Privacy Notice

This is a convenience translation. The German version is legally binding.

How we process personal data on tattoodeck.com and in the Tattoodeck application.

1. Controller

URBANEE (sole proprietorship), owner: Egor Dvortsevoy

Heylstraße 11, 10825 Berlin, Germany

Email: support@tattoodeck.com

We are not legally required to appoint a data protection officer; please send requests to the address above.

2. Two roles: website/account and studio data

For the website, our marketing communication and the accounts of our customers (studios, artists) we act as controller.

For the data a studio processes about its own clients in Tattoodeck (appointments, contact details, consent forms, health information, images), that studio is the controller. We act as processor under Art. 28 GDPR and only on the studio's instructions. A data processing agreement is available on request.

3. Data we process

• Account data: name, email address, password hash or Google sign-in, studio name, role, language and time zone

• Studio master data: address, Instagram handle, logo, services and working hours; phone number and VAT ID only if the studio voluntarily enters them

• Usage data: sign-in and change timestamps, audit logs, technical logs

• Technical data: IP address, date and time of access, page requested, browser type — kept as server logs for security and troubleshooting

• Communication: emails and support requests sent to us

• Billing data: subscription status, plan, artist count and checkout identifiers. We never receive card or bank details; those are processed solely by Stripe.

• Content processed for the studio: client records, appointment history, requests, reference images, messages, and consent forms including health answers and signature

4. Purposes and legal bases

• Providing the Service, contract performance, registration, login, support: Art. 6(1)(b) GDPR (contract)

• Invoicing, subscription management, tax and commercial record keeping: Art. 6(1)(b) and (c) GDPR

• Operations, security, fraud and abuse prevention, troubleshooting, product improvement: Art. 6(1)(f) GDPR (legitimate interests)

• Transactional emails such as appointment confirmations, reminders, portal links and consent requests: Art. 6(1)(b) GDPR or the studio's instruction

• Marketing communication, where it takes place: Art. 6(1)(a) GDPR (consent), revocable at any time

• Appointment reminders by SMS or WhatsApp: Art. 6(1)(a) GDPR (consent). Clients select these channels themselves; the phone number is used for that purpose only. Consent can be withdrawn at any time in the client portal or with the studio, after which reminders are sent by email only.

• Health data in consent forms: processed by the studio on the basis of Art. 9(2)(a) GDPR (explicit consent of the data subject); we process it solely as processor.

5. Health data and consent forms

Health answers from the consent quiz are special categories of personal data under Art. 9 GDPR. Within a studio they are visible only to the owner, management and the treating artist, enforced by database-level access rules.

Signed forms are immutable and stored with timestamp, IP address and checksum. PDF files are held in private storage and accessed only through short-lived signed links.

Client signing links are single-use and expire after 72 hours.

6. Hosting, processors and recipients

• Database, authentication and file storage hosting: Supabase, data centre in the European Union (Frankfurt am Main)

• Application and website hosting, content delivery: Cloudflare

• Payment processing for subscriptions: Stripe Payments Europe, Ltd. (Dublin, Ireland) — receives billing and contact data for payment, subscription management and invoicing

• Client deposits, where enabled: Stripe, using the respective studio's own credentials

• Email delivery: Resend or our host's delivery service, sending via notify.tattoodeck.com

• SMS and WhatsApp reminders, where a studio enables these add-on channels: Twilio Ireland Limited (Dublin, Ireland), and for WhatsApp additionally WhatsApp Ireland Limited — receives the phone number and the reminder text

• Calendar connections, where enabled: Google Calendar, Apple iCloud (CalDAV), Calendly, Cal.com — only after the studio explicitly links them; while a connection is active, appointment data is transferred to that provider

• Tax advisers, legal advisers and authorities where legally required

Agreements under Art. 28 GDPR are in place with all processors. Transfers to third countries take place only on the basis of an adequacy decision or EU standard contractual clauses (Art. 44 et seq. GDPR).

7. Retention

• Account data: for the term of the contract, then deleted within 30 days to 3 months

• Invoices and accounting records: 10 years pursuant to Section 147 AO and Section 257 HGB

• Signed consent forms: 10 years, then deleted automatically

• Server and security logs: usually 30 days

• A studio's client data: as instructed by the studio; deletion or anonymisation on request, while signed consent records are retained as evidence until the end of the retention period

8. Cookies and analytics

We use only strictly necessary cookies and local storage: login session, language selection and security features (Art. 6(1)(f) GDPR, Section 25(2)(2) TDDDG).

We use no tracking, no advertising networks and no consent-requiring analytics, which is why there is no cookie banner. Stripe's checkout sets its own cookies necessary for payment.

9. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR), and the right to withdraw consent at any time.

Please send requests to support@tattoodeck.com. We respond within one month.

If your request concerns data a studio processes about you, please contact that studio directly; we forward requests where needed. In Tattoodeck, studios can run access, export and deletion for their clients themselves.

10. Security

We apply appropriate technical and organisational measures: encryption in transit (TLS), encryption at rest, role-based access rules at database level, tenant separation, private file storage with short-lived signed links, audit logs and least-privilege access.

11. Right to complain

You may lodge a complaint with a data protection authority. The authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information, Alt-Moabit 59–61, 10555 Berlin, Germany.

12. Changes to this notice

We update this notice when the Service or the legal situation changes. The current version is always available on this page; the date is shown at the end.

Last updated: 3 September 2026

Back to the homepage