Affichr is committed to protecting your privacy. This policy explains what personal information we collect, why we collect it, who we share it with, and your rights regarding your data.
Affichr is a booking and client-management platform for tattoo artists, studios, and salons. We serve the United States first and Canada second. EEA and UK artist accounts may be created, but full artist operations remain gated until Affichr completes payment, tax, representative, and legal review.
For account administration, security, billing, subscriptions, platform analytics, fraud prevention, legal compliance, and product operations, Affichr acts as the data controller (or, in California terms, the "business"). For client data that an artist or studio enters, imports, or manages for their own services, the artist or studio is generally the controller and Affichr acts as their processor/service provider under the Artist Data Processing Addendum. Affichr may also act as an independent controller where required for security, legal compliance, payment records, abuse prevention, support, and platform-level obligations.
Questions about this policy? Email us at info@affichr.com.
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Creating and managing your account | Name, email, phone number, password, profile settings | Contract / Consent |
| Processing booking requests and appointments | Profile, booking data, location or address data where enabled, payment data | Contract |
| Collecting deposits and processing payments | Payment data, Stripe token | Contract |
| Sending appointment confirmations and reminders | Email, phone number, push token, reminder preferences | Contract / Consent / Legitimate interest |
| Providing Google Sign-In and Google Calendar sync | Google account profile data, OAuth tokens, selected calendar ID, Google Calendar event metadata, Google push watch-channel metadata, Affichr appointment event details | Consent / Contract |
| Sending subscribed cancellation-list alerts by client availability or area | Cancellation-list preferences, selected alert channels, weekly windows, approximate client location, artist broadcast target area, and unsubscribe or STOP status | Consent / Legitimate interest |
| Rate limiting public booking, uploads, and abuse-prone workflows | Hashed IP address or email where applicable, user agent, outcome/reason code, timestamps, and limited upload metadata | Legitimate interest / Legal obligation |
| Health screening before tattoo services | Health questionnaire answers | Explicit consent where required / Legal obligation / Vital interests / Article 9(2) health and safety bases where applicable |
| Generating and storing consent forms | Health data, signature, IP address | Legal obligation / Explicit consent where required |
| Video consultations | Meeting tokens, appointment data | Contract / Consent |
| Sending marketing emails (to opted-in users) | Email, name | Consent (US CAN-SPAM, Canada CASL) |
| Providing AI Assistant features | AI messages and enabled account context, excluding health questionnaire answers, processed by the configured AI provider or self-hosted model endpoint | Consent / Contract |
| Handling access, deletion, correction, and limitation requests | Hashed requester email and IP address, request type, verification status, retained-record reasons, and operator notes | Legal obligation / Legitimate interest |
| Monitoring reliability and resolving support issues | Redacted app or Edge Function event metadata, redacted errors, route/screen/platform, status, and hashed contact data where provided | Legitimate interest |
| Moderating uploaded images for safety and platform abuse | Uploaded image metadata and temporary image review data | Legitimate interest / Legal obligation |
| Preventing fraud and abuse | IP address, login events | Legitimate interest / Legal obligation |
| Complying with legal obligations (tax records, health records) | Transaction data, consent forms | Legal obligation |
| Improving the platform | Aggregated usage data, crash reports, and optional analytics events | Legitimate interest for strictly necessary diagnostics; consent for optional analytics where required |
| Data Type | Retention Period | Reason |
|---|---|---|
| Account data (active account) | Until you delete your account | Service delivery |
| Account data (deleted account) | Eligible account data is deleted or anonymized when the in-app deletion request is completed; retained records remain only for the periods listed below | User request, legal retention exceptions, fraud prevention, security, and dispute preservation |
| Consent forms & health records | 7 years minimum | Legal requirement (state/provincial health regulations) |
| Payment and transaction records | 7 years | Tax, accounting, payment processor, and dispute requirements |
| Appointment history | 3 years after last appointment | Dispute resolution / Legal claims |
| Communication logs (in-app messages) | 2 years after account closure | Dispute resolution |
| Uploaded design files | Until the artist deletes them or closes their account | Artist ownership of their files |
| Declined or deleted booking reference images | 30 days after declined or deleted request aging | Booking reference cleanup and PII minimization |
| AI conversations | 90 days unless deleted earlier | Assistant continuity, abuse prevention, and support |
| AI rate-limit and audit logs | 180 days | Security, abuse prevention, and troubleshooting |
| Public booking and upload abuse telemetry | 30 days | Rate limiting and abuse prevention |
