Privacy Policy
Last updated: July 12, 2026
1. Who We Are
Insomnia Tattoo is a tattoo studio located at Str. D10, No. 11 Bis, Apt. 2, Mamaia Nord, Constanța. We protect your personal data in accordance with the European Union General Data Protection Regulation (GDPR).
Contact for GDPR requests: contact@insomniatattoo.ro
2. What Data We Collect
We collect the following categories of personal data:
- Full name
- Email address
- Phone number
- Booking details (body area, desired style, size)
- Reference images uploaded for consultation
- Support conversations and attachments you choose to send
- Reviews, revision number and the client-level milestone linked to an update, reactions, saved items, loyalty points, and activity history
- Notifications, read/unread state, and organization actions requested in the account
- Technical and security data (pseudonymized IP, device, browser, and access logs)
- Usage data through analytics or advertising services only after consent
3. Why We Collect This Data
We use your personal data for the following purposes:
- Managing bookings and communicating with you
- Managing accounts, saved items, reviews, and loyalty features
- Resolving Help Center requests and preventing abuse
- Improving our services
- Website traffic analysis (Google Analytics 4, Meta Pixel) - only with your consent
- Authentication, account protection, and incident investigation
4. Legal Basis
Booking requests, accounts, and service-related support are processed to take pre-contractual steps or perform our relationship with you (Art. 6(1)(b) GDPR).
Security, fraud prevention, legal claims, and limited service improvement rely on legitimate interests (Art. 6(1)(f) GDPR), subject to necessity and impact assessments.
Consent (Art. 6(1)(a) GDPR) applies to non-essential cookies and optional processing and may be withdrawn at any time.
Tax, accounting, and valid authority requirements rely on legal obligations (Art. 6(1)(c) GDPR).
5. How Long We Keep Data
Booking data is retained for the duration of the relationship with the studio and for 2 years after the last interaction, for internal records.
Reference images are deleted within 90 days after the tattoo is completed.
Support conversations and attachments are automatically deleted 24 months after resolution or closure unless a legal obligation or a specific dispute requires preservation.
Reviews and their current revision data are retained while the account and content remain active or as needed for moderation, appeals, and legal claims.
Security logs are retained only as long as necessary to investigate and protect the platform under the internal retention schedule.
Analytics data is anonymized and aggregated according to Google and Meta policies.
6. Where We Store Data
Application data is stored in PostgreSQL. Reference images are currently stored as objects accessible through provider-level public URLs until a coordinated migration to private storage is completed. The application does not include those URLs in booking API responses, and in-app access goes through authenticated routes.
We use necessary providers for hosting/storage, email, error monitoring, optional Google sign-in and, only with consent, analytics/advertising. They act under applicable contracts and instructions.
Where a provider processes data outside the EEA, the transfer must rely on an adequacy decision or GDPR safeguards such as Standard Contractual Clauses.
7. Your Rights
Under GDPR, you have the following rights:
- Right of access - you can request a copy of your personal data
- Right to rectification - you can request correction of inaccurate data
- Right to erasure ("right to be forgotten") - you can request deletion of your data
- Right to restriction of processing
- Right to data portability
- Right to object to processing
- Right to lodge a complaint with ANSPDCP (National Supervisory Authority for Personal Data Processing)
- Right to withdraw consent where processing relies on consent
8. Exercising Your Rights
You can export or delete account data in My Account → Settings. For rectification, restriction, objection, or a complex request, use Personal data in the Help Center or email contact@insomniatattoo.ro.
We may request only the additional information needed to verify identity. We respond without undue delay and normally within one month; an extension is possible only under GDPR conditions and with notice.
Erasure is not absolute: data strictly required by law or for a legal claim may be retained, with an explanation of the applicable exception.
9. Guest bookings — anonymization
If you booked without creating an account, you can request anonymization of personal data in those bookings (name, phone, email, description, reference images).
You submit the request online; you will receive a confirmation email.
10. Cookies and Local Storage
We use essential cookies for website functionality (JWT authentication, language preference) and analytics cookies (Google Analytics 4, Meta Pixel) that are activated only with your explicit consent.
For complete details, please see our Cookie Policy.
11. Security and Incidents
We use role-based access, protected sessions, rate limiting, file validation, non-disclosure of reference-image URLs in booking API responses, and audit logs for sensitive actions. No system can promise zero risk.
Incidents are documented and assessed. Where an incident may risk individual rights, we notify the competent authority within the GDPR deadline and, for a high risk, the affected individuals.
Support conversations are not used for solely automated decisions with legal effects. A future AI assistant will be clearly identified before activation.
12. Contact
For any questions regarding personal data protection or to exercise your rights, you can contact us at:
Email: contact@insomniatattoo.ro
Operational support: support@insomniatattoo.ro or the private Help Center chat
Address: Str. D10, No. 11 Bis, Apt. 2, Mamaia Nord, Constanța
This privacy policy may be updated periodically. We encourage you to review it regularly.