Legal

PRIVACY POLICY

Last updated: July 2026

1. Who We Are

This service is operated by [STENCIL LEGAL ENTITY — TBC] (company number [COMPANY NUMBER — TBC], registered at [REGISTERED ADDRESS — TBC]) ("STENCIL", "we", "us"). STENCIL operates from the United Kingdom.

2. Our Roles: Controller vs Processor

STENCIL acts in two different roles depending on the data:

  • Controller — for artist and studio account data, billing metadata, and how we operate, secure, and improve the platform, STENCIL is the data controller and determines the purposes and means of processing.
  • Processor — for the personal data an artist collects about their own clients (booking details, messages, and reference photos), the artist is the controller and STENCIL processes that data on the artist's behalf under our Data Processing Agreement.

3. Data We Collect

We collect only what we need to run the service:

  • Account information — name, email, login credentials, and profile details you provide.
  • Booking details — appointment information, messages, and quote details between artists and clients.
  • Reference images — photos uploaded to support a tattoo booking (see Section 5).
  • Usage and device data — log data, device identifiers, and IP address used to operate and secure the service.
  • Payment metadata — transaction records such as amounts, plan, and status. Full card details are handled directly by our payment providers — Paddle for subscriptions and Stripe for client deposit and balance payments — and are never stored by us.

4. How We Use Your Data & Legal Basis

We process your personal data on the following legal bases:

  • Performance of a contract — to create your account, provide the platform, and process bookings and subscriptions.
  • Legitimate interests — to secure the service, prevent fraud, and improve our product.
  • Consent — for optional marketing communications, non-essential cookies, and special category data, where required.
  • Legal obligation — to comply with tax, accounting, and other legal requirements.

We do not sell your personal data.

5. Reference Photos & Special Category Data

Reference images and body-placement photos uploaded for a booking may reveal information that qualifies as special category data. Where an artist collects such images from their clients, the artist is the controller and is responsible for obtaining any explicit consent required before uploading them. STENCIL processes these images only to provide the booking and communication features, and applies the same security measures as for all personal data. Do not upload special category images without the necessary consent.

6. Data Sharing

We share personal data only with:

  • Service providers / sub-processors — hosting, database, email, and analytics tooling that help us run the platform. The current list is in our Data Processing Agreement.
  • Paddle — our Merchant of Record and payment provider for STENCIL subscriptions. Paddle.com handles subscription checkout, billing, payments, tax compliance, invoicing, and refunds, and receives the data necessary for those purposes.
  • Stripe — our payment processor for client deposit and balance payments between clients and artists (via Stripe Connect). Stripe processes these payments, routes funds to the artist's connected account, and receives the data necessary for those purposes.
  • Professional advisers and authorities — legal and accounting advisers, or authorities where required by law.

7. Data Retention

We keep personal data only for as long as needed to provide the service and to meet legal, accounting, and reporting obligations. Account and booking data is retained while your account is active and for up to 24 months after closure, after which it is deleted or anonymised. Transaction records may be retained longer where required by law (typically up to 7 years).

8. Your GDPR Rights

We follow UK GDPR and, where applicable, EU GDPR principles. You have the right to access, rectify, erase, restrict, or object to the processing of your personal data, to receive a portable copy, and to withdraw consent at any time. To exercise these rights, contact us at the email below; we respond within one month.

You also have the right to complain to a supervisory authority. In the UK, that is the Information Commissioner's Office (ICO) at ico.org.uk.

9. EU Representative (Article 27)

STENCIL operates from the UK and has no establishment in the EU. Where the EU GDPR applies to our processing, we will appoint an EU representative under Article 27 and publish their details here:

[EU ARTICLE 27 REPRESENTATIVE — TBC]

10. International Transfers

Where personal data is transferred outside the UK/EEA, we rely on appropriate safeguards such as the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses (SCCs), or adequacy decisions, to protect your information.

11. Data Security

We apply appropriate technical and organisational measures: data is encrypted in transit and at rest, access to personal data is restricted, and we review our practices regularly.

12. Cookies

We use essential cookies and local storage to keep you signed in, secure your session, and process payments. Our analytics provider, Plausible, is cookieless and collects no personal data — no cookies, no cross-site tracking. We set no advertising or marketing cookies today; any non-essential cookies would only be set with your consent via our cookie banner. You can review or withdraw your choices anytime using the “Cookie preferences” link in the footer. For full details, see our Cookie Policy.

13. Contact

Questions about your privacy or this policy? Email STENCIL at support@stencils.life.