Privacy Policy
Last updated September 15, 2026
tats.to is booking and portfolio software for independent tattoo artists, operated by Thomas Ford as a sole trader. This policy explains what we collect, why we hold it, who else sees it, and what you can ask us to do with it. It covers tats.to and app.tats.to.
Whose data is whose
Two different relationships run through this service, and they carry different responsibilities.
- Artists. When you open an account, we decide how your account data is handled and we answer for it directly.
- Clients of artists. When you book, join a waitlist, leave a review or sign a waiver, that record belongs to the artist you dealt with. They decide what happens to it. We hold and process it on their behalf, and we act on their instruction.
- What this means for a request. If you are a client and want your details corrected or deleted, ask the artist first. Write to us and we will pass it on, and we will act ourselves where the law puts the obligation on us.
What we collect
- Account details. Your name, email address and password. If you sign in with Google or Instagram we receive your basic profile and an access token instead of a password.
- Artist profile. Everything you choose to publish: display name, bio, location, styles and techniques, years of experience, portfolio images, avatar, profile links, your page accent and your booking settings.
- Billing. Your plan, its renewal date, and the identifiers that match you to your Stripe records for your subscription. Card numbers go straight to Stripe. They never reach our servers and we cannot see them.
- Connected accounts. Google Calendar connections read busy times from your primary calendar without personal event names or details. Booking sync also creates a separate Tats calendar, reads events there and adds, updates or removes your booking events. Older connections can still read personal event names until you reconnect with the new permissions. We encrypt access and refresh tokens. Disconnecting deletes the stored tokens and requests that Google revoke access; calendars and events already in Google stay there. We retain the Google account identifier and Tats calendar identifier until account deletion so reconnecting can reuse that calendar. Instagram connections let us import your posts into your portfolio. Disconnecting Instagram deletes its token and lets you keep or remove imported images.
- Client records. Names, email addresses, phone numbers, tattoo ideas, booking times, notes an artist writes, waitlist entries and reviews. Most of this is entered by a client on a public booking page, or by the artist in their dashboard.
- Signed waivers. The signer name, the drawn signature, the date of birth, the answers given to the health questions on the artist form, which acknowledgments were accepted, the time of signing, and the IP address it was signed from. Health answers are special category data under the UK GDPR and the GDPR, and we treat them that way: the signature, the health answers, the flagged answers an artist sees on a booking, the date of birth, any contact details the form asked for and any note the artist wrote about checking who was in front of them are encrypted where they are stored, they are visible to the artist who owns the waiver and to nobody else, and they are deleted a year after the appointment. We never ask for a driving license, a passport or any other identity document, and there is nowhere in the product to upload one.
- Technical records. Server logs, error reports sent to Sentry when something breaks, and self-hosted Umami analytics. tats.to runs the service database and analytics under the same privacy practices. Analytics records can include the page visited, a broad device class, campaign tags, sign-up steps, and a random identifier used to connect a visit on tats.to with sign-up on app.tats.to. We use those anonymous product and conversion-funnel records to find which pages and workflows work, improve the product, and diagnose experience problems. We do not send Umami your email, artist handle, profile, portfolio, or form content. Server logs and Sentry reports can include an IP address and the page that failed.
Website traffic
Cloudflare handles traffic to tats.to and app.tats.to before it reaches our servers. It processes IP addresses, requested URLs, request headers and content sent through the website to deliver pages and protect the service from abuse. This processing happens even though we do not use Cloudflare Web Analytics.
What we do not do
- We do not sell personal data, and we do not share it for anyone else's advertising.
- Our product analytics is self-hosted and limited to tats.to and app.tats.to. We run no advertising pixels or tracking across unrelated websites.
- We do not read an artist's client book or waivers for our own purposes. Support access happens when you ask for help.
- We take no commission, so we have no reason to profile your clients or your earnings.
Why we hold it
- To run the service. Show your public page, take bookings, sync your calendar, send confirmations and reminders, and keep your dashboard accurate.
- To take payment. Charge your subscription. Anything a client pays you is arranged directly between the two of you and never passes through us.
- To keep records that have to exist. A signed waiver is a legal record. It is kept as signed, with a hash of the rendered document so it can be shown to be unaltered.
- To hold health answers lawfully. Health answers on a waiver are special category data, and the law needs a specific reason to hold them beyond the ordinary one. Ours is your explicit consent, given when you sign, so that your artist can judge whether it is safe to tattoo you and can show later what you told them. You can withdraw it at any time by deleting the waiver, and nothing about your appointment changes if you do.
