Tatbook

Privacy Policy

Last updated: 2026-04-22

1. Who We Are

Tatbook is operated by Nation Network LLC, a Utah limited liability company ("Nation Network LLC", "we", "us", "our"). This Privacy Policy explains what personal information we collect, how we use it, and the rights you have with respect to that information.

Nation Network LLC is the data controller of personal information submitted by shop owners and their staff when they register and use the Service. For personal information submitted by customers of a shop that uses the Service (for example, a customer who books an appointment at a shop that uses Tatbook), Nation Network LLC acts as a data processor on behalf of that shop; the shop is the controller of its customers' personal information.

2. Information We Collect

Shop users: name, email address, hashed password, two-factor-authentication secret, shop name, shop hours, tax and payout information provided to Stripe during Stripe Connect onboarding, and profile content (biography, portfolio images, flash designs) that you choose to submit.

Shop customers: name, phone number (encrypted at rest, and hashed separately for lookup), optional email address, appointment details, service selections, consent-to-contact preferences, and any reference images or notes the customer submits during booking. Customers do not create accounts on the Service; identity is managed by per-booking manage tokens delivered by SMS.

Automated collection: server logs, IP address, device and browser information, and usage telemetry necessary to operate and secure the Service.

3. How We Use Information

  • to provide, maintain, and improve the Service;
  • to process subscription billing and customer deposits via Stripe;
  • to send transactional SMS messages (appointment confirmations, reminders, cancellations);
  • to send transactional email (invitations, receipts, trial reminders);
  • to deliver push notifications via Firebase Cloud Messaging when enabled;
  • to provide customer support and respond to inquiries;
  • to detect, investigate, and prevent fraud and abuse;
  • to comply with legal obligations.

4. Legal Bases for Processing

Where the General Data Protection Regulation ("GDPR") or the United Kingdom GDPR applies, we rely on the following legal bases:

  • Performance of a contract: to provide the Service you have asked us to provide;
  • Legitimate interests: to operate and secure the Service, to improve it, and to communicate with you about your use of it;
  • Consent: where you have given us consent, for example for marketing communications or for optional features;
  • Legal obligation: to comply with laws that apply to us.

5. How We Share Information

We share personal information only as described below. We do not sell personal information.

Service providers we rely on:

  • Stripe, Inc.: payment processing (subscriptions and Stripe Connect deposits). When you create a Shop, we automatically register a Stripe Express Connect account in your name, sharing your email address and Shop name with Stripe. You complete identity and bank verification with Stripe directly from the Payment Processor settings page. See Stripe's Privacy Policy.
  • SMS delivery provider: outbound text-message delivery on our behalf.
  • Email delivery provider: outbound and inbound email delivery on our behalf.
  • Google LLC (Firebase Cloud Messaging): push notifications to opted-in users.
  • Google Calendar: optional, per-shop, via OAuth. We access only the calendars you explicitly authorize.
  • Cloud storage provider: object storage for portfolio images, flash designs, and customer-submitted reference images (United States).
  • Cloud hosting provider: application and database hosting (United States).

Other disclosures: we may disclose personal information when required by law, legal process, or a valid governmental request; to enforce these terms or protect the rights, property, or safety of Nation Network LLC, our users, or the public; or in connection with a merger, acquisition, financing, reorganization, or sale of assets (with appropriate confidentiality protections).

6. International Data Transfers

The Service is operated from the United States and personal information is stored and processed in the United States. If you access the Service from outside the United States, you understand that your information will be transferred to, stored, and processed in the United States. Where we transfer personal information from the European Economic Area, the United Kingdom, or Switzerland to the United States, we rely on the Standard Contractual Clauses approved by the European Commission, on our service providers' participation in the EU-US Data Privacy Framework (including Stripe's), or on another transfer mechanism permitted by applicable law.

7. Google User Data (Google Calendar Integration)

Artists may optionally connect a Google Calendar to their Tatbook account via Google OAuth. This section describes exactly how we handle Google user data obtained through that integration.

What we access. With your explicit consent we request two Google OAuth scopes: read-only access to the list of calendars on your Google account (calendar.calendarlist.readonly), used solely so you can choose which calendar Tatbook syncs to; and access to view and edit calendar events (calendar.events), used solely on the calendar you select. We do not access your email, contacts, files, or any other Google data.

How we use it. Google Calendar data is used exclusively to provide the user-facing calendar sync feature: we create, update, and remove events on your selected calendar that mirror your Tatbook appointments, and we read event details only as needed to maintain those synced events. We do not use Google user data for advertising, and we do not use it to develop, improve, or train artificial-intelligence or machine-learning models.

What we share. We do not sell, rent, or transfer Google user data to any third party. It is processed only on our hosting infrastructure in the United States as necessary to provide the sync feature. Tatbook's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How we protect it. Google OAuth tokens are encrypted at rest and are scoped to the individual artist account that authorized them. All traffic between Tatbook and Google is encrypted with TLS.

Retention and deletion. We retain your Google OAuth token only while the integration is connected. Disconnecting Google Calendar in Tatbook (Settings → Google Calendar) immediately revokes the token with Google and deletes it from our systems, along with your calendar selection; deleting your account does the same. You can also revoke Tatbook's access at any time from your Google account security settings. Events previously created on your calendar remain yours and are not deleted when you disconnect.

