Privacy policy

Last updated 29 September 2026

StudioBuilder is software for tattoo artists and studios to manage enquiries, bookings, deposits, consent forms and client messages. This policy explains what personal data we handle, why, and the choices you have. It covers our website at studiobuilder.io, the StudioBuilder app, and the booking forms, quote pages and consent forms that studios share with their clients.

1. Who we are

StudioBuilder is operated by Steven Graham, a sole trader based in the United Kingdom (“we”, “us”). For anything about your data, email privacy@studiobuilder.io.

2. Our two roles

  • For artists and studios who use StudioBuilder (“customers”), we are the controller of your account data: your name, email address, studio details, billing information and how you use the app.
  • For the clients of those studios, the studio is the controller and we are its processor. When you send an enquiry, pay a deposit or sign a consent form with a studio that uses StudioBuilder, the studio decides how your information is used and we store and process it on the studio's behalf and on its instructions. If you are a client and want to access, correct or delete your information, please contact the studio first. We will help them respond, and you can also write to us.

3. What we collect

From customers (artists and studios)

  • Account details: name, email address, password (stored only as a secure hash by our sign-in provider).
  • Studio details: studio name, handle, logo, colours, business phone number, opening hours, prices and message templates.
  • Team details: the email addresses of artists you invite, their roles and their commission or chair rent settings.
  • Billing details: your plan and payment history. Card details are handled by Stripe and never reach our servers.
  • Connected accounts: if you connect Stripe or Google Calendar, the identifiers and access tokens needed to use them (see section 5).

From studios' clients (processed for the studio)

  • Contact details: name, email address, phone number and social media handle.
  • Enquiry details: tattoo idea, placement, size, budget, preferred dates and any reference photos you upload.
  • Booking details: quotes, deposits, appointment times, notes the studio adds and designs it uploads.
  • Consent forms: your answers, signature, date of birth and any health information you choose to give (such as allergies, medical conditions or medication). This is special category data. It is collected so the artist can tattoo you safely and is visible only to the studio.
  • Messages: emails and text messages between you and the studio, and a record of calls to the studio's StudioBuilder number.

Collected automatically

  • Technical logs from our hosting provider (IP address, browser type, pages requested and errors), kept for security and fault-finding.
  • Essential cookies that keep you signed in and remember which studio you are working in. We do not use advertising or tracking cookies.

4. Why we use it and our lawful basis

  • To provide the service you or your studio signed up for, including sending the emails and texts the studio sets up (contract, and for client data, the studio's instructions).
  • To take payment for subscriptions and to let studios take deposits (contract).
  • To keep the service secure, prevent abuse and fix problems (our legitimate interests).
  • To contact customers about their account, billing and important changes (contract and legitimate interests). We will only send marketing emails if you opt in, and every one will have an unsubscribe link.
  • To meet legal obligations, such as keeping accounting records.

Health information on consent forms is processed for the studio under its own lawful basis, which for most studios is your explicit consent given when you sign the form.

5. Google Calendar

Artists can choose to connect their Google Calendar. If you do, StudioBuilder asks for permission to see your list of calendars and to view and edit events. We use this access only to:

  • check when you are busy, so clients are never offered a booking time that clashes with your own plans;
  • add, update and remove events for sessions booked through StudioBuilder; and
  • let you choose which calendars count as busy and which calendar bookings are added to.

We read only busy and free times from your calendars, not the titles or details of your own events, and we do not store them. We store the ID of each event we create so we can update it later. Your Google access tokens are encrypted when stored. You can disconnect at any time from My details in the app, which deletes the tokens, or remove access from your Google account's security settings.

StudioBuilder's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not use Google user data for advertising, we do not sell it, we do not use it to train artificial intelligence or machine learning models, and no person reads it unless you ask us to for support, it is needed for security, or the law requires it.

6. Who we share data with

We do not sell personal data. We share it only with the service providers that run parts of StudioBuilder for us:

  • Supabase: database, sign-in and file storage.
  • Vercel: website and app hosting.
  • Resend: sending and receiving email.
  • Twilio: text messages and phone calls.
  • Stripe: subscription billing, and deposits paid to studios' own Stripe accounts.
  • Google: calendar sync, only for artists who connect it.

Each provider may only use the data to provide its service to us. We may also disclose data if the law requires it, or to protect the rights and safety of our users.

7. International transfers

Some of our providers store or process data outside the UK, including in the European Economic Area and the United States. Where they do, the transfer is protected by UK adequacy regulations, the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or the UK Extension to the EU-US Data Privacy Framework.

8. How long we keep it

  • Account and studio data: while the subscription is active, then for 90 days so it can be exported or restored, after which it is deleted.
  • Client data: for as long as the studio keeps it. Studios can edit or delete client records at any time.
  • Billing records: six years, as UK tax law requires.
  • Backups are overwritten on a rolling basis within 30 days of deletion.

9. Security

Data is encrypted in transit and at rest. Each studio's data is kept separate from every other studio's at the database level, uploaded files such as consent forms and reference photos are private and shared only through short-lived links, and access tokens for connected services are encrypted.

10. Your rights

Under UK data protection law you can ask to access, correct or delete your personal data, to restrict or object to how it is used, and to receive a copy in a portable format. Where we rely on your consent you can withdraw it at any time. Email privacy@studiobuilder.io and we will respond within one month. If you are a studio's client, we will pass your request to the studio and help it respond.

If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office at ico.org.uk. We would appreciate the chance to put things right first.

11. Children

StudioBuilder is for businesses and is not aimed at children. Tattooing anyone under 18 is illegal in the UK, and studios are responsible for checking their clients' age.

12. Changes

We will update this page when our practices change and change the date at the top. If a change is significant, we will tell customers by email before it takes effect.