Legal
Privacy Policy
This Privacy Policy explains how flatneedle collects, uses, stores, shares, transfers, deletes, and protects personal data.
Effective Date: June 12, 2026
Last Updated: June 12, 2026
This Privacy Policy explains how flatneedle, operating the flatneedle service ("flatneedle," "Company," "we," "us," or "our"), collects, uses, stores, shares, transfers, deletes, and otherwise processes personal data in connection with our website, desktop applications, mobile applications, downloadable software, cloud-connected features, subscriptions, and related services (collectively, the "Service").
flatneedle is a software service for 3D tattoo design preview, texture and design visualization, schedule management, project workflow support, and team schedule sharing.
This Privacy Policy is intended for users globally. Depending on your location, you may have additional rights under applicable privacy, data protection, consumer protection, e-commerce, and information network laws.
By accessing or using the Service, creating an account, subscribing to the Service, using team sharing features, uploading files, synchronizing data, or otherwise providing information to us, you acknowledge that your personal data may be processed as described in this Privacy Policy.
1. Who We Are
Data Controller / Business Operator: flatneedle
Brand / Service Name: flatneedle
Business Address: Sangagadong 1049, Gohyeon-ro, Geoje-si, Gyeongsangnam-do, Republic of Korea
Support Email: cs@flatneedle.com
Privacy Email: cs@flatneedle.com
Support Contact: cs@flatneedle.com
If you have any privacy-related questions, complaints, or requests, please contact us using the contact details above.
2. Personal Data We Collect
The personal data we collect depends on how you use the Service, the features you enable, the information you submit, and the platform or device you use.
2.1 Information You Provide Directly
- name or display name, if you provide one,
- email address,
- account login information or password credential flow handled through authentication providers,
- customer support or inquiry details,
- billing-related contact details you provide to us, if any,
- preferences, settings, profile details, and other information you choose to provide,
- project files, uploaded images, design files, text, notes, and other content you submit through the Service.
2.2 Information Collected Through Authentication and Sign-In
When you create or access an account using email/password sign-in, Google Sign-In, or another supported authentication method, we may receive and process:
- email address,
- unique user ID, account identifier, or authentication identifier,
- login provider information,
- basic profile information such as name and profile image, where made available by the provider and permitted by you,
- account creation date, sign-in timestamps, token metadata, and security-related events.
2.3 Schedule, Calendar, Project, and Team Sharing Data
When you use schedule, calendar, project, or team sharing features, we may collect, store, and process information such as:
- schedule and calendar information, including event date, event time, calendar ID, event ID, and schedule status,
- project information, including project name, project details, project notes, and project-related settings,
- schedule notes, contact notes, client-related notes entered by you, information notes, and other workflow notes,
- payment-related notes, price notes, deposit notes, or amount memos entered for schedule management purposes,
- team information, including team ID, team name, team membership, team role, shared calendar settings, and member visibility settings,
- owner information for shared schedules, such as owner user ID, owner email address, display name, or similar account identifier,
- design images, record images, uploaded reference images, project image metadata, and other user-generated project content.
If you enable team sharing, share a calendar with a team, or participate in a shared team workspace, selected schedule information, project names, event dates, event times, notes, payment or amount memos, calendar information, and owner information may be visible to members of the same team.
By default, personal project content such as design images, record images, contact notes, information notes, private project files, and private workflow records is stored for the account owner and is intended to be accessible only by that account owner across their own devices when signed in. Such private project content is not made visible to team members merely because you join a team.
Team members may view only the information made available through team sharing features, such as shared calendar events and related schedule fields. Unless a feature expressly states otherwise, team-shared calendar viewing does not give team members access to your private design images, record images, contact notes, information notes, or private project files.
Team sharing is intended to help team members coordinate schedules and project workflows. You should not enter sensitive information into schedule notes, project notes, payment memo fields, or team-shared fields unless you are authorized to store and share that information with the relevant team members.
2.4 User-Generated Content
You may upload, create, import, store, or process content through the Service. Such user-generated content may include:
- tattoo design images, reference images, and records,
- 3D-related project files, texture previews, design previews, or visual materials,
- project names, schedule notes, contact notes, project information, and workflow records,
- uploaded files, images, text, and other content submitted through the Service.
