Privacy notice
Reviewed October 6, 2026 • Version 2026-10-06.1
TattooRelay is operated by Dead Hamster Tattoo Studio LLC. This notice explains the operator's handling of information through this version of the booking and document application. Contact deadhamstertattoo@gmail.com for privacy questions. The artist or studio also handles client records for its own professional and legal obligations and is responsible for explaining its separate practices.
Information handled
- Account identity and verified email from the authentication service; profile name, phone, biography and optional profile photo.
- Booking requests, descriptions, placement, budgets, preferred dates, references, appointment details, intake answers, consent text/signature and timestamps, aftercare acknowledgments and recorded deposit information.
- Passkey public credentials and security/session records. Face ID or fingerprint processing stays with your device; the app does not receive your biometric template.
- Calendar connection information, authorization tokens or app-specific credentials when an artist connects a supported calendar.
- Support/privacy requests and technical security information such as IP address, browser/request metadata, security events and provider logs.
Do not put full card numbers, bank credentials, government ID images or unnecessary medical details in reference photos, biographies, booking notes or ordinary bug reports. This release provides reference photos and profile photos, not a dedicated government-ID collection system. Required ID can be reviewed at the studio. Forms may contain sensitive information supplied by a client; artists must collect only what is necessary and handle it lawfully.
Purposes and access
Information is used to authenticate accounts, operate bookings and document workflows, connect calendars, send appointment/form communications, provide support, investigate abuse and meet applicable legal obligations. Authorized artists access their own studio records; clients access appointments matched to their verified account email. Private client links also grant access to the relevant appointment while valid, so share them carefully. The operator may access information when necessary for support, security, legal obligations or service administration.
Service providers and disclosure
Depending on enabled features, Cloudflare provides hosting and database/file storage; Supabase provides authentication; Resend delivers appointment email; Google and Apple/iCloud provide connected calendar or sign-in services. External payment links are handled by the selected payment provider. Providers receive information needed for their roles and also maintain their own policies. Information may be processed outside your state or country depending on provider configuration; this notice does not promise domestic-only storage.
The platform does not sell personal information or share it for cross-context behavioral advertising. This release includes no advertising tracker or AI model-training pipeline for client records. A new use requiring notice or consent must be disclosed before it begins. Information may be disclosed where law requires, to protect people or security, or in a business transfer subject to applicable protections. This does not authorize unrestricted disclosure or override mandatory privacy rights.
Cookies and local storage
Essential secure cookies support sign-in, OAuth verification and session security. Browser local storage may save language and interface preferences. Signing out clears the active app session; removing browser data can remove local preferences and require signing in again. This version does not install optional advertising cookies. Any future nonessential tracking must have the notice and choice required by applicable law.
Retention and deletion
Records are kept for service operation and applicable studio record-retention, legal, security and dispute obligations. An archived or cancelled appointment is not automatically erased. Retention can vary by document and jurisdiction. A deletion request may require retaining a specific legally required record; the operator and studio should explain any applicable exception and restrict further use where appropriate. Account requests do not automatically delete third-party provider accounts, copies already shared or records independently held by a studio. No universal deletion deadline or automatic destruction of tattoo records is promised.
Your choices and requests
Edit your profile in your account and manage passkeys in Settings. In Privacy & account controls, download a structured copy of account/appointment records or submit a verified access, correction, deletion, restriction or appeal request. A downloaded copy does not automatically include all photo bytes or provider logs; ask support for additional information. Signed documents cannot simply be edited; corrections may require a supplemental record.
Rights depend on applicable law and may include access, correction, portability, deletion, restrictions, consent withdrawal and appeal. Authorized agents may contact support; identity and authority may be verified using proportionate measures. Do not email an ID unless a secure verification method is separately arranged. Requests are reviewed manually and must be handled within any applicable legal deadline. Privacy requests will not result in unlawful retaliation. You may contact the relevant privacy regulator where permitted. Because this release does not sell or share data for behavioral ads, an opt-out preference signal does not trigger an advertising disclosure.
Children and security
This service is intended for adult account holders. Artists must manage any legally permitted minor procedure through an authorized adult and verify all state/local restrictions; using the software never authorizes tattooing a minor. Children under 13 must not submit information or create accounts. Report information collected from a child to support for review and removal where required. Age verification is a professional responsibility and is not automated by this release.
Access checks, secure session cookies, optional passkeys, origin checks and protected file routes reduce risk. No system is perfectly secure. The app does not claim HIPAA compliance, SOC 2 certification, end-to-end encryption, or an independent security audit. Report suspected exposure through Security & reporting.