Legal
Privacy Policy
This policy describes what information we collect through hermitstab.com and our connected business tools, how it is stored, and your rights regarding that information.
Last updated: March 22, 2026
Who We Are
Hermit Stab is the tattoo practice of Katie Haus, operating out of Firefly Tattoo LLC at 502 W 4th St Suite 8, Bloomington, IN 47404. This website is maintained by a sole developer on Katie's behalf.
Information We Collect
We collect information that you voluntarily provide through our website forms:
Contact Form
- Name, email address, phone number, and Instagram handle
- Preferred contact method
- Tattoo inquiry details (description, size, placement, cover-up information)
- Availability preferences
- Reference photos and body placement photos (up to 8 images)
Booking Form
- Email address and Instagram handle (used to verify your identity)
- Selected appointment time slot
Consent Form
- Full name, pronouns, age, date of birth, phone, email, and mailing address
- Tattoo description and body location
- Health screening answers (e.g., fainting history, medications, heart conditions, allergies, skin conditions)
- A photo of your government-issued ID
- Your typed signature and date
- Whether you consent to follow-up communications
The consent form also saves your in-progress draft to your browser's session storage so you don't lose your work if you navigate away. This data stays in your browser only, is never sent to us until you submit, and is cleared when you close the tab or complete the form.
How We Use Your Information
- Contact inquiries: To review your tattoo request, communicate with you about scheduling, and manage the booking process.
- Booking data: To schedule and confirm your appointment.
- Consent form data: To fulfill legal and safety requirements for performing tattoo services, including verifying your identity and screening for health conditions that may affect the procedure.
- Government ID photo: To verify your identity and age before your appointment. This is a standard requirement for tattoo services.
- Email communications: To send you booking confirmations, consent form links, and appointment-related follow-ups. We only send emails related to services you have requested.
How We Store Your Information
Your data is stored in a PostgreSQL database on a private server that is maintained by our sole developer. Uploaded photos (reference images, body placement photos) are stored on the same server.
Government ID photos from the consent form are stored in Cloudflare R2 object storage, which provides encryption at rest. Only our developer has credentials to access this storage.
A PDF copy of your completed consent form is also generated and stored for recordkeeping.
Who Has Access to Your Information
Access to your data is limited to Katie Haus (the tattoo artist) and the developer who maintains this website and its supporting systems. We do not sell, rent, or share your personal information with any other parties.
Instagram API
We use a private business tool that connects to the Instagram API to manage the @hermit.stab Instagram account. This tool is used for content publishing, viewing account metrics, and logging direct message conversations for business record-keeping purposes.
The tool accesses only data associated with the hermit.stab Instagram business account, including publicly available profile information, content publishing data, account insights and metrics, and direct message conversations initiated by users who contact the business. This data is used solely for operating and managing the tattoo business.
If you have communicated with hermit.stab via Instagram and would like your message data removed from our records, please contact us using the information below and we will delete it promptly. Your interactions with Instagram are also governed by Meta's privacy policy.
Third-Party Services
We use a small number of third-party services to operate this website and business. These include a bot-detection service on our forms, a cloud storage provider for securely storing uploaded files, an email service for sending appointment-related communications, and the Meta/Instagram API for managing our social media presence. Your information is shared with these providers only to the extent necessary for them to perform these functions.
We do not use any analytics, advertising, or tracking services on this website. We do not embed any social media tracking pixels.
Cookies
This website does not set any cookies of its own. Cloudflare Turnstile, which we use for bot protection on our forms, may set cookies as part of its verification process. These are strictly necessary for security and do not track you for advertising or analytics purposes.
Data Retention
Consent form data (including health screening responses, your signature, and your government ID photo) is retained as a legal record of your informed consent to the tattoo procedure. This data is necessary for liability and legal compliance purposes and is retained indefinitely. We cannot delete consent records on request because they serve as legal documentation that may be required in the event of a dispute or regulatory inquiry.
Contact inquiries and booking data are retained to manage ongoing client relationships. If you would like this data deleted, you may contact us using the information below.
Your Rights
You may contact us to:
- Request a copy of the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your contact inquiry or booking data
As noted above, we are unable to delete consent form records, as they are retained for legal and liability purposes. We will respond to requests within a reasonable timeframe.
Contact
If you have questions about this privacy policy or want to make a data request, please reach out through our contact form or message us on Instagram at @hermit.stab.