Your privacy
East Coast Worldwide Studios respects your privacy. This page explains, in plain language, what information we collect, why, who we share it with to run the studio, and the choices you have.
Last updated: July 30, 2026
East Coast Worldwide Studios, Inc. is a tattoo, body-piercing, laser tattoo-removal, and fine-jewelry studio located at 8833 Perimeter Park Blvd, Suite 501, Jacksonville, FL 32216. In this policy, "we," "us," and "the studio" mean East Coast Worldwide Studios. "You" means anyone who visits our website, contacts us, books with us, shops with us, or comes into the studio.
This policy covers our public website (eastcoastworldwide.com and its subdomains, including our online jewelry shop), our booking and payment flows, and the data we handle as a business. If you have any questions, email us at [email protected].
We only collect what we need to provide our services, run appointments, take payment, meet our legal obligations as a body-art studio, and stay in touch with you.
| Appointment bookings | When you book online, we collect your name, email, phone
number, the service you want, your appointment details, and — where the law sets a minimum
age for a piercing — the age of the person receiving the service. Bookings are handled by
our scheduling provider, Bookeo, and on East Coast Worldwide's own secured
booking system, which also records the booking policies you accept (for example the
non-refundable-commitment acknowledgment) with a timestamped copy of the exact text you
agreed to.
If you reschedule or cancel an appointment yourself online, we record that agreement the same way: the exact wording you confirmed, the amount of any fee it covers, the version of our booking terms in force, the date and time, your IP address and the device/browser you used — as evidence of the electronic agreement (Fla. Stat. § 668.50). We keep these records so that we can show, if a payment is ever queried with your bank, precisely what you were shown and agreed to. You remain bound by the version of our terms you accepted — if we update them later, your existing appointment keeps the terms you agreed to, and the exact text stays viewable in your booking portal and at a permanent link. |
|---|---|
| Payments & deposits | Online deposits, gift-card purchases, and card payments are processed by Stripe. In the studio, in-person sales and gift cards run through our point-of-sale system, Lightspeed. If you choose to keep a card on file to reserve an appointment, the card is saved directly with Stripe and we store only a reference to it — we do not store full card numbers; our payment processors handle card data directly. |
| Consent forms & waivers | Before a tattoo, piercing, or laser session you complete a digital consent form and waiver through Smartwaiver. These capture the information required by law and for your safety — name (including middle name), date of birth, ID/age verification (including your driver's-license or state-ID number and issuing state, when provided on the waiver), health-screening answers, the procedure, and your signature. Completed waivers are also imported into and retained on East Coast Worldwide’s own secured systems and linked to your customer record, so staff can confirm a current waiver is on file and correctly identify returning clients; license numbers are stored encrypted. When you sign a waiver or notarization on one of our own devices or your own, we also record the date and time, the IP address, and the device/browser you signed with, as evidence of the electronic signature (Fla. Stat. § 668.50). We do not track your precise location. |
| Jewelry shop browsing | Our online jewelry shop lets you browse in-stock pieces. Browsing is read-only — there is no checkout — so we don't collect personal information just because you look at it, beyond ordinary website logs and cookies (below). |
| Contact & quote forms | When you send a message, request a custom-jewelry or engagement-ring quote on our Custom Jewelry page, or apply for a job, we collect what you put in the form — typically your name, email, phone, and your message or portfolio link — so we can respond. If you apply for a job you may also choose to upload a resume or CV; job applications and any uploaded resume are stored on our own secured systems (we keep promising applicants on file) and are seen only by management. |
| Email signups | If you join our newsletter, we collect your name and email to send studio news and offers. You can unsubscribe at any time. |
| Site feedback | If you use the "Spotted a problem?" feedback form, we collect your message and the page you were on, plus your name and email only if you choose to provide them (so we can reply). It goes to management to improve the site. |
| Phone calls & voicemail | When you call the studio, our phone system shows us the caller's number (caller ID) and we may match it to an existing customer record so we can serve you faster. We keep a log of calls — the date and time, whether it was incoming or outgoing, how long it lasted, and whether it was answered — and where the number matches a customer record, authorized staff can see that history alongside your other contact with us. This log goes back several years. Where a number belongs to more than one person (a shared household or work line) we do not guess which of you called; the call is shown as a possible match on each record and labelled as such. We do not record the audio of ordinary calls. If you leave a voicemail, we keep the recording and caller ID, and authorized staff can listen to it inside our private staff portal. Voicemails may be automatically transcribed to text (via an AI transcription service) so staff can read them; a transcript is treated like the recording and deleted with it. Voicemails are deleted when no longer needed. |
| Website usage | Like most websites, our servers automatically log basic technical data — IP address, browser type, the pages you view, and the date/time — to keep the site secure and working. |
| Staff portal (employees) | We run a private, login-protected staff portal for our
team. It holds employee information — schedules, sign-offs, payroll and commission data,
contact details, and professional-credential and identity records (for example, a staff
member's tattoo license or CPR card, and — for their government photo ID — images of the ID
(front and back), the driver's-license number stored encrypted, and the
license address, kept as employment records). For team members engaged through a business
(an LLC), it also holds the W-9 they upload and the business details on it —
business name, federal tax classification, business address, and the employer identification
number (EIN) stored encrypted. Staff addresses include both a mailing address
and the address where they live.
