Privacy Policy

Last Updated: June 20, 2026

This Privacy Policy explains how Maelo App Inc. ("Maelo", "we", "us"), a federal corporation (Corporations Canada No. 1736630-2) based in Vancouver, British Columbia, Canada, collects, uses, discloses, and protects personal information through the Maelo platform at maelo.app and its apps (the "Service"). We comply with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), British Columbia's Personal Information Protection Act (PIPA), Canada's Anti-Spam Legislation (CASL), and — for users in the EU/EEA and UK — the GDPR / UK GDPR. By using the Service you consent to the practices described here.

1. Roles — Who Controls Your Data

Maelo plays two roles depending on the data:

  • As a controller, for information we collect to run the platform (account data, billing, technical logs, our own communications with you).
  • As a service provider for Artists, when an Artist uses Maelo to manage their own Clients. The Artist controls their Client list; Maelo processes that data on the Artist's behalf. Artists are independently responsible for handling Client information lawfully.

2. Information We Collect

  • Account information (Artists): name, preferred name, email, username, auth credentials, profile and avatar images, business/studio details, timezone, settings, and branding.
  • Booking information (Clients): name, email, optional phone, the details you submit in a booking request (description, placement, size, reference images, budget, preferred dates), and messages with the Artist.
  • Sensitive information: waivers and details that may be sensitive (e.g., tattoo placement, any health-related answers a waiver collects). We treat this with a higher standard of consent and protection; waiver submissions are encrypted at rest and collected only with your express consent.
  • Payment information: processed by Stripe. We do not store full card numbers; we retain limited transaction metadata needed to operate bookings and payouts.
  • Technical information: IP address, browser/user-agent, device data, and usage/diagnostic logs used for security, fraud prevention, and reliability.
  • AI information: if AI features are enabled, mathematical representations (embeddings) of certain messages — see Section 12.

3. How We Use Your Information

We use personal information to:

  • Provide, operate, and maintain the Service (accounts, bookings, messaging, payments, calendars, notifications)
  • Send transactional communications (booking confirmations, reminders, receipts, security notices)
  • Send marketing or product-update emails only with your consent (CASL), with an unsubscribe link in every such message
  • Prevent fraud and abuse and keep the Service secure
  • Comply with legal obligations
  • Improve the Service using aggregated, de-identified analytics

We collect only what is needed for these purposes (data minimization) and do not use personal information for materially new purposes without appropriate consent.

4. Legal Basis and Consent

  • PIPEDA / BC PIPA: we rely on your consent (express for sensitive information; implied for routine processing necessary to deliver a service you requested), and on other lawful bases where permitted.
  • CASL: we obtain consent before sending commercial electronic messages and honour withdrawal of consent.
  • GDPR / UK GDPR: our lawful bases are performance of a contract (Art. 6(1)(b)), consent (Art. 6(1)(a)), legitimate interests (Art. 6(1)(f)), and legal obligation (Art. 6(1)(c)). For sensitive data we rely on explicit consent (Art. 9(2)(a)).

You may withdraw consent at any time (subject to legal or contractual restrictions) by contacting us or using in-product controls.

5. How We Disclose Information — Service Providers

We do not sell or rent your personal information. We share it only:

  • With the Artist / Client you are transacting with, as needed to fulfil a booking
  • With service providers who process data on our behalf under contractual and technical safeguards: Stripe (payments); Cloudflare (hosting, storage, security/Turnstile, edge AI); Hetzner (managed database hosting); Apple / Google (calendar sync and maps when you connect them); and email-delivery and error-monitoring providers used to run the Service
  • When required by law — to comply with a valid legal request or to protect the rights, safety, or property of Maelo, our users, or the public

6. Where Your Data Is Stored (Cross-Border Transfers)

Maelo operates globally and uses providers located outside Canada. Your personal information may be stored or processed in the European Union (database hosting), the United States, and other countries via our providers' global infrastructure. While in another country, data may be accessible to that country's courts, law enforcement, and regulators under its laws. We use contractual and technical safeguards (including, where applicable, GDPR Standard Contractual Clauses) to require comparable protection for personal information transferred outside Canada, consistent with PIPEDA and BC PIPA.

