Draft. Effective on publication.

Sittings Privacy Policy (DRAFT v2 — round-1 gate revision 2026-08-06; NOT yet signed off)

Effective date: [ON SIGN-OFF]. Operator: Chapman Cox dba Sittings, [POSTAL ADDRESS — CHAPMAN FILLS; CAN-SPAM/CASL blocker until filled]. Privacy contact (all requests, questions, complaints, and appeals): chapman@getsittings.com — answered by Chapman, who is also the accountable privacy officer.

The short version

We collect the minimum we need, we never sell any data, we treat health information with strict controls we describe precisely below, and you can exercise your rights by emailing us directly. Sittings is a solo-operated business: the person who built the system answers the privacy mail.

Two hats, said plainly

Who and what this covers

  1. Visitors and applicants (getsittings.com): pilot applications — name, studio/Instagram handle, city, weekly inquiry volume, your description of your inbox, email address; plus campaign parameters (utm fields) and PostHog analytics (below).
  2. Artists (sittings.ink app): account email, studio settings, pricing criteria, reference images, drafts, roles, and audit events tied to your account actions.
  3. Clients of artists: inquiry contents — contact details, the tattoo request, budget, placement, reference images; the raw email (full body, headers, and attachments) when an artist forwards inquiries; appointment and deposit records; where health questions are enabled (see below), your consent evidence including IP address and browser user-agent.
  4. Prospective artists we contact (when our outreach program is active): name, studio, city, and the business email you have published publicly, with a record of where and when we found it (consent provenance), verification-check results, and a permanent record if you opt out (suppression list). Sources: public business listings and your own public pages.
  5. Operational records: abuse-protection logs (IP, artist-page slug, timestamp), email delivery status and provider message IDs, sanitized payment-webhook records, and security audit events.

Health information — the exact truth

Tattoo inquiries can brush against health topics. Here is precisely what our system does and does not do:

Washington Consumer Health Data — standalone notice

Washington's My Health My Data Act asks for its notice to stand alone, so it lives on its own page: Consumer Health Data Privacy Policy — linked prominently from our homepage and from every surface where health questions can be asked. The summary below repeats its substance; the standalone page governs.

AI processing, disclosed exactly

Two distinct uses of Anthropic's Claude models: parsing sends up to the first 20,000 characters of a message's raw text plus sender/subject envelope data, to extract the inquiry's facts — so incidental health content in a message DOES transit Anthropic at this step; drafting sends selected structured inquiry facts (not the raw body) to compose the artist's reply.

[NO-TRAINING CLAIM WITHHELD pending the vendor-terms verification pass — CHAPMAN GATE: once Anthropic's executed terms are verified, this section states the verified commitment and terms version; until then the policy makes no training claim.]

Processors — current vs planned

ProviderStatusData it receivesPurpose
Supabaseliveall application/app datadatabase + storage
Vercelliverequest traffichosting
Anthropicliveinquiry textAI parsing + drafting
PostHogliveusage events + network/device metadataproduct analytics
Google Workspaceliveemail to/from our mailboxour mailbox
Postmarkplanned (activation pending)transactional email content + delivery metadatasending/receiving product email
Stripeplanned (deposits)card details are entered with and held by Stripe — we never see full card numbers; we DO store payment metadata: amounts, currency, status, Stripe session/payment-intent identifiers, timestamps, policy snapshots, and webhook payloads (sanitized when the related inquiry is deleted)client deposits
Outreach tooling (e.g. a sequencer + list-verification vendor)plannedprospective-artist business contact data onlyour own outreach; never client or health data

Access is limited by purpose and by contract; our vendor-terms review (retention, training, access location for each provider) is in progress, and this table states only what we have verified. Updated when a planned provider goes live.

Analytics, honestly

PostHog receives page/event data plus ordinary network and device metadata (IP-derived location, browser). An application generates a pseudonymous identifier (an internal application ID) — while your application exists, we could link those events to it; deleting your application removes the primary link, though residual correlation may persist in backups and operational logs until their disclosed retention periods expire. We do not put your name, email, or answers in analytics events.

Deletion and your other rights — separate procedures, stated separately

Retention — concrete

Email rules we hold ourselves to

Canada — cross-border and accountability

We operate from the United States: Canadian artists' and clients' data is processed and stored in the US and may be subject to lawful access under US law. Chapman is the accountable privacy contact; you may request access or correction, complain to us first, and escalate to the Office of the Privacy Commissioner of Canada (or your provincial regulator) if unsatisfied.

Minors

Sittings is intended for adults. The application form requires an 18+ attestation; inquiry intake is the artist's client relationship and we do not verify client ages. If we learn an inquiry or application came from a minor, we delete it and tell the artist to do the same. Parents/guardians: email us and we will delete a minor's data on verification.

Purposes, mapped

Screening pilot applications (application data) · authenticating artists (account data) · parsing and drafting inquiry replies (inquiry text, via Anthropic) · scheduling and deposits (appointment + payment records, via Stripe when live) · sending and receiving product email (delivery records) · keeping the service safe (abuse logs, audit events) · understanding product usage (pseudonymous analytics) · our own outreach (published business contacts, with provenance and suppression) · meeting legal obligations (consent evidence, financial records, deletion records).

Changes

Material changes get a dated note here and, for artists, advance email. Where the law requires it — including any expansion of health-data collection, use, or sharing — we ask for fresh, specific, affirmative consent BEFORE the change applies to you; an updated page is never treated as consent for that.


Consumer health privacy (WA) · Back to the site