Home/Data Retention
Legal

Data Retention Summary

Last updated: July 2026

This page gives a plain-language summary of how long Linebook generally keeps different categories of data. In most cases the studio controls its clients' data and Linebook processes that data on the studio's behalf; for Linebook's own account, billing, security and compliance records, Linebook acts for its own business purposes. It is not a contract, not legal advice, and not a promise of immediate deletion in every case — actual retention may vary where law, legal holds, disputes, fraud or security reviews, tax or accounting rules, backup lifecycles, or other legitimate needs require different treatment.

01How to read this summary

  • Studios can generally manage, export and delete much of their own data through the service or by contacting Linebook.
  • Studio clients should usually contact the studio first for access or deletion requests, because the studio decides how client data is collected and used.
  • Some data may remain in rolling backups, logs, or compliance records for a limited period even after it is deleted from the live product.
  • For certain encrypted sensitive intake records, Linebook may use crypto-shredding — deleting the relevant encryption key so the encrypted data is no longer readable in the ordinary service environment.

02Retention by data category

Data categoryWhat it includesGeneral retention approach
Studio account dataStudio name, contact details, subscription/account details, studio settingsKept while the account is active, and usually for a reasonable period afterward to support export, reactivation, support, legal, accounting, fraud, or contract-administration needs.
Studio staff & login dataUser profile details, roles, login email, hashed password, sign-in/account metadataKept while the user or studio account remains active. Removed when the user is deleted or the account is fully closed, subject to security or legal retention needs.
Booking & client-management dataBooking records, appointment history, service details, booking notes, artist assignmentGenerally kept while the studio account is active, plus a reasonable period afterward for export, reactivation, support, and legitimate business or legal needs.
Client contact detailsClient name, email, phone, related contact fieldsUsually kept with the associated booking or studio account data unless deleted earlier on the studio's instruction or through the studio's rights-handling process.
Sensitive intake dataHealth screening responses, signed waivers, date of birth, intake consent recordsBy default, kept for about seven years from the client's last service, unless the studio configures a different period or applicable law requires different treatment.
Intake placement photosPlacement/body-area photos submitted through the intake flowUsually follow the sensitive-intake path: about seven years from the client's last service by default, unless the studio configures otherwise or law requires different treatment.
Finished-tattoo photosPhotos of completed work attached to bookings or shared through studio workflowsStored encrypted and delivered through an authorised route. The high-quality client copy is deleted roughly 30 days after a studio shares it; a smaller studio archive copy stays with the related booking until the studio deletes it or the account is removed.
Client reference imagesReference images uploaded by or for a clientRetained according to the studio's workflow, the life of the related request or booking, and any manual deletion by the studio.
Billing & payment referencesSubscription billing references, tax references, transaction IDs, Stripe-related references, deposit references recorded in LinebookKept as needed for accounting, tax, reconciliation, audit, fraud, dispute, and other legal or financial recordkeeping. Linebook does not store full payment-card details.
Transactional email recordsBooking confirmations, reminders, intake links, password/login emails, service noticesKept only as long as reasonably needed for delivery, troubleshooting, abuse prevention, audit, and proof-of-notice needs.
Marketing & lifecycle email recordsCampaign records, studio-owner lifecycle emails, unsubscribe records, suppression-list entriesKept only as long as reasonably needed for campaign operations and compliance. Suppression records may be kept longer so opt-out requests continue to be honoured.
Technical & security logsApplication logs, request traces, error logs, authentication events, access-control and abuse signalsKept for the minimum period reasonably needed for security, operations, reliability, support, and incident review, with rolling expiry under infrastructure or provider settings.
Session & security cookiesSession sign-in state, short-lived OAuth/security values, challenge-related valuesUsually expire automatically at sign-out, session end, flow completion, or short-lived security expiry.
BackupsProvider-managed database and storage backupsKept on a rolling backup lifecycle under provider settings, then overwritten or expired in the ordinary course.
Legal, abuse & compliance recordsLegal requests, fraud reviews, takedown records, incident records, compliance logs, subprocessor recordsKept as long as needed for the matter involved, and longer where required for legal, audit, regulator, abuse-prevention, or repeat-issue tracking purposes.

03Sensitive intake records

Linebook applies a distinct retention approach to certain sensitive intake records collected for a studio — health screening responses, signed waivers and signature records, date of birth, and intake placement photos. Unless a studio configures a different period, these records generally default to about seven years from the client's last service. That default is intended to support common operational, liability and recordkeeping needs, but it may differ where local law, legal claims, insurance matters or studio-specific practices require different treatment.

Where deletion is appropriate and no hold applies, Linebook may delete the encrypted records directly and, where applicable, may also use crypto-shredding — deleting the relevant wrapped key so the encrypted intake data is no longer readable or recoverable within Linebook's encrypted intake system.

04Photos are not all treated the same way

  • Intake placement photos generally follow the sensitive-intake retention path above.
  • Finished-tattoo photos are retained based on the studio's sharing workflow and the associated booking: the high-quality copy a client can download expires roughly 30 days after sharing, while a smaller studio archive copy remains with the booking. Both are stored encrypted, and access runs through an authorised route rather than a public link, so ending a share also ends access.
  • Client reference images may remain available with the related request or booking until the studio deletes them or the related records are removed.

05Logs, backups & deletion caveats

Even when data is deleted from the live service, some related information may continue to exist for a limited time in rolling system backups, operational or security logs, incident files, legal or compliance records, or provider-managed infrastructure. Linebook generally avoids promising exact deletion times for every system, because deletion timing can vary by data category, provider lifecycle, and legal or operational constraints.

06When Linebook may keep data longer

Linebook may need to retain some data longer than the general summary above where reasonably necessary for: legal holds or anticipated litigation; active disputes, claims, chargebacks or enforcement matters; fraud, abuse or security investigations; tax, accounting, audit or bookkeeping obligations; regulatory or law-enforcement requirements; copyright, takedown or platform-compliance matters; backup and disaster-recovery lifecycles; or completion of a valid deletion, export or account-closure workflow.

07Requesting deletion or access

If you are a client of a studio, please contact the studio first — the studio controls that client data, and Linebook helps the studio respond. If you are a studio user, you can manage certain data through the product or contact us for help with account closure, export or deletion. Reach us via our contact page or hello@linebook.ink.

This summary is informational only, is not legal advice, and is subject to applicable law, contractual requirements, valid legal requests, and legitimate security, backup, accounting and compliance needs. See also our Privacy Policy and Security Overview.