This Privacy Policy describes how RIO ART NYC LLC ("TattooPro", "we", "us", "our") collects, uses, shares, retains, and deletes personal information when you use the TattooPro mobile application (the "App") and related services available at tattoopro.app (collectively, the "Service").
If you do not agree with this Policy, do not use the Service.
For users in the European Union, RIO ART NYC LLC operates as a trader within the meaning of Article 3(f) of Regulation (EU) 2022/2065 (the Digital Services Act). The following information is provided to comply with Articles 30 and 31 of the DSA:
EU users who believe a service offered through TattooPro does not comply with applicable consumer-protection law may contact us at the address above and we will respond without undue delay.
| Category | Examples | Why we need it |
|---|---|---|
| Identity & account | Display name, email, password (hashed), role (Artist / Client) | Create your account; sign you in |
| Contact | Phone number (optional), city, country | Allow clients to reach you; geographic discovery |
| Professional profile (Artists) | Studio name, tattoo styles, portfolio photos, pricing notes, AI assistant tone preferences | Build your public profile shown to clients |
| Client profile (Clients) | Body-zone preferences, reference photos, intake form answers | Communicate placement and references to your artist |
| Financial records (Artists only) | Tattoo session amounts, expenses, deductions, state of work | Power your private financial dashboard and tax estimates |
| Messages | Text and image attachments you send in chat | Deliver chat between artist and client |
| Appointments | Date, duration, notes | Sync your booking calendar |
We do not collect or store your payment card data. All purchases are processed by Apple StoreKit; we receive only an opaque transaction identifier and product ID from Apple to grant entitlement.
UserDefaults (CA92.1), file timestamps (C617.1), available disk space (E174.1), and system boot time (35F9.1) for legitimate app functionality only.If you choose to sign in with Apple or Google, we receive the email and display name associated with your account from the provider. With Sign in with Apple, you may use Apple's "Hide My Email" relay; we honor that.
We do not use your data for behavioral advertising, do not sell or rent your personal information, and do not track you across other companies' apps and websites. The App declares NSPrivacyTracking = false in its privacy manifest.
The App offers two optional AI features:
You can use the App without using either feature. The first time you tap an AI feature, an in-app consent screen explains the data flow and asks for your explicit, opt-in approval, in line with App Store Review Guideline 5.1.2(i).
We share information only with the parties below and only for the purpose stated:
| Recipient | Purpose | Data shared |
|---|---|---|
| Google LLC (Firebase: Auth, Firestore, Storage, Functions, Cloud Messaging, App Check) | Backend infrastructure | All categories listed in §2 except payment data |
| Google LLC (Vertex AI, Cloud Run) | AI features (only if you opt in) | Recent chat thread, tone settings, anonymized aggregates |
| Apple Inc. (StoreKit 2, APNs, App Attest, Sign in with Apple) | Purchases, push delivery, anti-abuse, sign-in | Opaque transaction IDs, push tokens, attestation tokens, the Apple ID identifier you authorize |
| Law enforcement / regulators | Compliance with valid legal process | Only what is legally required and narrowly tailored |
We do not have third-party advertising or analytics SDKs in the App.
Data is processed in the United States and in Google Cloud regions (primarily us-east1 and us-central1). Where required (EEA, UK, Switzerland), transfers rely on Standard Contractual Clauses approved by the European Commission and on Google's supplementary technical and organizational measures.
You can permanently delete your account at any time directly inside the App: Settings → Account → Delete account. The deletion flow:
If for any reason you cannot delete in-app, email support@tattoopro.app with your account email and we will action the request within 30 days.
Depending on where you live, you have rights under laws including the EU/UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), Brazil's LGPD, and others:
To exercise any right, email support@tattoopro.app. We respond within 30 days.
The Service is not intended for children under 13 (or under 16 in the EEA). We do not knowingly collect personal information from children. If you believe a child has provided us with information, contact support@tattoopro.app and we will delete the information.
We use TLS 1.2+ for all network traffic, Firebase Authentication for identity, Firestore Security Rules to enforce per-user access at the database layer, and Firebase App Check (App Attest) to ensure requests originate from a genuine instance of the App. No system is perfectly secure. If you suspect unauthorized access to your account, contact us immediately.
We may update this Policy. The "Last updated" date at the top reflects the most recent version. For material changes we will notify you in-app and via email at least 30 days in advance.
RIO ART NYC LLC
516 E 80th St, Apt 25
New York, NY 10075
United States
Email: support@tattoopro.app
General support: support@tattoopro.app