Privacy Policy

Last updated: 19 May 2026 — Effective immediately.

This Privacy Policy describes how RIO ART NYC LLC ("TattooPro", "we", "us", "our") collects, uses, shares, retains, and deletes personal information when you use the TattooPro mobile application (the "App") and related services available at tattoopro.app (collectively, the "Service").

If you do not agree with this Policy, do not use the Service.

1. Who we are

1.1 Trader Information (EU Digital Services Act — Art. 30 & 31)

For users in the European Union, RIO ART NYC LLC operates as a trader within the meaning of Article 3(f) of Regulation (EU) 2022/2065 (the Digital Services Act). The following information is provided to comply with Articles 30 and 31 of the DSA:

EU users who believe a service offered through TattooPro does not comply with applicable consumer-protection law may contact us at the address above and we will respond without undue delay.

2. Information we collect

2.1 Information you provide directly

CategoryExamplesWhy we need it
Identity & accountDisplay name, email, password (hashed), role (Artist / Client)Create your account; sign you in
ContactPhone number (optional), city, countryAllow clients to reach you; geographic discovery
Professional profile (Artists)Studio name, tattoo styles, portfolio photos, pricing notes, AI assistant tone preferencesBuild your public profile shown to clients
Client profile (Clients)Body-zone preferences, reference photos, intake form answersCommunicate placement and references to your artist
Financial records (Artists only)Tattoo session amounts, expenses, deductions, state of workPower your private financial dashboard and tax estimates
MessagesText and image attachments you send in chatDeliver chat between artist and client
AppointmentsDate, duration, notesSync your booking calendar

We do not collect or store your payment card data. All purchases are processed by Apple StoreKit; we receive only an opaque transaction identifier and product ID from Apple to grant entitlement.

2.2 Information collected automatically

2.3 Information from third-party sign-in

If you choose to sign in with Apple or Google, we receive the email and display name associated with your account from the provider. With Sign in with Apple, you may use Apple's "Hide My Email" relay; we honor that.

3. How we use your information

We do not use your data for behavioral advertising, do not sell or rent your personal information, and do not track you across other companies' apps and websites. The App declares NSPrivacyTracking = false in its privacy manifest.

4. AI features and third-party AI processing

The App offers two optional AI features:

You can use the App without using either feature. The first time you tap an AI feature, an in-app consent screen explains the data flow and asks for your explicit, opt-in approval, in line with App Store Review Guideline 5.1.2(i).

5. Sharing of information

We share information only with the parties below and only for the purpose stated:

RecipientPurposeData shared
Google LLC (Firebase: Auth, Firestore, Storage, Functions, Cloud Messaging, App Check)Backend infrastructureAll categories listed in §2 except payment data
Google LLC (Vertex AI, Cloud Run)AI features (only if you opt in)Recent chat thread, tone settings, anonymized aggregates
Apple Inc. (StoreKit 2, APNs, App Attest, Sign in with Apple)Purchases, push delivery, anti-abuse, sign-inOpaque transaction IDs, push tokens, attestation tokens, the Apple ID identifier you authorize
Law enforcement / regulatorsCompliance with valid legal processOnly what is legally required and narrowly tailored

We do not have third-party advertising or analytics SDKs in the App.

6. International transfers

Data is processed in the United States and in Google Cloud regions (primarily us-east1 and us-central1). Where required (EEA, UK, Switzerland), transfers rely on Standard Contractual Clauses approved by the European Commission and on Google's supplementary technical and organizational measures.

7. How long we keep your information

8. Account deletion

You can permanently delete your account at any time directly inside the App: Settings → Account → Delete account. The deletion flow:

  1. Removes your profile and all linked records, messages, appointments, and uploads.
  2. Revokes your Sign in with Apple token via Apple's REST endpoint.
  3. Cancels real-time data sync and signs you out on every device.
  4. Active App Store subscriptions are not automatically refunded — you must cancel them through Settings → Apple ID → Subscriptions on your device. Refund eligibility is governed by Apple's policy.

If for any reason you cannot delete in-app, email support@tattoopro.app with your account email and we will action the request within 30 days.

9. Your rights

Depending on where you live, you have rights under laws including the EU/UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), Brazil's LGPD, and others:

To exercise any right, email support@tattoopro.app. We respond within 30 days.

10. Children

The Service is not intended for children under 13 (or under 16 in the EEA). We do not knowingly collect personal information from children. If you believe a child has provided us with information, contact support@tattoopro.app and we will delete the information.

11. Security

We use TLS 1.2+ for all network traffic, Firebase Authentication for identity, Firestore Security Rules to enforce per-user access at the database layer, and Firebase App Check (App Attest) to ensure requests originate from a genuine instance of the App. No system is perfectly secure. If you suspect unauthorized access to your account, contact us immediately.

12. Changes to this Policy

We may update this Policy. The "Last updated" date at the top reflects the most recent version. For material changes we will notify you in-app and via email at least 30 days in advance.

13. Contact

RIO ART NYC LLC
516 E 80th St, Apt 25
New York, NY 10075
United States
Email: support@tattoopro.app
General support: support@tattoopro.app