Privacy Policy
Privacy Policy
1. Who this covers
Tattify connects tattoo clients with tattoo artists. Both use the same app, and this policy applies to both, plus to anyone who browses artists on our website without an account, and anyone without an account who reports an artist to us for impersonating them (§8).
You must be 18 or older to use Tattify. We do not knowingly collect information from anyone under 18. If we learn that we have, we delete it. If you believe a minor has given us information, write to privacy@tattify.tech.
2. What we collect
When you create an account
Your name, email address, and a password. The password is stored in hashed form by our authentication provider; we never see it.
Your phone number, if you give us one. In the app the field is optional.
⚠️ What we use your phone number for, stated plainly: nothing yet. We collect it so that we can send you text-message reminders and notifications about your appointments in the future. Tattify does not send text messages today — the capability is not built, and no phone number has ever been used for anything. If you would rather not give us one, leave the field blank; nothing in the app depends on it.
When you set up an artist profile
Your studio or shop name, your studio address, a profile photo, portfolio images, your working hours and availability, the deposit amounts you charge, and the styles you list. Your legal first and last name, which is never shown to clients (§4). And, if you choose to upload one, a photo of your tattoo or studio license (§5). We derive your studio's time zone from your address, and we keep it, because payout timing depends on it.
When you request an appointment
Your answers to the artist's questions, the reference photos you upload, and the details of what you are asking for.
When you message someone
The content of your messages and any photos you attach. We also store the notification text we generate from a message, so the conversation and the notification stay consistent.
This includes what you write to Tattify. Artists have a conversation with Tattify itself, which we use to tell them about a dispute, a payout matter or the outcome of a report — and they can write back into it, with photographs, and a person at Tattify reads what they send. We store those messages and those photographs the same way we store any other. §5 and §12 say what happens to them.
Created by using Tattify
- Appointment records — dates, times, status, what was agreed. - What an artist said happened at an appointment when they closed it out — that the tattoo went ahead, or that the client did not turn up. The client is not shown the record, but a client marked as a no-show is told so, in the chat and by notification (§6). When an artist moves an appointment the client missed, we also keep the missed date alongside the new one, and only the artist is shown it. All of this is kept with that appointment's record, for as long as §10 keeps that, and it is not added up across a client's appointments or used to judge them. - Payment records — amounts, dates, whether a payment succeeded, was refunded, or was disputed. - Payout records — what was paid to an artist, and when. - Your card's brand and last four digits. Never the number. See §4. - Which legal document version you accepted, and when. - Device tokens for notifications, if you allow them, and — while you have a chat screen open — which conversation your device is looking at, refreshed while you are on it. We use that for one thing: not sending you a notification about a message you are already reading. - When you last read a conversation. The other party to that conversation can see it. - Anyone you have blocked, and when. Kept until one of you unblocks. See §10. - Anything you report. If you file a report, we keep what it was filed on — a portfolio image, a profile, or a request — the reason you chose, whatever you wrote to explain it, and what we decided. If you file a complaint about an artist, the same. See §8 and §10. - Anti-abuse counters: on payment attempts; on the other things you do while signed in, such as sending messages, requests or reports; and on address lookups and artist searches. The last kind is the only thing in Tattify that is derived from your network (IP) address, and what is stored is not the address: it is a one-way scrambled value computed from it with a secret only our server holds, which lets us count requests from the same place without recording where that place is. It cannot be turned back into an address by anyone reading our database. That counter is deleted within a day, and we keep it for one purpose: stopping somebody from running our artist list or our address lookup at machine speed. The other two are kept differently; §10 says how.
Notes an artist writes about a client
An artist can write private notes on a request. The client never sees them. They are stored with the request.
Your location
Tattify asks for permission to use your device's location on the Explore screen, where you browse artists — including before you have an account.
If you allow it:
- Your coordinates are sent to our servers to run the search. They are not written to our database and are not kept. - Your coordinates are also passed to your phone's own geocoding service — Apple's on iOS, Google's on Android — to turn them into a place name to show you. That lookup is handled by your device's operating system under its provider's terms, not ours.