| App monitoring events | 30 days for resolved or ignored events; 90 days for non-open events; open events require operator review | Reliability troubleshooting with PII minimization |
| Push notification tokens | Until disabled, expired, deleted, or account closure | Notification delivery |
| Push delivery logs | Up to 1 year | Delivery troubleshooting and abuse prevention |
| Google OAuth tokens, selected calendar ID, and watch-channel metadata | Until you disconnect Google Calendar, delete your account, or the token is revoked or replaced | Google Calendar sync and secure account linking |
| Google Calendar-derived blocked slots | Overwritten on each sync and cleared when Google Calendar is disconnected or the account is deleted, subject to backups and legal/security holds | Preventing double bookings and showing accurate availability |
| Client location used for cancellation-list broadcasts | Until the client removes the preference, the artist deletes/anonymizes the client record, or the account closes, subject to legal retention exceptions | Subscribed nearby-opening alerts and artist travel broadcasts |
| Marketing consent records | 3 years after consent | Proof of consent (US CAN-SPAM, Canada CASL) |
| Login security telemetry and device fingerprints | 180 days | Security, suspicious-login investigation, and user alerts |
| Privacy request workflow records | Request lifecycle plus legal audit policy | DSAR verification, review, retained-record documentation, and legal compliance |
| Admin audit logs | Operational/legal policy | Admin accountability and security investigations |
We share your data with the following third parties only to the extent necessary to operate Affichr. We do not sell your personal data. Mobile phone numbers, SMS consent records, and text messaging opt-in data are not shared with third parties for their marketing or promotional purposes.
| Provider | Purpose | Data Shared | Location | Privacy Link |
|---|---|---|---|---|
| Supabase | Database, authentication, private file storage, Edge Functions, and retention workflows (our backend) | All data stored on the platform | AWS (us-east-1 or your chosen region) | supabase.com/privacy |
| Cloudflare Turnstile | Invisible bot detection and abuse prevention for login and other protected flows | Client IP address, TLS fingerprint, user-agent header, Turnstile sitekey and associated origin, and challenge outcome data | USA / global infrastructure | Cloudflare Turnstile Privacy Addendum |
| Stripe, Inc. | Payment processing, deposit collection | Name, email, tokenized card data, transaction amounts | USA | stripe.com/privacy |
| Twilio | SMS appointment reminders and notifications | Phone number, message content | USA | twilio.com/legal/privacy |
| Resend | Transactional and reminder emails | Email address, name, appointment details | USA | resend.com/privacy |
| Daily.co | Video consultations | Meeting tokens, session metadata (no video stored) | USA | daily.co/privacy |
| Google API Services | Google Sign-In and Google Calendar sync for users who enable those features | Google account profile data for sign-in; OAuth tokens, selected calendar ID, watch-channel metadata, Google Calendar event metadata, and Affichr appointment event details for calendar sync | USA | policies.google.com/privacy |
| Apple Inc. | Sign in with Apple authentication for users who choose it | Apple user identifier, name if shared, email address or private relay address | USA | apple.com/legal/privacy |
| Google Firebase / FCM | Push notification delivery and mobile app infrastructure | Device push tokens, notification metadata, delivery status | USA / global infrastructure | policies.google.com/privacy |
| PostHog | Privacy-scoped product analytics and feature usage measurement | Account ID, role, plan, app version, platform, and non-sensitive workflow events | USA | posthog.com/privacy |
| Groq | Cloud AI Assistant model provider when selected | AI messages and enabled non-health account context | USA | groq.com/privacy-policy |
| Google Gemini API | Fallback AI model provider and image-safety moderation where enabled | AI messages, enabled non-health account context, uploaded image review data | USA / global infrastructure | policies.google.com/privacy |
| Self-hosted or API-compatible model endpoint | Optional AI Assistant model provider configured by the deployment | AI messages and enabled non-health account context | Deployment-controlled location | Controlled by the deployment operator |
| Browserless.io | PDF generation for consent forms | HTML content of consent forms (ephemeral, not stored) | USA | browserless.io/privacy |
| Shorebird | Over-the-air (OTA) app code updates | App version, platform, and update-delivery metadata (no account data) | USA / global infrastructure | shorebird.dev/privacy |
This section applies when you choose to sign in with Google or connect Google Calendar. These features are optional. Affichr's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
For Google Sign-In, Affichr accesses your Google account identifier, name, email address, and profile image so we can create or sign you into your Affichr account. For Google Calendar sync, Affichr requests Google Calendar access so we can read calendar availability, create Affichr appointment events, update sync state, and delete Affichr-created calendar events when appointments are cancelled. Calendar data may include the selected calendar ID, event IDs, event titles or summaries, start and end times, time zones, event status, and Google push notification watch-channel metadata. Affichr does not request Google Drive, Gmail, Contacts, or Google Photos data for Calendar sync.
