Privacy policy

Last updated 31 July 2026

This explains what personal data Runavel handles, why, who else touches it, how long it is kept and what you can ask us to do about it.

Two different roles, and why it matters

Runavel handles personal data in two distinct capacities, and your rights differ depending on which one applies:

  • For studios that subscribe - the account holder's name, email and billing details - Elixon LTD is the controller. This policy describes what we do with it.
  • For a studio's own clients - the people who book tattoos, sign consent forms and pay deposits - the studio is the controller and we are its processor. We hold that data on the studio's instructions, and we do not decide what it is used for. If you are a client of a studio and want your data corrected or erased, ask the studio; they can do it inside Runavel, and we will help them if they ask.

What we hold

  • Account: name, email address, password (hashed, never readable), two-factor secrets, and a log of actions taken in the account.
  • Studio: business name, addresses, opening hours, artist profiles and the photographs you publish.
  • Clients (entered by the studio): name, contact details, appointment history, notes, reference images, and signed consent forms - which may include health information such as allergies, medication or pregnancy, and which the studio collects for its own legal and safety reasons.
  • Payments: subscription status, invoices and deposit records. Card details are handled by Stripe and never reach us.
  • Technical: server logs, and error reports when something breaks. Error reports deliberately exclude request bodies, so form contents are never sent.

Why we hold it

  • Performing our contract with the studio - running the service it pays for.
  • Legal obligation - keeping payment and tax records, and retaining signed consents.
  • Legitimate interests - keeping the service secure, diagnosing faults, and understanding at a coarse level how the public pages are used.

Where a studio relies on consent from its own clients - for example to use a photo of their tattoo for marketing - that consent is recorded per use and can be withdrawn.

Who else processes it

We use a small number of processors, each for one job:

  • Fly.io - hosting and databases. Runavel runs in London.
  • Cloudflare R2 - file storage for photographs and consent documents, in the European jurisdiction.
  • Stripe - subscription payments and invoices.
  • Resend - sending email, such as confirmations and notifications.
  • Error monitoring - a service we host ourselves, so crash reports do not leave our infrastructure.
  • Umami - cookieless visitor statistics on public pages only.

We do not sell personal data, we do not share it for advertising, and we do not use it to train machine-learning models.

Cookies

Runavel sets a session cookie so you stay logged in, and a cookie remembering whether you chose the light or dark theme. That is all - both are strictly necessary for the site to work as you asked it to.

The visitor statistics on our public pages are cookieless and do not identify anyone, which is why you are not shown a cookie banner. Analytics are never loaded inside the application or on a studio's private screens.

How long we keep it

  • Account data: while the account exists, and a short period afterwards.
  • Signed consent documents: 5 years from signature, which is the retention period configured for the document vault.
  • Payment records: as long as tax and accounting law requires.

When a studio erases a client, we anonymise that person's details in place rather than deleting the records wholesale, and reference photographs are removed. Payment records and signed consents survive, because we are required to keep them and because they are evidence of what was agreed. Erasing them would put the studio at risk, not protect the client.

Security

Traffic is encrypted in transit. Signed consent documents are encrypted at rest, and passwords are stored hashed and are never recoverable. Two-factor authentication is available on every account and required for our own staff. Access between studios is isolated: every read and write is scoped to one account.

Our support staff can, in defined circumstances, view an account in order to help - read-only by default, time-limited, shown to you by a banner while it is happening, and recorded in an audit log we keep.

Your rights

You can ask us for a copy of your data, ask us to correct it, ask us to delete it, object to how we use it, or ask for it in a portable form. Write to support@runavel.com and we will respond within one month.

If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk. We would rather you raised it with us first.

Contact

Elixon LTD, 51 Roundmead, Bedford, United Kingdom, MK41 9HY. Privacy enquiries: support@runavel.com.