Platform · Security and access

PROTECTED RECORDS. CLEAN exits.

Client data, signed forms, and payment records are encrypted in the cloud. Team access is controlled by role. Shared tablets are secured with per-person PINs. When someone leaves the studio, they lose access instantly. No shared passwords to rotate.

30 days free Cancel anytime Cancel any time

Your client list is more sensitive than you think.

Names, phone numbers, dates of birth, home addresses, medical disclosures, photo IDs, signed waivers. If a laptop walked out of your shop tomorrow, that is what walked out with it. Most studios do not think of their client database that way because it has always lived in a filing cabinet.

Digital changes the risk profile. The upside: encryption you do not have to think about, access controlled by role, and one switch that ends a leaver's access. The downside: a shared login on a tablet everyone uses is not a security model. This is what that should look like done properly.

What the security model gives you.

Storage

Encrypted cloud storage

Client profiles, signed forms, and payment records are encrypted at rest and in transit by the Google Cloud platform underneath. Photo IDs and signed consent PDFs are held back behind server-issued links rather than sitting on a public path.

Permissions

Roles matched to the job

Managers see everything. Artists get the Queue, Appointments, Client Profiles and the Forms Archive. Front desk Staff see the Queue and Appointments. Health Officials see the Forms Archive only. Each person signs in as themselves, so what opens up is theirs, not a shared view everyone gets.

Kiosk lock

A tablet you can leave on the counter

Locked, the app shows only your logo and three client buttons. Turn on Auto-lock and it re-locks every time anyone returns to the home screen, so the handoff back to kiosk mode is automatic rather than remembered. It is a per-device setting, so the counter tablet locks while your own phone does not.

Revocation

One switch ends their access

When someone leaves, deactivating their team profile disables the login itself, so it stops working everywhere at once rather than device by device. Their history, forms and past sales stay exactly where they are, and the seat frees up immediately for the next hire.

Sign-in log

See every device on the account

The Account Portal lists every web, iOS and Android sign-in on your account, with the device, the platform and when it was last active. It is how you spot a login that should not be there. Renaming an entry helps; removing one does not sign anyone out, so deactivate the team profile when you actually mean to cut access.

Infrastructure

Built on Google Cloud

Hosted on Firebase / Google Cloud, the same infrastructure that powers a large portion of the consumer web. Encrypted at rest, served over HTTPS, with the operational maturity of a hyperscaler underneath.

What the security model does not do.

It is not a regulatory certification. We operate to modern cloud security standards; we do not carry a specific industry badge. If your jurisdiction requires a particular certification for client records, confirm independently.

It does not replace your own operational hygiene. A strong password matters. Not writing the Manager PIN on a sticky note matters. Signing out of shared tablets matters. The software raises the floor, but the floor is still built on human habits.

It does not log every read. Sign-ins are logged with device and last activity, but there is no record of who opened which client file or pulled which form. If you need that depth of access auditing, we are not there yet.

It is not a HIPAA platform. Tattoo intake is not clinical medical care. Health questions are captured to keep artists safe, not to function as a HIPAA-governed medical record.

Defaults that matter

Security built in.

0
Shared passwords
Every team member, their own login
4
Roles
Manager, Artist, Staff, Health Official
1
Switch to cut access
Deactivate the profile, the login stops
3
Sign-in methods
Email, Google, Apple, 12-character minimum

Quick answers.

How is my data protected?

Client data is encrypted at rest and in transit on Google Cloud. Access is scoped by role, so people reach the parts of the app their job needs. Sensitive files live in private storage rather than a public bucket.

What if multiple team members share a tablet?

Each person has a unique PIN for sign-in and sign-out. Only their data and permissions are active during their session. Signing out isolates the next person's session.

Can I remove a team member immediately?

Yes. A manager deactivates their team profile, which disables the login itself, so it stops working on every device at once. Their PIN stops unlocking the app and their records stay intact.

What can health officials actually see?

Forms Archive only. No client profiles, no appointments, no reports, no business data. The role is scoped to compliance review and nothing else.

Where is the data hosted?

On Firebase/Google Cloud infrastructure, which is the same infrastructure that powers a large portion of the consumer web. Encrypted at rest, served over HTTPS.

Works with the rest of your studio.

30 days free · cancel anytime

Try Tattoo Studio Pro free for 30 days.

Every feature, every plan. Your client data, protected and controlled the way it should be. Plans start at $29/month.

Cancel anytime

See how it works

Book a 20 min demo