2.5 Information Collected Automatically
- IP address,
- browser type and version,
- device type, operating system, and approximate technical environment,
- application version, platform, language, region, and system configuration,
- log data, crash data, diagnostics, and usage events,
- referrer URLs, page views, access times, session information, and interaction data,
- cookies, local storage, session tokens, or similar technologies used to maintain login state, preferences, and security,
- device identifiers, app instance identifiers, or notification tokens, if required for security, synchronization, diagnostics, or push notifications.
2.6 Subscription and Transaction Information
When you purchase, maintain, renew, cancel, or request support for a subscription, we may process or receive:
- subscription plan information,
- billing cycle and subscription status,
- order ID, customer ID, transaction ID, invoice or receipt identifiers,
- purchase status, renewal status, cancellation status, refund status, and tax-related status,
- limited billing or tax-related information necessary for service administration, support, accounting, and legal compliance.
Payment processing is generally handled by third-party payment providers. We do not intentionally store your full payment card number, bank account number, or government identification number unless expressly stated otherwise.
2.7 Payment or Amount Memo Fields
The Service may allow users to enter payment-related notes, price notes, deposit notes, or amount memos for schedule and project management purposes. These fields are user-entered workflow notes and are not intended to collect full payment card numbers, bank account numbers, government identification numbers, or other high-risk financial or identity data.
You are responsible for ensuring that the information you enter into payment or amount memo fields is appropriate for storage and, where team sharing is enabled, appropriate for sharing with members of the relevant team.
3. How We Use Personal Data
We use personal data for the following purposes:
- to create, authenticate, secure, and manage user accounts,
- to provide access to flatneedle software, 3D preview features, design visualization tools, cloud-connected features, and subscription services,
- to provide personal schedule management, project management, calendar synchronization, and team schedule sharing features,
- to display shared schedules, project information, owner information, and team-related data to authorized team members,
- to store, process, display, and synchronize user-generated content such as project notes, design images, record images, and uploaded files,
- to enable access to the same account data across supported devices, including desktop and mobile platforms,
- to process purchases, renewals, cancellations, refunds, invoices, taxes, and subscription administration,
- to provide customer support and respond to inquiries, bug reports, complaints, and legal requests,
- to communicate with you about your account, service updates, security notices, invoices, support requests, and policy changes,
- to maintain security, detect fraud, prevent abuse, protect accounts, and enforce our Terms of Use,
- to analyze service performance, troubleshoot issues, fix bugs, improve usability, and develop new features,
- to comply with legal obligations, accounting requirements, tax obligations, dispute handling, and regulatory requests,
- to protect our rights, users, systems, and business operations.
4. Legal Bases for Processing
Where applicable under laws such as the GDPR, UK GDPR, or similar frameworks, we process personal data on one or more of the following legal bases:
- Performance of a contract: to provide the Service, manage your account, process subscriptions, and deliver requested features.
- Your consent: where consent is required, such as for certain cookies, optional communications, optional permissions, or certain overseas transfers where consent is legally required.
- Legitimate interests: to operate, secure, analyze, and improve the Service, prevent abuse, and support our business operations.
- Compliance with legal obligations: to comply with tax, accounting, consumer protection, privacy, and other legal requirements.
- Protection of rights and legal claims: to establish, exercise, or defend legal claims and protect users, systems, and the Company.
5. Team Sharing and Visibility
flatneedle may allow users to create or join teams, share calendars, and view team-related schedules. When you use these features, certain information may become visible to other members of the same team.
Depending on your settings and the features you use, team members may be able to view:
- your display name, email address, user ID, or other owner identifier,
- shared calendar names and calendar sharing status,
- event date, event time, project name, schedule notes, payment or amount memo, and event status,
- team ID, team name, team membership, and role-related information,
- project-related content or notes that you choose to share,
- design images, record images, or other project materials only if you expressly upload, attach, or make them available through a feature that clearly indicates such sharing.
Sharing a calendar with a team does not automatically share your private project files, design images, record images, contact notes, or information notes. Calendar sharing is primarily intended to share schedule-related information.
