TattooLedger
Features
PricingCompareAbout
Sign inStart free trial

Legal & trust

Privacy policyTerms of serviceData processing addendumSubprocessorsSecurity

Data Processing Addendum

Effective July 28, 2026 · Incorporated into the Terms of Service

1. Roles and scope

For personal information that you (the artist or studio, the “Customer”) collect from your clients and store in Tattoo Ledger (“Client Data”), you are the organization responsible for it (controller); Tattoo Ledger is your service provider (processor). This addendum governs all processing of Client Data for the duration of your subscription.

2. Details of processing

Subject matterBooking, client management, waivers, and client communication for the Customer’s tattoo business
Data subjectsThe Customer’s clients; guardians of minor clients
Data categoriesContact details; appointment and project history; notes and images; waiver signatures with IP and timestamp; sensitive: health-history answers, government-ID photos, guardian identity data
DurationSubscription term plus the export window in the Terms

3. Our commitments

Instructions only

We process Client Data only to provide the service and on your documented instructions (your configuration and use of the product), never for our own marketing or profiling, and we never sell it.

Confidentiality

Personnel with access are bound by confidentiality obligations; access is role-limited and logged.

Security

We maintain the measures described on our Security page — encryption in transit and at rest, access control, tokenized client links, audit logging, backups — scaled to the sensitivity of health and identity data.

Subprocessors

You authorize the subprocessors listed at /legal/subprocessors. We post changes at least 30 days in advance; if you reasonably object to a change, you may terminate and export your data.

Assistance

We help you respond to client access, correction, and deletion requests (export tools, deletion on instruction) and provide information reasonably needed for your own compliance assessments.

Breach notice

We notify you without undue delay after becoming aware of a breach affecting Client Data, with enough detail for you to meet your own reporting duties. For Client Data, breach reporting to regulators and individuals is the Customer’s obligation; we support it.

Deletion and return

At termination, after the 90-day export window, we delete Client Data from production within 30 days and from backup rotation within a further 30 days.

Transfers

Client Data is hosted on Amazon Web Services in Canada (ca-central-1). Payment and email-delivery subprocessors process limited data in the United States. If GDPR ever applies to your clients, transfers rely on the subprocessors’ EU-approved mechanisms (standard contractual clauses / Data Privacy Framework), and this addendum operates as a processor agreement under Article 28.

Verification

On reasonable request (at most once yearly), we’ll answer security questionnaires and share summaries of our practices in lieu of on-site audits.

TattooLedger

The booking and studio management platform built for tattoo artists — consult to healed photo. Made in Canada.

Features

  • Books-open drops
  • Booking page & portfolio
  • Projects & series
  • Waivers & consent
  • Waitlist
  • Aftercare
  • Studios & front desk

Compare

  • vs Goldie
  • vs Porter
  • vs Square Appointments
  • vs Acuity

Company

  • Pricing
  • About & contact
  • Security
  • Sign in
  • Create account

Legal

  • Privacy policy
  • Terms of service
  • Data processing addendum
  • Subprocessors
© 2026 Tattoo Ledger. All rights reserved.Privacy questions: privacy@tattooledger.com