NOGHOST

Privacy Policy

Last updated: 14 July 2026

NoGhost is a booking, deposit, and consent-waiver platform for tattoo shops, operated by TRYNOGHOST LTD, a company registered in England and Wales (company number 17326678), registered office: 7 Longleat Drive, DY1 2TX, England ("we", "us").

This policy explains what personal information passes through NoGhost, why, and your rights over it. It covers two groups of people: shop owners and artists who subscribe to NoGhost, and clientswho book appointments through a shop's booking page. It applies whether you are in the United Kingdom, the United States, or elsewhere — see sections 8 and 9 for the rights that apply to you.

1. If you book a tattoo through a NoGhost page

The shop you are booking with decides how your information is used — you are their client. NoGhost processes it on their behalf to run the booking. (In legal terms: the shop is the "controller" / "business"; NoGhost is their "processor" / "service provider".)

When you book, we collect:

  • Identifiers and contact details — your name, email address, phone number, and date of birth (to confirm you are 18 or over).
  • Booking details — the tattoo you describe, its placement, your budget estimate, and any reference photos you choose to attach.
  • Payment information — your deposit is processed by Stripe. Your card details go directly to Stripeand never touch NoGhost's systems; we only see that a deposit was paid or refunded, and its amount.
  • Waiver and health information — when you sign the consent waiver we record your typed signature, the date and time, and your IP address, together with the exact waiver text you agreed to.

2. Health information in the waiver (sensitive data)

The waiver you sign includes confirmations about your health. This is special category data under UK and EU law, and sensitive personal information under US state privacy laws. It is processed only with your explicit consent, given when you sign, and only to create the consent record that protects both you and the shop. A PDF copy is emailed to you and kept on file for the shop.

We do not use your health information for any purpose other than creating and providing that consent record. We never sell it, never use it for advertising, and never share it beyond the shop you booked with and the infrastructure providers listed in section 5.

3. If you run a shop on NoGhost

We collect your name, email, password (stored only in securely hashed form), shop details, and subscription billing information (held by Stripe). We use this to provide the service, bill your subscription, and send you service emails such as new booking-request notifications. For this information we are the controller / business, and our legal basis is performing our contract with you.

4. How we use information

We use the information above only to:

  • hold and confirm bookings, and let the artist approve or decline a request;
  • take deposits, and issue refunds where a request is declined or cancelled;
  • provide signed waivers to you and your shop, and store them as consent records;
  • send booking-related emails (request received, confirmation, reminders, decline-and-refund notices, hold-expiry notices);
  • run, secure, and support the service, and bill shop subscriptions.

We do not send you marketing, we do not use your information for advertising, and we do not sell or share your personal information (including as "sell" and "share" are defined under California law). We have not sold or shared personal information in the past 12 months.

5. Who helps us run the service

NoGhost runs on trusted infrastructure providers, who process data only to provide their service to us: Supabase (database, login, and secure file storage), Stripe (all payments), Resend (email delivery), Vercel (website hosting), cron-job.org (scheduled reminders), and Twilio (text messages, only where a shop has enabled SMS).

6. Where information is stored, and transfers

We are a UK company, and some of our providers process data in the United States and elsewhere. Where information is transferred out of the UK or EU, it relies on recognised safeguards such as the UK extension to the EU-US Data Privacy Framework or standard contractual clauses. If you are in the United States, your information may be processed in the UK as well as the US.

7. How long we keep things

Booking and appointment records are kept while the shop uses NoGhost, so it has an accurate history. Signed waivers are legal consent records and are kept for as long as the shop reasonably needs them for legal protection (typically several years, in line with limitation periods for personal-injury claims). Reference photos are kept with the booking they belong to. Expired or declined booking requests are cancelled automatically, the deposit refunded, and only basic booking details retained. If a shop leaves NoGhost, its data is deleted or returned as described in our Terms, with waiver records handled as above.

8. Your rights — UK and EU (UK/EU GDPR)

You can ask for a copy of your information, ask us to correct or delete it, object to or restrict processing, withdraw consent, and ask for your information in a portable format. If you are a client of a shop, the quickest route is usually the shop itself (the controller), but you can also contact us directly and we will help. You can also complain to the UK Information Commissioner's Office (ico.org.uk) if you think something is wrong — though we'd appreciate the chance to fix it first.

9. Your rights — United States (California and other states)

If you live in California, or in another US state with a comprehensive privacy law (such as Virginia, Colorado, Connecticut, Utah, Texas, or Oregon), you have the following rights, subject to that state's law:

  • Know / access — what personal information we have collected about you, the categories, the sources, why we collected it, and who we disclosed it to.
  • Delete — ask us to delete personal information we hold about you (subject to exceptions, such as signed waiver records a shop must keep for legal protection).
  • Correct — have inaccurate personal information about you fixed.
  • Portability — receive a copy in a portable, readily usable format.
  • Opt out of sale, sharing, and targeted advertising — we do not sell or share your personal information, and we do not use it for targeted advertising or profiling, so there is nothing to opt out of.
  • Limit the use of sensitive personal information — we already use the health information in your waiver only to create your consent record, which is the limited purpose permitted by law.
  • Non-discrimination — we will never give you worse service or pricing for exercising any of these rights.

To exercise any of these rights, email billypriest12@outlook.com. We will verify your request using the email address on your booking or account, and respond within the timeframe your state's law requires (generally 45 days, extendable once where permitted). You may use an authorised agent. If we deny your request you may appeal by replying to our decision, and if you remain unhappy you may contact your state attorney general.

10. Cookies

NoGhost uses only essential cookies: the login session for shop dashboards, and cookies set by Stripe during payment for security and fraud prevention. We do not use advertising or analytics cookies, so there is no cookie banner to click — there is nothing to opt out of.

11. Age limit

NoGhost's booking service is for adults — shops using NoGhost only accept bookings from people aged 18 or over, and the booking form enforces this. We do not knowingly collect information from children. Minimum-age and parental-consent rules for tattooing vary by country and by US state, and it is the shop's responsibility to verify age and identity in person.

12. Changes and contact

If we make material changes to this policy we will update the date above and, for significant changes, notify shops by email. Questions, requests, or concerns: billypriest12@outlook.com, or write to TRYNOGHOST LTD, 7 Longleat Drive, DY1 2TX, England. See also our Terms of Service.