This privacy policy explains what personal data stageworks processes, why, and what rights you have. It applies to the website and app at stageworks.ai. We wrote it to comply with the EU General Data Protection Regulation (GDPR) and with the privacy laws of the United States, including the California Consumer Privacy Act (CCPA/CPRA) and the California Online Privacy Protection Act (CalOPPA).
1. Who we are
stageworks is run by Luie Hond, Scaldisstraat 92, 9040 Gent, Belgium, enterprise number 0773847291. We are the controller of your personal data.
For any question about privacy or to exercise your rights, email [email protected]. We do not have a data protection officer because the law does not require one for a service of our size.
2. What data we process
Account data
- Your name and email address, and whether your email address is verified.
- The identifier that our login service Auth0 gives your account, and which login methods you use (email and password, Google or Facebook). If you log in with Google or Facebook using the same email address as your account, we link that login to your account.
- Your preferred language.
- If you fill them in: your country, city, the instruments you play, what you do and your technical and organisational skills. Members of your bands see them.
- If you fill them in: practical information for shows, namely your licence plate and vehicle, your food preferences (vegetarian, vegan or pescatarian, and other food wishes in your own words) and your clothing size. Only owners and admins of your bands see it. For a show you play, they can show your licence plate and food preferences on the share link of that event, so the organiser can arrange parking and catering. Do not add medical information such as allergies.
- The bands you save, for example to find their riders again. Bands do not see who saved them, and saving a band does not make you a member.
- Your profile photo, if you upload one or log in with Google or Facebook. We crop and resize every photo and remove its metadata, such as the place where it was taken.
When you log in with Google or Facebook
If you choose to log in with Google or Facebook, that company shares your name, email address, profile identifier and profile photo with Auth0, and Auth0 passes your name, email address, account identifier and a link to your profile photo on to us. We save a copy of that photo on our own server, so the app never loads it from Google or Facebook. If you upload or remove a photo yourself, we stop using the one from Google or Facebook. We do not receive your password, your friends list, your posts or any other data from those accounts, and we never post anything on your behalf. Google and Facebook process your data under their own privacy policies.
Band data
- The bands (artists) you create or join, your role in each band, the instruments you play in each band if owners or admins fill them in, and requests to change roles.
- Members who have not joined yet: the name a member entered and, if they are invited by email, their email address and who sent the invitation and when, and the instruments they play in the band if a member fills them in.
- Who can play at a show: each member's answer (can, can't or maybe) and an optional note. For a booking request with several proposed dates, members answer per date.
- Events you or your bandmates add, such as gigs: name, venue and address, country and, for a country with several time zones, the time zone, date and time, a link to an external page, whether the show is public or private, whether it is confirmed and published, internal notes; the contact person of the band and of the organiser (name, email address, mobile number, and for the organiser their address and how they prefer to be contacted) and the contact person on the day; the run sheet; location details (the address for the band, a Google Maps link, a site plan, notes about loading and parking, and details of the band's vehicles); technical and stage details (such as the sound company and the stage size); hospitality; the fee, whether it includes VAT and what it includes, the payment methods and terms, the deposit with its due date and when it was received, and the customer the invoice goes to; files uploaded for the event and files from the vault shared on it; and a timeline of notes with who wrote them and when.
- Booking requests that you or your bandmates add: the organiser's contact person, organisation, email address and phone number, the requested event and venue, the country and, for a country with several time zones, the time zone, one or more proposed dates, each with a time, the proposed and agreed fee, the original request, the status, and a timeline of notes and status changes with who made them.
- Customers that owners and admins of a band add or import, to send the invoice for a fee to: whether the customer is a private person or a company, the name, the contact person of a company, email addresses (also a separate one for invoices), phone number, VAT number, company registration number and Peppol ID, the address, notes, and the events the customer is linked to. Customers belong to one band and are not shared with other bands. Owners and admins can export them to a CSV file.
- Files uploaded to a band's file vault, with their name, type, size, who uploaded them and whether they may be shown on the band's public page.
- The band's photo, its country, city and genres, and links to its website and social media, if an owner adds them.
