Legal
Privacy Policy
Last updated 25 July 2026
This policy explains what Patron collects, why, and what you can do about it. It covers Patron ("we", "us") and the Patron app.
It's written mainly for the studios and artists who use Patron. If you're a tattoo client who sent a request or booked through a studio's Patron page, the studio decides what it collects and why; Patron stores your request, messages, images, and any waiver answers on the studio's behalf.
What we collect
Your account: your name, email, and a securely hashed password. Studio owners also add a studio profile, like the shop name, Instagram handle, hourly rate, and default deposit.
Your clients' information: when a client reaches out or you add a booking, we store what's needed to manage it. That's their name, their email address and Instagram or WhatsApp handle, the messages they send, any reference links they paste, and the appointment and pricing details.
Email to your studio: every studio gets its own Patron email address. When a client writes to it, the message reaches us through our email provider, and we turn it into a request on your board along with any photos attached to it. The provider keeps its own copy for 30 days before deleting it, whether or not you ever open the message.
Consent and health details: if you use Patron's built-in waiver, we store your clients' answers, their date of birth, and their signature so you keep the signed record. Those answers can include sensitive health information a client chooses to disclose, like allergies, medical conditions, or medications. We hold this on your behalf and use it only to run the service for you. Patron is not a healthcare provider or a HIPAA-covered entity, and we don't treat this as HIPAA-regulated data. The studio decides what its waiver asks and is responsible for collecting and handling those answers lawfully.
Payments: deposits and fees are processed by Stripe and land in your own account. Stripe handles the card details. We never see or store full card numbers; we keep records of amounts, status, and timing so your ledger and payouts stay accurate.
Messages we send for you: Patron writes reminders, aftercare notes, and notifications in the app and sends them by email through our email provider. Text messaging isn't switched on yet.
Early-access waitlist: if you join our waitlist, we collect the email address you submit so we can tell you when Patron opens. Nothing else.
Technical data: basic logs and a sign-in cookie that keeps you logged in. We don't use cookies for advertising. A studio can also switch on Google Analytics for its own public booking page; when it's on, visitors are asked to accept or decline first, and nothing loads unless they accept. It's off by default, controlled in the studio's Settings, and a visitor can change their choice anytime from the page footer.
How we use it
We use this information to run Patron: to show your pipeline, read incoming messages, schedule and price work, route deposits to your Stripe, send the messages you set up, answer support requests, keep the service secure, and meet our legal obligations.
If you run the front-desk display in your waiting area, it shows a first name and last initial for the people due in that day. Nothing else reaches that screen. Not the tattoo, not the price, not their contact details.
How messages become requests
To turn a raw message into a structured request, Patron picks out the details that matter: placement, size, style, budget, and a short summary. This runs entirely on our own systems. The message text is not sent to any outside company for this, and no AI service is involved.
Nothing is invented. If the client didn't say something, the field is left blank rather than guessed at, and their original message is always kept alongside so the studio can read it themselves.
Who we share it with
We don't sell your data, and we never resell your clients. We share information only with the services that make Patron work, and only as much as each one needs:
- Netlify, our marketing-site host and form provider, for hosting the site and receiving early-access waitlist sign-ups.
- Vercel, for hosting the app itself, which means it handles the requests you make to it and keeps short-lived server logs.
- Stripe, for deposits, fees, and payouts into your own account.
- Resend, for the email Patron sends on your behalf, and for the client email that arrives at your studio's Patron address.
- Our hosting and database provider (Supabase), for storing your data securely.
- Google, for Analytics if a studio turns it on for its public booking page.
We may also share data when the law requires it, to protect people's safety, or as part of a sale or merger of the business. If ownership ever changes, we'll tell you.
Your clients' data is yours to control
For the client information you bring into Patron, you decide what to collect and why. We process it on your behalf so we can provide the service. Handling it lawfully is your responsibility, including any consent your clients need to give before you upload their messages or photos, and especially for the sensitive health details a waiver can collect, which many privacy laws protect more strictly.
Keeping it, and keeping it safe
We hold your data while your account is active and for as long as we need it for the purposes above or to meet legal duties. After that, we delete or anonymize it.
We protect it with encryption in transit, hashed passwords, and access controls. No system is perfectly secure, but we work to keep yours safe and we'll act quickly if something goes wrong.
Photos a client attaches to an email, waiver signatures, and progress shots are kept in private storage. There's no public address for them. When someone with access to your board opens one, we make a link that stops working within the hour. Reference links a client pastes into a booking form work differently: we store the link, and the image itself stays wherever they put it.
Your rights
Depending on where you live, you can ask us to show you the data we hold about you, correct it, delete it, or send you a copy. You can also object to certain uses. Email support@patron.ink and we'll take care of it. Asking is free, and we won't penalize you for it.
If a studio collected information about you as its client (through a booking or a waiver), the studio decides how that data is handled. Contact the studio directly, or email support@patron.ink and we'll route you to them.
If you're in California, the CCPA/CPRA gives you those same rights: to know, access, correct, delete, and to not be treated differently for using them. We do not sell or “share” (as those laws define it) your personal information or your clients', and we haven't in the past 12 months. See “Who we share it with” for the service providers we rely on.
Data leaving your country
Patron and the services it relies on may process your data in other countries. Where that happens, we use appropriate safeguards for the transfer.
Children
Patron is for tattoo professionals and their adult clients. It isn't meant for children, and we don't knowingly collect their information.
Where a studio uses the built-in waiver, it asks for a date of birth. If that shows the client is under 18, Patron won't record their signature and won't check them in.
Research participants
Separately from the product, we sometimes run interviews with tattoo artists and studio owners, like the questionnaire at /interview. Taking part is entirely voluntary and there's no account involved.
We collect only what you type: your name if you give it, and your answers. It reaches us as an email; it isn't added to a database, sold, or shared. We use it to decide what to build, and we may quote short extracts anonymously. Never with your name, your studio, or anything else that identifies you. Tell us in the form if you'd rather we didn't quote you.
We ask you not to include other people's personal details in your answers, and we'll remove any that arrive. We read the transcript, write up what we learned, and delete it within 30 days; what we keep after that is anonymous notes. Answers reach us by email through Resend, whose own copy expires after 30 days as well. To have yours deleted sooner, email support@patron.ink.
Changes to this policy
We'll update this policy as the product changes. If a change matters to you, we'll tell you by email or in the app before it takes effect.
Contact
Questions about your privacy, or want to exercise one of the rights above? Email us at support@patron.ink and we'll help.