What we collect, and what we do with it
waivers.tattoo is 2 things: this website, where a shop signs up, and the consent form a client signs on their own phone at a shop’s counter. They collect different things from different people, so this page takes them one at a time. waivers.tattoo is a product of Tattoo Waivers LLC, a Texas company. The person who built it wrote this page and answers hello@waivers.tattoo.
On this website
What you type. The start form asks for your shop, an email for the signed waivers, and, if you want to give them, your name, phone, city and state. If you pick your shop from the search, we also keep the address, phone and website Google returned for it. We use all of it to set up your shop’s page and to email you about it: your link, your QR code, and a few emails while your first waivers are free about getting set up. Reply to any of them and they stop. We do not sell it, rent it, or put you on a list you did not ask for.
The shop search. When you search for your shop on the start page, what you type goes to Google’s Places service to find it, under Google’s own privacy policy. We keep only the shop you picked.
If you start the form and leave. We keep what you had entered so far, the shop you picked and any email or name, so we can follow up once about getting set up. Nothing else is done with it, and a note to hello@waivers.tattoo deletes it.
Payment. When you activate, Stripe takes your card on its own page. Your card number never reaches our servers. We keep Stripe’s reference to your subscription and the receipts, as long as tax law needs them.
How you got here. If an ad or a link brought you, your browser remembers which one and attaches it to your signup, so we know which ads bring shops. It lives in your browser’s own storage for up to 7 days — in-app browsers, the kind Facebook and Instagram open a link in, throw the shorter kind away between 2 pages, so we keep the longer copy and the ad that brought you does not get lost on the way to the form. It holds the link’s tracking parameters and the site you came from, never who you are, and clearing your browser clears it. The start page also tests 2 versions of its wording; a cookie remembers which one you saw for the visit, so it does not flip on you, and carries nothing else.
Advertising. We advertise on Facebook and Instagram, and this website carries Meta’s pixel. It tells Meta which pages you visited here and sets 2 cookies in your browser (one that identifies the browser, one that identifies the ad click that brought you). When you sign up, activate, or move through the site, our servers tell Meta what happened and send the email and phone you gave us, hashed, so Meta can match you to an account it already holds and count the ad that worked. Those are the shop owner’s own details on a business signup. Meta uses what it gets under its own data policy. You can limit it in your Facebook and Instagram ad settings, or with a browser that blocks trackers. The pixel runs on this website only. It never runs on a shop’s signing pages.
Logs. Our servers keep ordinary access logs: the page requested, the time, your IP address and browser. They are for keeping the site running and are not used for advertising.
Your rights. Ask, and we tell you what we hold about you, fix it, or delete it. Billing records stay as long as tax law requires; everything else goes when you ask.
On the waiver form
A shop that uses waivers.tattoo puts a QR code on its counter. When a client scans it and signs, the form collects what the shop’s consent record needs: name, address, phone, email, age and date of birth; a photo the client takes of their government ID; the answers to a short health questionnaire; the artist, the tattoo description and its placement; and if the shop turns it on, photos of the needle and pigment lot numbers. Then the consent text, the client’s signature, and the date and time.
The form runs on the shop’s own web address. It carries no advertising pixel, no analytics, and no third-party scripts. What a client types goes to our servers and to the shop, nowhere else. The one exception is the street address: as a client types it, what they have typed so far goes from our servers to Google’s Places service to suggest the full address, under Google’s own privacy policy. Google sees the typed letters and the shop’s location, never the client’s device or anything else on the form.
The shop is asking for this information, and it is the shop’s record. State regulations require shops to keep it, in most states for at least 2 years. We process it on the shop’s behalf: we render the signed waiver as a PDF, email it to the shop, store a copy so the shop can find it later, and keep the client’s name and contact details in the shop’s client list.
The health answers and the ID photo are the most sensitive things on the form. They go into the signed PDF the shop receives and nowhere else: not into the client list, not into any message, never into any marketing, and never to anyone but the shop and the people who keep the service running when the shop needs help.
The client list is the shop’s to keep in touch with. A shop can use its clients’ names and contact details to reach them about their appointment, their aftercare, and the shop’s news and offers. We never sell a client’s information. A client who wants no more messages from a shop replies STOP to a text, uses the link in an email, tells the shop, or writes to us and we pass it on.
The form is built for adult clients. Where a state allows a minor to be tattooed with a parent’s or guardian’s consent, the shop, not the form, is responsible for that consent and its record.
If you are a client and have a question about your record, ask the shop first; it is theirs. If you want our help, write to hello@waivers.tattoo and we work it out with the shop.
Where it lives, and for how long
On Amazon Web Services, in the United States, encrypted in transit and at rest. Access is limited to the people who keep the service running. Signed waivers (PDFs) and the client list stay in the shop’s account while the shop is a customer and for 90 days after it cancels, so it can export everything; after that we delete what we hold. The shop keeps its own copy for as long as its state requires, and the PDF we email at every signature is that copy. No system is perfectly secure. If a breach touches your data, we tell you, and the shop, as soon as we know.
Who sees it
The shop. The people who run waivers.tattoo, when the shop needs help. The services it runs on: Amazon Web Services for hosting, storage and email; Stripe for payments; Google for the shop search and the form’s address suggestions; Meta for the advertising described above, on this website only; and Twilio, which carries a shop’s text messages to its own clients. Nobody else, unless the law requires it, and then we tell the shop unless the law forbids it. We never sell data, a client’s or a shop’s.
We send the emails the service needs: a signed waiver to the shop at every signature, a shop’s setup and billing emails, and a few during the free waivers. No newsletters. Every one of them is answered by a person if you reply.
Text messages
A shop can text its own clients through waivers.tattoo. A client gives their mobile number on the shop’s form, and hearing from the shop after that day is 2 separate boxes, both optional and both unticked, under the box that accepts the terms. The first covers the client’s own aftercare and how their healing is going; the second covers the shop’s news, offers and events. A client ticks either, both or neither, and still signs, because saying yes is not a condition of getting tattooed or pierced. We keep the 2 apart when we send: a client who agreed only to the first never gets a promotional message. Every text names the shop it is from and is sent by waivers.tattoo on that shop’s behalf. How often depends on the shop, and message and data rates may apply. Reply STOP to any message to stop, or HELP for help.
Mobile phone numbers and text-message opt-in consent are never shared with third parties or affiliates for marketing or promotional purposes, and are excluded from every kind of sharing described elsewhere on this page. We do not sell them, and we do not hand them to anyone for their own marketing.
Changes
If this page changes in a way that matters, the date above changes with it, and shops with an account hear about it by email first. The terms say what the deal is; this page says what we collect.