You can say no. Explore still works — you type a location instead — and nothing else in the app is affected. You can change your mind in your device settings.
Artists' studio locations are different: an artist types their address and we do store it, because clients need to find them. See §5 and §8.
Your calendar
Tattify never asks for access to your calendar, and never reads or changes it. When you tap Add to Calendar on a confirmed appointment, Tattify hands the appointment's details to your device's own calendar screen, already filled in. You choose whether to save it, and your device saves it — nothing comes back to us, including whether you saved it at all.
You may still see Tattify listed under Calendars, and under Reminders, in your device's privacy settings. iOS requires an app to declare those categories before it can open the calendar screen at all. The listing reflects what the app could ask for, not anything it has asked for or received.
What we do not collect
We do not use analytics, tracking, advertising identifiers, or crash reporting. The app contains no third-party analytics or tracking software of any kind, and neither does our website: no tag manager, no pixel, no external scripts. Our website sets no cookies on any public page.
We do not sell your information and we do not share it with advertisers. We never have.
3. Why we use it
- To create and run your account - To let clients find artists, and to work out how far away they are - To let you send, receive and answer requests - To let you message the other party to a request - To take deposits, payments, tips and refunds, and to pay artists - To notify you about your requests, appointments and payments - To handle chargebacks, disputes and reports - To detect and prevent abuse - To meet our legal, tax and accounting obligations
4. Payment information
We never see or store your card number. When you add a card it goes directly to Stripe, our payment processor. Stripe stores it and gives us a reference — enough to charge the card you authorized, plus its brand and last four digits so you can tell which card it is. We also give Stripe your email address with each payment, so that Stripe can send you a receipt (§7).
We hold records about payments: amounts, dates, and outcomes.
Every payment we create at Stripe carries identifiers for the request, the client and the artist. Those identifiers are internal reference numbers, not names — and they are deliberately designed to outlive the records they point at, so that a payment can still be traced after an account is deleted. See §12.
For artists: to be paid you create a Stripe Connect account. Stripe collects your date of birth, the last four digits of your SSN and your bank details directly from you, on Stripe's own pages. Those never pass through Tattify and are stored in no Tattify system. Your legal first and last name is the exception. You give it to us when you sign up; we keep it privately, never show it to clients or other users, and pass it to Stripe when your payout account is created so that Stripe's identity check verifies it. If you upload a license, we compare the name on it with this one (§5). We delete it when you delete your account; Stripe's copy stays with Stripe (§12). Beyond that, we see only whether your account is verified and able to receive payments.
Stripe processes your information under its own privacy policy: stripe.com/privacy.
5. Who we share it with, and what each one gets
We share information only with the companies that make Tattify work, and only what each needs.
Stripe — What they get: Payment and payout records; a client's email address and internal id; an artist's identity and bank details, collected by Stripe directly; Why: Processing payments, paying artists, and emailing clients a receipt after each payment Supabase — What they get: Your account, messages, photos, requests, appointment and payment records; Why: Our database and file storage Vercel — What they get: Website traffic; Why: Hosting tattify.tech Expo, and Apple or Google — What they get: The content of a notification — see §6; Why: Delivering push notifications Resend — What they get: Your email address, and the content of the email; Why: Sending account emails, and the ones in §7 Anthropic — What they get: the photo of a license an artist chooses to upload, and nothing else — not the artist's name, address or account; Why: an automated AI reader extracts the details printed on the license so that Tattify can check them. Anthropic makes no decision about the artist: the comparison and the badge are Tattify's. Google (Places) — What they get: The address text as it is typed — and, as of 2026-09-14, no longer your device's IP address ‡; Why: Turning a typed address into map coordinates Google Maps or Apple Maps — What they get: An artist's full studio address; Why: Opening directions when a client taps the address Your phone's OS provider (Apple or Google) — What they get: Your device's coordinates; Why: Turning them into a place name on the Explore screen
‡ This row changed on 2026-09-14 and the change is in the reader's favour. Until that date the app called Google's address service directly from the phone, so Google received the device's IP address along with what was typed. The call now goes through Tattify's own server, which passes on the address text and nothing that identifies the device — so what Google receives is the typed text and our server's address, not yours. What Tattify itself now holds as a result is the scrambled counter described in §2, and that is the whole of the trade.