Affichr uses Google user data only to provide user-facing features you enable: account sign-in, calendar connection, blocked-time detection to reduce double bookings, creation of Affichr appointment events in your selected Google Calendar, deletion of Affichr-created events after cancellation, sync health checks, and support or security troubleshooting. Affichr may store Google Calendar-derived busy windows in your Affichr availability settings so your booking workflow can avoid unavailable times. If you enable the AI Assistant and allow availability context, Google Calendar-derived busy-window data may be used only to answer your own assistant request about your schedule; it is not used to train AI models.
Affichr does not sell Google user data, does not share it with advertising platforms, data brokers, or information resellers, and does not use it for targeted advertising, retargeting, personalized ads, surveillance, creditworthiness, lending, or unrelated product analytics. Google user data is shared only with service providers needed to run Affichr, such as Supabase for secure backend storage and Edge Functions. If you create an Affichr appointment event, Google receives the event details needed to place that event on your calendar, such as appointment time, service type, client name, client email where available, notes that the artist entered for the appointment, reminder settings, and video consultation link where applicable. Human access to Google user data is limited to cases where you ask for support and authorize review, where access is necessary for security or abuse investigation, or where required by law.
Google OAuth tokens are sent only to Affichr's backend, encrypted before storage, and not exposed to the Flutter client after connection. Google Calendar tokens are encrypted at rest, transmitted over TLS, protected by Supabase Row-Level Security and server-side access controls, and used only by authenticated Edge Functions. Affichr stores only the minimum calendar data needed for sync, availability, auditability, and troubleshooting. Google Calendar event data is not stored in public files or public buckets.
You can disconnect Google Calendar in Affichr settings. When you disconnect, Affichr clears stored Google OAuth tokens, selected calendar IDs, watch-channel metadata, and Google Calendar-derived blocked slots from active records, and makes a best-effort request to revoke the token with Google. You can also request account deletion through the in-app deletion flow or by emailing info@affichr.com. Account deletion removes or anonymizes eligible Google account profile data and Google Calendar sync data, subject to legal, security, dispute, backup, and fraud-prevention retention exceptions described in this policy.
Affichr does not use Google user data to develop, improve, or train generalized AI or machine learning models. Google user data is not used to build advertising profiles. AI Assistant providers are not permitted to use Affichr customer data for training, and Google Calendar-derived availability context is sent to an AI provider only when the user enables the AI Assistant and the relevant context source for a user-facing assistant response.
The AI Assistant is optional and requires an in-app disclosure acceptance before use. You may turn off AI access in settings. If enabled, Affichr sends your prompt and enabled account context to the configured AI model provider to generate a response. Default context is conservative and focuses on appointments, availability, and aggregate deposit status. Additional context sources such as client names, tags, private client notes, consultation notes, booking requests, project information, and search results require additional selection or configuration. Health questionnaire answers, consent form health answers, full payment card data, and authentication secrets are not included in AI Assistant context.
