Privacy Policy
Last updated: 11.09.2026
We take the protection of your data seriously. This Privacy Policy explains what personal data we collect when you use Taddoo, how we process it and what rights you have. Switzerland is our primary jurisdiction; the Swiss Federal Act on Data Protection (revFADP / revDSG, in force since 1 September 2023) applies. For users located in the European Union, the General Data Protection Regulation (GDPR) also applies and we comply with both regimes in parallel.
This Privacy Policy covers the Taddoo web application as well as our iOS app Tattoomii Artist (available on the Apple App Store). Both are operated by Tattoomii GmbH and process your data as described below. The same controller, processors, and rights apply across web and app.
1. Controller
Tattoomii GmbH, Badenerstrasse 541, 8048 Zurich, Switzerland.
Contact: Noa Walser, hello@taddoo.com
We have not appointed a representative in the EU under Art. 27 GDPR because the threshold for mandatory appointment is not met. EU residents can reach us directly at the email above.
2. Roles: who is responsible for what
Studios use Taddoo to organise communication with their own customers. For the data of those customers the studio is the controller and we process it as a processor on the studio's instructions. For the data of the studios and their staff themselves, meaning account, billing, usage and security data, we are the controller. Requests from end customers about their data are forwarded to the studio responsible, which answers them.
3. What data we process
- Account data: name, email, studio name, password hash, multi-factor secret, locale and theme preferences.
- Email content: through the Gmail OAuth connection, incoming and outgoing customer emails are read, stored encrypted in our database and used to generate reply drafts.
- Attachments and images: tattoo references are stored in access-controlled storage and delivered only through short-lived, individual links.
- Customer data of your studio: name, email, phone, tags, notes, appointment history, free-text notes you enter for that customer.
- Usage data: technical logs (IP, browser, timestamp) to ensure operation, debug issues, and detect abuse.
- Consent records: timestamp and version of the Terms and Privacy Policy you accepted, used as evidence of consent.
- Waitlist data: email address, locale and browser user agent when signing up to the waitlist.
- Billing data: name, billing address, tax details, plan, payment status and the last digits of the payment method. We never see full card details.
- Payment records of your studio: amount, currency, status, time, the link to the inquiry and appointment, and a reference to the payment transaction at the payment provider.
- Push data: device token, device platform and your notification settings, used only to deliver notifications you have switched on.
- Campaign data: recipient address, sending and delivery status, bounces and unsubscribes for emails a studio sends to its own customers.
- Booking link data: the time slots selected by a customer, appointment preferences and, where a deposit is requested, the information needed for that payment.
4. Google user data and Limited Use
To connect a Gmail mailbox, Taddoo requests the Google OAuth scopes gmail.readonly (to read incoming and outgoing customer emails), gmail.send (to send the reply you have approved) and gmail.modify (to mark a message as read after a reply is sent). We request only the narrowest scopes needed for these features and no scope beyond those described in this section. Google user data obtained through these scopes is used solely to provide the user-facing features of Taddoo described in this policy: reading customer inquiries, extracting structured fields, generating reply drafts that a studio member reviews, and sending the reply that a studio member has approved.
For online consultations, Taddoo additionally requests the Google OAuth scope meetings.space.created, but only for accounts where this feature is enabled. When you create an online consultation, Taddoo uses this scope to create a Google Meet room via the Google Meet REST API on behalf of the connected Google account (the artist's Gmail account on the Solo and Agency plans, the shared studio mailbox on the Studio plan), which becomes the host of the meeting. We store only the meeting link with the appointment and include it in the appointment emails sent to the customer. This scope is limited to meeting spaces created by Taddoo; Taddoo does not access your calendar, other meetings, participants, recordings or transcripts. The meeting link is deleted together with the appointment.
