Affichr — Legal Version 1.9 · Effective: August 19, 2026 · Last updated: July 22, 2026

Privacy Policy

Affichr is committed to protecting your privacy. This policy explains what personal information we collect, why we collect it, who we share it with, and your rights regarding your data.

Contents

  1. Who We Are
  2. Data We Collect
  3. Why We Collect Your Data (Legal Basis)
  4. How Long We Keep Your Data
  5. Third-Party Service Providers
  6. Google API Services and Google User Data
  7. Your Rights
  8. Delete Your Account
  9. Cookies & Analytics
  10. Children's Privacy
  11. Data Security
  12. Data Breach Notification
  13. International Data Transfers
  14. Consumer Health Data
  15. California Privacy (CCPA / CPRA)
  16. EU/UK Privacy (GDPR)
  17. Other US State Privacy Rights
  18. Canadian Privacy (PIPEDA)
  19. Changes to This Policy
  20. Contact & Complaints

1. Who We Are

Affichr is a booking and client-management platform for tattoo artists, studios, and salons. We serve the United States first and Canada second. EEA and UK artist accounts may be created, but full artist operations remain gated until Affichr completes payment, tax, representative, and legal review.

For account administration, security, billing, subscriptions, platform analytics, fraud prevention, legal compliance, and product operations, Affichr acts as the data controller (or, in California terms, the "business"). For client data that an artist or studio enters, imports, or manages for their own services, the artist or studio is generally the controller and Affichr acts as their processor/service provider under the Artist Data Processing Addendum. Affichr may also act as an independent controller where required for security, legal compliance, payment records, abuse prevention, support, and platform-level obligations.

Questions about this policy? Email us at info@affichr.com.

Affichr is operated by Nima Jolan as a sole proprietorship based in Montréal, Québec, Canada. You can reach us for any privacy matter at info@affichr.com or by mail at Affichr, 2065 rue Parthenais, bureau 293, Montréal, QC H2K 3T1, Canada.

2. Data We Collect

2.1 Data You Provide Directly

2.2 Data Collected Automatically

2.3 Data We Do NOT Collect

3. Why We Collect Your Data (Legal Basis)

Purpose Data Used Legal Basis
Creating and managing your account Name, email, phone number, password, profile settings Contract / Consent
Processing booking requests and appointments Profile, booking data, location or address data where enabled, payment data Contract
Collecting deposits and processing payments Payment data, Stripe token Contract
Sending appointment confirmations and reminders Email, phone number, push token, reminder preferences Contract / Consent / Legitimate interest
Providing Google Sign-In and Google Calendar sync Google account profile data, OAuth tokens, selected calendar ID, Google Calendar event metadata, Google push watch-channel metadata, Affichr appointment event details Consent / Contract
Sending subscribed cancellation-list alerts by client availability or area Cancellation-list preferences, selected alert channels, weekly windows, approximate client location, artist broadcast target area, and unsubscribe or STOP status Consent / Legitimate interest
Rate limiting public booking, uploads, and abuse-prone workflows Hashed IP address or email where applicable, user agent, outcome/reason code, timestamps, and limited upload metadata Legitimate interest / Legal obligation
Health screening before tattoo services Health questionnaire answers Explicit consent where required / Legal obligation / Vital interests / Article 9(2) health and safety bases where applicable
Generating and storing consent forms Health data, signature, IP address Legal obligation / Explicit consent where required
Video consultations Meeting tokens, appointment data Contract / Consent
Sending marketing emails (to opted-in users) Email, name Consent (US CAN-SPAM, Canada CASL)
Providing AI Assistant features AI messages and enabled account context, excluding health questionnaire answers, processed by the configured AI provider or self-hosted model endpoint Consent / Contract
Handling access, deletion, correction, and limitation requests Hashed requester email and IP address, request type, verification status, retained-record reasons, and operator notes Legal obligation / Legitimate interest
Monitoring reliability and resolving support issues Redacted app or Edge Function event metadata, redacted errors, route/screen/platform, status, and hashed contact data where provided Legitimate interest
Moderating uploaded images for safety and platform abuse Uploaded image metadata and temporary image review data Legitimate interest / Legal obligation
Preventing fraud and abuse IP address, login events Legitimate interest / Legal obligation
Complying with legal obligations (tax records, health records) Transaction data, consent forms Legal obligation
Improving the platform Aggregated usage data, crash reports, and optional analytics events Legitimate interest for strictly necessary diagnostics; consent for optional analytics where required

