Privacy Policy
Contents
1. Who we are
ServaloDesk is a software service for tattoo studio owners. When we refer to "ServaloDesk", "we", "us", or "our", we mean the company operating this service. When we refer to "you", we mean either a studio owner (our direct customer) or a client of that studio whose data is processed through our platform.
Studio owners are data controllers for their clients' personal data. ServaloDesk acts as a data processor on their behalf.
2. What data we collect
Studio owners and team members
- Account data: name, email address, password (hashed, never stored in plain text)
- Billing data: subscription plan and payment history. Card details are processed and stored by Stripe — we never see or store raw card numbers
- Usage data: pages visited, features used, API response times (aggregated, used to improve the product)
- IP address: logged on sign-in for security purposes
End clients (booked through a studio)
- Booking data: name, email, phone number, requested tattoo style, preferred dates, deposit amount
- Consent form data: health disclosures, date of birth, electronic signature, IP address, and timestamp at the time of signing
- Payment data: deposit transaction ID (processed by Stripe; card data never touches our servers)
3. How we use it
- To provide the ServaloDesk service — bookings, reminders, consent forms, team management
- To send transactional emails (booking confirmations, reminders, receipts)
- To process subscription billing via Stripe
- To investigate security incidents and prevent fraud
- To comply with legal obligations
We do not sell personal data. We do not use client data to train machine learning models. We do not serve behavioural advertising.
4. Who we share it with
We share data only with sub-processors needed to operate the service:
- Stripe — payment processing
- Resend — transactional email delivery
- Twilio — SMS reminders (if enabled)
- Hetzner — cloud hosting (servers located in the EU and US)
We may disclose data to law enforcement if required by a valid legal process. We will notify affected studios where legally permitted to do so.
5. How long we keep it
- Active accounts: data is kept for as long as the subscription is active
- Cancelled accounts: studio data is retained for 90 days after cancellation to allow re-activation, then deleted
- Consent forms: retained for 7 years (standard requirement for medical-adjacent records) unless the studio owner requests earlier deletion
- Server logs: retained for 30 days then automatically purged
6. Your rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion ("right to be forgotten")
- Export your data in a portable format
- Object to or restrict processing
Studio owners can export all studio data from the dashboard at any time. To exercise any other right, email [email protected].
End clients (people who booked through a studio) should contact the studio directly, as they control your data. If you can't reach them, contact us and we'll assist.
7. Security
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Passwords are hashed using bcrypt. Database backups are encrypted. We conduct periodic security reviews. See our Security page for details.
8. Cookies
We use a single session cookie to keep you signed in. We do not use third-party tracking cookies or cross-site advertising trackers. The analytics we collect are first-party and aggregated — no individual profiles are built from them.
9. Changes to this policy
We'll notify active studio owners by email if we make material changes to this policy. The "Last updated" date at the top of this page reflects the most recent revision.
Questions about this policy? Email [email protected].