Privacy
Plain language. You should not need a lawyer to understand what a directory does with your name.
Version 2.0. Last updated 28 August 2026
The short version
Read the site and we hold nothing about you. Send a request and we hold what the artist needs to answer you.
- No analytics product, no advertising pixel, no tracking cookie, no third party script on any page you read.
- No payment rail. We never see a card number because we never ask for one.
- The nearest to you feature does its arithmetic in your own browser. Your coordinates are not sent anywhere.
- We do not sell your details, and we do not hand them to anybody except the artist you picked and the providers that run the service.
- Ask and we tell you what we hold, correct it, or delete it.
- If you are listed here and would rather not be, say so and your page comes down. No reason needed.
This summary is here to be read. The sections underneath it are the ones that count.
Who is answerable
The controller of everything on this page, which is the legal word for whoever is answerable for it, is Talomis, run by Tony Krohn. Talomis is a directory of tattoo artists that connects a client to an artist for a consultation and then gets out of the way.
Write to bookings@neotradatlas.com about anything on this page. A person reads it.
What we hold, and why
One row for each kind of thing we hold, what it is for, and the legal ground it sits on. If a category is not listed here, we do not hold it.
- Reading the site
Nothing you type, because there is nothing to type. No account, no sign in, no advertising tracker, no cross site profile, no cookie set by us on any page. Our host and our database see your IP address the way every web server does, in ordinary server logs.
- A request
Your first name and last name, your email address, your phone number if you give one, what you write about the idea, where it goes on your body, the styles, the size and the timing, and whether you want colour. We record that you confirmed you are 18 or older and that you accepted the Talomis terms, the two boxes on the form, and we record the tag on the link you arrived from.
- Photographs you upload
Up to three reference images and one placement photograph, held in a private store. The image files keep whatever information your camera wrote into them, which on a phone can include the place the photograph was taken. We do not strip it and we do not read it.
- A consultation time
The time you picked, and a short lived hold on it. The consultation goes on the artist's calendar with your name, your email, your phone number and your description written into the event, and you are invited to it, so Google sends you the invitation.
- An artist account
The email address on the account, and a password if you set one rather than using a sign in link. Your handle, name, city, state, shop name, shop address, styles, bio, booking link, follower number if you enter one, your photographs, your links, your conventions and guest spots, your store rows, and your booking settings. We log the date you claimed the page and the email address you claimed it with, and the date you accepted the booking terms.
- A Google Calendar connection
An access token and a refresh token, encrypted before they are stored, plus which provider it is and whether the connection is live. The tokens are never sent to a browser.
- A page nobody has claimed
The artist's public handle, their name, their city and country, coordinates worked out from that city, their styles, up to three of their published work images with a written description of each, and, where the artist published one publicly, a contact email address.
- Counting
Two kinds of row. One when an artist's page is opened, carrying the artist's id and the tag on the link. One when somebody starts an intake or opens live times, carrying the artist's id, the kind of event and the same tag. Neither row carries a name, an account, a device id, a fingerprint or the page you came from. Two visits by the same person are two rows that cannot be joined, by us or by anybody holding the database.
- Stopping abuse
When you send a request or upload a photograph, Cloudflare's bot check sees your IP address and some ordinary details about your browser. Our own rate limiter keeps a shortened one way hash of your IP address, and of an email address on some paths, for a few days. A shortened hash of an IP address is a pseudonym rather than an anonymisation, and we call it that rather than calling it anonymous.
- Writing to us
Your name, your email address, the subject and your message. The contact form stores nothing at all: the message is delivered as email and there is no copy of it in the database.
Two things we do that you would want told plainly. When you send a request to an artist who has not joined Talomis yet, we relay it to the contact email they have published, and a copy comes to our own desk mailbox so a person can tell whether it landed. And when you pick a consultation time, your name, your email, your phone number and your description are written into the calendar event on the artist's calendar, and you are added as a guest, which is why the invitation arrives from Google rather than from us.