- To keep the service safe. Rate limiting, abuse investigation, fraud prevention, and diagnosing errors.
- To answer you. Support conversations and the context needed to resolve them.
- To improve sign-up. Understand which tats.to pages and campaigns lead working artists to create and finish setting up an account, and where people leave that process.
Who else processes it
We use a small number of companies to run the service. Each one gets only what its job needs.
- Stripe. Subscription billing.
- Google. Calendar availability, booking events on your connected calendar, and sign-in if you use it.
- Meta. Instagram sign-in and portfolio import, if you connect it.
- Resend. Transactional email.
- Sentry. Error reporting, so a broken page gets found before you have to report it.
- DigitalOcean. Self-managed servers and database.
- Cloudflare. Website delivery, caching and security. Requests pass through its network, including requests to the artist app and public booking and waiver pages.
Cookies
We set a session cookie on app.tats.to when you sign in. It keeps you signed in and protects account form submissions. We also set a boolean sign-in hint across tats.to and app.tats.to so the public header can offer Sign in instead of sign-up. The hint contains no account details and cannot authorize a request. Our analytics does not set cookies. It stores a random sign-up identifier and first-touch campaign tags in your browser for up to 30 days. You can stop optional analytics in your browser by setting localStorage key umami.disabled to 1 or by using browser privacy controls. There are no advertising cookies or pixels.
How we use funnels
A conversion funnel is a count of the steps people take before an outcome, such as visiting a page, starting sign-up, and creating an account. We use aggregate funnel counts to see where people stop, not to build a marketing profile about a person.
How long we keep it
- While your account is open. We keep your account and studio data for as long as you use the service.
- After you close your account. We delete your account data within 30 days, apart from records we are required to keep.
- Billing records. Kept for as long as tax and accounting rules require, which is generally seven years.
- Signed waivers. A year after the appointment, the signer name, the signature, the health answers, the flagged answers, the date of birth, the contact details and any ID note are deleted automatically. What remains is the fact that a waiver was signed, the full wording of the document it was signed against including the questions it asked, which acknowledgments were accepted and the statements they were written as, and a hash of the document. That is enough for the record to stand as evidence of what was agreed. None of the answers the signer gave survive it, and nothing left in the record names the person who signed. You can have the whole record deleted sooner, either from the link you signed from or by asking the artist.
- Logs and error reports. Kept for a short operational window and then discarded.
- Sign-up analytics. The random browser identifier expires after 30 days. If you create an account, the linked opaque identifier and one-time sign-up milestones remain until the account is deleted. Umami analytics contains no profile or form content.
Your rights
Whoever you are and wherever you live, you can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Artists can ask for a copy of their client book, bookings and leads.
If you signed a waiver, you do not have to ask anyone. The link you signed from will delete it for you, and it works without an account because you never had one. The artist can delete it from their side too.
If you are in the United Kingdom or the European Economic Area, the UK GDPR and the GDPR give you further rights, including the right to object to processing, to restrict it, and to complain to your data protection authority. Where we rely on your consent, you can withdraw it at any time.
We do not charge for these requests, and we do not treat you differently for making one.
Where your data lives
Our servers are in the United States, so using tats.to means your data is stored there. For anyone in the United Kingdom or the European Economic Area that is an international transfer, and we rely on the standard contractual clauses our providers offer for it.
Cloudflare operates a global network, so website traffic may also be processed outside the United States.
Security
Traffic runs over TLS. Passwords are hashed and never stored in a readable form. Access to production data is limited to what is needed to operate the service. Every studio's data is scoped to that studio, and the public pages return only the fields they are meant to.
No service can promise it will never be breached. If a breach affects your data, we will tell you and the relevant authority within the time the law allows.
We take security seriously and have gone to great lengths to retain the trust of our community.
Age
Accounts are for adults. You must be 18 or older to open one, and the service is not directed at children. Where an artist's local rules allow them to tattoo a minor with a guardian present, the waiver for that appointment is the artist's record to collect and keep lawfully.
Changes
If this policy changes in a way that affects you, we will email account holders before it takes effect. The date at the top always reflects the current version.
Contact
Write to [email protected] with any question about this policy, or to make a request about your data. tats.to is operated by Thomas Ford, a sole trader in Michigan, United States.