7. Data Retention

  • Account and booking data: for the life of your account plus a reasonable period for legal, tax, accounting, and dispute-resolution purposes
  • Payment/transaction records: as required by financial and tax law
  • Technical logs: a limited period for security and diagnostics
  • On account deletion we remove or de-identify personal data across our systems (see data deletion status), except records we must retain by law

8. Security

We protect personal information with administrative, technical, and physical safeguards, including encryption in transit (TLS), encryption at rest for sensitive fields (e.g., waiver submissions, calendar tokens), role-based database access, scoped tenant isolation, and bot/abuse protection. No system is perfectly secure, but we work to protect your data and respond quickly if an issue arises.

9. Your Rights

Subject to applicable law, you have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate or incomplete information
  • Withdraw consent to processing or marketing
  • Delete your account and associated personal data
  • Port your data in a portable format
  • Object to / restrict certain processing (GDPR)

We respond to access and correction requests within 30 days (PIPEDA / BC PIPA). To exercise any right, contact our Privacy Officer (Section 14). You may also complain to:

  • the Office of the Information and Privacy Commissioner for British Columbia (OIPC BC)
  • the Office of the Privacy Commissioner of Canada (OPC)
  • your EU/EEA Data Protection Authority
  • the UK Information Commissioner's Office (ICO)

10. Marketing and Unsubscribe (CASL)

Every marketing email includes an unsubscribe link. You can also email privacy@maelo.app with "Unsubscribe" in the subject. We process opt-outs promptly (within 10 business days as required by CASL). Transactional messages necessary to a booking are not marketing and may still be sent.

11. Cookies and Analytics

We use strictly necessary cookies for authentication and security, and privacy-respecting analytics to understand and improve the Service. We use Cloudflare Turnstile for bot protection. Where required, we obtain consent for non-essential cookies/analytics.

12. Artificial Intelligence

AI Draft Suggestions

Our AI Draft Assistant helps Artists compose replies to Client messages. When enabled:

  • The AI may learn from your communication style to suggest future drafts
  • All processing uses Cloudflare's edge AI infrastructure

Your data is protected:

  • Per-user isolation — your responses are stored in your own private namespace; other users' data never influences your suggestions, and yours never influences theirs.
  • PII stripping — before any learning, we automatically remove email addresses, phone numbers, dates/times, and dollar amounts.
  • No shared training — your data is never used to train models shared with other users or third parties.
  • Opt-out — disable AI learning at any time in Settings → AI Assistant while still receiving suggestions based on your written context.

Receipt Scanning (OCR)

When an Artist uploads a receipt image for expense tracking, we use a vision AI model on Cloudflare Workers AI (Llama 3.2 Vision) to extract details such as vendor, date, amount, and line items. The image and extracted data are stored in the Artist's own account. Cloudflare Workers AI does not retain or train on this data.

Background Generation

Some background images can be AI-generated on Cloudflare Workers AI from a text prompt you provide. Generated images are stored in your account; the prompt is not used to train shared models.

Automated Decision-Making (GDPR Article 22)

Our AI features provide suggestions and extracted data only. They do not make automated decisions producing legal or similarly significant effects; all final decisions remain with you.

AI Data Retention

  • Embeddings are retained while your account is active
  • Disabling learning stops new messages from being processed
  • Account deletion removes associated AI data

13. Children

The Service is not directed to, and may not be used by, anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will delete it.

14. Privacy Officer and Contact

We have designated a Privacy Officer at Maelo App Inc. responsible for compliance with this policy and applicable privacy law (PIPEDA / BC PIPA). Contact: privacy@maelo.app (response time: within 30 days).

15. Breach Notification

If a privacy breach occurs that creates a real risk of significant harm, we will notify affected individuals and the OIPC BC / OPC (and applicable EU/UK authorities) as required by law, and keep records of breaches as required.

16. Changes to This Policy

We may update this policy. If we make material changes we will update the "Last Updated" date and, where appropriate or required, notify you by email or in-app, and seek new consent where needed.


© 2026 Maelo. All rights reserved. | Back to Home | Terms of Service