Affichr may use a cloud model provider or a deployment-controlled self-hosted model endpoint. When self-hosted AI mode is configured, cloud fallback is disabled unless the deployment explicitly enables cloud fallback.
Some uploaded images may be reviewed by automated image-safety systems to detect unsafe, unlawful, or abusive content. Affichr stores moderation metadata and decisions, not additional copies of image bytes beyond the underlying uploaded file needed to provide the service.
Depending on where you live, you have rights regarding your personal data. To exercise any right, contact us at info@affichr.com. For EEA/UK requests, we will respond without undue delay and no later than one month after receiving a verified request unless the law permits an extension. For verified CCPA-style requests, we will respond within 45 days unless an extension is permitted with notice. Some public booking pages may also offer a scoped access, deletion, correction, restriction, objection, portability, or consent-withdrawal request flow for client records tied to a specific artist relationship.
If you have an Affichr account, you can delete it yourself in the app or by email — see Section 7, Delete Your Account for the full steps and the records we are legally required to keep.
Public privacy request flows return a neutral response and do not confirm whether a matching record exists. The workflow stores hashed requester email and IP information, may send an email verification challenge, and requires operator review before export, correction, limitation, anonymization, or deletion is completed. Records that must be retained for legal, financial, health, fraud-prevention, security, or dispute reasons may be preserved with the retained reason documented.
Client-facing exports are designed to include client-provided data, appointments, consent records, messages, shared designs, and shared consultation materials. They do not include internal artist notes by default. Where an access request legally requires review of internal notes that contain personal data, Affichr or the artist may provide the required information in a redacted or summarized form to protect the rights and privacy of others.
Badges: CA-US California (CCPA/CPRA) · EU EU/UK (GDPR) · CA Canada (PIPEDA)
You can delete your Affichr account at any time. There are two ways to do it:
Deleting your account removes your profile, your booking and client data, your uploaded files, and your settings, except for records we are required to keep. By law we must retain some records for a set period even after deletion — for example, signed consent forms and health records (7 years), payment and tax records (7 years), security and admin audit logs, and evidence needed for an active dispute or chargeback. Those records are kept only for as long as the law or the dispute requires, and then deleted.
The Affichr mobile app does not use browser cookies. Affichr may use privacy-scoped product analytics in the mobile and web app to understand feature usage and improve workflows. Optional analytics are off until you opt in where consent is required, including for EEA/UK visitors and unknown-region public web visitors. If you access Affichr via a web browser, we may use:
Cloudflare Turnstile: Affichr uses Turnstile in invisible mode on login and other protected flows as a strictly necessary security measure. Turnstile evaluates limited client-side signals to distinguish people from bots, prevent credential abuse, and protect Affichr from malicious traffic. It is not used by Affichr for advertising or cross-context behavioral tracking. See the Cloudflare Turnstile Privacy Addendum.
Operational monitoring events are filtered before storage to reduce collection of emails, phone numbers, IP addresses, health data, payment details, tokens, signed URLs, storage paths, screenshots, and free-form notes. We do not use advertising cookies or share data with advertising networks. We do not use session replay in the authenticated app, admin dashboard, booking forms, payment flows, health or consent forms, client notes, or design files.
If you believe a minor has registered on Affichr, please notify us immediately at info@affichr.com.
Affichr implements industry-standard security measures including:
No system is 100% secure. If you believe your account has been compromised, contact us immediately at info@affichr.com.
In the event of a personal data breach that poses a risk to individuals, Affichr will:
Affichr primarily stores and processes data in the United States. Your data may be processed by our service providers, including Supabase, Cloudflare, Stripe, Twilio, Resend, Daily.co, Google, Apple, PostHog, Groq, Gemini, Browserless.io, Shorebird, or a deployment-controlled self-hosted or API-compatible model endpoint, in the United States or other countries where their infrastructure operates. A self-hosted model endpoint may process AI context in the location chosen by that deployment operator.
For EEA/UK personal data transferred to the United States or another country without an adequacy decision, we rely on appropriate safeguards where required, including the EU Standard Contractual Clauses, the UK International Data Transfer Addendum or equivalent UK transfer mechanism, and, where available and applicable to a specific provider, certification under the EU-US Data Privacy Framework and the UK Extension. We do not rely on consent as the routine legal basis for international transfers.