We do not sell your details. We do not share them for advertising. We do not build a profile of you across sites, and there is nothing here that could.
What stays on your device
Your location never leaves your browser. When you tap
nearest to you on the coastline, your browser hands the coordinates to the
page and the page does the arithmetic in your own browser. There is no
request, no geocoding service and no map tiles. The only place a
coordinate is written is your own device, under the key
talomis.near, and it dies with the tab. Talomis does not
see it. The site is a set of static files, so this is a thing you can
check by reading the source.
The other things kept on your device, all of them small, none of them sent to us:
atlasRefandatlasSrc, the tag on the link you arrived from, so a request sent three screens later still names the link that brought you. Session only.talomisViewed, the artists already counted this visit, so one visit is one count. Session only.talomisSelf, set when an artist opens their own page, so they do not inflate their own numbers. Session only.talomis:sound, whether you turned the sound on. It stays off until you ask for it, and no audio is even started before you do.- If you are an artist and you make a signing key, the private half is generated in your browser and stored there, in a form this code cannot read back out. It is never transmitted to us or to anybody.
No page you read loads anything from another company's server. The fonts, the images and the scripts are served from this site, so reading it does not announce you to anybody. There is one exception and it is deliberate: when you start filling in the booking form, Cloudflare's bot check loads from Cloudflare, and it sees your IP address. It loads on engagement rather than on page load, so a visitor who reads a page and leaves makes no request to Cloudflare at all.
No payments, no card details
There is no payment rail on this site. Talomis does not process payments, hold funds, take deposits or act as a payment agent for anybody. We hold no card number, no bank detail and no payment token, because nothing here asks you for one. There is no payment processor in the list below, and its absence is the point rather than a gap.
Whatever you and your artist agree is paid directly to them, under their own policy. Nobody from Talomis will ask you for money.
One honest note, because Talomis and the older atlas sites share a database. Some artists took a paid subscription on those older sites, billed by Stripe, before Talomis existed. If that is you, Stripe holds that billing relationship. Nothing on Talomis is for sale to artists and no new payment starts here.
Google Calendar, exactly
This section only applies to artists who choose to connect a calendar. Nothing here touches a client's Google account, and no client is asked to connect anything.
When an artist connects Google Calendar, Talomis asks for exactly two permissions and nothing else.
- See when you are busy
(
calendar.freebusy). This is the only reading permission and it returns time ranges only. It does not return event titles, descriptions, guests or locations. We use it to work out which consultation times to offer, and for nothing else. We cannot see what your appointments are. - Create and delete events
(
calendar.events). This is a writing permission. We use it to put a confirmed consultation on your calendar with the client invited, to add a Google Meet link when you offer video consultations, to mirror the conventions and guest spots you enter in your studio, and to remove those events when a consultation is cancelled or declined.
Reading is busy times only. We do not list your events, search them, or read the contents of any event we did not create. The one exception is that we look up an event we put there ourselves, by the id we stored when we created it, and we read three fields from it: the start, the end, and whether it is still there. That is how a consultation you move or delete in your own calendar gets picked up on your page. We never read the title, the description, the guests or the location, of that event or of any other.
Being straight about the permission itself: the second permission is broader than the use we make of it, because Google does not offer a narrower one that can create an event. Google will not let the connection complete unless both permissions are granted. The limits above are limits we hold ourselves to in code, and this policy is where we are held to them.
What we write into your calendar. A consultation event we create carries the client's name, their email address, their phone number if they gave one, and what they wrote about the tattoo, and the client is added as a guest so Google sends them the invitation. That is the point of booking a consultation, and it means Google holds that information as part of your calendar.
We do not use Google user data for advertising, and we do not use it to train any AI model. We do not sell it, and we do not share it with third parties except Google itself and the providers listed below that are required to operate the service.
