Privacy Policy
Effective July 28, 2026
1. Who we are
Tattoo Ledger (“we”, “us”) is operated by Miles Rae, operating as Tattoo Ledger, based in Ontario, Canada. We provide booking and studio-management software for tattoo artists and studios at tattooledger.com. This policy explains what personal information we collect, why, and the rights you have over it.
2. Two kinds of people use Tattoo Ledger
If you’re a tattoo artist, studio, or assistant (our customer): we are responsible for the personal information in your account — your name, email, and billing details. This whole policy applies to you directly.
If you’re a tattoo client (you booked, signed a waiver, or received emails through Tattoo Ledger): your artist or studio is responsible for your information. They decide what to collect and how long to keep it; we store and process it on their instructions. To access, correct, or delete your information, contact your artist or studio first — we help them fulfil those requests. We never sell your information or use it to advertise to you, and you never need an account with us.
3. What we collect and why
| Category | Examples | Purpose |
|---|---|---|
| Artist account data | Name, email, password (hashed), studio name, timezone | Provide and secure your account |
| Billing data | Payment card (held by Stripe, not us), billing address, tax status | Subscription billing and tax compliance |
| Client records (processed for artists) | Client name, email, phone, appointment history, notes, reference images | Run the artist’s bookings and client relationships |
| Waiver & health data (processed for artists) | Consent signatures, health-history answers, signer IP address and timestamp | Create the consent record the artist keeps |
| Identity & guardian data (processed for artists) | Government-ID photos; guardian name, date of birth, relationship, ID and signature for minors | Age verification and guardian consent where the artist requires it |
| Technical data | Authentication cookie, server logs (IP, browser) | Sign-in, security, and abuse prevention |
4. Sensitive information
Health-history answers and government-ID photos are sensitive. We collect them only when an artist’s waiver requires them, with the signer’s express consent captured in the signing flow, and we protect them with encryption in transit and at rest and strict access controls. An ID photo is retained as part of the signed waiver record it belongs to — it exists exactly as long as that record does, and is deleted with it. We never use sensitive information for anything except providing the service to the artist who collected it.
5. Cookies
We use only cookies that are strictly necessary to sign you in and keep the service secure (our authentication cookie). We do not use advertising cookies or third-party trackers, so we do not show a cookie banner. If this ever changes, we will update this policy and ask for consent where required.
6. Who we share information with
We share personal information only with the service providers who help us run Tattoo Ledger, listed on our Subprocessors page. Application data is hosted on Amazon Web Services in Canada (Montréal, ca-central-1). Some providers — payment processing (Stripe) and email delivery (Resend, built on Amazon SES) — process data in the United States, where it may be accessible to authorities under local law. We do not sell personal information, and we do not share it for cross-context behavioural advertising.
7. Retention and deletion
We keep account data while your subscription is active and for 90 days after closure so you can export it. When an artist deletes a client record — or closes their account and the export window ends — the associated data, including waiver records, is deleted from production within 30 days, except where the artist exports consent records first for their own legal obligations. Deleted data leaves backup rotation within a further 30 days.
8. Security
Safeguards are proportionate to sensitivity: TLS everywhere, encryption at rest, hashed passwords, role-based access with audit logging for assistant actions, tokenized single-purpose links for client pages, and two-factor authentication on administrative access. Details on our Security page.
9. Your rights
Everyone: you may request access to and correction of your personal information, withdraw consent (which may limit our ability to serve you), and request deletion. Artists can export client data (CSV) at any time. Quebec residents: you additionally have rights to data portability and de-indexing under Quebec law. California and other US state residents: you have rights to know, delete, correct, and opt out of sale/sharing — we do not sell or share personal information as those laws define it. We respond to requests within 30 days. Tattoo clients: route requests through your artist (see section 2); if you can’t reach them, contact us and we’ll help.
10. If something goes wrong
If a breach of security safeguards creates a real risk of significant harm, we will report it to the Office of the Privacy Commissioner of Canada (and Quebec’s Commission d’accès à l’information where applicable), notify affected individuals and affected artists without unreasonable delay, and keep records of all breaches as the law requires.
11. Minors
Tattoo Ledger accounts are for adults. Where artists tattoo minors lawfully, our waiver flow collects guardian consent — guardian identity, relationship, and signature — as configured by the artist and required by their local rules.
12. Privacy officer & complaints
Our person in charge of the protection of personal information is Miles Rae, Founder, reachable at privacy@tattooledger.com. If you’re not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, in Quebec, the Commission d’accès à l’information (cai.gouv.qc.ca).
13. Changes
We’ll post changes here with a new effective date, and email account holders about material changes before they take effect.