What members of a band see depends on their role. Owners and admins see all band data. Members see the calendar, events without fees, deposits, customers, invoice and payment details or the timeline of notes, which dates are on hold (without details about the request), and who is in the band. When owners or admins ask who can play at a show, they get a link to share with the band. Anyone with that link sees the date, time and place of the show, the name of the event or, for a booking request without an event name, the organisation or contact person of the organiser, and the first name, the initial of the last name, the profile photo, the answer and the note of every member, and can answer for every member. Owners and admins can also change any member's answer in the app. When owners turn on the band's public files page, anyone with its link can see and download the files marked as public, with their name, type and size. When owners or admins turn on the share link of an event, anyone with that link sees the name, date, time and address of the event, the run sheet, the contact person on the day, the contact person of the band, the location, technical and hospitality details, and the files shared on it, and, if owners or admins turn it on, the first name and initial, licence plate and vehicle and/or food preferences of the members who said they can play, but never fees, payment details or internal notes. When owners turn on the band's public events page, anyone with its link can see the name, date, time, venue and city of the upcoming events marked as published, without fees or notes. When owners or admins turn on the band's calendar link, every member of the band can see, copy and share it, so they can subscribe to it in a calendar app of their choice (such as Google Calendar, Apple Calendar or Outlook). Anyone with that link, and the calendar app that fetches it, sees the name, venue, city, date, time and status (confirmed or option) of the band's events from the last 6 months onwards, and the proposed dates of booking requests on hold, shown only as "Date on hold" with the city, but never fees, contact details or notes. Only add information about other people (for example a venue contact in a note, an organiser in a booking request, or a customer) when you are allowed to share it. Organisers, customers and people invited by email whose details a band adds can contact us to exercise their rights (see section 7).
When you send a booking request through a band's request form
A band can open a public request form. If you use it, we receive your name, email address and the date you ask for, and the other details the band asks for: your organisation, phone number, event name, venue and city, country (and time zone), time, proposed fee and your message. We store them as a booking request for that band. Its owners and admins can see the request and get an email about it, and we email you a copy. To stop spam, we use your IP address to limit how many requests can be sent from it.
When you connect an AI assistant
Owners and admins can connect an AI assistant, such as Claude or ChatGPT, in Settings → AI assistants. The assistant registers with us, and you log in to stageworks and agree. We then store the name of the assistant and the web address it returns to, and, with your account, the access and refresh tokens we give it, what they allow and when they expire. We do not keep what you ask the assistant.
When you ask the assistant something, it fetches the data it needs from the bands where you are an owner or admin: events and booking requests, including fees, deposits, the contact details of organisers, notes, and the names of band members who can play or who wrote a note. It can also add and change events and booking requests, and add notes, in your name: these show in stageworks as added by you. It cannot delete anything, or accept or decline requests.
Technical data
- Session data: your IP address, browser (user agent) and the time of your last activity, so you stay logged in securely.
- Server logs and error reports, which can contain your IP address, the page you visited and technical details about an error.
Analytics
Only if you accept analytics cookies in the cookie banner, we use Google Analytics to see how stageworks is used: which pages are visited and for how long, the type of device and browser, and from which country or region. Google Analytics gives your browser a random identifier in a cookie. It uses your IP address to estimate your country or region, but does not store it.
We turned off Google signals and ad personalisation, so this data is not used for advertising. Without your consent, Google Analytics is not loaded at all. We do not use advertising or other tracking tools, and we do not build profiles of you.
3. Why we use your data, and on what legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating and running your account, logging you in | Performance of our contract with you (art. 6(1)(b)) |
| Providing band features: events, booking requests, members, roles and files | Performance of our contract with you (art. 6(1)(b)) |
| Emailing an invitation to someone a member invites to join their band | The legitimate interest of the band, and ours, in letting bands invite new members (art. 6(1)(f)) |
| Receiving booking requests through a band's request form, and emailing the band and you about them | The legitimate interest of the band, and ours, in handling booking requests (art. 6(1)(f)) |
| Storing the contact details of organisers that a band adds to a booking request | The legitimate interest of the band, and ours, in handling booking requests (art. 6(1)(f)) |
| Storing the details of customers that a band adds or imports, to invoice them | The legitimate interest of the band, and ours, in invoicing its customers (art. 6(1)(f)) |
| Service emails, such as confirming that you want to delete your account or change a role | Performance of our contract with you (art. 6(1)(b)) |
| Security, preventing abuse, fixing errors and keeping the service available | Our legitimate interest in a safe and working service (art. 6(1)(f)) |
| Measuring how stageworks is used with Google Analytics, so we can improve it | Your consent (art. 6(1)(a)), which you can withdraw at any time (see section 8) |
| Giving an AI assistant that an owner or admin connects access to their bands' events and booking requests | Performance of our contract with that owner or admin (art. 6(1)(b)), and for the data of other people the legitimate interest of the band in managing its bookings with the tools it chooses (art. 6(1)(f)) |
| Handling your questions and requests to exercise your rights | Legal obligation (art. 6(1)(c)) and our legitimate interest (art. 6(1)(f)) |
You can object to processing based on our legitimate interest at any time (see section 7). We do not make decisions about you based solely on automated processing.
4. Who we share data with
We never sell your data. We only share it with service providers that help us run stageworks, under a data processing agreement:
- Okta (Auth0) handles logging in. Your account is stored in the EU region.
- DigitalOcean hosts our servers, database and uploaded files in Amsterdam.
- Cloudflare protects and speeds up the website. All traffic to stageworks.ai passes through Cloudflare.
- Sentry collects error reports so we can fix bugs. We configured it not to send personal details such as names or email addresses on purpose, but an error report can contain an IP address or technical data.
- Resend sends our service emails, including the invitations that members send and the emails about booking requests sent through a request form.
- Google (Google Ireland Limited) provides Google Analytics, only if you accept analytics cookies.
Google and Facebook only receive data when you choose to log in with them. Other members of your bands see your name, email address, profile photo and role, and, depending on their role, what you add to the band. We may disclose data when the law requires it, or to protect our rights or someone's safety.
If you connect an AI assistant, the data it fetches goes to the company behind it, such as Anthropic for Claude or OpenAI for ChatGPT. You choose that company, not us: it is not our service provider, and it processes the data under its own terms and privacy policy. Depending on your settings there, it may keep your conversations or use them to improve its models. Only connect an assistant that you trust with the data of your bands.
Transfers outside the EU
Some of these providers are based in the United States or can access data from there (Cloudflare, Okta, Sentry, Resend and Google). We only use providers that are certified under the EU-U.S. Data Privacy Framework or that have signed the European Commission's Standard Contractual Clauses. You can ask us for a copy of the safeguards.
An AI assistant that you connect may process data in the United States or elsewhere outside the EU. That transfer happens at your request, under the terms of the company behind the assistant.
5. How long we keep data
- Account data, including the bands you saved: as long as you have an account. A saved band is removed when you remove it or the band is deleted. When you delete your account, we delete it straight away, including your profile photo and your account at Auth0. A photo you replace or remove is deleted straight away too.
- Band data: as long as the band exists, or until an owner or admin deletes it. When an owner or admin deletes an event, we delete it straight away with its files, notes, timeline and availability answers, and its share link stops working. When they delete a booking request, we delete it with its notes and availability answers. An event created from a request, or the request an event came from, stays. When an owner or admin deletes a customer, we keep it as deleted, so it can be restored and stays on the events it was linked to, until the band is deleted. When you leave a band, an owner removes you from it, or you delete your account, events, booking requests, customers and files you added stay with the band, because they belong to the band. Your name is then no longer shown next to the notes you wrote in a booking request or in the timeline of an event, or next to the booking requests you added. A band whose only member deletes their account is deleted with everything in it.
- The band's calendar link: until an owner or admin makes a new link or turns it off, or the band is deleted; then the old link stops working. When someone leaves the band, is removed from it or deletes their account, owners and admins get an email asking them to make a new link.
- Members who have not joined yet: until they join, a member removes them, or the band is deleted. The link in an invitation stops working after 7 days.
- Availability answers: until the event or request they belong to, or the band, is deleted, or the member leaves or is removed from the band.
- Sessions: until 120 minutes after your last activity. If you choose to stay logged in, a login cookie is kept until you log out, for at most about 400 days.
- Connections with AI assistants: an access token is valid for 1 hour and a refresh token for 30 days. When you disconnect an assistant, its tokens stop working straight away. We delete revoked tokens within a day and expired tokens within 8 days. When you delete your account, we delete its tokens straight away.
- IP addresses used to limit requests through a request form: at most 1 hour.
- Server logs: at most 14 days.
- Error reports: at most 90 days.
- Analytics data: at most 2 months in Google Analytics. The Google Analytics cookies expire after at most 2 years. When you withdraw your consent, we remove them from your browser.
- Your choice in the cookie banner: 12 months, then we ask again.
- Emails about your privacy requests: as long as we need them to show that we handled your request, and no longer than 5 years.
6. Security
All traffic is encrypted with HTTPS. Access to our servers is limited and protected with keys, passwords are handled by Auth0 and never reach us, and sensitive actions such as deleting an account need a confirmation link sent by email. No system is perfectly secure. If a data breach is likely to put your rights at risk, we will tell you and the supervisory authority as the law requires.