How the tokens are held. The access token and the refresh token are encrypted before they are written down, with AES 256 GCM under a key derived with HKDF SHA 256 from a secret that lives in the server's own secret store and is not in any code repository. A fresh random value is used for each encryption. The ciphertext sits in one column that no browser can read: the database grants a browser the connection status and nothing else. You can disconnect at any time from your studio, or revoke access directly at your Google account permissions page. When you disconnect, the stored tokens are deleted and automated booking stops.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Where the connection is made today: the calendar is still connected in the older atlas studio, because Google sends the consent screen back to that address, and that step moves to this site at launch. The two permissions above, and the limits on them, are the same either way.
Who else touches it
Each one handles data only to do its own part of the job, under a contract, and none of them is allowed to use it for anything of their own.
- Supabase. The database, the sign in, and the private store your photographs live in. Everything above passes through here. Their policy
- Cloudflare. Hosting and delivery of the site, so Cloudflare sees the ordinary request details every host sees, including your IP address. Their policy
- Cloudflare Turnstile. The bot check on the request form. It loads from Cloudflare when you start filling the form in, not when you read a page, and your IP address is sent with the check. Their policy
- Resend. The email that carries a request to an artist, a copy back to a client, a reminder before a consultation and a cancellation notice. Their policy
- Google. Only when an artist has connected a calendar, and only for the two permissions set out above. Their policy
- OpenStreetMap Nominatim. Used once when a page was built, to turn a city and state name into map coordinates. No visitor data goes near it. Their policy
There is no payment processor on that list, because there is no payment on this site. There is no analytics company on it either.
We will also hand over data when the law requires it, and we will tell you when we are allowed to tell you. If Talomis is one day passed to somebody else, this policy and the covenant go with it, and you will be told before anything moves.
Where in the world it goes
Talomis is run from the United States and the providers above are mostly United States companies, so data reaches the United States. Nearly half the artists listed here work in the United Kingdom or the European Union, so this matters and it is not buried.
Where information about somebody in the UK or the EU is transferred to the United States, we rely on the standard contractual clauses in our agreements with those providers, and on the UK addendum where it applies. Some of them are also certified under the EU and UK data privacy frameworks. You can ask us which mechanism covers which provider and we will tell you.
How long it is kept
Where there is an automatic timer, it is named. Where there is not, that is said rather than dressed up, because a retention promise nothing enforces is worse than no promise at all.
- Requests, and the photographs with them
Kept while the artist's page is open, because the request is that artist's record of their own client. There is no automatic timer on it today and we would rather say that than print a number nothing enforces. Ask us and we delete the record and the photographs within thirty days. If an artist's page comes down, the requests attached to it come down with it and we delete the photographs in the same pass. If the bot check rejects a request, the record and the photographs are deleted straight away and nothing is sent to anybody.
- An artist account and page
Kept while the page exists. Ask us to remove the page and it goes, along with the requests, the links, the conventions, the store rows and the counting rows attached to it. Your account itself is deleted on request.
- Google Calendar tokens
Deleted the moment you disconnect, from your studio or from your Google account. Nothing survives the disconnection and automated booking stops with it.
- Counting rows
Kept as counts. They carry no identifier for you and there is no timer on them. They go when the artist's page goes.
- Abuse limits
The hashed keys are deleted automatically within a few days of being written. Nothing else is kept about the attempt.
- Email
Mail you send us stays in the mailbox until it is cleared out. The contact form itself keeps no copy in the database.
- Backups
Ordinary backups age out on their own schedule, so a deletion clears the live system first and works its way out of the backups after that. It is not instant and we will not pretend it is.
What you can ask for
Wherever you live, you can ask us to show you what we hold about you, to correct it, or to delete it. Email bookings@neotradatlas.com, say what you want, and we answer within thirty days. There is no fee and no form.
We will ask you enough to be sure it is you, which usually means writing from the address the record is under. We ask for the least we can get away with and we do not keep what you send to prove it.
