Last updated: May 5, 2026
InkBookr is a workspace for tattoo artists, studios, and clients. This policy explains what personal data we collect when you use inkbookr.com, why we collect it, how we use it, and the rights you have over it.
It applies to everyone who uses the service, with specific additional rights for users in the European Economic Area (EEA) and the United Kingdom under the GDPR/UK GDPR, and for California residents under the CCPA/CPRA.
We collect only what we need to run the service:
ai-generations bucket), and credit usage records.We use the data above to:
We do not use your data to train AI models, and we do not sell personal information.
If you are in the EEA or UK, we rely on the following lawful bases under Article 6 GDPR:
We share data with a small set of vetted sub-processors who help us run the service. Each is bound by a data processing agreement.
| Processor | Purpose | Region |
|---|---|---|
| Supabase | Authentication, database, file storage | US / EU |
| Vercel | Application hosting and edge delivery | Global |
| Dodo Payments | Payment processing and subscription billing | Global |
| Resend | Transactional email (bookings, invitations, receipts) | US |
| OpenRouter | AI model routing for the AI Sketchpad | US |
| Sentry | Error monitoring and performance telemetry | US / EU |
We do not share personal data with advertisers, data brokers, or social networks.
Some of our sub-processors are based in the United States. When we transfer personal data outside the EEA or UK, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable) as the transfer mechanism, together with supplementary technical measures such as encryption in transit and at rest.
You have the right to:
If you are a California resident, you have the right to:
To exercise any of these rights, email privacy@inkbookr.com. We will respond within 30 days.
InkBookr is not directed to children. We do not knowingly collect personal information from anyone under 16 in the EEA/UK or under 13 in the United States. If you believe a child has provided us with personal data, please contact us and we will delete it.
We protect your data with TLS in transit, encryption at rest in Supabase, row-level security on database tables, and least-privilege access controls for our team. No system is perfectly secure, so if you believe you have found a vulnerability, please report it to security@inkbookr.com.
When we make material changes to this policy we will update the “last updated” date above and notify active users by email and through an in-app banner before the changes take effect.
Questions about this policy or about how we handle your data? Reach out:
privacy@inkbookr.comPostal address: [TODO — add registered business address before publishing].