4. How Long We Keep Your Data

Data Type Retention Period Reason
Account data (active account) Until you delete your account Service delivery
Account data (deleted account) Eligible account data is deleted or anonymized when the in-app deletion request is completed; retained records remain only for the periods listed below User request, legal retention exceptions, fraud prevention, security, and dispute preservation
Consent forms & health records 7 years minimum Legal requirement (state/provincial health regulations)
Payment and transaction records 7 years Tax, accounting, payment processor, and dispute requirements
Appointment history 3 years after last appointment Dispute resolution / Legal claims
Communication logs (in-app messages) 2 years after account closure Dispute resolution
Uploaded design files Until the artist deletes them or closes their account Artist ownership of their files
Declined or deleted booking reference images 30 days after declined or deleted request aging Booking reference cleanup and PII minimization
AI conversations 90 days unless deleted earlier Assistant continuity, abuse prevention, and support
AI rate-limit and audit logs 180 days Security, abuse prevention, and troubleshooting
Public booking and upload abuse telemetry 30 days Rate limiting and abuse prevention
App monitoring events 30 days for resolved or ignored events; 90 days for non-open events; open events require operator review Reliability troubleshooting with PII minimization
Push notification tokens Until disabled, expired, deleted, or account closure Notification delivery
Push delivery logs Up to 1 year Delivery troubleshooting and abuse prevention
Google OAuth tokens, selected calendar ID, and watch-channel metadata Until you disconnect Google Calendar, delete your account, or the token is revoked or replaced Google Calendar sync and secure account linking
Google Calendar-derived blocked slots Overwritten on each sync and cleared when Google Calendar is disconnected or the account is deleted, subject to backups and legal/security holds Preventing double bookings and showing accurate availability
Client location used for cancellation-list broadcasts Until the client removes the preference, the artist deletes/anonymizes the client record, or the account closes, subject to legal retention exceptions Subscribed nearby-opening alerts and artist travel broadcasts
Marketing consent records 3 years after consent Proof of consent (US CAN-SPAM, Canada CASL)
Login security telemetry and device fingerprints 180 days Security, suspicious-login investigation, and user alerts
Privacy request workflow records Request lifecycle plus legal audit policy DSAR verification, review, retained-record documentation, and legal compliance
Admin audit logs Operational/legal policy Admin accountability and security investigations

5. Third-Party Service Providers

We share your data with the following third parties only to the extent necessary to operate Affichr. We do not sell your personal data. Mobile phone numbers, SMS consent records, and text messaging opt-in data are not shared with third parties for their marketing or promotional purposes.

