Legal

Privacy Policy

Last updated: 14 July 2026

This policy explains how [Tattivo legal entity, e.g. Tattivo Ltd] (“Tattivo”, “we”, “us”) collects, uses, and protects personal data when you use the Tattivo platform at tattivo.app, including the public booking, consent, and waitlist forms that tattoo studios use to work with their clients.

1. Who is responsible for your data

Tattivo is a booking and studio-management platform used by independent tattoo studios. When you submit an enquiry, consent form, or waitlist entry to a studio, that studio is the data controller — it decides why your data is collected and how it is used. Tattivo acts as the studio’s data processor, providing the software that stores and handles the data on the studio’s behalf. For studio account holders (owners and artists), Tattivo is the controller of your account data.

If you have a question about how a particular studio uses your data, contact the studio directly. For questions about the platform itself, contact us at [privacy contact email].

2. What we collect

CategoryExamples
Studio accountsOwner/artist name, email, hashed password, role
Client contact dataName, email, phone number
Booking & project dataTattoo descriptions, placement, reference images, appointments, quotes
Consent recordsSigned consent forms and the details they contain
MessagingEmail and SMS content exchanged between a studio and its clients
Payment metadataAmounts, deposit status, and Stripe references — we do not store card numbers
Technical dataIP address and basic device/browser information, used for security and rate-limiting

We only collect what is needed to run bookings and studio operations. We do not store raw payment card details — card payments are handled by Stripe.

3. How we use it

  • To provide the booking, consent, waitlist, messaging, and payment features studios rely on.
  • To send transactional emails and SMS about your booking (for example, quotes, confirmations, and reminders) where you have agreed to receive them.
  • To keep the platform secure — validating and rate-limiting public inputs, and detecting abuse.
  • To meet legal and regulatory obligations (for example, retaining consent records).

We do not sell your personal data, and we do not use it for advertising.

4. Legal bases (UK/EU GDPR)

Where GDPR or UK GDPR applies, we and the studios we serve rely on:

  • Consent — for marketing/booking communications you opt in to (you can withdraw it at any time).
  • Contract — to provide the service you or the studio requested.
  • Legitimate interests — to run and secure the platform, balanced against your rights.
  • Legal obligation — where we must retain records (such as consent forms).

5. Who we share it with

We share data with the following sub-processors, each under a data-processing agreement, only as needed to run the service:

ProcessorPurposeData shared
SupabaseDatabase, authentication, file storageAll application data
VercelHostingRequest data in transit; logs
ResendEmail delivery and receiptRecipient email and message content
TwilioSMS deliveryRecipient phone and message content
StripePaymentsPayment amounts and payment references (not card numbers)
AnthropicIn-app AI assistantAssistant conversation content

We may also disclose data where required by law, or to protect our rights, safety, or the integrity of the platform.

6. International transfers

Some of our processors are located outside your country. Where personal data is transferred internationally, it is protected by appropriate safeguards such as Standard Contractual Clauses. [Confirm your processors’ regions and transfer mechanisms with counsel].

7. How long we keep it

We retain personal data for as long as the relevant studio remains an active customer and for as long as needed to fulfil the purposes above or to meet legal obligations. As a general guide, [define your retention period — e.g. client data retained while the studio is active, then deleted or exported on account closure; consent records retained for X years]. When data is deleted, related records are removed and stored files are deleted from our storage.

8. How we protect it

  • Encryption in transit (HTTPS/TLS) and at rest.
  • Strict tenant isolation — database Row-Level Security ensures a studio can only access its own data.
  • Least-privilege access, multi-factor authentication for team accounts, and server-only handling of privileged keys.
  • Input validation, injection and XSS protections, rate-limiting, and signed private storage for uploaded files.

More detail is available in our internal security and data-handling policy on request.

9. Your rights

Depending on where you live, you may have the right to access, correct, delete, export, or restrict the use of your personal data, and to object to certain processing or withdraw consent. Because a studio is usually the controller of client data, the quickest route is to contact the studio you dealt with. You can also contact us at [privacy contact email] and we will help route your request. You have the right to complain to your local data-protection authority.

10. Cookies & local storage

Tattivo uses only essential cookies and browser storage needed to keep you signed in, run the app (including offline support for installed users), and remember basic preferences. We do not use third-party advertising or tracking cookies.

11. Children

Tattivo’s booking forms are intended for adults. Clients must confirm they are 18 or over to submit an enquiry. We do not knowingly collect data from children.

12. Changes to this policy

We may update this policy from time to time. When we make material changes we will update the date above and, where appropriate, notify studios.

13. Contact

Questions about this policy can be sent to [privacy contact email], or by post to [registered business address].