Legal
Privacy Policy
Last updated: April 2026
Calibre (“we”, “us”, “our”) operates a body art studio management platform serving studios and clients across Australia. We take your privacy seriously and are committed to handling personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This policy explains what information we collect, why we collect it, how we use and protect it, and what rights you have over your data.
1. Information We Collect
Personal Information
When you register or book an appointment, we collect your full name, date of birth (required for age verification — you must be 18+ for tattoo and some piercing services), email address, phone number, and mailing address where relevant.
Booking & Consent Data
All bookings generate a digital consent record that includes the procedure type, date, attending artist, studio location, and your signed acknowledgement of risks and aftercare obligations under the NSW Tattoo Industry Regulation 2023. These records are retained for a minimum of three years as required by law.
Photos & Procedure Imagery
Studios may upload healed-work photography for portfolio purposes. If your image is included, the studio is responsible for obtaining your separate consent as required under applicable privacy and media laws. We do not process or analyse these images automatically.
Biometric Data — AR Jewellery Try-On
Our AR try-on feature uses your device camera to render jewellery overlays in real time. All image processing happens entirely on-device using your browser’s native WebGL and MediaDevices APIs. We do not transmit, store, or analyse facial geometry or biometric identifiers. Camera access is only active while you have the AR feature open.
2. How We Use Your Information
Service delivery — Processing bookings, generating digital consent forms, sending appointment reminders, and facilitating communication between you and your studio.
Booking management — Enabling studios to manage their schedules, maintain artist rosters, and fulfil their statutory record-keeping obligations.
Personalised recommendations — Our self-hosted AI analyses your booking and browsing history to suggest artists, services, and jewellery styles that match your preferences. This processing occurs entirely within our infrastructure — see Section 5.
Analytics & improvement — Aggregated, de-identified usage data helps us improve the platform. We do not sell individual-level data to third parties for advertising.
Financial records — Calibre Ledger records transactions against studios for accounting and tax compliance purposes. Client payment data flows through Stripe and is not stored on our servers in raw form.
3. Data Storage & Security
Your data is stored in Supabase hosted on AWS infrastructure in the ap-southeast-2 (Sydney) region, maintaining Australian data sovereignty. All data is encrypted at rest using AES-256 and in transit via TLS 1.3.
Access to your personal data is restricted to authorised platform personnel and the studio(s) you have booked with. We employ row-level security policies at the database level to enforce these boundaries.
Consent records are subject to an immutable append-only audit log. Once signed, a consent form cannot be altered — only superseded by a new version with fresh acknowledgement.
4. Self-Hosted Intelligence
Calibre’s AI features — client tagging, tattoo matching, sentiment analysis, and personalised recommendations — run on Ollama (Qwen 3.5) deployed within our own infrastructure.
Your data is never sent to OpenAI, Google, Anthropic, or any other third-party AI provider. All inference happens on servers we operate and control. Model outputs are used only to improve your in-platform experience and are not used to train external models.
5. Third-Party Integrations
Stripe
Handles payment processing. Your card details are tokenised by Stripe and never touch our servers. Stripe's privacy policy governs their handling of payment data.
MYOB / QuickBooks
Studio operators may connect their accounting software. We share only the transaction data necessary to reconcile bookings — no personal client information beyond invoice metadata.
Vercel
Our web hosting provider. Request logs may be retained by Vercel for up to 30 days for security and debugging purposes.
6. Cookies & Local Storage
We use a minimal set of cookies and browser storage:
Keeps you authenticated between page loads. Expires when you sign out or after 7 days of inactivity.
Protects form submissions against cross-site request forgery. Session-scoped.
Stores your saved jewellery items locally in your browser. Never transmitted to our servers unless you choose to sync.
Remembers your preferred try-on settings (lighting, scale) for convenience.
We do not use advertising cookies or third-party tracking pixels.
7. Your Rights
Under the Australian Privacy Act 1988 and the Australian Privacy Principles, you have the following rights:
Access
Request a copy of the personal information we hold about you.
Correction
Ask us to correct inaccurate or out-of-date information.
Deletion
Request erasure of your account and associated data, subject to our statutory retention obligations (3-year consent records).
Complaint
Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au if you believe we have breached the APPs.
To exercise any of these rights, contact us at privacy@calibre.studio. We will respond within 30 days.
8. Contact Us
If you have any questions about this Privacy Policy or how we handle your personal information, please get in touch:
Email: privacy@calibre.studio
Post: Privacy Officer, Calibre, Sydney NSW, Australia