Provider Purpose Data Shared Location Privacy Link
Supabase Database, authentication, private file storage, Edge Functions, and retention workflows (our backend) All data stored on the platform AWS (us-east-1 or your chosen region) supabase.com/privacy
Cloudflare Turnstile Invisible bot detection and abuse prevention for login and other protected flows Client IP address, TLS fingerprint, user-agent header, Turnstile sitekey and associated origin, and challenge outcome data USA / global infrastructure Cloudflare Turnstile Privacy Addendum
Stripe, Inc. Payment processing, deposit collection Name, email, tokenized card data, transaction amounts USA stripe.com/privacy
Twilio SMS appointment reminders and notifications Phone number, message content USA twilio.com/legal/privacy
Resend Transactional and reminder emails Email address, name, appointment details USA resend.com/privacy
Daily.co Video consultations Meeting tokens, session metadata (no video stored) USA daily.co/privacy
Google API Services Google Sign-In and Google Calendar sync for users who enable those features Google account profile data for sign-in; OAuth tokens, selected calendar ID, watch-channel metadata, Google Calendar event metadata, and Affichr appointment event details for calendar sync USA policies.google.com/privacy
Apple Inc. Sign in with Apple authentication for users who choose it Apple user identifier, name if shared, email address or private relay address USA apple.com/legal/privacy
Google Firebase / FCM Push notification delivery and mobile app infrastructure Device push tokens, notification metadata, delivery status USA / global infrastructure policies.google.com/privacy
PostHog Privacy-scoped product analytics and feature usage measurement Account ID, role, plan, app version, platform, and non-sensitive workflow events USA posthog.com/privacy
Groq Cloud AI Assistant model provider when selected AI messages and enabled non-health account context USA groq.com/privacy-policy
Google Gemini API Fallback AI model provider and image-safety moderation where enabled AI messages, enabled non-health account context, uploaded image review data USA / global infrastructure policies.google.com/privacy
Self-hosted or API-compatible model endpoint Optional AI Assistant model provider configured by the deployment AI messages and enabled non-health account context Deployment-controlled location Controlled by the deployment operator
Browserless.io PDF generation for consent forms HTML content of consent forms (ephemeral, not stored) USA browserless.io/privacy
Shorebird Over-the-air (OTA) app code updates App version, platform, and update-delivery metadata (no account data) USA / global infrastructure shorebird.dev/privacy
Affichr does not sell, rent, or trade your personal information to advertisers or data brokers. Data is shared with third parties only to deliver the services described above.

5.1 Google API Services and Google User Data

This section applies when you choose to sign in with Google or connect Google Calendar. These features are optional. Affichr's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

Data Accessed

For Google Sign-In, Affichr accesses your Google account identifier, name, email address, and profile image so we can create or sign you into your Affichr account. For Google Calendar sync, Affichr requests Google Calendar access so we can read calendar availability, create Affichr appointment events, update sync state, and delete Affichr-created calendar events when appointments are cancelled. Calendar data may include the selected calendar ID, event IDs, event titles or summaries, start and end times, time zones, event status, and Google push notification watch-channel metadata. Affichr does not request Google Drive, Gmail, Contacts, or Google Photos data for Calendar sync.

Data Usage

Affichr uses Google user data only to provide user-facing features you enable: account sign-in, calendar connection, blocked-time detection to reduce double bookings, creation of Affichr appointment events in your selected Google Calendar, deletion of Affichr-created events after cancellation, sync health checks, and support or security troubleshooting. Affichr may store Google Calendar-derived busy windows in your Affichr availability settings so your booking workflow can avoid unavailable times. If you enable the AI Assistant and allow availability context, Google Calendar-derived busy-window data may be used only to answer your own assistant request about your schedule; it is not used to train AI models.

Data Sharing

Affichr does not sell Google user data, does not share it with advertising platforms, data brokers, or information resellers, and does not use it for targeted advertising, retargeting, personalized ads, surveillance, creditworthiness, lending, or unrelated product analytics. Google user data is shared only with service providers needed to run Affichr, such as Supabase for secure backend storage and Edge Functions. If you create an Affichr appointment event, Google receives the event details needed to place that event on your calendar, such as appointment time, service type, client name, client email where available, notes that the artist entered for the appointment, reminder settings, and video consultation link where applicable. Human access to Google user data is limited to cases where you ask for support and authorize review, where access is necessary for security or abuse investigation, or where required by law.

Data Storage and Protection

Google OAuth tokens are sent only to Affichr's backend, encrypted before storage, and not exposed to the Flutter client after connection. Google Calendar tokens are encrypted at rest, transmitted over TLS, protected by Supabase Row-Level Security and server-side access controls, and used only by authenticated Edge Functions. Affichr stores only the minimum calendar data needed for sync, availability, auditability, and troubleshooting. Google Calendar event data is not stored in public files or public buckets.

