How we handle personal information
Last updated 24 August 2026
Bonehead Ledger is a booking and enquiry tool for tattoo artists, built and run by Bonehead Digital, New Zealand. Our privacy officer is Tom and the address for anything on this page is privacy@boneheaddigital.com.
Two layers, and which one you’re in
If you enquired with a tattoo artist, the artist is responsible for your details. They decide what to collect and why, they answer your requests, and their own notice is on their page under “how your details are handled”. We hold that information for them and act on their instructions. We don’t use it for anything of our own.
If you’re an artist or studio using the app, we’re responsible for your information, and this page is your notice.
What we collect, and why
From artists and studios using the app: your name, email, phone and Instagram handle, your sign-in details, the settings and page content you write, and a record of when you last used the app. We need it to give you an account, to run your public pages, and to support you when something breaks.
From people enquiring with an artist: what you type into their form, which is your name, how to reach you, and what you’re after, plus any reference images you attach and the technical details of the visit described below. Giving it is voluntary, and you can always contact the artist another way instead, but without it they have no way to reply or to book you in.
We also keep records our own operation needs: error reports with personal details stripped out, counts and totals used to see whether the tool is working, and a log of every time we open a workspace to help with support.
Information we get about you from someone else
Sometimes a person’s details reach an artist without that person filling in a form. A client refers a friend and passes on their number. An artist moves an existing booking list into the app. When that happens the artist should tell you where your details came from, what they hold, and how to ask for them to be corrected or removed, and the first message they send you is where that belongs. This paragraph is the standing notice for it.
Who else touches it
We use these services to run the app. None of them use your information for their own purposes.
- Supabase, the database and file storage where everything lives.
- Vercel, which serves the app and the pages. Its logs carry reference numbers and error codes, never personal details.
- Resend, which sends notification email. When someone enquires, the artist gets an email with that person’s contact details in it, so the enquiry reaches them even if the app is down.
- Sentry, which collects error reports. Personal details are stripped before they leave and again on arrival.
- Backblaze, which holds backup copies. They are encrypted before they leave us, so Backblaze can’t read them.
- Meta, but only as described below, and only for artists who have advertising measurement switched on.
Some of these store information outside New Zealand and Australia, including in the United States and Europe. They hold it under their own security and privacy terms, on our instruction, and they’re not free to do anything else with it.
Artists can also connect their own Stripe account for deposits. That’s their arrangement with Stripe, and card details never reach us.
Advertising measurement
Artists using the app usually advertise on Meta. Where an artist has this switched on, their pages carry their own Meta pixel, and we send Meta a scrambled version of the contact details along with what happened, such as an enquiry, a booking, or a completed tattoo, so Meta can tell the artist which ads actually brought people in.
The contact details are hashed before they go, which means Meta receives a fingerprint rather than the details themselves. We never send what you typed into the form. Every page running a pixel says so at the bottom.
How Meta’s measurement works · your Meta ad settings, where you can switch off the use of this kind of activity.
Every artist uses their own advertising account. Nothing is pooled across artists, and no combined pixel exists.
Cookies and tracking
The app sets a sign-in cookie for people with accounts. Public pages don’t set cookies to identify you. They do read the campaign tags that ads add to a link, and where the artist has measurement on, the Meta pixel sets its own cookies. That’s the lot, and the opt-out above covers it.
How long we keep it
Each artist sets a retention period, 12 months by default. Enquiries that never became work are anonymised automatically once it passes: the personal details go, and only counts and dates remain. Records of actual work, such as bookings, payments and signed terms, are kept while the artist needs them.
Artist accounts are kept while the account is open. When an artist leaves, their pages and links stop working straight away, they get an export if they want one, and the workspace is deleted about 30 days later.
Backup copies are encrypted and roll off on their own schedule, which is why deletion clears the live system first and the backups in time.
Marketing
Artists can only send you marketing if you ticked the separate box for it, and you can tell them to stop at any time. The app never sends messages on an artist’s behalf without them, and we never market to an artist’s clients ourselves.
Your rights
You can ask to see the information held about you and to have anything wrong corrected. If you enquired with an artist, ask them, since it’s theirs. If you’re an artist, or you can’t get hold of the artist you dealt with, email privacy@boneheaddigital.com. There is no charge, and we answer within 20 working days.
Asking for your details to be deleted works the same way. The steps for all three, and what we need from you to find your records in the first place, are on the see, fix or remove your details page.
If you’re not happy with how a request was handled, you can complain to the Office of the Privacy Commissioner in New Zealand at privacy.org.nz, or to the OAIC in Australia at oaic.gov.au.
Keeping it safe
Each artist’s workspace is walled off from every other one in the database itself, not just in the screens. Files are served through links that expire. Personal details are kept out of our logs and error reports. Support access to a workspace is logged every time. If something goes wrong that could cause real harm, we tell the artist quickly so they can notify the people affected and the Privacy Commissioner, and we help them do it.
Changes
If this page changes in a way that matters, we’ll tell artists using the app. The date at the top is always the current version.