SmyrnaInk
Privacy Policy
DRAFT — PENDING LEGAL REVIEW
This page is not a legally binding final text. It will be updated once the company is incorporated and reviewed by counsel.
Cette page n'existe qu'en anglais ; la version anglaise fait foi.
This draft describes how personal data is processed on the www.smyrnaink.com marketing site and the SmyrnaInk SaaS platform.
Controller and roles
Controller for the marketing site (www.smyrnaink.com): Smyrna Software Ltd. Şti. (in formation), Izmir, Türkiye. Contact: (will be published once incorporation is complete).
On the SaaS platform (studio panels and studio landing pages) each tattoo studio is the controller of its customer data; SmyrnaInk acts as processor. A data processing agreement (DPA) is concluded with each studio.
Hosting and data location
The application is hosted on Vercel. Database, authentication and file storage run on Supabase (PostgreSQL) in the Frankfurt region (EU, eu-central). Operational customer data is stored within the EU.
Cookies and session
The platform uses only strictly necessary httpOnly and secure session cookies for authentication. No advertising/tracking cookies are used on the marketing site. The language cookie (NEXT_LOCALE) serves a functional purpose.
Sub-processors
The platform uses the following sub-processors: Supabase (database/auth/storage — EU Frankfurt), Vercel (hosting/edge), Paddle (Merchant of Record — payments/invoicing), OpenAI and Vercel AI Gateway (chatbot), Meta Platforms Ireland (Messenger and Instagram messages and Lead Ads forms — direct integration; WhatsApp Business separate), Google (calendar sync), Upstash (rate limiting), Sentry (error monitoring), Resend (transactional email), Cloudflare (DNS). The current list is provided as an annex to the DPA.
Meta integration (Facebook, Instagram)
A studio administrator may connect their Facebook Page and the linked Instagram business account to SmyrnaInk. We then receive from Meta: the Page/account ID and name, the content of Messenger and Instagram messages sent to the Page together with the sender's platform ID (PSID/IGSID), and Lead Ads form fields (name, email, phone, free text). The Page access token is stored encrypted in a vault (Supabase Vault), never in tables.
The sole purpose is the studio's inbox and lead management. This data is not used for advertising, profiling, resale or model training and is not shared with third parties. Replies are subject to Meta's 24-hour rule.
Retention: raw webhook events are stripped of content after 7 days (only the structure remains) and deleted after 90 days. Message and lead records follow the studio's retention and anonymisation processes.
Deletion: removing the connection in Settings deletes the token. When you remove the app from your Meta account or submit a data deletion request through Meta, all connections are closed, tokens are deleted and you receive a confirmation code (status page: /data-deletion). In-studio customer deletion also anonymises Meta-originated records.
Third-country transfers
Smyrna Software Ltd. Şti. is established in Türkiye; in the absence of an EU adequacy decision, access to studio data is safeguarded under Art. 44 et seq. GDPR through Standard Contractual Clauses (SCC) and a Transfer Impact Assessment (TIA). The SCC and TIA annexes are being prepared and will be published on this page once legal review is complete.
Your rights
Under the GDPR you have the right of access, rectification, erasure (right to be forgotten — the platform implements an anonymization procedure), restriction of processing, data portability and objection. Requests: (will be published once incorporation is complete). You retain the right to lodge a complaint with a supervisory authority.