Data Retention and Deletion

You can disconnect Google Calendar in Affichr settings. When you disconnect, Affichr clears stored Google OAuth tokens, selected calendar IDs, watch-channel metadata, and Google Calendar-derived blocked slots from active records, and makes a best-effort request to revoke the token with Google. You can also request account deletion through the in-app deletion flow or by emailing info@affichr.com. Account deletion removes or anonymizes eligible Google account profile data and Google Calendar sync data, subject to legal, security, dispute, backup, and fraud-prevention retention exceptions described in this policy.

AI and Model Training

Affichr does not use Google user data to develop, improve, or train generalized AI or machine learning models. Google user data is not used to build advertising profiles. AI Assistant providers are not permitted to use Affichr customer data for training, and Google Calendar-derived availability context is sent to an AI provider only when the user enables the AI Assistant and the relevant context source for a user-facing assistant response.

5.2 AI Assistant and Image Moderation

The AI Assistant is optional and requires an in-app disclosure acceptance before use. You may turn off AI access in settings. If enabled, Affichr sends your prompt and enabled account context to the configured AI model provider to generate a response. Default context is conservative and focuses on appointments, availability, and aggregate deposit status. Additional context sources such as client names, tags, private client notes, consultation notes, booking requests, project information, and search results require additional selection or configuration. Health questionnaire answers, consent form health answers, full payment card data, and authentication secrets are not included in AI Assistant context.

Affichr may use a cloud model provider or a deployment-controlled self-hosted model endpoint. When self-hosted AI mode is configured, cloud fallback is disabled unless the deployment explicitly enables cloud fallback.

Some uploaded images may be reviewed by automated image-safety systems to detect unsafe, unlawful, or abusive content. Affichr stores moderation metadata and decisions, not additional copies of image bytes beyond the underlying uploaded file needed to provide the service.

6. Your Rights

Depending on where you live, you have rights regarding your personal data. To exercise any right, contact us at info@affichr.com. For EEA/UK requests, we will respond without undue delay and no later than one month after receiving a verified request unless the law permits an extension. For verified CCPA-style requests, we will respond within 45 days unless an extension is permitted with notice. Some public booking pages may also offer a scoped access, deletion, correction, restriction, objection, portability, or consent-withdrawal request flow for client records tied to a specific artist relationship.

If you have an Affichr account, you can delete it yourself in the app or by email — see Section 7, Delete Your Account for the full steps and the records we are legally required to keep.

Public privacy request flows return a neutral response and do not confirm whether a matching record exists. The workflow stores hashed requester email and IP information, may send an email verification challenge, and requires operator review before export, correction, limitation, anonymization, or deletion is completed. Records that must be retained for legal, financial, health, fraud-prevention, security, or dispute reasons may be preserved with the retained reason documented.

Client-facing exports are designed to include client-provided data, appointments, consent records, messages, shared designs, and shared consultation materials. They do not include internal artist notes by default. Where an access request legally requires review of internal notes that contain personal data, Affichr or the artist may provide the required information in a redacted or summarized form to protect the rights and privacy of others.

Right to Access CAEUCA-US Request a copy of the personal data we hold about you.
Right to Rectification CAEU Ask us to correct inaccurate or incomplete personal data.
Right to Erasure ("Right to be Forgotten") EUCA-US Request deletion of your personal data, including through the in-app account deletion flow where available. Note: legally required records (consent forms, tax records, payment dispute records, and security audit records) cannot be deleted before their retention period ends.
Right to Data Portability EU Receive your data in a structured, machine-readable format.
Right to Object EU Object to processing based on legitimate interests (e.g., marketing, analytics).
Right to Restrict Processing EU Request that we limit how we use your data in certain circumstances.
Withdraw Consent CAEU Withdraw marketing consent at any time. Withdrawal does not affect the lawfulness of prior processing.
Right to Know / Opt-Out of Sale CA-US California and other eligible US residents: know what data we collect and opt out of any "sale" or "sharing" of data. Affichr does not sell personal information or share it for cross-context behavioral advertising.
Limit Sensitive Data Use CA-US Request limits on sensitive personal information where required by law. Affichr uses sensitive health information only to provide requested services, comply with law, and protect safety.
Appeal a Rights Decision US If applicable state law gives you an appeal right, you may appeal our decision by replying to our response or contacting us again at the address below.