There is no Twilio and no SMS provider, because there is no text messaging.
The agreements behind that list
Every company above handles your information under an agreement with us that limits what they may do with it. They are not all the same kind of agreement, and the differences are worth stating plainly rather than flattening into one sentence.
- Stripe — data processing terms forming part of the Stripe Services Agreement, accepted when Tattify's account was opened. - Supabase, Vercel and Resend — each provider's data processing terms, incorporated into the terms Tattify accepted for each account. - Expo — a separate data processing agreement, in place. - Google — Google Cloud Platform's data processing terms, accepted on 2026-09-14, when the address lookup described below was set up. - Anthropic — the data processing addendum incorporated into Anthropic's Commercial Terms of Service, which Tattify accepted when it opened its account. Those terms do not allow Anthropic to train its models on what we send.
⚠️ Stripe is not only acting on our instructions, and this is the one difference on the list that changes what you can ask us for. For its own legal obligations — verifying an artist's identity, preventing fraud and money laundering, and reporting to tax and financial regulators — Stripe decides for itself what it collects and how long it keeps it, and answers to its regulators rather than to us. For everything else it handles on Tattify's behalf, it acts on our instructions. This is why §12 says that closing an artist's Stripe account is between the artist and Stripe: for those records we cannot instruct Stripe to delete, and implying otherwise would be telling you something untrue.
Apple and Google also receive information, under a different kind of arrangement, and we name it rather than implying a contract that is not there. They carry the content of push notifications to your phone (§6), and they receive the ordinary information involved in distributing and updating an app. What governs that is Apple's and Google's developer agreements — the terms Tattify accepted in order to publish an app in their stores — together with each company's own published privacy terms. It is not a data processing agreement of the kind the list above describes, and neither company offers one for this purpose.
Two rows of the table are covered by no agreement of ours at all, and that is not an oversight. Your phone's own geocoder, and the maps app that opens when you tap an address, are software on your device rather than services Tattify engaged; we contract with neither. What reaches them is governed by your own relationship with whoever made your phone.
About the address lookup
When an artist types a studio address, what they type is sent to Google as they type it, to convert it into coordinates. This happens:
- for the address an artist enters at sign-up, before any privacy setting has taken effect; - for the address an artist later edits; - and for anything anyone types into the location box on Explore — including someone with no account, and including a home address.
It happens even when an artist has marked their studio private. The private setting stops clients seeing the address inside the app; it does not stop the lookup.
The request goes through Tattify's own server, not from your phone to Google. That changed on 2026-09-14. Google receives the address text and our server's network address; it does not receive yours. Our server keeps no record of what you typed — only the scrambled request counter described in §2, which is deleted within a day.
Google is a contracted processor for this, under Google Cloud's data processing terms, and handles the address text on Tattify's instructions rather than as an independent service setting its own terms.
What the other party to a request sees
- A client sees the artist's public profile, and — once an appointment is booked — the studio address, which is put into the conversation and stays there afterwards, including after the artist edits or hides it. - An artist sees the client's name, their answers, and their photos. - Neither sees the other's email address, phone number, or payment details. - Both can see when the other last read the conversation. - Tattify is a party to one conversation of its own, with each artist. We write to an artist there about disputes, payouts and the outcome of a report; the artist can write back, including photographs, and a person at Tattify reads it. Clients are not part of that conversation and cannot see it. §12 says what happens to those photographs when an artist deletes their account — they are the one thing deletion does not reach.
What is public to anyone
- Portfolio images, and artists' profile photos. They are stored so that anyone with the link can open them, with no account — this is measured behaviour, not a theoretical possibility. - An artist's booking-link page, which renders their profile and portfolio to anyone who opens it. - Artist profiles in search. Someone with no account can browse artists. - The questions an artist asks on their request form. Anyone who opens that artist's booking link can read them, with no account.
A client's profile photo is not public. Only the client and the artists they have sent a request to can see it, through a link that expires after a short time.
Reference photos and chat photos are not public. They are served from private storage through links that expire after an hour.
