1. Two different sets of data
This policy covers two things that look alike and are not, so it is worth being clear at the top.
Your studio's data — your account, your billing, your emails to us. Here we are the controller: we decide what to do with it, and this policy is the answer.
Your clients' data — the people who book with you, their photos, their phone numbers, their appointments. Here you are the controller and we are your processor: we only do what you tell us. The terms of that are in the Data Processing Addendum.
If you are a client who booked a tattoo through a page on inktok.pro, the studio you booked with is who holds your data. Ask them, and they can correct or delete it. We will help them do it.
2. What we collect about your studio
When you register
- Studio name and the address of your booking page
- Your name and email address, and a password we store only as a hash
- Your billing entity: sole trader, self-employed or company, with the registration number, address and VAT number where that applies
While you use it
- What you put in: prices, opening hours, portfolio images, artists, bookings
- Server logs — IP address, browser, the page requested and when. Kept 30 days, for security and for working out what broke
- Emails you send us, and what we answered
Payment details
We never see your card. Stripe takes the payment and tells us only that it succeeded, the amount, and the last four digits for your invoice.
What we do not do
There is no analytics script on this site, no advertising pixel, no third-party tracker and no profiling. We do not sell data to anybody, and there is nobody to sell it to.
3. Why we are allowed to
| What | Why | Legal basis |
|---|---|---|
| Account and studio data | To give you the service you signed up for | Performance of a contract |
| Billing details | Invoices, and the tax law that requires them | Legal obligation |
| Server logs | Security, abuse, debugging | Legitimate interest |
| Service emails | Trial ending, payment failed, something changed | Performance of a contract |
| Product news | Telling you about new features | Consent — and one click to stop |
5. Data outside the EU
Your database and your uploaded images live on servers in Germany. Some of the companies above are American, which means some data reaches the United States. Where it does, the transfer is covered by the European Commission's Standard Contractual Clauses, or by the provider's certification under the EU–US Data Privacy Framework.
6. How long we keep it
| What | How long |
|---|---|
| Your account and everything in it | While the account is open, then 90 days |
| Invoices and accounting records | 5 years, because Latvian tax law says so |
| Server logs | 30 days |
| Support email | 2 years |
| Backups | Rolling 30 days, then overwritten |
You can ask us to delete the account sooner than the 90 days, and we will — except for the invoices, which we are not allowed to throw away.
7. What you can ask for
Under the GDPR you can ask us to:
- Show you what we hold about you
- Correct anything wrong — most of it you can edit yourself in the panel
- Delete it
- Export it in a machine-readable file
- Stop or limit a particular use, including product emails
- Object to anything we do on the basis of legitimate interest
Write to privacy@inktok.pro. We answer within 30 days, and it costs nothing.
If you think we have got it wrong, you can complain to the Latvian Data State Inspectorate (Datu valsts inspekcija) or to the authority in the country you live in. We would rather you told us first.
8. Keeping it safe
- Everything travels over HTTPS; nothing is served unencrypted
- Passwords are stored as bcrypt hashes — we cannot read yours, and neither can anyone who takes the database
- Each studio's data is separated at the query level: one studio's login cannot reach another's records
- Backups are encrypted and kept apart from the live database
- Access to production is limited to the people who need it
If something goes wrong anyway and personal data is exposed, we will tell the supervisory authority within 72 hours and tell you without undue delay.
9. Children
InkTok is for professionals and is not meant for anyone under 18. We do not knowingly collect data from children. If a studio's client is a minor, that is the studio's responsibility under the law that applies to them.
10. Changes
If we change this policy in a way that matters, we will email you before it takes effect. The date at the top always says which version you are reading.
Who you are dealing with
InkTok is operated by Amare Baltic SIA, a limited liability company registered in Latvia.
- Company
- Amare Baltic SIA
- Registration
- 40203563664 · Commercial Register of the Republic of Latvia
- VAT number
- LV40203563664
- Registered address
- Kluba iela 13A-8, Aloja, Limbaži Municipality, LV-4064, Latvia
- hello@inktok.pro