Badges: CA-US California (CCPA/CPRA) · EU EU/UK (GDPR) · CA Canada (PIPEDA)

7. Delete Your Account

You can delete your Affichr account at any time. There are two ways to do it:

Deleting your account removes your profile, your booking and client data, your uploaded files, and your settings, except for records we are required to keep. By law we must retain some records for a set period even after deletion — for example, signed consent forms and health records (7 years), payment and tax records (7 years), security and admin audit logs, and evidence needed for an active dispute or chargeback. Those records are kept only for as long as the law or the dispute requires, and then deleted.

If you only want to stop notifications or marketing, you don't need to delete your account — you can turn off SMS, email, or push messages in your settings, or reply STOP to a text.

8. Cookies & Analytics

The Affichr mobile app does not use browser cookies. Affichr may use privacy-scoped product analytics in the mobile and web app to understand feature usage and improve workflows. Optional analytics are off until you opt in where consent is required, including for EEA/UK visitors and unknown-region public web visitors. If you access Affichr via a web browser, we may use:

Cloudflare Turnstile: Affichr uses Turnstile in invisible mode on login and other protected flows as a strictly necessary security measure. Turnstile evaluates limited client-side signals to distinguish people from bots, prevent credential abuse, and protect Affichr from malicious traffic. It is not used by Affichr for advertising or cross-context behavioral tracking. See the Cloudflare Turnstile Privacy Addendum.

Operational monitoring events are filtered before storage to reduce collection of emails, phone numbers, IP addresses, health data, payment details, tokens, signed URLs, storage paths, screenshots, and free-form notes. We do not use advertising cookies or share data with advertising networks. We do not use session replay in the authenticated app, admin dashboard, booking forms, payment flows, health or consent forms, client notes, or design files.

9. Children's Privacy

Affichr is intended for users 18 years of age and older. We do not knowingly collect personal data from children under 18. If we become aware that a user under 18 has created an account, we will delete the account and associated data promptly.

If you believe a minor has registered on Affichr, please notify us immediately at info@affichr.com.

10. Data Security

Affichr implements industry-standard security measures including:

No system is 100% secure. If you believe your account has been compromised, contact us immediately at info@affichr.com.

11. Data Breach Notification

In the event of a personal data breach that poses a risk to individuals, Affichr will:

12. International Data Transfers

Affichr primarily stores and processes data in the United States. Your data may be processed by our service providers, including Supabase, Cloudflare, Stripe, Twilio, Resend, Daily.co, Google, Apple, PostHog, Groq, Gemini, Browserless.io, Shorebird, or a deployment-controlled self-hosted or API-compatible model endpoint, in the United States or other countries where their infrastructure operates. A self-hosted model endpoint may process AI context in the location chosen by that deployment operator.

For EEA/UK personal data transferred to the United States or another country without an adequacy decision, we rely on appropriate safeguards where required, including the EU Standard Contractual Clauses, the UK International Data Transfer Addendum or equivalent UK transfer mechanism, and, where available and applicable to a specific provider, certification under the EU-US Data Privacy Framework and the UK Extension. We do not rely on consent as the routine legal basis for international transfers.

13. Consumer Health Data

Affichr may collect consumer health data when clients submit health questionnaires, contraindication information, pregnancy status, medication information, allergies, skin condition information, consent forms, or other information connected to tattoo, salon, consultation, or body-service safety. Depending on your location, this information may be protected by state consumer health data laws, including Washington's My Health My Data Act.