You control what you enter into the Service and, where available, which calendars or items are shared. Please review your team sharing settings before entering sensitive or confidential information.
If you are using flatneedle on behalf of a studio, business, or organization, you are responsible for ensuring that your use of team sharing complies with your organization's policies and applicable privacy laws.
6. Retention of Personal Data
We retain personal data only for the period necessary to provide the Service, operate accounts, synchronize user content, support team sharing features, process subscriptions, maintain security, handle disputes, and comply with legal obligations.
| Category | Retention Period | Notes |
|---|---|---|
| Account information | While the account is active; deleted or anonymized after account deletion unless legal retention applies. | Email address, account ID, login provider, authentication identifiers, and account settings. |
| Private project data | Until the user deletes the relevant project, uploaded file, or account, unless legal retention applies. | Project names, design images, record images, contact notes, information notes, project files, and related metadata. |
| Private calendar and schedule data | Until the user deletes the relevant event, calendar, project, or account, unless legal retention applies. | Event dates, times, notes, payment or amount memos, calendar IDs, event IDs, and project links. |
| Team sharing data | While the team, shared calendar, shared event, or team membership remains active; deleted, disabled, or anonymized when no longer necessary. | Team ID, team name, membership, role, owner identifiers, shared calendar state, and shared schedule fields. |
| Customer support and inquiry records | Up to 3 years after the inquiry is resolved, unless a longer period is required for legal claims or dispute handling. | Support emails, inquiry content, response history, and complaint records. |
| Subscription, transaction, billing, tax, refund, and invoice records | As required by applicable law. In Korea, certain e-commerce records may be retained for 5 years, 3 years, or 6 months depending on the record type. | Order IDs, transaction IDs, subscription status, invoice identifiers, payment processor records, refund history, and tax-related information. |
| Security logs, access logs, diagnostics, and crash logs | Normally up to 12 months, unless a longer period is necessary for security investigation, abuse prevention, legal claims, or compliance. | IP address, device/browser information, app version, authentication logs, crash reports, and security events. |
| Backups | Deleted or overwritten according to our backup cycle, normally within 90 days after deletion from active systems, unless legal retention applies. | Backup deletion may not be immediate because backups are maintained for security, restoration, and service continuity. |
When retention is no longer necessary, we delete, anonymize, or securely dispose of the information, unless continued retention is required or permitted by law.
7. Sharing of Personal Data
We do not sell your personal data for money in the ordinary sense of that term. We may share personal data with the following categories of recipients where necessary:
- Team members and workspace participants: if you use team sharing features, selected schedule, project, owner, and team information may be visible to members of the same team.
- Authentication, hosting, cloud, database, and infrastructure providers: to operate accounts, cloud synchronization, storage, security, and backend services.
- Payment, billing, tax, subscription, and refund processing providers: to process purchases, renewals, cancellations, refunds, taxes, invoices, and subscription administration.
- Customer support, analytics, monitoring, communications, and security service providers: to provide support, troubleshoot issues, detect abuse, improve performance, and communicate with users.
- Professional advisors: such as lawyers, accountants, auditors, or insurers.
- Governmental, judicial, law enforcement, or regulatory authorities: where required by law, court order, lawful request, or to protect rights and safety.
- Acquirers, investors, or successors: in connection with a merger, acquisition, restructuring, financing, transfer, or sale of all or part of our business or assets.
We require service providers to process personal data only as necessary to provide services to us and in accordance with applicable contractual and legal obligations.
8. Key Third-Party Services Used by flatneedle
Depending on how you use the Service, we may use third-party services such as:
- Firebase Authentication / Google: account creation, authentication, login, account security, token handling, and related infrastructure.
- Firebase, Google Cloud, or other cloud infrastructure providers: hosting, database, storage, synchronization, logging, diagnostics, and backend operations.
- Google Sign-In: optional sign-in and profile information where enabled by you and supported by the Service.
- Lemon Squeezy: payment processing, subscription administration, tax handling, invoicing, refund-related operations, and payment support.
- Analytics, crash reporting, monitoring, or communication tools: if enabled, to understand performance, diagnose errors, and improve the Service.
