flash.

Privacy Policy

Last updated 4 September 2026

How CRTYX HOLDINGS LIMITED handles personal data in Flash. Written to describe what the software actually does, so it should match what you see.

Who is responsible for what

For your own account (your email, your profile, your subscription), CRTYX HOLDINGS LIMITED is the data controller.

For an artist's or studio's client records, the artist or studio is the controller and we are their processor. We hold that information to run the service for them and for no other purpose. The terms of that arrangement are in our Data Processing Agreement.

If you are booking a tattoo, your artist decides what they keep about you and why. Ask them first about anything to do with your booking record; we will help them, but it is their call.

What we hold

  • Account: name, email, password hash, pronouns if you give them, role, and your subscription status.
  • Artist and studio profiles: handle, bio, styles, city, links, portfolio images, page settings, and any verification details you submit.
  • Bookings: the brief, placement, size, budget, reference images, dates, quoted price and deposit records. Deposits are records only, we never see the money.
  • Messages: what you and your client, shop or fellow artist write to each other, and any photos attached.
  • Contact preferences: a phone number only if a client gives one for reminders, and whether reminders are switched on for that booking. Texts are sent from a name rather than a number, so they cannot be replied to; the switch is on the booking page in your account.
  • Operational records: an append-only audit log of administrative actions, notification delivery records, and rate-limiting counters.

Health information: we do not hold any

Medical and consent answers are special category data under UK GDPR, and Flash does not store them at all. An artist builds their own form here, but the client fills it in on the studio's own device and the completed copy is saved to that device. Nothing is uploaded to us. All we record against a booking is the date the paperwork was done.

How it is protected

Message bodies and attachment references are encrypted at rest with AES-256-GCM, so a database dump shows who messaged whom and when, but not what was said. We hold the key, which is what makes dispute resolution and account deletion workable. It is not end-to-end encrypted, and we would rather say so plainly.

Access is controlled by a single authorisation layer covered by automated tests. Support staff can “view as” an account only with the action recorded in the audit log and a banner shown throughout, and never to reach the admin panel. Reading a message thread they are not part of requires a written reason and is logged before any content is returned.

Why we are allowed to hold it

  • Contract: running your account and the bookings you make through it.
  • Legitimate interests: keeping the service secure, preventing abuse, counting page views on public pages, and improving the product.
  • Consent: SMS reminders, which a client opts into per booking, and non-essential storage on your device.
  • Legal obligation: keeping the records we are required to keep.

Page views on public artist pages are counted from a salted, one-way hash of IP address and browser, rotated daily. We do not store the IP address, we set no cookie for it, and the hash cannot be reversed or matched to the same person the next day.

Who else sees it

Only the processors we need to run the service: application hosting, database hosting, file storage for images, email delivery, and SMS delivery for the appointment reminder a client has opted into. They act on our instructions and are bound by contract, and none of them gets your data for their own purposes.

Where any of them processes data outside the UK, it is under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or under UK adequacy regulations. Artists and studios can ask us for the current list of named sub-processors at any time.

We do not sell personal data, we do not share it with advertisers, and we run no advertising or third-party analytics scripts. We do not make any decision about you by automated means that has a legal or similarly significant effect, and we do not profile you.

How long we keep it

  • Account, profile and messages: while your account is open.
  • Notification delivery records: 90 days.
  • Page-view hashes: rotated daily, and never reversible to a person.
  • Audit log: kept as a security record and not deleted on request, so there is an honest account of who accessed what.
  • Bookings after account closure: kept as anonymised records, because they are an artist's own business records.

Closing your account anonymises your personal details. Your artist may keep their own records of your booking under their own retention rules, and their insurer or local authority may require them to.

Your rights

You can access, correct, export, restrict or object to our use of your data, and ask us to delete it. Export and deletion are self-serve from your account settings. The export is a JSON file of everything we hold about you.

Email privacy@flash.tattoo for anything else. If you are unhappy with how we have handled it you can complain to the Information Commissioner's Office at ico.org.uk.

Cookies

Short version: one cookie to keep you signed in, and one optional preference remembered on your device. The detail is in our Cookie Policy.

Flash is a trading name of CRTYX HOLDINGS LIMITED, a company registered in England and Wales under company number 12383952.

Terms · Privacy · Cookies · Refunds · DPA

Privacy - booked in a flash