Taddoo's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular: we do not use Google user data for advertising and do not sell or transfer it to third parties such as advertising platforms, data brokers, or for profiling, credit-worthiness, or lending purposes; we do not allow humans to read your Google user data except (a) with your explicit consent for specific messages, (b) where necessary for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) where the data has been aggregated and anonymised. Email content is transmitted to our AI sub-processors only to generate the draft requested, and neither we nor those providers use your Google user data to develop, train, or improve generalised AI or machine-learning models.
We transfer Google user data only in the following cases: to provide or improve the user-facing features described above (including to the hosting and AI sub-processors listed on our sub-processor page, who act strictly on our instructions); for security purposes such as investigating abuse; or to comply with applicable law. We do not transfer or sell Google user data to any third party for advertising, data brokerage, profiling, market research, or any other purpose, and we do not transfer Google user data as part of a merger, acquisition, or sale of assets. Our employees, agents, and contractors are bound to comply with these same restrictions.
5. Purpose of processing
Google user data obtained through the Gmail scopes is used only as described in the preceding section (reading customer inquiries, extracting structured fields, generating reply drafts that a studio member approves, and sending and marking those replies); it is not used for any other purpose. More generally, we process your data exclusively to deliver the Service: generating reply drafts, managing appointments, updating customer profiles, securing the platform. We do not train our own AI models on your data. We do not sell, rent, or share your data with third parties for advertising or profiling purposes.
No advertising inside the product. Neither the signed-in Taddoo web application nor the Tattoomii Artist app contains advertising SDKs or third-party tracking SDKs. We do not use an advertising identifier (such as Apple's IDFA), we do not build advertising profiles, and we do not track you across apps or websites owned by other companies in the sense of Apple's App Tracking Transparency framework. On our public marketing pages (landing pages, pricing, blog, sign-up) we use an aggregated, cookieless reach measurement provided by our hosting provider and, to measure our own advertising campaigns, the Meta Pixel and the Meta Conversions API; both are described in sections 16 and 17. The data described above is otherwise used only to operate the Service for you.
6. Legal bases
Under Swiss revDSG processing of personal data does not generally require a specific legal basis, but it must be lawful, proportionate and transparent. For EU users (GDPR) the following legal bases apply:
- Performance of contract (Art. 6(1)(b) GDPR): account, email content, appointments, drafts.
- Legitimate interest (Art. 6(1)(f) GDPR): technical logs, abuse detection, security.
- Consent (Art. 6(1)(a) GDPR): Gmail mailbox connection, waitlist enrolment. You may withdraw consent at any time.
- Legal obligation (Art. 6(1)(c) GDPR): retention of billing and tax records.
7. Payments
If you book a plan we process name, billing address, tax details, the plan selected, payment status and the last digits of the payment method. We never see full card details; these are collected and processed solely by our payment provider, which is an independent controller for that data and applies its own privacy policy. The legal basis is performance of the contract, and for the retention of accounting records the statutory obligation.
If a studio collects deposits or in-person payments from its own customers through the Service, the payment runs through the studio's own account with the payment provider. We store the amount, currency, status, time, the link to the inquiry and appointment and a reference to the transaction, so that the studio can keep its books. We do not receive or hold the funds.
8. Push notifications and the app
If you switch on push notifications we store a device token, the device platform and your notification settings. Delivery runs through the push service of the respective operating system provider, to which the token and the content of the notification are transmitted. You can switch push off at any time in the app or in your device settings; we delete the token as soon as it becomes invalid or you sign out of the app. The app contains no advertising identifier and no cross-app tracking.
9. Campaign emails and booking links
Where a studio sends campaign or reminder emails to its own customers, we process the recipient address, the sending and delivery status, bounces and unsubscribes. The studio is the controller and decides on content and recipients; we provide the unsubscribe mechanism and honour unsubscribes permanently.