Affichr may collect consumer health data when clients submit health questionnaires, contraindication information, pregnancy status, medication information, allergies, skin condition information, consent forms, or other information connected to tattoo, salon, consultation, or body-service safety. Depending on your location, this information may be protected by state consumer health data laws, including Washington's My Health My Data Act.
Consumer health data is collected directly from the client, from the artist or studio when they document a consent or service record, and from service activity needed to create appointments, consent PDFs, reminders, and records.
We use consumer health data to provide the requested booking and consent-form service, help the artist assess whether the service can be performed safely, comply with health-record retention requirements, prevent fraud or abuse, and respond to lawful requests. We share consumer health data only with the artist or studio connected to the appointment, our infrastructure processors, and legal or safety recipients where required or permitted by law. We do not sell consumer health data.
Where applicable, you may request access, deletion, withdrawal of consent for future collection or sharing, and information about how your consumer health data is used. Some records, including signed consent forms and legally required health or transaction records, may be retained for the required period even after a deletion request.
Affichr does not use geofencing around health care facilities to identify, track, or target consumers based on consumer health data.
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives you specific rights over your personal information. This is our primary US privacy framework.
Identifiers (name, email, phone, IP address, and hashed identifiers used for privacy requests and abuse prevention); commercial information (booking and payment history); internet or network activity (app usage, device data, public booking telemetry, login security telemetry, and redacted monitoring metadata); geolocation at the city or region level, whether inferred from IP address or supplied in your settings; audio/visual information you upload (reference photos, designs); professional or business information for artists and studios; sensitive personal information (health questionnaire answers, account login credentials, and precise location where you choose to share it); and inferences drawn from the above.
Affichr does not sell your personal information and does not share it for cross-context behavioral advertising. We do not use or disclose your sensitive personal information beyond what is needed to provide the services you asked for, keep the platform secure, prevent fraud, comply with the law, and improve the service — uses that do not trigger a separate right to limit.
As a California resident you may exercise these rights by emailing info@affichr.com or, for client records, using the request flow on an artist's public booking page:
We respond to verified requests within 45 days (extendable by another 45 days with notice). You may use an authorized agent, and you may appeal a decision by replying to our response.
If you are in the European Economic Area (EEA) or the United Kingdom, the GDPR or UK GDPR applies to the processing of your personal data. Affichr may be subject to these laws when we offer services to, or monitor, individuals in the EEA/UK.
Our legal bases for processing are:
You have the rights to access, rectify, erase, restrict processing, object, receive data portability, and withdraw consent at any time. To exercise them, email info@affichr.com. We respond within one month unless an extension is permitted. You also have the right to lodge a complaint with your local data protection authority (for example, the CNIL in France or the ICO in the UK).
Where transfers of your data leave the EEA/UK, we rely on Standard Contractual Clauses or other appropriate safeguards, as described in Section 12.
If you live in a US state other than California that has a comprehensive privacy law (for example Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and others), you may have rights to access, correct, delete, or get a copy of your personal information, to opt out of targeted advertising or any sale of data, to limit certain sensitive-data processing, and to appeal a denied request. Affichr does not sell personal information and does not use it for targeted advertising.
To exercise a state-specific right, email info@affichr.com and tell us which state you live in. Because Affichr serves artists, studios, salons, and clients across the US and Canada, the exact rights that apply can depend on your role, your location, and the type of data involved.
If you are in Canada, Affichr is designed to comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws.
To make a request, email info@affichr.com. You may also file a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca.
We may update this Privacy Policy from time to time. When we do, we will update the "Effective" date at the top and notify registered users by email at least 30 days before material changes take effect. Continued use of Affichr constitutes acceptance of the updated policy.
For any privacy-related question, request, or complaint, email us at info@affichr.com or write to Affichr, 2065 rue Parthenais, bureau 293, Montréal, QC H2K 3T1, Canada.
If you are not satisfied with our response, you may escalate to the relevant authority: