Guest access

Public policy draft

Privacy Policy

What data Virtual Museum uses, why it is used, how consent works, and how privacy requests are handled.

Data we use

The app may use account data, authentication state, checkout and entitlement records, support references, preferences, consent choices, and product interaction signals.

Public browsing can work with less information than account, checkout, support, or protected access workflows.

Why we use data

Data supports sign-in, protected access, checkout, entitlement reconciliation, support, security, analytics, personalization, and product improvement.

Analytics and personalization should respect the current consent and data classification rules.

Account-essential and analytics data

Account, checkout, entitlement, support, security, and billing functions may require essential records even when optional analytics are not enabled.

Optional analytics should not be treated as required for account access, checkout, support, security, or entitlement fulfillment.

Providers

The app may rely on providers for hosting, authentication, database operations, payments, billing, analytics, maps, and media delivery.

Provider sharing should stay limited to the purpose needed for the feature, evidence, support, security, or compliance workflow.

Retention and deletion

Some records may need to remain for security, audit, payment, refund, entitlement, tax, fraud prevention, dispute, or legal reasons.

User-clearable data and legally required retained data must stay separated in product copy and support responses.

Privacy requests

Users can ask for access, correction, deletion, consent review, or other privacy help through support.

Support should verify identity before acting on account-specific privacy requests.

All policy pages