server the web cannot reach and served only after an ownership check on every request, role-based staff access, mandatory two-factor authentication for staff using the admin panel, audit logging of sensitive administrative actions, and protected backups.

13. Changes

If we make material changes to this policy we will announce them on the website or by email to the guardian's address.

Your choice about cookies

We always use a few cookies that make the site work — signing in, payments, your language. We would also like to use measurement and marketing cookies, but only if you agree. The member area, where your child's profile and artwork live, carries none of them either way. Read the Cookie Policy

Choose individually

Essential — Always on. Sign-in, security, payments, language and this choice itself.

Whatever you choose here, no measurement or marketing tool ever runs inside the member area.