Team members can also complete and sign their IRS Form W-9 in the portal. That record holds the name, business name, federal tax classification and address they enter, their taxpayer identification number (SSN or EIN) stored encrypted and only ever displayed with the digits masked, their typed name and drawn signature, and — as evidence of the electronic signature — the date and time, IP address and device used to sign. The portal also holds a records archive — the studio's historical business and employment documents, moved into the portal so they are held in one access-controlled place rather than a shared cloud folder. For team members past and present this can include signed contracts and confidentiality agreements, W-9s, direct-deposit authorizations, images of a government photo ID, professional licenses and health certifications, and copies of the tax forms we filed for them (such as a Form 1099-NEC or W-2), which carry a taxpayer identification number. It also holds the studio's own business records — tax returns, payroll tax filings and state tax correspondence. Every document in this archive is visible only to management by default; a document is shown to the team member it concerns only after a manager has reviewed it and chosen to share it, and documents concerning former team members remain management-only. These are retained as employment and tax records for as long as the law requires. The completed form is generated as a PDF and stored privately. A replaced W-9 is kept rather than deleted, because tax forms we already relied on have to stay reproducible. The portal also holds annual training records: for each required training a team member completes, we keep when they started and finished reading it, the exact version of the training text they read, their typed name and drawn signature, and the date/time, IP address and device used to sign — plus the certificate PDF generated from it, which we may show to a Department of Health inspector. Training signatures and certificates are stored privately. This is internal employee data, not part of the public website; it is restricted to authorized staff and management, and does not apply to customers. |
We do not sell your personal information. We share it only with the service providers we use to operate the studio, and only as needed for them to do their job for us:
| Bookeo | To schedule and manage your appointments. |
|---|---|
| Stripe | To securely process online payments, deposits, and gift cards. When you buy a gift card on our website, your card details go directly to Stripe (they never touch our server); we keep the purchase details — your name and email, the recipient's name and email if you send it as a gift, your gift message, and the card number we issue — so we can deliver the certificate and look it up for you later. |
| Moov | Our payments provider for staff payroll direct deposit. We send a staff member’s bank-account details to Moov so their pay can be deposited. This applies to our team only — not to customers. |
| Lightspeed | Our in-studio point-of-sale — to process in-person sales and track products and gift cards. |
| Smartwaiver | To collect and store your digital consent forms and waivers. |
| Anthropic (Claude AI) | To automatically read documents our business uploads — vendor receipts/invoices, our own staff members' professional credentials (e.g. a tattoo license or CPR card), and a staff member's W-9 when they are engaged through a business — so we can extract dates, figures and business details. This is used for business and staff records; we do not send customer personal information to Anthropic. |
| ClickSend | To send you text messages about your appointments and visits — booking confirmations and cancellations, appointment reminders, aftercare follow-ups, and our post-visit survey. We send your name, phone number, and the message text to ClickSend for delivery. Reply or contact us any time to stop receiving texts. |
| SMTP2GO | To deliver the emails we send you (appointment reminders, receipts, follow-ups, and other studio communications). |
| Your online account ("my" link) | If you ask us for a private link to your account, we email it to the address we already hold for you. Signed in that way you can see your own appointments, your purchase history, your store credit and the messages we've sent you, and you can send us a message or upload a reference photo for a tattoo or laser project. Reference photos you upload are stored privately — they are not published, not shared outside the studio, and only you and our staff can open them. You can delete an upload yourself until your artist has looked at it. The link is a key to your own account, so please don't forward it. |
| Zendesk | Our customer-support helpdesk. Email you send to our support address is received and stored there, so anything you write to us — your name, email address, and whatever your message describes — is held by Zendesk on our behalf. Our own historical staff records were also filed there and may name the customers a team member served on a given day, along with the service and its price. |
| Our Google Business Profile (maps, reviews, hours) and Google Analytics (GA4), which uses cookies to help us understand how the site is used (pages visited, general location, device) so we can improve it. Google is also offered as a way of signing in — to our staff for the internal staff portal, and to customers for their own account page. When you sign in with Google, Google confirms to us that you control a particular email address. If you choose to connect a Google account (staff or customer), we store that account's identifier and the email address Google verified for it so we can recognise the same account next time; the connection can be removed at any time from your account's security page, and we email you whenever a sign-in method is added or removed. | |