8. Data Retention

We retain shop account data and the personal information within it for as long as the shop's subscription is active. After cancellation, data is retained for up to ninety (90) days to allow for export and recovery, and is then deleted in the ordinary course of business, except where a longer retention period is required by law or for legitimate business purposes such as financial recordkeeping, fraud prevention, or the defense of legal claims. Anonymized or aggregated data may be retained indefinitely.

9. Security

We use administrative, technical, and physical safeguards designed to protect personal information against loss, theft, misuse, and unauthorized access, disclosure, alteration, and destruction. Customer phone numbers are encrypted at rest and looked up via a separate SHA-256 hash column; we do not store plaintext phone numbers in queryable columns. All traffic between your browser and the Service is encrypted with TLS. Shop data is isolated at the application layer by a global Eloquent scope keyed on the shop identifier. No method of transmission or storage is perfectly secure; we cannot guarantee absolute security.

10. Your Rights

Depending on the law that applies to you, you may have some or all of the following rights with respect to your personal information:

  • the right to know what personal information we hold about you and to access a copy of it;
  • the right to correct inaccurate personal information;
  • the right to request deletion of your personal information;
  • the right to restrict or object to certain processing;
  • the right to data portability (to receive your personal information in a structured, commonly used, machine-readable format);
  • the right to withdraw consent where processing is based on consent;
  • the right to lodge a complaint with a supervisory authority (for residents of the European Economic Area or the United Kingdom).

To exercise any of these rights, contact us at support@tatbook.app. We will respond within the timeframe required by the law that applies to your request. You may designate an authorized agent to submit a request on your behalf; we may require verification of the agent's authority and of your identity.

11. California Residents (CCPA and CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA"), provides you with additional rights. This section describes those rights and supplements the information above.

Categories of personal information we have collected in the previous twelve (12) months:

  • identifiers (name, email address, phone number, IP address, account identifiers);
  • commercial information (subscription records, transaction history);
  • internet or other network activity information (server logs, browser and device information, usage telemetry);
  • geolocation information (coarse location derived from IP address);
  • professional information (for shop users: shop name and role);
  • inferences drawn from the above to operate and improve the Service.

Categories of sources: directly from you, automatically from your device and browser, and from our service providers (such as Stripe and our SMS and email delivery providers).

Business and commercial purposes for collection: to provide, operate, and secure the Service; to process payments; to send transactional communications; to provide support; to detect and prevent fraud; to comply with law.

Categories of third parties with whom we share personal information: the service providers listed in Section 5, each bound to contractual confidentiality and use-limitation obligations.

We do not sell personal information and we do not share personal information for cross-context behavioral advertising. We have not done so in the previous twelve (12) months.

California residents have the right to know, delete, correct, opt out of sale or sharing, limit the use of sensitive personal information, and be free from retaliation for exercising these rights. To exercise any of these rights, email support@tatbook.app. We will verify your request by asking you to confirm information already associated with your account.

12. Other United States State Privacy Laws

If you are a resident of Virginia, Colorado, Connecticut, Utah, Oregon, Texas, or any other United States state with a comprehensive privacy law, you may have rights under that state's law similar to those described in Section 9. To exercise those rights, email support@tatbook.app. We will respond within the timeframe required by the law that applies to you. You may appeal a denial of a request by replying to our response; we will review and respond to the appeal within the applicable statutory period.

13. Cookies and Similar Technologies

The Service uses strictly-necessary cookies for session management, security (CSRF tokens), and authentication. Stripe's JavaScript libraries may set additional cookies necessary to process payments; see Stripe's Privacy Policy for details. We do not use advertising cookies or third-party analytics cookies for behavioral tracking. Your browser settings let you block or delete cookies; disabling strictly-necessary cookies will prevent the Service from functioning.

14. SMS Consent

The Service sends transactional SMS messages (appointment confirmations, reminders, cancellations, and other messages necessary to provide the Service) to the phone numbers that shops and customers provide. These messages are necessary to deliver the Service for which the customer booked. Customers may opt in to non-transactional marketing SMS during booking or through the manage-booking link.

Mobile opt-in and SMS consent data is never shared with or sold to third parties or affiliates for marketing or promotional purposes.

All Service SMS is outbound-only from a single registered toll-free number. You can stop receiving messages at any time by replying STOP. Reply HELP for help. Message and data rates may apply. Message frequency varies.

15. Children's Privacy

The Service is intended for adults who are at least 18 years of age. The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided personal information to the Service, please contact us at support@tatbook.app and we will delete that information.

16. Data Breach Notification

If we become aware of a security incident affecting personal information, we will investigate and will notify affected users and applicable regulators as required by law. Where the law requires notice within a specific timeframe (for example, within 72 hours under the GDPR), we will meet that requirement. Notice will be provided by email to the address on file and, where appropriate, through the Service.

17. Contact

Questions about this Privacy Policy, or requests regarding your personal information, should be directed to support@tatbook.app. See also our Terms of Service.

© 2026 Nation Network LLC. All rights reserved.  ·  Terms of Service  ·  Privacy Policy