We may also share information when the law requires it, to enforce our Terms, to investigate fraud or a report, or if Tattify is ever sold or merged.
6. Notifications
A push notification carries the message itself. When someone sends you a message, the notification's title is their name and its body is the message text, shortened if long. To reach your phone it passes through Expo's push service and then Apple's or Google's, and it can be read on your lock screen by anyone holding your phone.
Studio addresses are deliberately stripped out of notifications and never appear in one.
Automatic notifications are titled Tattify rather than a person's name. Some of them carry a money figure: a deposit charged, kept or refunded, or a payment for an appointment, will show the amount on a lock screen. Some show the other person's name — for example when an artist proposes an appointment, or a client accepts or declines one. Two of them show an appointment's date and time: the notification that an appointment has been booked, and the one that it has been moved to a new date. None of them shows a studio address. Messages Tattify sends an artist about a dispute, a payout or a report say only that there is something to read — no amount, no name, no booking details.
If several messages arrive in the same conversation within a minute, you get one notification rather than one for each; the messages themselves all arrive.
You can turn notifications off in your device settings. Doing so does not stop the messages themselves, which stay in the app.
7. Email
We send email through Resend, and one kind through Stripe.
1. Account email — confirming your address, resetting your password, confirming an email change, and telling you when your password has been changed. 2. Notices we have to send you — telling an artist about a warning, a removal or a suspension, and telling a client when a request was declined because the artist's account was closed. 3. If you report an artist from our website for impersonating you, an email asking you to confirm the report. You receive it whether or not you have a Tattify account. 4. Feedback you send us from inside the app. 5. Payment receipts. After each payment a client makes — a deposit, a deposit for a further appointment, or a tattoo payment — Stripe emails a receipt to the email address on the account. It shows the amount, what it was for, the date, the card's last four digits and our support address. Stripe sends it, not Resend, and Stripe already holds your email address (§4, §5).
⚠️ Feedback is different, and we say so here rather than leave you to find out. When you send feedback from the app, it is sent to us as an email containing what you wrote — up to 4,000 characters — together with your name, your account email address, your role and your account's internal id. It is not stored in Tattify's database at all, which also means it is not covered by account deletion: the message and your identity stay in our support mailbox until it is deleted there. If you would rather send feedback without that, email privacy@tattify.tech instead.
Emails about your appointments and payments are part of the service and cannot be turned off while your account is open.
8. Reports and complaints
A client can report an artist from a request or its chat. What you write — up to 2,000 characters — is stored with the report and is read by Tattify.
The artist is not shown the report. If the outcome is a warning or removal, they are told that a report about one of their bookings was reviewed, and what the result is. They are not told who reported them or what was said.
The artist can respond to us, in their own conversation with Tattify (§2, §5), including with photographs, and a person reads what they send. They still are not shown the report and still cannot see who filed it. What they write is kept with the record of the decision. It is not an appeal: nothing obliges us to reverse an outcome or to reply.
Reports, and the decisions taken on them, are kept as a record of the decision. §10 says for how long, which is: with no time limit.
Reports on a portfolio image, a profile or a request
Anyone signed in can file a report on a portfolio image, on an artist's profile, or on a request. Either party to a request can report it. A report on a request is about the request as a whole — its chat, questions, answers and photos together — and does not point at any one message or photo. The reporter chooses a reason and can write up to 2,000 characters. We keep all of it.
A report records what it was filed on. For a request, that means we can see which request it is and who the two parties are, and the person reviewing it sees the other party to the request as the one the report concerns. For an image or a profile, we see whose it is.
One kind of content is hidden automatically, without anybody at Tattify looking first: a portfolio image is hidden at three different reporters. The one other exception is a report that an artist is impersonating someone: from a signed-in person, it can hide the artist's whole profile straight away (see If you report impersonation, below). Nothing else is hidden automatically, and a report on a request changes nothing in the request or its chat.
We do not tell the person whose image was hidden. There is no message, no email and no notification — it stops appearing, and that is all. They can ask us at support@tattify.tech. The person who reported is not shown to them, and the other party to a reported request is not told that a report was filed.