Through booking and payment links, customers of a studio enter data themselves, such as preferred appointments, the time slots they select and, where a deposit is requested, the details needed for that payment. We process this data exclusively on behalf of the studio. The links are time-limited and can only be opened with the individual token they contain. A separate notice for customers is available here: Privacy notice for customers
10. Processors and third parties
To operate and provide the Service we engage carefully selected service providers as processors. They act exclusively on our instructions and are contractually bound to confidentiality, security and deletion. We engage them in the following categories: hosting and delivery of the web application, database and file storage, background processing and short-lived caching, AI models for extraction and drafting, mailbox and calendar connection, payment processing, sending of system and campaign emails, and push notifications.
The complete and continuously maintained list of the sub-processors we engage, with company, purpose, processing location and the safeguard we rely on, is published on a separate page. Data processing agreements are in place with all of them. List of sub-processors | Data Processing Agreement
We do not sell personal data. For advertising purposes we share data only with Meta within the campaign measurement described in section 17. We disclose data to authorities or courts only where we are legally obliged to do so, and where legally permitted we inform the affected studio in advance.
11. International data transfers
Because we are based in Switzerland, transfers from the EU to Switzerland are transfers to a third country within the meaning of Chapter V GDPR. Switzerland benefits from an adequacy decision of the EU Commission, so no additional safeguards are required. Some of our service providers are headquartered in the United States or process data there. For those transfers we rely on the EU Standard Contractual Clauses together with the adaptations recognised by the Swiss FDPIC and, where applicable, on the recipient's certification under the EU-US Data Privacy Framework and its Swiss extension. Where possible we choose processing in the EU. The processing region and the safeguard relied on for each provider are stated in the list of sub-processors.
12. Data security
We take appropriate technical and organisational measures to protect your data against unauthorised access, loss or misuse. Data is encrypted in transit and at rest. Access tokens for connected accounts are stored with an additional layer of encryption. Email content, attachments and images are held in access-controlled systems and are delivered only through short-lived links scoped to your studio. The data of different studios is technically separated and every access is checked at studio level. Access by our team to production data is limited to what is necessary, protected by multi-factor authentication and logged. We apply rate limiting and abuse detection and review our measures continuously. No method of transmission or storage is completely secure. In the event of a personal data breach we notify the competent authority and, where required, the individuals concerned within the statutory deadlines.
13. Automated processing and AI
We use Large Language Models to extract structured fields from incoming customer emails and to draft replies. Drafts are NEVER sent automatically: a studio member reviews and approves each draft manually. No automated individual decision-making with legal effect in the sense of Art. 22 GDPR or Art. 21 revDSG takes place.
14. Retention and deletion
We retain your data for as long as your account is active. After termination you have 30 days in which to request an export; once that period has expired we delete or anonymise the personal data, subject to statutory retention obligations (e.g. ten-year retention of accounting records under Swiss CO Art. 958f).
Account and data deletion. You can request deletion of your account and the personal data associated with it at any time by emailing hello@taddoo.com from the address linked to your account. Because artist mailboxes in a studio are provisioned by the studio, an artist can also ask their studio administrator to remove their account; the studio administrator can request deletion of the studio account and all associated data the same way. After we receive a request we delete or anonymise the data within 30 days, except where a statutory retention obligation applies (see above). Deleting your account also disconnects any linked Gmail mailbox and removes stored email content, attachments, customer records, and drafts.
Guide values for individual categories: technical logs are generally kept for up to 90 days; consent records for the term of the contract and thereafter until the statutory limitation periods expire; accounting and tax records for ten years under Art. 958f of the Swiss Code of Obligations; unsubscribes from campaign emails permanently, so that we can continue to honour them. If a connected mailbox is disconnected we delete the access tokens immediately.
15. Your rights
You have the rights of access (Art. 25 revDSG / Art. 15 GDPR), rectification (Art. 32 revDSG / Art. 16 GDPR), erasure (Art. 17 GDPR), restriction (Art. 18 GDPR), data portability (Art. 28 revDSG / Art. 20 GDPR), and objection (Art. 21 GDPR). You may withdraw any consent at any time with effect for the future. Contact hello@taddoo.com.
