Studiobase

Privacy Policy

Last updated: 19 May 2026

This is the privacy policy for Studiobase — the web app at studiobase.app and the Studiobase artist app on iOS. It explains what we collect, why, who we share it with, how long we keep it, and the rights you have over it. Written plainly; defined terms in bold.

1. Who we are

Studiobase is operated by Cassaro Assessoria Comercial e Administrativa para Profissionais Criativos Ltda. (the "Operator", "we", "us").

The first studio using Studiobase is Tattoo Heroes, 290 High Road Leyton, London E10 5PW, United Kingdom. Studiobase is also offered as a software-as-a-service to other tattoo studios; in that case the studio you work with is a separate data controller.

For all privacy questions, contact support@studiobase.app.

2. What we collect

The data we hold depends on whether you're a studio user (admin, receptionist, finance, artist) or a studio client (someone booking a tattoo).

From studio users

  • Email address and full name (used to sign in)
  • Role (admin, receptionist, finance, artist) and which studio you belong to
  • For artists: phone, email, Instagram handle, specialties, working days
  • Login timestamps and basic usage logs

From studio clients (entered by the studio)

  • Name, phone number, email, Instagram
  • Date of birth, gender, address (from consent forms)
  • Health flags entered on consent forms: pregnancy / breastfeeding, transplant history, blood disorders, allergies, current medication, age verification, antibiotics
  • Photo of ID document (consent form attachment)
  • Photographs of reference artwork, completed tattoos, completion photos
  • Signature captured at the time of consent
  • Booking history, transaction history (amount, payment method, tip, notes), deposit history

Health data is treated as a special category of personal data under UK GDPR and EU GDPR. We process it because it's necessary for the provision of the tattoo / piercing service and to comply with the studio's legal obligations around aftercare and safety.

Automatically

  • Standard server logs (IP address, browser/device type, time of request) — kept transiently by our hosting providers for security and abuse prevention
  • Web-vitals performance metrics via Vercel Speed Insights (no IP, no cookies, no personal identifiers)

3. Why we use it

  • To run the studio's day-to-day operations: bookings, transactions, consent forms, expenses, artist payments
  • To let artists see their own bookings and history
  • To let reception flag health risks before a session begins
  • To produce financial reporting (P&L, cash flow) for the studio
  • To send booking-related communications (e.g. consent link emails)
  • To debug bugs and keep the service secure

We do not sell personal data. We do not use it for advertising or to train AI models.

4. Legal bases (UK / EU GDPR)

  • Contract: to provide the studio service to studio users
  • Legitimate interest: to keep the platform secure, prevent abuse, and improve performance
  • Legal obligation: to retain certain transaction records (tax, accounting)
  • Explicit consent: to process health data via consent forms; you can withdraw this consent at any time

5. Who we share it with

We share data with a small number of service providers — only what they need to do their job:

  • Supabase (PostgreSQL hosting, authentication, file storage). Servers in the EU. Data Processing Agreement in place.
  • Vercel (web hosting, edge runtime, Speed Insights). Data Processing Addendum in place.
  • TeamUp (optional calendar integration) — only if your studio has enabled it. We pull booking events from your studio's TeamUp calendar.
  • JotForm (consent form intake) — when reception uses the JotForm consent form, JotForm receives the form submission and forwards it to Studiobase via webhook.

We do not share personal data with advertisers, data brokers, or any party outside the providers listed above without your explicit consent.

6. How long we keep it

  • Active accounts: for as long as the studio uses Studiobase.
  • Closed accounts: personal data is deleted within 30 days of a verified deletion request, unless a longer period is required by law (for example, tax records — kept for 7 years in the UK, 5 years in Brazil).
  • Transaction records: retained for the legally required accounting period after the studio leaves Studiobase.
  • ID photos and completion photos: deleted when the related booking is older than 24 months, unless the studio has a documented legal reason to keep them.
  • Server access logs: rolling 30-day window at the infrastructure level.

7. Your rights

Under UK GDPR, EU GDPR and Brazil's LGPD you have the right to:

  • Access the data we hold about you
  • Correct anything that's wrong
  • Delete your data (the "right to be forgotten")
  • Limit how we process it
  • Receive a copy of your data in a portable format
  • Object to processing based on legitimate interest
  • Withdraw any consent you've previously given
  • Lodge a complaint with a supervisory authority — the ICO in the UK (ico.org.uk), or ANPD in Brazil (gov.br/anpd)

Email support@studiobase.app from the address on your account and we'll respond within one calendar month.

8. Security

  • All traffic between your device and Studiobase is encrypted over TLS.
  • Passwords are stored as bcrypt hashes — we never see plaintext passwords.
  • Access to studio data is controlled by row-level security in the database: artists can only see their own bookings and transactions; receptionists see their studio; admins see their studio.
  • Health data is stored in the same encrypted database, accessible only to staff with the appropriate role in the studio.
  • Backups are encrypted at rest with the infrastructure provider.

No system is perfectly secure. If we discover a breach affecting your personal data, we'll notify you and the relevant supervisory authority within 72 hours of becoming aware of it.

9. Children

Studiobase is intended for adults working in or visiting a tattoo studio. We do not knowingly collect personal data from children under 13. The under-18 flag on consent forms exists to prevent tattooing minors, not to collect their data systematically.

10. International transfers

The Operator is incorporated in Brazil. Our primary infrastructure providers (Supabase, Vercel) host data in the EU. When data crosses borders (for example, between an EU server and a Brazilian operator), it does so under the European Commission's Standard Contractual Clauses and equivalent LGPD-compliant safeguards.

11. Cookies

Studiobase uses essential cookies only — the ones required to keep you signed in. We do not use marketing cookies, advertising trackers, or cross-site fingerprinting. Vercel Speed Insights collects aggregated, anonymous performance metrics without setting cookies or identifiers.

12. Changes to this policy

When this policy changes, we'll update the "Last updated" date at the top. For material changes (new categories of data, new sub-processors, changes to your rights) we'll email active studio admins so they can pass the information to their teams and clients.

13. Contact

Operator: Cassaro Assessoria Comercial e Administrativa para Profissionais Criativos Ltda.

Email: support@studiobase.app

Studio address (Tattoo Heroes): 290 High Road Leyton, London E10 5PW, United Kingdom