If we decide to remove a reported portfolio image rather than only hide it, it is taken out of public reach at once and moved to private storage that only Tattify can read. We keep it there for 180 days from the removal, as the record of why it was removed, and then delete it. If the artist's account is deleted in that time, it goes with the account.
If you report impersonation
If you report that an artist is impersonating you, we keep your name, your email address, the link you gave us and what you wrote — whether or not you have a Tattify account. If you report from the app, we take your name and email address from your account and keep that copy even if you later delete your account. If you report from our website, we also email you a link to confirm the report (§7).
A report from a signed-in person can put the artist under review straight away: their profile is hidden and their photos are taken out of public reach while we look. The Terms of Service and the Artist Agreement describe the rest of the process. The artist is not told who reported them.
9. Where your information is stored
Tattify's database and files are stored in the United States — specifically in Supabase's Oregon region. Our website is hosted in the United States by Vercel.
Our providers — Stripe, Resend, Expo, Google, Anthropic — operate internationally and may process information outside the United States.
Our database is backed up, and photographs are not included in those backups. How long a backup still holds something after it has been deleted is a question about time rather than about place: §10 states the period and what it means for deletion, and it is stated there and nowhere else.
10. How long we keep things
We keep different information for different lengths of time, for different reasons.
While your account is open
Your account and your profile are kept for as long as your account is open.
Your requests, appointments, messages and photos are not. They are kept for as long as the windows below allow, and then they are deleted — even though your account is still open and you are still using Tattify. A booking you had last year, and the conversation and photos that went with it, will not be there indefinitely.
Records that could be needed for a dispute — 180 days past the appointment
Card networks let a client dispute a charge months after it happens, and tattoo appointments are often booked far in advance. So the information that would be needed to resolve a dispute — the request, its messages, its photos, the appointment record — is kept until 180 days after the appointment date. Not 180 days after the payment: the appointment is the event the dispute is about, and artists here book six to eight months out.
If a request never became an appointment, we keep it for 180 days after the last activity on it.
If a dispute is filed — kept until it is resolved, then 180 days
If a payment is disputed, everything relating to that appointment is kept until the dispute is fully closed, and then for a further 180 days after the dispute closes. This overrides the 180 days from the appointment and can run well past it: a dispute filed late in the appointment window, or a second one filed after the first closes, extends the hold rather than shortening it.
Four other things hold a record past its window
A dispute is not the only thing that stops the clock. A record is also kept, past the 180 days, while any of these is true of the booking it belongs to:
- a report about it has not been resolved — we cannot look into something and delete the thing we are looking at; - a payment on it is under review by us — the same reason; - any money on it has not come to rest. A deposit still only authorised, a payment we took and could not finish recording, a refund that failed, an amount still owed in either direction, or a deposit charged that has never been paid out to the artist. A booking in one of those states is a booking somebody may still be owed something on, and the record is the only evidence of it.
Each of these ends when the thing itself ends, and the ordinary window then applies. None of them has a deadline of its own, because none of them is a timer — they are open questions, and they are kept until they are answered.
Financial records — seven years
Payment amounts, dates and outcomes are kept for seven years to meet tax and accounting requirements. These records are de-identified: the amounts and dates remain, your name and contact details do not.
Our internal alerts — 90 days
When something goes wrong — a payment that did not settle, a refund that failed, a job that did not run — our system writes an internal alert so a person can look into it. An alert can name the booking, the artist or the payment it is about. These are kept for 90 days after the last time we saw the problem, or after it was marked resolved, whichever is later.
An alert about a problem nobody has resolved yet is kept until it is resolved. We do not delete the record of an open problem because it has reached a certain age.
One kind of alert is kept for seven years instead of 90 days, on the same clock as the payment record it belongs to. It is the note we write when a card payment goes through without our being told which country the card was issued in — the note is the only record that the rate we charged was never confirmed, and the payment it explains is itself kept seven years, so a shorter period would leave the payment on file with the explanation missing. It names the booking, not you.
