Privacy Policy
Last updated: 12 June 2026
Inkframe is a business tool for tattoo artists, operated by Cyber-Jack in the United Kingdom ("we", "us"). This policy explains what data we hold, why, and the rights you and the people in your book have under UK data protection law (UK GDPR and the Data Protection Act 2018).
1. Who is responsible for the data
There are two relationships:
- Your account. For the data that makes up your Inkframe account (your email, password and profile), we are the controller.
- Your clients' data. For everything you enter about your clients and bookings, you are the controller and we are your processor. We act only on your instructions and do not use your clients' data for our own purposes. As the controller you are responsible for telling your own clients how their data is used and for having a lawful basis to hold it - especially the medical and consent information collected on consent forms.
2. What we collect
Account data
- Your email address (used to log in and to contact you).
- A securely hashed version of your password - we never store or see your actual password.
- Your profile: display name, handle, bio, location, Instagram, currency, accent colour, avatar.
- Technical logs needed to run and secure the service (e.g. request times, error logs).
Business data you enter
- Clients: names, phone numbers, email addresses and your notes.
- Bookings and money: appointment dates, deposits, balances and the studio split you choose to record. Inkframe is track-only - no card payments are processed through it.
- Photos you upload (reference, stencil, healing, portfolio and flash images).
- Consent forms: where you use the public consent form, the medical questionnaire answers and typed signature your clients provide. This is treated as special-category (health) data.
- Enquiries sent through your public page, including any reference images.
3. Lawful basis
- For your account and providing the service to you: performance of a contract with you, and our legitimate interest in running and securing Inkframe.
- For your clients' data: you choose and are responsible for the lawful basis (typically your contract with the client and, for health/consent data, the client's explicit consent given on the form).
4. Where your data is stored
Inkframe runs on our own managed servers in the United Kingdom, behind Cloudflare. Data is encrypted in transit (HTTPS/HSTS). Backups are taken regularly and kept on UK and encrypted off-site storage so your book can be restored if hardware fails.
5. Who else processes data (sub-processors)
- Cloudflare - content delivery, TLS and security in front of the service.
- Brevo (Sendinblue) - sends transactional email such as enquiry notifications, appointment reminders and password resets.
- Google Analytics - anonymised, aggregate usage statistics, only if you accept analytics cookies. IP addresses are anonymised.
We do not sell your data or your clients' data to anyone, ever.
6. How long we keep it
We keep your data for as long as your account is active. If you delete your account (Settings → Delete account), your account and all the client data, photos and consent forms held under it are permanently erased from the live system, and removed from backups as those backups rotate. As a controller, bear in mind tattoo studios often need to keep consent and aftercare records for several years - export anything you need before deleting.
7. Your rights
You can, at any time:
- Access your data - it is all visible in the app, and finance records can be exported as CSV.
- Correct anything inaccurate - edit it in the app.
- Erase your account and all its data - Settings → Delete account.
- Object or restrict processing, and complain to the ICO if you think we have got something wrong.
If you are a client of an artist who uses Inkframe and want your data changed or removed, please contact that artist directly - they control their own book. We will support them in actioning your request.
8. Cookies
Inkframe uses one essential cookie to keep you logged in. The marketing site uses an optional analytics cookie that only loads if you accept it.
9. Security
Passwords are hashed (bcrypt). Each artist's data is isolated from every other artist's. Access requires a valid login session. Public write actions are rate-limited and the service sits behind a security-monitored firewall.
10. Changes & contact
We may update this policy and will change the date above when we do. Questions, requests or concerns: [email protected].