You may lodge a complaint with the competent supervisory authority. In Switzerland this is the Federal Data Protection and Information Commissioner (FDPIC, www.edoeb.admin.ch). EU residents may also complain to the supervisory authority of their habitual residence.
16. Cookies and reach measurement
Inside the signed-in application we use strictly necessary cookies only (signed-in session, language and theme preference, filter selection). For reach measurement on our public pages we use an aggregated, cookieless measurement provided by our hosting provider: it stores no information on your device and reads none from it, builds no cross-site profiles and passes no data to advertising platforms. In addition, on our public marketing pages the following cookies are set for the campaign measurement described in section 17: _fbp and _fbc (set by the Meta Pixel, 90 days) and td_attr (set by us, 90 days; it stores the campaign parameters of the link you arrived through, such as utm_source and the Meta click identifier fbclid). Beyond the sign-up itself these cookies are not used inside the signed-in application. The Tattoomii Artist app contains no analytics or advertising SDKs.
17. Meta Pixel and Conversions API (campaign measurement)
We advertise Taddoo on Facebook and Instagram. To understand which of our ads lead to a sign-up, we use the Meta Pixel and the Meta Conversions API of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland ('Meta') on our public marketing pages only (not inside the signed-in application and not in the app). This is what happens: the Meta Pixel, a small script from Meta, records that a page was viewed and sets the cookies _fbp and _fbc described in section 16. Independently of the browser, our server reports three events to Meta: 'Lead' when an account is created, 'StartTrial' when the free trial starts, and 'Subscribe' with the subscription amount when a paid subscription begins. Together with these events we transmit your e-mail address and your account ID exclusively in hashed form (SHA-256), plus your IP address, your browser user agent and the values of the _fbp and _fbc cookies, so that Meta can match the event to the ad click. We do not transmit names, phone numbers, addresses, health data, customer data of studios or any content from your account.
Purpose and legal basis: measuring and optimising our own advertising campaigns (Art. 31 revDSG, legitimate interest; for visitors in the EU, Art. 6(1)(a) GDPR consent where local law requires it for the cookies concerned, otherwise Art. 6(1)(f) GDPR). We do not use the data for advertising profiles across other websites. Meta processes the data as an independent controller for its own purposes and, for the measurement itself, jointly with us under Meta's Controller Addendum; Meta may transfer data to the USA on the basis of the EU-US Data Privacy Framework (including the Swiss extension) and the EU standard contractual clauses. Details on Meta's processing: https://www.facebook.com/privacy/policy. In our own database we store, per account, the campaign parameters of the link you arrived through (for example utm_campaign and fbclid), your IP address and user agent at sign-up and the time the events were sent; this data is deleted together with the account.
Your choices: you can block the Meta Pixel with a content blocker or by disabling third-party cookies in your browser, delete the cookies _fbp, _fbc and td_attr at any time, and manage how Meta uses data from other websites in your Facebook or Instagram settings ('Your activity off Meta technologies'). The server-side events are tied to your account; you can object to this processing at any time by e-mail to hello@taddoo.com.
18. Children and minors
Taddoo is a business tool for tattoo studios and is not directed at children. We do not knowingly collect personal data directly from children. Where a studio enters data about its own end customers, that studio acts as the controller for its customer relationship and is responsible for any applicable age requirements. If you believe a child has provided us personal data directly, contact hello@taddoo.com and we will delete it.
19. Changes to this policy
We may update this Privacy Policy. The current version is available on this page; the version identifier is shown under 'Last updated'. We will notify you by email of any material changes.
20. Governing law
This Privacy Policy is governed by Swiss law. Mandatory data protection rights granted by the law of your habitual residence remain unaffected. The English version of this Policy prevails in case of any discrepancy with translations.