The record of what our staff do — seven years
When someone at Tattify acts on an account — issuing a refund by hand, reissuing a payout, correcting a booking that got stuck — we record who did it, what they did, and what the record looked like before and after. These are kept for seven years, the same period as our financial records, because they are the explanation of how those figures came to be what they are.
Why those two are kept even after you delete your account
The two categories above are kept even when they name you, and a deletion request does not reach them. We keep them to detect and investigate fraud, to answer a payment dispute, and to meet the record-keeping obligations that come with handling money. Deleting the record of a problem, or of what we did about it, on the request of someone it concerns is not something we can offer.
They are internal records, not part of your account: nobody sees them in the app, and they are not used to make decisions about you beyond resolving the thing they are about. §12 says what a deletion request does and does not reach.
What we delete sooner
Operational records go quickly: notification delivery records (7 days, or 30 days if a send failed), scheduled-job records (7 days), and internal service logs held by our providers for short periods (hours to about a day).
Our anti-abuse counters are kept for different lengths of time, and we would rather say so than give you one figure that is right for one of them.
- The counter behind address lookups and artist searches — the scrambled value described in §2, which is derived from a network address and is not one — is deleted within a day, whether or not you come back. - The counters behind payment attempts and the other things you do while signed in are different, and they are the one place on this page where we do not have a period to give you. Each is a list of times you did one kind of thing, kept against your account. Old entries are cleared out the next time the same account does that same kind of thing — which for someone who keeps using Tattify means they never last more than an hour, and for an account that stops, or that is deleted, means the last few entries stay indefinitely. They hold nothing but your account's internal reference number, the kind of action, and the times. We are fixing this, and until it is fixed this page says what happens rather than a period we do not enforce.
Our record of sending ourselves an alert summary — that one went out, when, and how many alerts it covered — goes at 90 days with the alerts themselves. It names no user. (One row of it survives: the one carrying the current summary number, kept so the count cannot silently restart and hide a summary that was never delivered. It names no user either.)
The record of each deletion run — seven years
One record is the exception to "scheduled-job records go in 7 days", and it is the record of the deletions themselves. Each nightly run of the deletion job writes what it examined, what it deleted, and what it held back and why — and that last part carries the internal reference numbers of records that are still here, because "this booking was kept, for this reason, until this date" is the whole of what it says. It holds no names, no contact details and no message content. We keep it seven years, with our financial records, because it is the evidence that the periods on this page were honoured, and it is the one record that could not be reconstructed from anywhere else once the things it describes are gone.
Reports about content, and blocks — kept with no time limit
When somebody files a report — on a portfolio image, on a profile, or on a request — we keep who reported it, which image, profile or request it was filed on, the reason they chose, anything they wrote to explain it, and what we decided. For a report on a request, that record identifies both parties to the request. §8 describes how reporting works.
Impersonation reports are kept the same way, with no time limit: the reporter's name, email address, link and what they wrote, and what we decided — including a report from someone with no account, a report we did not uphold, and a report whose reporter has since deleted their account.
When somebody blocks somebody else, we keep who blocked whom and when, because that is what makes the block work.
Neither of these has a period, and neither is deleted on a schedule. A block ends when either person unblocks. A report is kept as the record of a decision.
They are also not removed by the reported thing going away, so a report can outlive the image, the profile or the request it was about.
What deletion does reach: if your account is deleted outright — the case in §12 where you have no bookings or payouts at all — the reports you filed and the blocks you set go with it. The one exception is a report that an artist is impersonating you: it is kept, with your name and email address, as described above and in §8. If your account is one where booking and payment records are kept, they stay, still carrying your account's internal reference number, though your name and contact details have been removed from your profile. If you want a report you filed removed, write to privacy@tattify.tech.
Removed content — 180 days
A portfolio image we remove after a report is kept privately for 180 days from the removal, then deleted. §8 says why.
Our backups — seven days
Deleting something removes it from our live systems immediately. A copy can remain in a backup for a short time afterwards, and that is the part a privacy policy usually leaves out.
Our database is backed up once a day, and we keep seven days of those backups. A record deleted today — by you, or by the nightly clean-up described above — is still inside the backups taken before it was deleted, and it goes when the last of those ages out. Seven days is therefore the outside figure for how long anything deleted still exists anywhere in our systems. We keep no continuous or point-in-time copy, so there is nothing older, and nothing finer-grained, than that.
A backup is not something we search. It exists to restore the database if something goes badly wrong. Nobody at Tattify reads one to look a person up, and restoring one is a whole-database operation rather than a way of retrieving a single record.
Your photographs are not in the backups at all. Uploaded images — request photos, portfolio images, chat photos — are held in file storage separate from the database, and that storage is not part of the backup. A deleted photo is gone at the moment it is deleted, with no copy to age out.
11. Your choices
- See or correct your information — most of it is editable in the app. For anything else, write to us. - Delete your account — in the app; §12 says exactly what that does. - Request a copy of your information — privacy@tattify.tech. - Turn off notifications — in your device settings. - Stop emails — appointment and payment emails are part of the service and cannot be turned off while your account is open. There is no marketing email to unsubscribe from.
We aim to respond within 30 days. If we need longer, or need to verify who you are, we will say so.
Depending on where you live you may have further rights. Write to privacy@tattify.tech and we will tell you what applies.
12. Deleting your account — exactly what happens
You can delete your account from within the app. It cannot be undone.
When it takes effect. Everything described below is removed from our live systems straight away. A copy of the database records can still sit inside a backup for a short time afterwards, and then it is gone — §10 states the period, and explains why a backup is not something we can search. Photographs are not in our backups at all, so a deleted photo goes at once and completely.
When deletion is refused
Deletion is refused while:
- a deposit you paid is on an upcoming appointment, or, for artists, a client's deposit you hold is — cancel the appointment first; - a payment on any of your bookings is under dispute with a bank — you can delete once it is resolved; - money is in an unresolved state: a payment that needs a person to resolve it, a deposit charged for a booking that was never written (which clears by itself in a few days), a consultation conversion or a bank check that did not finish, an appointment whose status cannot be confirmed, or, for artists, a refund still settling with Stripe (up to 30 days); - we cannot reach Stripe to confirm that none of the above applies — try again later.
The app tells you which. Before deleting, you are asked for your password again, and deletion goes through only if you have signed in within the last five minutes. This applies when you delete your own account, not when we delete an account suspended for impersonation at the end of its 90 days, as the Terms of Service and Artist Agreement describe, since its holder can no longer sign in.
If you have no appointments and no payouts at all
Your account is deleted outright. Your account is removed, your photos are deleted, and your email address is freed up to sign up again. Reports you filed and blocks you set go too, except a report that an artist was impersonating you, which is kept with your name and email address (§8, §10).
⚠️ One exception applies on this path as well: photographs you sent to Tattify itself. If you are an artist and you sent us pictures in your Tattify thread, those files stay in our storage after everything else has gone. The paragraph below explains why and what to do about it; it is the same exception, and it is not limited to the other path.
⚠️ Two things sit outside this, and outside everything else in this section. Our internal alerts and the record of what our staff did on your account are not deleted by a deletion request — not on this path and not on any other. §10 says how long each is kept and why. If nothing ever went wrong on your account and nobody at Tattify ever had to act on it, there is nothing in either; that is the usual case, and it is not something we can promise in advance.
Otherwise — what is deleted
Your request answers and their photos; an artist's reference photos, portfolio images, availability and contact details; your saved payment methods; your notification tokens; your favourites, in both directions; and the photo messages you sent to another person.
⚠️ One exception, and it is ours rather than yours: photographs you sent to Tattify itself. If you are an artist and you sent us pictures in your Tattify thread — contesting a chargeback, or answering a report — those files are not removed by deleting your account. Nobody can open them afterwards: the permissions on them are tied to your artist profile, so once that is gone no account can reach them. But the files themselves remain in our storage until we remove them, and we do not have an automatic process that does. If you want them gone, write to privacy@tattify.tech.
What is anonymised
Your name becomes "Deleted user". Your profile photo and bio are removed. An artist's address, area, shop name and styles are cleared, which is what takes them out of search.
