This is placeholder wording, not final legal copy. It will be replaced with a lawyer-reviewed version before real launch.
From artists, at signup and while using bink:
From clients, during a booking:
Data collected is used only to operate the booking, deposit, and consent flow: confirming bookings, processing deposits via Stripe, generating and storing signed consent records, and sending booking-related SMS/email notifications (confirmations, receipts, reminders).
Medical/health disclosures collected during consent are sensitive information. They are stored as part of the signed consent record, visible only to the artist for the relevant booking, and are not used for any purpose beyond that booking's health and safety requirements.
Data is stored with Supabase (hosted in Australia). Signatures, consent PDFs, and reference images are kept in a private storage bucket, never publicly accessible. Every table enforces row-level security so an artist can only ever access their own bookings and consents.
Signed consent records are retained to meet skin-penetration record-keeping requirements under applicable state health regulations. Retention periods will be finalised as part of the legal review of this policy.
We share data with the following processors, only as needed to operate bink:
We do not sell client or artist data to third parties.
You can request access to, correction of, or deletion of your data by contacting us. Some data (e.g. signed consent records) may need to be retained for the legal record-keeping period noted above, even after a deletion request.
Questions about this policy can be sent to hello@bink-au.com.