Privacy Policy
Last updated: March 2025
1. Who we are
Tattoo Planner is a studio management platform for tattoo artists and studios, operated by Tattoo Planner B.V. (the "Company", "we", "us"). We are registered in the Netherlands and act as the data controller for the personal data described in this policy.
Contact: [email protected]
2. What data we collect
We collect personal data in order to provide and improve our service. This includes:
- Account data: name, email address, business name, and billing address provided during registration.
- Usage data: log files, IP addresses, browser type, pages visited, and actions taken within the platform.
- Client data you enter: when you use Tattoo Planner to manage your studio, you may enter client names, contact details, appointment records, and uploaded files. You are the data controller for this data; we process it on your behalf as a data processor.
- Payment data: billing and subscription information processed via our payment provider. We do not store full card details.
- Communications: messages you send to our support team.
3. Legal basis for processing
We process personal data on the following legal bases under the General Data Protection Regulation (GDPR):
- Contract performance: to deliver the services you subscribed to.
- Legitimate interests: to improve our platform, prevent fraud, and ensure platform security.
- Legal obligation: to comply with applicable tax and financial regulations.
- Consent: for marketing communications, where you have opted in.
4. How we use your data
- To create and manage your account and subscription.
- To provide customer support and respond to enquiries.
- To send transactional emails (booking confirmations, invoices, password resets).
- To send product updates and newsletters, if you have opted in.
- To detect and prevent fraud, abuse, or security incidents.
- To comply with legal obligations.
5. Data sharing
We do not sell your personal data. We share data only with trusted service providers who process it on our behalf under strict data processing agreements, including:
- Cloud infrastructure providers (hosting and storage within the EU/EEA).
- Payment processors for billing and invoicing.
- Email delivery services for transactional and support messages.
- Analytics tools to understand platform usage (anonymised where possible).
We may disclose data when required by law or to protect the rights and safety of our users.
6. International transfers
We store and process your data within the European Union and European Economic Area. In cases where a sub-processor operates outside the EEA, we ensure appropriate safeguards are in place, such as EU Standard Contractual Clauses.
7. Data retention
We retain account data for as long as your subscription is active and for up to 2 years after termination, unless a longer retention period is required by law. Anonymised usage statistics may be retained indefinitely.
Client data you have uploaded is deleted within 30 days of account closure upon request.
8. Your rights
As a resident of the EU/EEA, you have the following rights under GDPR:
- Right of access: request a copy of the personal data we hold about you.
- Right to rectification: request correction of inaccurate or incomplete data.
- Right to erasure: request deletion of your personal data, subject to legal obligations.
- Right to restriction: request that we limit processing of your data.
- Right to data portability: receive your data in a structured, machine-readable format.
- Right to object: object to processing based on legitimate interests or for direct marketing.
- Right to withdraw consent: withdraw any previously given consent at any time.
To exercise these rights, contact us at [email protected]. We will respond within 30 days.
You also have the right to lodge a complaint with your local supervisory authority. In the Netherlands: Autoriteit Persoonsgegevens.
9. Cookies
We use cookies to keep you signed in, remember your preferences, and understand how the platform is used. You can manage cookie preferences through your browser settings. Functional cookies required for the service to operate cannot be disabled.
10. Analytics and session replay
We use analytics tools, including Google Analytics and Microsoft Clarity, to understand how visitors interact with our website and to improve performance, content, and marketing.
Microsoft Clarity may collect behavioral metrics such as clicks, scroll depth, page interactions, heatmaps, and session replay data. This information helps us identify usability issues, improve conversion flows, detect abuse, and optimize the website experience.
These services may use first-party and third-party cookies and similar technologies to collect usage data. Where required by law, we only activate this processing after cookie consent is provided.
For more information about how Microsoft collects and processes data, please see the Microsoft Privacy Statement.
11. Data security
We implement industry-standard security measures including encryption in transit (TLS), encryption at rest, access controls, and regular security reviews. No method of transmission over the internet is completely secure; we cannot guarantee absolute security.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes by email or via an in-app notice at least 14 days before the change takes effect. Continued use of the service after changes become effective constitutes acceptance.
13. Contact
For privacy-related questions or requests, contact our privacy team:
Tattoo Planner B.V.
Email: [email protected]