What is kept, and this is the part worth reading
This list is not only about what stays visible to the other person. Two of the entries below — the record of what our staff did and our internal alerts — are records we keep for ourselves, and a deletion request does not reach them at all. They are marked where they appear.
- The text of every message you sent stays in the other person's conversation, word for word, shown as from a deleted user. Only photo messages are removed. The other person keeps the whole conversation. - The notification text generated from those messages, likewise. - Booking and payment records — amounts, dates, outcomes — so that the other party's payment and appointment history keeps working. Your name and contact details are removed from them. - Payout records and dispute records. - Your record of accepting our legal documents, kept as evidence that you accepted them. - The record of what our staff did on your account, including before-and-after snapshots of the records that were changed — kept seven years, and not removed by this deletion. §10. - Our internal alerts about problems involving your bookings or payments, which can name the booking, the payment or the artist — kept 90 days, longer while the problem is unresolved, seven years for the one kind described in §10, and not removed by this deletion. - The anti-abuse counters behind payment attempts and other signed-in actions — your account's internal reference number, the kind of action, and the times. Not removed by this deletion, and with no period behind them, for the reason §10 gives. - An artist's studio time zone, because payout dates depend on it. - Reports you filed — what you reported, your reason, what you wrote and what we decided — and anyone you had blocked. Kept with no time limit, and not removed by this deletion, because this is the path where booking and payment records are kept. §10. - At Stripe: the identifiers on each payment, which are designed to outlive the deleted records, and the email address each payment's receipt was sent to. Deleting your account does not remove either from a payment Stripe has already processed.
What happens at Stripe
Your saved card is detached, your Stripe customer record is deleted, and any open card holds are cancelled.
⚠️ For artists: your Stripe Connect account is not deleted, not disabled, and not touched. Your identity details, the last four of your SSN, your date of birth and your bank details remain with Stripe. Closing that account is between you and Stripe.
Signing in afterwards
You can never sign in again. Your sign-in is disabled, your email and phone number are obfuscated, your password is removed and every session is ended — while the underlying account row is kept, so that the records above still resolve.
And one exception
Feedback you sent us by email is outside all of this. See §7.
13. Security
Passwords are hashed by our authentication provider and are never visible to us. Card numbers never reach our servers. Access to your information is restricted by database rules that limit each account to its own data, and the records only Tattify should see are unreachable by any account at all.
No system is perfectly secure, and we cannot guarantee that unauthorized access will never occur.
14. California residents
We do not sell your personal information. We do not share it for cross-context behavioral advertising. We never have.
Tattify makes money from a flat platform fee on bookings. We have no advertising business, no data-sharing arrangements, and no analytics or tracking software of any kind.
Whether or not California law formally requires it of a business this size, we will honour these requests from any California resident:
- Know what personal information we hold about you - Get a copy of it - Correct anything inaccurate - Delete your account and your information, subject to §12
Contact privacy@tattify.tech. We will not treat you differently for asking.
15. Changes to this policy
We may update this policy. When we do, we publish a new version with a new date; a published version is never edited. The current version will be available in the app and at tattify.tech/legal/privacy.
If a change materially affects how we handle your information, we will tell you.
We ask you to confirm you have read this policy when you sign up, alongside the age confirmation and the terms for your role. All three are shown together on the way into the app, each with its own box to tick.
When a new version is published, we ask you again. You will see it the next time you open Tattify, and you will be asked to confirm that you have read it before you book, are booked, or change your payment details. Your existing appointments, messages and payments stay open to you while you decide. We record that you were shown that version and confirmed it, together with the date — that record is the only thing we keep about it.
We do not warn you before a new version takes effect. It takes effect when we publish it, and the ask happens the next time you open the app.
Some changes will always be reflected in a new version of this policy: analytics or crash reporting of any kind; text messaging; any new company that receives your data; storing location, using it in the background, or using it for anything but the Explore search; and any change to what a notification carries. We aim to publish that version before the change reaches you. If a change reaches you first, we publish the new version as soon as we practically can afterwards, and it says what changed.
16. Contact
privacy@tattify.tech
Tattify Technologies, LLC 22547 Raspberry Ln Wildomar, CA 92595
Questions in the meantime? Email hello@tattify.tech.