Vishar CRM
Privacy notice.
How the private CRM handles Meta account connections, WhatsApp and Instagram service communications, and related client records.
Who operates the service
Vishar CRM is operated by Vishar Tattoo Limited for authorised tattoo artists and booking staff. It is a private workspace used to manage tattoo enquiries, client communication, appointments and related service records.
Questions or data requests can be sent to [email protected].
Meta account connections
An authorised artist may choose to connect a WhatsApp Business account or Instagram professional account through Meta. Meta provides an authorisation result and the account identifiers required to verify that the selected account belongs to that artist.
The browser does not choose the final artist route. Vishar CRM verifies the signed provider identity, the selected WhatsApp Business Account or Instagram professional account, and the artist's CRM permissions before a connection is accepted.
Provider access tokens, app secrets and signing credentials are kept in encrypted Cloudflare Worker secrets or a separately encrypted server-side token store. They are not stored in the browser or in CRM-readable Postgres records, and they are never exposed to other artists.
Information processed
When a connected client sends a service message, the CRM may process the provider account identifier, message identifier, sender name or handle, phone number where supplied by WhatsApp, message text, timestamps, delivery status, referral context and attachment type. Provider media links are temporary and are not retained as permanent public URLs.
The CRM also stores the artist-owned conversation, replies sent by authorised staff, internal status and a content-limited activity record. Activity records identify the channel, conversation and action without creating a second copy of message content or participant identifiers.
Why the information is used
The information is used to answer tattoo enquiries, discuss projects, arrange consultations and appointments, provide booking-related service communications, maintain reliable conversation history, prevent duplicate delivery and protect the service from unauthorised routing.
It is not sold, used for unrelated advertising or shared between artists. Marketing messages require a separate positive marketing choice and are not inferred from an enquiry or provider connection.
Access and artist separation
Only active CRM users with permission for the relevant artist can see or act on that artist's conversations. Database authorisation and artist membership checks enforce this separation. Hiding a control in the interface is not treated as the security boundary.
Unknown, disabled, mismatched or ambiguous provider accounts are rejected. The service does not fall back to a default artist when a WhatsApp or Instagram route cannot be resolved safely.
Service providers and international processing
Meta provides WhatsApp, Instagram, authentication and provider messaging services. Cloudflare hosts the private edge services and encrypted credential bindings. Supabase provides the authoritative CRM database and private storage. These providers process only the information needed to deliver and secure the service under their applicable terms and data-protection arrangements.
Cloud providers may process or support data outside the UK. Where UK personal data is transferred internationally, the service relies on the provider's applicable UK transfer mechanism, such as adequacy regulations or contractual safeguards.
Retention and security
Conversation and enquiry records are retained while needed to respond, arrange and complete the requested work, maintain necessary business records, resolve disputes or meet legal obligations. Credentials are removed or replaced when an integration is disconnected or reauthorised.
The service uses encrypted server-side credential storage, short-lived authenticated sessions, artist-scoped database access and provider signature checks. No internet service can promise absolute security, but access and stored data are deliberately limited to what the workflow needs.
Access, correction and deletion
To request access, correction, restriction, disconnection or deletion of information associated with Vishar CRM, email [email protected]. Include the artist or business name and the WhatsApp number or Instagram account involved so the correct workspace can be identified without collecting unnecessary information.
A connected artist can also ask for the Meta integration to be disconnected. The request will be verified before credentials and connection records are removed. Some limited records may be retained where required for a legal obligation or to establish, exercise or defend a legal claim.
Depending on the circumstances, UK GDPR rights can include access, correction, erasure, restriction, portability and objection. You can also complain to the UK's Information Commissioner's Office at ico.org.uk/make-a-complaint.
Changes to this notice
This page will be updated when the Meta connection or data-handling workflow changes materially. The date below identifies the current published version.
Last updated: 1 September 2026.