Privacy Policy

Last updated: June 2026


1. Data Controller

tattou.ink is operated by the sole proprietorship distrAnS (registered in France — SIREN 103 686 655), headquartered in Paris, France.

Contact: privacy@tattou.ink


2. Purpose of this Policy

This privacy policy describes how tattou.ink collects, uses, retains, and protects the personal data of platform users, in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679 and the French Data Protection Act (loi Informatique et Libertés) of 6 January 1978, as amended.

It applies to:


3. Data Collected

3.1 Data collected when an Artist signs up

When registering on tattou.ink as an Artist, we collect the following data:

3.2 Data collected when a Client signs up

When a Client registers to book a session, we collect:

3.3 Data collected during use of the platform

During use of the platform, we may process:


4. Sensitive Data

Skin tone constitutes personal data that may be classified as data relating to ethnic origin, a special category under Article 9 of the GDPR.

This data is collected for a purely operational and artistic purpose: to allow the Artist to adapt inks and tattooing techniques to the Client's skin characteristics.

Legal basis: explicit consent of the Client, collected at registration (Article 9.2(a) of the GDPR).

The Client may withdraw this consent at any time, which will result in the deletion of this data.


Processing activityLegal basis
Creating and managing an Artist or Client accountPerformance of a contract (Art. 6.1.b)
Displaying the calendar, managing bookingsPerformance of a contract (Art. 6.1.b)
Sending transactional emailsPerformance of a contract (Art. 6.1.b)
Processing payments via StripePerformance of a contract (Art. 6.1.b)
Collecting skin toneExplicit consent (Art. 9.2.a)
Sending push notificationsConsent (Art. 6.1.a)
Error logs and monitoring (Sentry)Legitimate interest — security and reliability of the service (Art. 6.1.f)
Platform improvementLegitimate interest (Art. 6.1.f)
Compliance with legal obligations (accounting, transaction records)Legal obligation (Art. 6.1.c)

6. Purposes of Processing

Your data is used exclusively for the following purposes:


7. Sub-processors and Data Recipients

tattou.ink uses the following sub-processors. Each has contractual guarantees in place that comply with the GDPR (Standard Contractual Clauses or an equivalent adequacy mechanism where applicable).

Sub-processorRoleLocation
SupabaseDatabase and authenticationEuropean Union (via AWS Paris)
CloudflareImage storageFrance
Amazon Web Services (AWS)Email sending (Amazon SES)France
Fly.ioApplication server hostingFrance
NetlifyFront-end hostingEuropean Union / United States*
StripeOnline payments (only if activated by the Artist)United States*
Google Places APIStudio address searchUnited States*
ExpoPush notification deliveryUnited States*
SentryMonitoring and error loggingUnited States*

* For transfers outside the EU, these providers rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or benefit from a recognised adequacy decision.

Your data is never sold to third parties or used for advertising purposes.


8. Data Retention

DataRetention period
Artist account (registration data)Duration of the contractual relationship + 3 years
Client account (registration data)Duration of the contractual relationship + 3 years
Chat messages and shared files2 years after the last interaction
Booking data5 years (accounting obligations)
Payment data (Stripe references)5 years (accounting obligations)
Skin toneUntil consent is withdrawn or account is deleted
Technical logs (Sentry, server logs)90 days
Push notification tokensUntil revoked or the application is uninstalled

9. Your Rights

Under the GDPR, you have the following rights regarding your personal data:

To exercise your rights, contact us at: privacy@tattou.ink

We will respond within one month. If you are not satisfied with our response, you have the right to lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés): www.cnil.fr.


10. Data Security

tattou.ink implements appropriate technical and organisational measures to protect your data against unauthorised access, loss, alteration, or disclosure, including:

In the event of a data breach likely to result in a risk to your rights and freedoms, we undertake to notify the CNIL within 72 hours in accordance with Article 33 of the GDPR, and to inform you directly if the risk is high (Art. 34).


11. Cookies and Trackers

tattou.ink uses only cookies that are strictly necessary for the operation of the platform (authentication session management). No advertising or third-party tracking cookies are used.


12. Minors

tattou.ink is a platform intended for adults. Tattooing minors is regulated or prohibited in many countries. We do not knowingly collect personal data from individuals under the age of 18. If you believe a minor has registered on the platform, please contact us so that we can delete the relevant data.


13. Changes to this Policy

We may update this policy to reflect legal, technical, or service-related changes. In the event of a material change, you will be notified by email or via a prominent notice on the platform. The date of the last update is shown at the top of this document.


14. Contact

For any questions regarding this policy or the exercise of your rights:

tattou.ink
distrAnS
Paris, France
privacy@tattou.ink