These third parties may process personal data in accordance with their own privacy policies, contractual terms, and applicable law. The specific providers we use may change over time as the Service evolves.
9. International Transfers of Personal Data
Because we may use global cloud, authentication, payment, infrastructure, and support providers, your personal data may be transferred to, stored in, or processed in countries outside your country of residence, including countries that may not provide the same level of legal protection as your home jurisdiction.
Transfers may occur in connection with services operated by providers such as Google, Firebase, Google Cloud, Lemon Squeezy, and other infrastructure or service providers. Such transfers may include account identifiers, email address, profile information where applicable, subscription data, transaction identifiers, technical logs, schedule data, team sharing data, user-generated content, and related service usage data to the extent necessary to provide the Service.
Where required by applicable law, we take reasonable steps to implement appropriate safeguards for cross-border transfers, such as contractual protections, technical safeguards, and transfer mechanisms recognized under applicable law.
10. Cookies and Similar Technologies
We use cookies and similar technologies such as local storage, session storage, authentication tokens, and device or app identifiers to:
- keep you signed in,
- remember preferences and session state,
- maintain security and detect suspicious activity,
- support synchronization and account functionality,
- measure performance and improve the Service,
- analyze errors, crashes, and service reliability.
You can usually control cookies and similar technologies through your browser, device, or operating system settings. However, disabling them may affect login, security, synchronization, or functionality.
11. Push Notifications
If the Service provides notifications, we may process notification tokens, device identifiers, account identifiers, schedule information, and notification settings to send you account, schedule, team, security, or service-related notifications.
You can usually control notifications through the Service settings or your device settings. Disabling notifications may affect reminders, schedule alerts, team updates, or similar features.
12. Data Security
We implement reasonable technical, administrative, and organizational safeguards designed to protect personal data against unauthorized access, disclosure, alteration, loss, or destruction. Such measures may include:
- access controls and role-based restrictions,
- authentication and authorization controls,
- encryption in transit where supported,
- secure cloud infrastructure and monitoring,
- logging, diagnostics, and abuse detection,
- operational security practices,
- data minimization and retention controls where appropriate.
However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials and for using strong account security practices.
13. Your Rights
Depending on your location and applicable law, you may have the right to:
- request access to personal data we hold about you,
- request correction of inaccurate or incomplete personal data,
- request deletion of personal data,
- request restriction of processing,
- object to certain processing activities,
- withdraw consent where processing is based on consent,
- request portability of your personal data where applicable,
- opt out of certain communications, analytics, or data sharing where applicable,
- lodge a complaint with a supervisory authority or privacy regulator where permitted by law.
You may exercise your rights by using features available in the Service or by contacting us at cs@flatneedle.com. We may need to verify your identity before acting on certain requests.
Where supported by the Service, you may delete individual projects, calendars, events, uploaded images, and other user-generated content directly in the app. Deleting content from the app is intended to remove it from active systems associated with your account, subject to backup cycles and legal retention obligations.
Some data may not be immediately deleted if retention is required by law, needed for security, required for dispute resolution, necessary to complete transactions, or retained in backup systems for a limited period.
14. Account Deletion
If you create an account with flatneedle, you may request deletion of your account and associated personal data.
You may request account deletion by:
- using the account deletion feature inside the app, if available,or
- contacting us at cs@flatneedle.com from the email address associated with your account.
After receiving and verifying your request, we will delete or anonymize personal data associated with your account unless retention is required or permitted by law. Deleting your account may also delete or disable access to your personal schedules, project data, uploaded files, team memberships, and subscription-related access.
After account deletion, active account data and private user-generated content are deleted or anonymized within a reasonable operational period, normally within 30 days, unless retention is required by law, security, dispute handling, transaction records, backup operation, or legitimate legal claims. Backup copies may remain for a limited period and are overwritten or deleted according to our backup cycle, normally within 90 days.
If your account is part of a team, certain records may remain visible to team administrators or other team members where necessary for shared workspace continuity, legal compliance, security, dispute handling, or where the data belongs to the team or organization rather than solely to your personal account. Where appropriate, we may remove or anonymize your personal identifiers from such records.