Artists can do most of it without asking. Edit or remove anything on the page from the studio, disconnect the calendar, turn automated booking off, or press the export button, which is promise 005 of the covenant and hands you your page, your work, your captions and your requests in one plain open file. To have the whole page taken down, email us and it comes down.
Clients can cancel a consultation with the link in the confirmation email, and can ask us to delete a request they sent. If the artist has already received it by email, we will tell you that, because we cannot reach into somebody else's mailbox and we will not pretend otherwise.
If you are in the UK or the EU
The UK GDPR and the EU GDPR give you these rights, and we honour them for anybody who asks, wherever they are:
- Access. A copy of what we hold about you.
- Rectification. Correct anything wrong.
- Erasure. Have it deleted.
- Restriction. Have us stop using it while something is being sorted out.
- Portability. Get it in a machine readable file. For artists that is the export button, and it works now.
- Objection. Object to anything we do on the ground of legitimate interests, including a listing you did not ask for. If you object to a listing, we do not weigh it against anything. We take the page down.
- Withdraw consent. Where consent is the ground, which here means the calendar connection, take it back at any time. That does not undo what was done before you took it back.
- No automated decisions. Nothing here decides anything about you automatically, and there is no profiling.
You can also complain to your own data protection authority. In the UK that is the Information Commissioner's Office. In the EU it is the supervisory authority where you live, and the list is on the European Data Protection Board site. We would rather you told us first, but you do not have to.
One gap, named rather than hidden. Article 27 expects a controller outside the UK and the EU to appoint a representative there. Talomis is one person in the United States and has not appointed one. That is a shortfall on our side, not on yours: it takes nothing away from the rights above, and it does not stop you complaining to your own authority. Write to the address on this page and it reaches a person directly.
If you are in California
Under California law you can ask what personal information we have collected about you and where it came from, ask us to delete it, ask us to correct it, and ask what we disclosed and to whom. Use the same address as everybody else and we will not treat you any differently for asking.
We do not sell personal information and we do not share it for cross context behavioural advertising. We have not done either in the last twelve months, and there is nothing on this site that could: no advertising network, no data broker, no tracking pixel. So there is no opt out link, because there is nothing to opt out of.
The categories we collect are the ones listed above: identifiers such as a name, an email address and a phone number, commercial information such as the request you sent, internet activity such as a page count and an IP address seen by our host, and geolocation only in the sense that a photograph you upload may carry it. We collect them for the purposes given in the same list, from you directly, and from an artist's own public posts in the case of a listing. You can name an authorised agent to ask on your behalf.
Pages nobody claimed
Most of the artists on this site never asked to be here. Their page was built from their own public work, without them being asked first. That is the most sensitive thing this site does, so here is the whole of it.
What was taken and from where. Public content published by the artist under their own professional handle: the profile photograph, up to three post images, the bio text, and the city or shop they publicly tagged. The city was turned into map coordinates so the page appears in the right place. Where the artist published a business contact email publicly, that address was recorded, and it is what a client request gets relayed to. Copies of the images are held on our own servers so the page does not depend on links that expire, and each image carries a written description produced by an automated pass so it can be read by a screen reader and found by a search engine.
Why we think we are allowed to. The information is professional rather than private, it was published by the artist to be seen, it is used for the purpose it was published for, which is being found and hired, and the page carries no cut, no fee and no advertisement. That is a legitimate interests judgement under Article 6(1)(f), and a legitimate interests judgement is exactly the kind that a person is entitled to argue with.
So the way out is unconditional. Email us and your page comes down. You do not have to give a reason, claim the page first, prove who you are beyond writing from an address that makes sense, or talk to anybody about staying. We do not weigh your objection against our interest, we do not counter offer, and we do not ask again later. We aim to have it down within seven days and we confirm when it is done.
