Privacy Policy
Last updated: July 2026
This policy explains what data Linebook handles, why, and how we protect it — for studios and artists who use Linebook, and for their clients whose details a studio enters to manage bookings.
01Who we are
Linebook is booking software for tattoo studios and artists, operated from Ontario, Canada. When you run your studio on Linebook, you decide what client information to collect — you are the controller of your clients' data, and Linebook is your processor, handling it on your behalf to provide the service.
02What we collect
See our Cookie Policy for the current inventory of cookies and similar technologies and additional information about our current cookie and analytics practices.
03How we use it
We use data only to provide and improve Linebook: to run your booking site and console, secure authentication and booking flows, process your subscription and connected-payment references, send transactional emails (like booking confirmations and receipts), measure service reliability and performance, keep records, and support you. We do not sell your data, and we don't use your clients' data for our own marketing.
04Security & encryption
We take security seriously. Passwords are hashed, connections are protected in transit, and access to client contact details (name, email, phone) is limited according to role and function. Different data categories are protected differently depending on the feature used, with the additional encryption-at-rest controls described below for sensitive intake content and intake placement photos. No system is perfectly secure, but we design the product to reduce unnecessary access and the blast radius of any incident.
05Sensitive intake data (health, waivers, intake placement photos)
If a studio uses Linebook to collect sensitive intake information — a health/medical screening, a signed consent form, a date of birth, or an intake placement photo — that information gets additional protection. Photos of finished work attached to a booking receive comparable storage and delivery protection (see below). It is encrypted at rest using a studio-specific key structure, and is intended to be viewable only by signed-in members of that studio through the product's authenticated workflows.
Intake placement photos are processed differently from other image features. For those intake placement photos, Linebook strips location and device metadata (EXIF/GPS), re-processes the file, and stores the result in encrypted form rather than at a public link; they're shown to a studio through an authenticated, studio-scoped route. Clients are asked to exclude faces. Finished-tattoo photos are also re-encoded, encrypted at rest under a studio-scoped key, and delivered only through an authenticated route, including the gallery link a studio shares with its client — so ending that share, or deleting a photo, also ends access through a link already sent. Other image features — such as portfolio and flash images, or client reference images — may use different storage and delivery paths and should not be understood as covered by these statements unless we expressly say so. In particular, client reference images may be stored substantially as uploaded and may include embedded metadata unless the studio or client removes it before upload.
Linebook's ordinary admin and support tools are designed to limit access to this encrypted intake content through role-based access controls and authenticated studio workflows. To be clear, this is a statement about access controls and tooling design, not a statement that hosted infrastructure can never process encrypted data in order to show it back to the authorised studio user. We do not store government-ID images in this intake flow — only an “ID checked, 18+” attestation.
Consent is captured as separate, specific opt-ins (health, waiver and photos are agreed to individually, not bundled), reflecting laws such as Washington's My Health My Data Act and Quebec's Law 25. The studio is the controller of this data and Linebook is its processor; a Data Processing Agreement (DPA) is available to studios on request.
If a studio's intake workflow involves consumer health data in a jurisdiction with specific requirements, see our Consumer Health Data Privacy Policy, which supplements this policy.
By default this data is retained for about 7 years from the client's last service (aligned to liability and limitation windows), after which it is deleted; a studio can export it, and can honour a client's erasure request — deleting a studio's intake key renders its encrypted intake content unreadable in the ordinary service environment rather than deleting it file-by-file. Deletion may be subject to backup lifecycle, legal holds, disputes, and legally required retention (e.g. tax/accounting).
Honest note: this is a strong “encrypted at rest, access-controlled” design intended to reduce breach, casual-access and operator-access risk for sensitive intake content. Like any hosted service that shows a studio its own data, it is not a claim the information is mathematically inaccessible to our own infrastructure. Studios operating in Washington, Nevada or Connecticut, or handling EU or Quebec residents' data, should review their own obligations — this is not legal advice.
06Who processes data for us (sub-processors)
We use a limited number of third-party service providers to host, secure, support, measure and operate Linebook — including infrastructure hosts, database and file-storage providers, a payment processor, an email provider, anti-abuse and access-control providers, and privacy-preserving analytics. Our current provider list, including each provider's role, data categories and region information, is published on our Subprocessors page, which we update when providers are added, replaced or removed.
07Payments & deposits
Client deposits and payments run through the studio's own payment setup — including its own Stripe account when connected. That money goes directly to the studio; Linebook never holds it. Stripe handles the sensitive payment details under its own privacy terms; we only record references and amounts so your books balance.
08Sharing
We do not sell personal data and do not disclose it except: to our service providers and sub-processors as needed to operate the service; when a studio instructs us to through its use or configuration of the service; in connection with an optional third-party integration a studio chooses to connect; to protect the rights, safety, security or integrity of Linebook, studios, clients or the public; or to comply with applicable law, regulation, court order or other valid legal process. A studio's data is isolated to that studio — one studio can't see another's.
Where appropriate and lawful, we review legal requests for validity, interpret them narrowly, and may object to overbroad or improper requests. Unless legally prohibited or clearly inappropriate, we may notify the affected customer before disclosing their information.
09Retention
We retain different categories of data for different periods depending on the feature used, the studio's configuration, operational needs and legal requirements. In general, account and booking records are kept while the account is active and for a limited period afterward to support export, reactivation, compliance and dispute resolution. Sensitive intake data is retained according to the studio's intake retention settings, which by default may be around seven years from the client's last service. Other data classes — such as logs, analytics, and connected-integration records — may have different retention periods. When data is no longer needed we delete it in the ordinary course, subject to any legal retention obligations (for example, tax records). For a data-class breakdown, see our Data Retention Summary.
10Your rights
Depending on where you live, you may have rights to access, correct, export or delete personal data. If you're a client of a studio, the studio controls your data — contact them first; we'll support them in responding. If you run a studio, you can access and export your data in the console, or reach us to help. To make a request, use our contact page.
11International
Linebook is operated from Ontario, Canada, and uses service providers that may process data in different jurisdictions depending on the provider, service, feature and current configuration. The current provider-region information is listed on our Subprocessors page. By using Linebook you understand your data may be handled in those jurisdictions under this policy.
12Children
Linebook is a tool for businesses, not a service for minors, and isn't directed at children. We don't knowingly collect data from children through the product. Studios are responsible for how they handle any client who is a minor under the laws that apply to them.
13Changes & contact
We try to keep this policy tightly aligned to how the product actually works. Because Linebook includes configurable features and third-party services, some details may depend on the feature a studio uses or the current provider configuration; where that matters, read this policy together with our Cookie Policy, Subprocessors page and Security Overview.
We may update this policy as Linebook evolves; material changes will be flagged. Questions, or a privacy request? Reach us at our contact page or hello@linebook.ink.