Privacy Policy

What data we hold, why, and how to get it back or have it deleted.

Last updated 2026-05-06

Placeholder template. Have a solicitor review and replace before you take real customers, especially for GDPR / UK GDPR compliance.

1. Data controller

Stagers Hub, contact support@stagershub.com. If we appoint a Data Protection Officer, contact details will be added here.

2. What we collect

  • Account info: email, name, OAuth identifiers when you sign in with Google or Apple.
  • Workspace content: your inventory items, photos, receipts, projects, sign-off PDFs, and any data you enter.
  • Usage: pages visited, features used, AI queries made, all anonymised at the analytics layer (PostHog or similar).
  • Billing: handled by Stripe; we never see card numbers.

3. Why we hold it

  • To deliver the service you signed up for (legitimate interest).
  • To bill you under contract.
  • To improve the product (anonymised usage analytics, opt-out in Settings).
  • To meet legal obligations (tax records etc.).

4. Where it lives

Database and file storage: Supabase, in the EU (London region) by default. US-region tenants are stored in us-east-1. Backups are encrypted at rest.

AI agent queries are sent to Anthropic for processing. Anthropic does not retain the contents for training under the API terms. We log only the token counts and a short summary of each query for cost tracking.

5. How long we keep it

For active accounts: as long as you use the service. Soft-deleted items are kept for 30 days then permanently purged. Cancelled accounts: all your data is purged 30 days after cancellation, except for invoice records we are required to keep for tax purposes.

6. Your rights

Under UK GDPR you have rights to access, correct, delete, or export your data, and to object to processing.

Self-service deletion: workspace owners can delete their entire workspace from Settings → Danger zone → Delete workspace. The deletion is staged: every page in the workspace locks immediately and the data is held for a short grace period in case you change your mind. After the grace period the data is permanently purged. Non-owner team members can leave a workspace from the same Danger zone (their profile is removed; the studio's data stays).

Anything else: email support@stagershub.com for export, correction, restoration during the grace period, or any other rights request. We will action it within 30 days.

7. Cookies

We use only strictly-necessary cookies (auth session) and an opt-in analytics cookie. No advertising trackers, no third-party share buttons that load tracking scripts.

8. Sub-processors

  • Supabase — database + storage + auth
  • Vercel — hosting
  • Stripe — billing
  • Anthropic — AI agent
  • Postmark or Resend — transactional email

9. Changes

We will notify you 30 days before any material change to this policy.