What removal actually removes. The page, the stored copies of the images, the descriptions written for them, the coordinates and the contact address, and the entry from the sitemaps and the plain text files that assistants read. What it cannot remove is anything a search engine, an assistant, an archive or another person already copied. We ask the search engines to drop the page and they usually do, on their own schedule. We say this plainly because a removal promise that pretends to reach the whole internet is a lie.
The same route works for one photograph rather than the whole page, or for correcting a shop name, a city or a style that is wrong.
Public pages are meant to be found
Every page on this site except an artist's own signed in studio is deliberately open to search engines and AI assistants. Nothing is blocked in robots.txt except that studio, and /llms.txt is written so an assistant can read the site properly and send a person to the artist. Being read and cited is how anybody finds an artist here.
What that means for you, said before rather than after: anything on a public page can be indexed, cached, quoted, summarised by an assistant, and archived by people we have nothing to do with. Once that has happened we cannot take it back. Treat anything you publish on your page as published to the internet, because it is.
What is not public: your account email, a client's request, the photographs a client uploads, your calendar tokens, and anything else in the studio. Client photographs sit in a private store that no anonymous visitor can read or even list, reachable only by the artist the request was sent to, through a link that stops working after an hour, and by one operator account for support and moderation.
This is for adults
You must be 18 or older to send a request, hold an account or upload anything here, and sending a request requires you to confirm it. This site is not built for children and we do not knowingly collect anything from anybody under 18.
If you believe we hold something belonging to somebody under 18, write to us and we delete it. A parent or guardian does not need to explain themselves to us.
How it is protected
What is actually in place: everything travels over an encrypted connection. The database enforces row level security, so an artist can read their own rows and nobody else's, and the browser key that every visitor carries grants nothing a stranger could not already ask for. Client photographs sit in a private store with anonymous reading and listing switched off. Google tokens are encrypted before storage under a key held in a server secret store. The powerful database key is never in a browser, never in a build and never in the code repository. Uploads are checked by reading the actual bytes rather than trusting the file name. Forms are rate limited and behind a bot check. Artists can turn on a second step at sign in.
What we will not claim: that any of this makes the site unbreakable. No system is perfectly secure and anybody who tells you theirs is has something to sell. We are a small operation and we would rather you knew the size of us than believed a slogan.
If you find a hole, write to us before you write about it anywhere else and we will fix it and thank you properly.
If something goes wrong
If a breach puts your information at risk, we tell you. We say what happened, what was reached, what we have done and what you should do, and we say it as soon as we understand it rather than waiting until the story is tidy. If we do not know something yet, we say that instead of guessing.
Where the law sets a clock we work to it, which in the UK and the EU means telling the supervisory authority within seventy two hours of finding out, and telling you without undue delay where the risk to you is high. Under United States state laws we notify as those laws require.
If this changes
Covenant promise 006: what is written here does not change quietly. A change is listed below with the date on it, the old words stay readable, and artists are asked to accept again where the change affects them. If a change means we would use something we already hold for a new purpose, we tell you before we do it, not after.
The record
-
Version 2.0, 28 August 2026
Rewritten against a full read of the code on the day 1.0 was written. Added: the legal basis for every category, that our host and our bot check see IP addresses, that every artist page view is counted and not only pages with live times, that the bot check loads from Cloudflare when you engage the form, that a booked consultation writes your details into the artist's calendar event and invites you, that a request to an artist who has not joined is copied to our own desk mailbox, that uploaded photographs keep their camera information, the honest position on retention, UK and EU rights with the representative gap named, California rights, the security posture, breach notification, and the unconditional removal right for an unclaimed page.
-
Version 1.0, 28 August 2026
First version on this site, ported from the atlas policy dated 19 August 2026.
Contact
One mailbox, read by a person. Use it to see what we hold, correct it, delete it, take a page down, or argue with any of the above. Talomis mail moves onto this domain at launch and this address changes with it.
Email us about your databookings@neotradatlas.com
The terms