| Meta (Facebook & Instagram) | For our social-media presence and to display and manage our posts. See "Social media" below. Facebook may also be offered to our staff as a way of signing in to our internal staff portal, in which case Facebook confirms to us that the team member controls a particular email address. Employees only — not customers. |
| Review platforms (Google, Facebook, Yelp) | We retrieve the public reviews and ratings customers have posted about us on these platforms and display a selection of them (reviewer first name/display name, rating, and review text as publicly posted) on our website's Reviews page. We only display content that is already public on those platforms; to change or remove a review, edit or delete it on the platform where you posted it and it will drop off our site on the next refresh. |
| Email providers | To send appointment, newsletter, and transactional emails on our behalf. |
| Cloudflare | Our website’s network and security layer. When you submit the website feedback form or the custom-jewelry quote form, Cloudflare’s Turnstile anti-spam check receives your IP address and basic browser signals to confirm you’re a real person and block automated spam. |
| EasyPost | To track shipments related to your order. We send shipment tracking numbers to EasyPost, which retrieves delivery status from the carrier (USPS, UPS, FedEx, DHL) so we can keep your order updated. |
We may also share information when the law requires it (for example, age and health records required of body-art establishments, or a lawful request), or to protect the safety and rights of our customers, staff, and the studio.
We maintain Facebook and Instagram accounts to showcase our work. From time to time we re-share (repost) public content from the Instagram accounts of our affiliated artists and jewelry vendors, always with credit to the original account. We only repost content that is already public, and we credit the source. If you are an artist or vendor and would like a post removed or credited differently, email [email protected].
Our website uses cookies and similar technologies to keep the site working (for example, to keep you logged in where applicable and to keep the site secure) and to measure general traffic. We use Google Analytics (GA4), which sets cookies to measure visits and how the site is used. Some embedded features — such as map, review, and social widgets — may set their own cookies. You can control or block cookies in your browser settings; some parts of the site may not work as well if you do.
We keep your information only as long as we need it for the purpose it was collected, and as long as the law requires. Consent forms, waivers, and health records are kept for the period required of body-art establishments. Booking and payment records are kept for our business and tax records. You can ask us to delete information we are not legally required to keep (see "Your choices and rights").
We use industry-standard safeguards to protect your information: encrypted (HTTPS) connections, access controls that limit data to authorized staff, and reputable service providers (such as Stripe and Smartwaiver) that handle sensitive data on certified systems. No system is perfectly secure, but we take reasonable steps to keep your information safe.
You can:
To make any of these requests, email [email protected] and tell us what you'd like. We may need to verify your identity before acting on a request.
Our website and services are intended for adults. Tattoos are performed only on 16–17-year-olds with a parent/guardian present and full notarized consent; certain piercings are available to minors only with a parent or legal guardian's notarized consent (and, under 16, accompaniment), as required by Florida law. We do not knowingly collect information from children online except where a parent or guardian provides it as part of a minor's appointment and consent.
When a minor receives a piercing (any age) or a tattoo (16–17), Florida law requires a notarized parental consent on the state Department of Health forms. A parent or guardian may enter the consent details ahead of time, and a commissioned notary on our staff completes and electronically notarizes the form in person. To do this we collect: the minor's name and date of birth; the parent/guardian's name, address, and signature; the piercing or tattoo description; the type of identification the notary relied on and, in our internal notarization log, optionally the ID number and expiration; and, for a tattoo, the document shown as proof of the parent/guardian relationship. We verify a photo ID by scanning its barcode to read the date of birth and expiration — the ID image itself is never stored. The completed, notarized consent (a tamper-evident sealed PDF) and a notarization journal are retained on our own secured systems, linked to the customer record and the transaction, and kept for the period Florida law requires (and typically longer). These records are available to the Department of Health on inspection.
As the studio grows and we add new features or services, we may update this policy. When we do, we'll change the "Last updated" date at the top of this page. Significant changes may also be noted on the site.
Questions about your privacy or this policy? We're happy to help.
East Coast Worldwide Studios, Inc.
8833 Perimeter Park Blvd, Suite 501
Jacksonville, FL 32216
904.685.6516
[email protected]
Last updated: July 22, 2026.
Tell us what's wrong or what we could do better. Name & email are optional — add them only if you'd like a reply.