7. Your rights
Under the GDPR you have the right to:
- access your data and get a copy of it;
- rectify data that is wrong or incomplete (you can change your name and language yourself in Settings);
- erasure of your data (see Deleting your data);
- restrict how we process your data;
- data portability: receive your data in a structured, machine-readable format;
- object to processing based on our legitimate interest.
Email [email protected] to use these rights. We answer within one month and may ask you to confirm your identity first. It is free, unless a request is clearly unfounded or excessive.
You can also file a complaint with a supervisory authority. In Belgium this is the Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), Drukpersstraat 35, 1000 Brussels. If you live in another EU country, you can contact the authority there.
8. Cookies
We use cookies that are strictly necessary for stageworks to work. They do not need your consent:
- a session cookie that keeps you logged in during your visit;
- a security cookie (XSRF-TOKEN) that protects forms against forgery;
- a login cookie that keeps you logged in, if you choose to stay logged in;
- a cookie (cookie_consent) that remembers your choice in the cookie banner for 12 months.
Only if you accept them in the cookie banner, we also use analytics cookies from Google Analytics (_ga and _ga_ followed by an identifier). They expire after at most 2 years.
Your choice applies to the whole website, also after you log in. You can change it at any time with Cookie settings at the bottom of the home page or of this page. If you withdraw your consent, we remove the analytics cookies.
Your light or dark mode choice is saved in your browser's local storage and never sent to us. Cloudflare can set a strictly necessary security cookie to block malicious traffic. We do not use advertising or social media cookies. Our fonts are hosted on our own server.
9. Children
You must be at least 13 years old to use stageworks. stageworks is not aimed at children under 13, and we do not knowingly collect their data. If you think a child under 13 has given us personal data, contact us and we will delete it.
10. Information for residents of the United States
This section applies to residents of California and other U.S. states with consumer privacy laws, such as Colorado, Connecticut, Virginia, Utah, Texas and Oregon.
In the last 12 months we collected these categories of personal information, from you directly or through the login service you chose, for the purposes in section 3:
- Identifiers: name, email address, account identifier, IP address, the contact details of organisers that bands add to booking requests or that organisers send through a request form, the contact details of customers that bands add, and the email addresses of people that bands invite.
- Visual information: your profile photo.
- Commercial information: event fees, deposits and booking request fees that your band records, and the customers it invoices.
- Internet or other electronic network activity: session, log and error data, and, if you accept analytics cookies, how you use stageworks (see section 2).
- Professional information: the bands you are part of, your role in them and the instruments you play in them.
We disclose these categories only to the service providers listed in section 4, for business purposes. We do not sell or share personal information, we do not use it for cross-context behavioral advertising, and we do not collect or use sensitive personal information to infer characteristics about you. We have not done so in the last 12 months. If you connect an AI assistant, it receives the personal information it asks for at your direction (see section 4).
Depending on where you live, you have the right to know what personal information we collect, use and disclose; to access it and get a copy; to have it corrected; to have it deleted; and to opt out of sale, sharing, targeted advertising and profiling (which we do not do). We will not discriminate against you for using these rights. To make a request, email [email protected]. We verify your request by checking that it comes from the email address of your account. You can let an authorized agent make a request for you, with your signed permission. If we refuse your request, you can appeal by replying to our answer. We will respond to your appeal within the time the law requires, and if you disagree you can contact your state's attorney general.
Do Not Track and Global Privacy Control. We do not track you across websites, so there is nothing to switch off. We treat a Global Privacy Control signal as a valid request to opt out of sale and sharing. Browsers' Do Not Track signals have no effect. We only use Google Analytics if you accept it in the cookie banner, without advertising features.
11. Deleting your data
You can delete your account and data yourself at any time:
- Log in to stageworks.
- Go to Settings → Danger zone and choose to delete your account.
- Open the confirmation email we send you and confirm.
We then delete your account, your login at Auth0 and every band that you are the only member of. If you are the only owner of a band that has other members, first make another member owner. Content that you added to bands that still have other members stays with those bands. AI assistants you connected are disconnected.
Can't log in any more, or did you log in with Facebook or Google? You can also ask us to delete your data by emailing [email protected] from the email address of your account. We delete it within 30 days and confirm when it is done. Removing stageworks from the apps in your Facebook or Google settings stops future data sharing, but does not delete the data we already have. To do that, use one of the options above.
12. Changes to this policy
We update this policy when stageworks changes the way it handles personal data. The date at the top shows the latest version. We will let you know by email or in the app before an important change takes effect.