Categories and Sources

Consumer health data is collected directly from the client, from the artist or studio when they document a consent or service record, and from service activity needed to create appointments, consent PDFs, reminders, and records.

Use and Sharing

We use consumer health data to provide the requested booking and consent-form service, help the artist assess whether the service can be performed safely, comply with health-record retention requirements, prevent fraud or abuse, and respond to lawful requests. We share consumer health data only with the artist or studio connected to the appointment, our infrastructure processors, and legal or safety recipients where required or permitted by law. We do not sell consumer health data.

Your Consumer Health Data Rights

Where applicable, you may request access, deletion, withdrawal of consent for future collection or sharing, and information about how your consumer health data is used. Some records, including signed consent forms and legally required health or transaction records, may be retained for the required period even after a deletion request.

Affichr does not use geofencing around health care facilities to identify, track, or target consumers based on consumer health data.

14. California Privacy (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives you specific rights over your personal information. This is our primary US privacy framework.

Categories of personal information we collect

Identifiers (name, email, phone, IP address, and hashed identifiers used for privacy requests and abuse prevention); commercial information (booking and payment history); internet or network activity (app usage, device data, public booking telemetry, login security telemetry, and redacted monitoring metadata); geolocation at the city or region level, whether inferred from IP address or supplied in your settings; audio/visual information you upload (reference photos, designs); professional or business information for artists and studios; sensitive personal information (health questionnaire answers, account login credentials, and precise location where you choose to share it); and inferences drawn from the above.

We do not sell or share your personal information

Affichr does not sell your personal information and does not share it for cross-context behavioral advertising. We do not use or disclose your sensitive personal information beyond what is needed to provide the services you asked for, keep the platform secure, prevent fraud, comply with the law, and improve the service — uses that do not trigger a separate right to limit.

As a California resident you may exercise these rights by emailing info@affichr.com or, for client records, using the request flow on an artist's public booking page:

We respond to verified requests within 45 days (extendable by another 45 days with notice). You may use an authorized agent, and you may appeal a decision by replying to our response.

15. EU / UK Privacy (GDPR)

If you are in the European Economic Area (EEA) or the United Kingdom, the GDPR or UK GDPR applies to the processing of your personal data. Affichr may be subject to these laws when we offer services to, or monitor, individuals in the EEA/UK.

Our legal bases for processing are:

You have the rights to access, rectify, erase, restrict processing, object, receive data portability, and withdraw consent at any time. To exercise them, email info@affichr.com. We respond within one month unless an extension is permitted. You also have the right to lodge a complaint with your local data protection authority (for example, the CNIL in France or the ICO in the UK).

Where transfers of your data leave the EEA/UK, we rely on Standard Contractual Clauses or other appropriate safeguards, as described in Section 12.

16. Other US State Privacy Rights

If you live in a US state other than California that has a comprehensive privacy law (for example Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and others), you may have rights to access, correct, delete, or get a copy of your personal information, to opt out of targeted advertising or any sale of data, to limit certain sensitive-data processing, and to appeal a denied request. Affichr does not sell personal information and does not use it for targeted advertising.

To exercise a state-specific right, email info@affichr.com and tell us which state you live in. Because Affichr serves artists, studios, salons, and clients across the US and Canada, the exact rights that apply can depend on your role, your location, and the type of data involved.

17. Canadian Privacy (PIPEDA)

If you are in Canada, Affichr is designed to comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws.

To make a request, email info@affichr.com. You may also file a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca.

18. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Effective" date at the top and notify registered users by email at least 30 days before material changes take effect. Continued use of Affichr constitutes acceptance of the updated policy.

19. Contact & Complaints

For any privacy-related question, request, or complaint, email us at info@affichr.com or write to Affichr, 2065 rue Parthenais, bureau 293, Montréal, QC H2K 3T1, Canada.

If you are not satisfied with our response, you may escalate to the relevant authority: