Privacy Policy
Last updated: 25 May 2026
StageFest is operated by StageSub AB (Sweden, org. nr. forthcoming). We take your privacy seriously and only collect the data needed to make festival planning work. This policy describes what data we collect, why, and your rights.
1. Data we collect
When you use StageFest we process the following categories of personal data:
- Account data: name, email, password (hashed). Required to sign in.
- Profile data (optional): phone number, postal address, instrument, role.
- Festival data: the ensembles, rehearsals, lessons, sheet music, chat messages, and broadcasts you create or are added to.
- Travel & accommodation (optional): arrival/departure dates, hotel info, travel documents you upload.
- Push tokens & device ID: a per-device identifier and Expo push token so we can deliver notifications. Not used for tracking across other apps.
- Purchase data: transaction IDs for in-app purchases (Apple/Google handle the payment itself; we receive only an order receipt for entitlement).
We do not collect location, microphone, camera, contacts, health, or biometric data.
2. Why we use it
- To provide the festival scheduling and communication features you signed up for.
- To deliver push notifications about schedule changes, messages, and broadcasts.
- To enable festival admins to coordinate participants and resources.
- To detect abuse or troubleshoot technical issues.
- To comply with legal obligations (e.g. tax/accounting for paid plans).
We do not use your data for advertising, profiling, or to train AI models, and we do not sell it to third parties.
3. Legal basis for processing
Under the EU General Data Protection Regulation (GDPR Article 6) we rely on the following lawful bases:
- Contract (Art. 6(1)(b)): account data, festival data, push tokens, and purchase entitlements — we need these to provide the service you signed up for.
- Consent (Art. 6(1)(a)): optional profile fields (phone, address, instrument, bio) and the share-contact-info toggle. You decide what to share with other festival participants and can revoke at any time.
- Legal obligation (Art. 6(1)(c)): purchase and tax records, retained for 7 years under Swedish bookkeeping law (Bokföringslagen 7:2).
- Legitimate interest (Art. 6(1)(f)): abuse-prevention logs, security telemetry, moderation records (see section 9), product-usage analytics, and audit trails of changes to your data. We balance these against your privacy rights and only retain what's necessary for safety, fraud prevention, and operating the service.
We do not rely on Art. 6(1)(d) (vital interests) or 6(1)(e) (public task).
3.1 Usage analytics
We collect anonymous usage data — pages and screens visited, features used, session length, platform, approximate browser/OS versions, and counts of standard product events (e.g. opening a festival, generating a schedule). We do not collect form contents, message bodies, sheet music, or any payload data. Your IP address is hashed before storage; we never keep raw IPs.
This data is used to understand how the product is used so we can improve it. Legal basis is legitimate interest (Art. 6(1)(f)). Retention is 90 days, after which events are automatically deleted. You can opt out at any time via Edit Profile → Opt out of usage analytics; the opt-out is honored immediately and applies across web and the native app.
3.2 Audit trail of data changes
We keep an append-only audit log of changes to data we hold on you (e.g. festival membership, contact details, role changes). Each entry records the action, who performed it, when, and what changed. Sensitive fields (phone, email, address, message content) are redacted in the audit log itself — the audit captures thefact of a change, not the sensitive payload. Legal basis is legitimate interest (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c)) for security and accountability. Retention is 2 years.
The audit trail is a security record and is not subject to opt-out. If you exercise your right to erasure (Art. 17), the audit log retains a pseudonymised reference to you (Art. 17(3)(b/e) exemption for legal obligation and public interest) so the historical record remains coherent.
4. Who can see your data
- Within a festival: admins of a festival see the participants and schedule. Other musicians see only the data relevant to ensembles they belong to. Contact details (phone/email) are hidden by default — each user controls whether to share them via the profile setting.
- Service providers (data processors):
- Supabase (Frankfurt, EU) — database, authentication, file storage.
- Expo / EAS — push notification delivery.
- Apple / Google — in-app purchases (you transact directly with them).
- Vercel — web hosting for the admin console.
- Anthropic — AI-assisted parsing of admin notes (web only). Only the text you submit is sent; not stored or used for training.
- Postmark (US) — transactional email delivery (invitation emails, UGC moderation reports, support acknowledgements). Receives recipient email address, sender name, festival name, and message body. Used only to deliver the email; not for marketing.
- Sentry (Germany, EU) — crash & error diagnostics from the mobile app. Receives stack traces, device model, OS version, and a randomly-generated install identifier. Does not receive your email, phone, address, or message content. We use this only to fix bugs.
5. How long we keep it
Data is retained for as long as your account is active. When you delete your account all personal data is removed within 30 days, except where law requires us to keep certain records (e.g. accounting records for 7 years under Swedish law).
6. Your rights (GDPR)
You have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Request deletion ("right to be forgotten").
- Export your data in a machine-readable format.
- Object to or restrict our processing.
- Lodge a complaint with the Swedish Authority for Privacy Protection (IMY).
To exercise any of these, email us at privacy@stagesub.app.
7. Security
Data is transmitted over HTTPS and stored encrypted at rest in Supabase's EU infrastructure. Access is restricted via row-level security policies tied to your festival memberships. We do not have access to passwords (only salted hashes).
8. Children
StageFest is intended for users aged 16 and older. Younger users may participate in festivals through a guardian admin who manages their participation on their behalf; we do not solicit accounts from minors directly.
9. Content moderation
StageFest includes user-generated content — primarily chat messages, broadcasts, and sheet-music uploads exchanged between festival participants. We take an active role in keeping these spaces safe.
Reporting. Every chat message can be reported via a long-press (mobile) or right-click (web) on the message. The report goes directly to StageFest support and includes the reported content, the reporter's identity, and an optional reason. We aim to review and act on reports within 24 hours.
Blocking. You can block another user from any message they sent. Blocked users' messages disappear from your view and they can no longer message you. Blocks are private — the other user is not notified.
What we don't tolerate. Sexual content of any kind (including nudity and explicit material), threats of violence, harassment, hate speech, doxxing, spam, illegal content, or impersonation of others. Accounts that post such content are suspended on first report and may be permanently terminated. Sexual content involving minors (CSAM) is additionally reported to relevant authorities (NCMEC for the US, national CSAM hotlines for the EU).
Festival admins can moderate the chats they are part of. Ensemble group chats are private to their members: an admin only sees an ensemble chat while they have joined it (and you are notified when an admin joins or leaves), so moderation of those chats is primarily report-based. StageFest acts as the platform-level moderator and reviews every report regardless of which chat it came from — contact us directly at support@stagesub.app.
10. Changes to this policy
We may update this policy. If we make material changes we will notify active users by email or in-app message. The "Last updated" date at the top reflects the most recent version.
11. Contact
Questions? Contact us at support@stagesub.app or via mail at StageSub AB, Sweden.