For account deletion records, we may retain a minimized deletion record, such as a hashed email identifier, deletion request timestamp, and scheduled deletion date, for up to one year to prevent abuse, support dispute handling, maintain security, and comply with operational or legal obligations. After the retention period, such records are deleted or further anonymized unless continued retention is required by law.
Transaction, tax, accounting, refund, security, and legal records may be retained for the period required by applicable law or legitimate business needs.
15. Children’s Privacy
The Service is not intended for children under the age required by applicable law to independently consent to online services in their jurisdiction. We do not knowingly collect personal data from children in violation of applicable law.
If you believe that a child has provided us with personal data unlawfully, please contact us so that we can take appropriate action.
16. Third-Party Sites and Services
The Service may contain links to or integrations with third-party sites, tools, platforms, SDKs, APIs, payment processors, authentication services, or cloud services. We are not responsible for the privacy practices of third parties, and we encourage you to review their privacy policies separately.
Your use of third-party services may be subject to separate terms, privacy policies, and account settings provided by those third parties.
17. California Privacy Notice
If you are a California resident, you may have rights under applicable California privacy laws, including rights to know, access, delete, correct, and opt out of certain forms of data sharing, subject to statutory exceptions.
Categories of personal information we may collect include identifiers, commercial information, internet or electronic network activity, user-generated content, professional or business-related information where provided by you, and inferences or preferences related to Service usage.
We do not use sensitive personal information for purposes that would require a separate "limit use" right unless otherwise disclosed.
To submit a privacy request, contact us using the contact details in this Privacy Policy.
18. EEA / UK / Switzerland Privacy Notice
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you may have rights under applicable data protection law, including the right to access, correct, delete, restrict, object to processing based on legitimate interests, withdraw consent, request portability, and lodge a complaint with your local supervisory authority.
Where we transfer personal data internationally, we use appropriate safeguards where required by applicable law.
19. Additional Information for Korean Users
This section provides additional information for users in the Republic of Korea in accordance with applicable Korean privacy laws.
19.1 Items of Personal Information Processed
- Required for account access: email address, account ID, login provider, authentication-related identifiers.
- Collected during Google Sign-In where available and authorized: name, profile image, email address, and account identifier.
- Schedule and calendar information: event date, event time, project name, schedule notes, payment or amount memo, calendar ID, and event ID.
- Project and workflow information: project name, project information, contact notes, information notes, design images, record images, uploaded files, and other user-entered content.
- Team sharing information: team ID, team name, team membership, team role, shared calendar settings, owner user ID, owner email address, and display name.
- Collected for subscription administration: order information, subscription status, billing-related identifiers, transaction identifiers, and limited billing information.
- Collected during service use: access logs, IP address, cookies or similar login/session data, device information, browser information, app version, crash logs, diagnostics, and usage events.
- Collected for inquiries: name, email address, inquiry content, response history, and support records.
- Collected for notifications, if enabled: notification token, device identifier, notification settings, and related account or schedule identifiers.
19.2 Purpose of Processing Personal Information
- member identification and account authentication,
- provision of software, 3D design preview, schedule management, project workflow, and subscription services,
- team schedule sharing, shared calendar operation, team member visibility, and team workflow coordination,
- storage and synchronization of schedules, projects, notes, images, and user-generated content,
- billing, refund, subscription administration, support, and customer communication,
- security, abuse prevention, fraud detection, service operation, diagnostics, and service improvement,
- compliance with applicable law, tax obligations, accounting obligations, and dispute handling.
19.3 Retention and Use Period
For Korean users, we retain and use personal information within the period necessary for the purposes of processing, unless a longer retention period is required by law.
| Type of Information | Retention Period |
|---|---|
| Account information | Until account deletion, unless legal retention applies. |
| Private project data, design images, record images, contact notes, information notes, and uploaded files | Until the user deletes the relevant content, project, or account, unless legal retention applies. |
| Private calendar and schedule data | Until the user deletes the relevant event, calendar, project, or account, unless legal retention applies. |
| Team sharing data | While the team, membership, shared calendar, or shared event remains active; deleted or anonymized when no longer necessary, unless legal retention applies. |
| Records on contracts, subscription purchases, or withdrawal of offers | 5 years under applicable e-commerce laws. |
| Records on payment and supply of goods or services | 5 years under applicable e-commerce laws. |
| Records on consumer complaints or dispute handling | 3 years under applicable e-commerce laws. |
| Records on advertisements or display | 6 months under applicable e-commerce laws. |
| Security logs, diagnostics, and access logs | Normally up to 12 months, unless longer retention is necessary for security, abuse investigation, legal claims, or compliance. |
| Backup data | Deleted or overwritten according to our backup cycle, normally within 90 days after deletion from active systems, unless legal retention applies. |
19.4 Destruction of Personal Information
When personal information is no longer necessary, we will delete or anonymize it without undue delay unless retention is required by law. Information stored in electronic form is deleted using commercially reasonable methods designed to make recovery difficult, and information in paper form, if any, is shredded or otherwise destroyed securely.
19.5 Entrustment and Overseas Transfer
We may entrust processing or transfer personal information overseas to service providers necessary for operation of the Service, such as providers of authentication, cloud infrastructure, database, storage, payment processing, diagnostics, analytics, and customer support.
If personal information is transferred overseas for cloud hosting, authentication, storage, payment processing, subscription management, diagnostics, or customer support, the transfer is carried out only to the extent necessary to provide the Service, perform the contract with the user, maintain security, or comply with applicable law.
- Recipient / Service Provider: Google / Firebase / Google Cloud
- Country: Republic of Korea, United States, and other countries or regions where Google, Firebase, or Google Cloud infrastructure and support services operate
- Purpose: authentication, login, account management, cloud infrastructure, database, storage, synchronization, security, logs, and operational support
- Items transferred: email address, account identifiers, profile information where applicable, authentication metadata, private project metadata, design and record image metadata, uploaded content stored in cloud storage, schedule data, team sharing data, service logs, IP address, device information, diagnostics, and usage data necessary for operation
- Transfer timing and method: transmitted securely via network when you create an account, sign in, synchronize data, upload content, use cloud-connected features, or use the Service
- Retention period: retained according to this Privacy Policy, the user's deletion choices, our backup cycle, applicable law, and the provider's operational necessity
- Recipient / Service Provider: Lemon Squeezy
- Country: United States and other countries or regions where Lemon Squeezy and its service providers process payment, tax, subscription, and support data
- Purpose: subscription management, payment processing, tax and invoicing support, refund-related operations, and payment support
- Items transferred: customer identifiers, email address, order identifiers, transaction identifiers, subscription and purchase status, refund status, limited billing information, and tax-related information
- Transfer timing and method: transmitted securely via network when you subscribe, purchase, renew, cancel, request support, or request refund-related processing
- Retention period: in accordance with this Privacy Policy, applicable law, and the provider's operational necessity
You may contact us to request information about overseas transfer, processing entrustment, or the providers used for the Service. If you refuse or withdraw consent where consent is legally required, some cloud synchronization, authentication, subscription, or payment features may not be available.
19.6 Rights of Data Subjects and How to Exercise Them
Korean users may request access, correction, deletion, suspension of processing, withdrawal of consent, or other rights available under applicable law by contacting us at the contact details listed in this Privacy Policy. We may verify identity before processing such requests.
19.7 Personal Information Protection Officer
Privacy Contact / Personal Information Protection Officer
Name or Department: flatneedle Privacy Team
Email: cs@flatneedle.com
Address: Sangagadong 1049, Gohyeon-ro, Geoje-si, Gyeongsangnam-do, Republic of Korea
20. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect operational, legal, technical, or business changes. If we make material changes, we may provide notice by updating the "Last Updated" date, posting a notice on the Service, sending an email, displaying an in-app notice, or using other reasonable means where required by law.
Your continued use of the Service after the effective date of an updated Privacy Policy means that the updated version will apply to the extent permitted by law.
21. Contact Us
If you have questions, concerns, complaints, or requests regarding this Privacy Policy or our privacy practices, please contact us:
flatneedle
Brand / Service: flatneedle
Sangagadong 1049, Gohyeon-ro, Geoje-si, Gyeongsangnam-do, Republic of Korea
Support Email: cs@flatneedle.com
Privacy Email: cs@flatneedle.com