Skip to main content
Back

Privacy Policy — StageRage

Last updated: September 24, 2026

1. Controller and contact

StageRage is the app and service name. The controller of the personal data described in this policy is Sebastjan Zavrl s.p., MGLightning, Podreča 126, 4211 Mavčiče, Slovenia. Contact us about privacy, your data, or this policy at [email protected].

This policy describes the live product. It does not make StageRage responsible for information you choose to disclose publicly or share with other tour members, venue, coordinator, or game participants, or third-party services.

2. Data we collect

  • Account and security data: email address, display name, country, selected touring role, hashed password, Google account identifier if you use Google sign-in, email-verification state, two-factor-authentication configuration (your TOTP secret is encrypted at rest), subscription status, and security/session data. We receive limited payment identifiers and status from Creem for Stage Operations Pro and, for legacy subscriptions or one-time support payments, from PayPal — not your full card details.
  • Profile and public contribution data: profile image, bio, skills, availability, crew tags, venue claims, reviews, ratings, comments, forum posts, map pins, votes, reports, uploaded media, and other content you submit. Reviews, comments, map pins, venue information, game leaderboards, and public-profile fields may be visible to other users and the public according to the feature and your settings.
  • Touring, coordination, and planning data: tour plans, member and permission information, schedules, tour and coordinator chat text and voice messages, event details, checklists, guest-list requests, hotels, flights, equipment/carnet data, calendar-feed credentials, coordinator workspace content (run-of-show, artist schedules, show-clock and transition records, classified documents, matched contact lists, and operational audit notes), and related notes. This data can contain personal data about you or people you add to a plan.
  • Toolkit data: private cargo/case templates, archived load plans, loader scan sessions (flightcase and truck label tokens with verification steps), stage plots, technical and hospitality riders, audio input/output lists, private wireless-device profiles, and RF coordination requests. RF frequency observations include city/country, device technical class, and frequency; we use them as aggregated local coordination evidence and do not expose the reporting account with the result.
  • Games and leaderboard data: multiplayer game rooms with their player list, moves, and results; arcade submissions recomputed from server-side replay events; and leaderboard entries showing your display name, score or wins, and account identifier. Friend, crew, and coordinator membership can be used to offer game-invite suggestions.
  • Support and communications data: messages you send to support, email replies and attachments we receive through our inbound support address, replies, account notices, verification and password-reset requests, and notification preferences.
  • Technical and security data: IP address, user-agent/device and browser information, authentication and rate-limit events, audit events (including staff actions on user data), error context, and server logs. We do not include request bodies, authentication cookies, or authorization headers in Sentry error reporting. Licensed Pro tools use a random per-browser install identifier inside a signed, cached license token bound to your account; if a protected tool detects that it was copied to an unrecognised website, it sends one abuse report containing that page address and your browser type so we can enforce our licence.
  • Optional analytics: only after consent, a normalized page/tool category, broad referral category (including a named search or AI discovery service where it is the referrer), sanitized campaign label, bucketed page-quality ratings for loading/interaction/visual-stability metrics (categories only — never raw timings or page addresses), and a rotating daily pseudonymous identifier. Consent-gated venue-search text may be kept as a roadmap signal; anything resembling personal data (emails, URLs) is replaced with a placeholder before storage. Event pages use an opaque server-generated event key, venue pages use a separate opaque server-generated venue key, and news articles use an opaque server-generated article key, so their creators or verified owners can see aggregate opted-in counts only. We do not put account IDs, raw event/venue/article IDs, ticket URLs, raw IP addresses, full referrers, prompts, AI answers, query strings, review text, precise coordinates, or browser fingerprints into product analytics.
  • Location, audio, and device permissions: if you choose a map, route, weather, or RF-location feature, we process the location or place name needed for that request; browser geolocation is used only for map "find my location" and RF placement, and RF GPS readings are rounded before reverse geocoding with no coordinate history. If you enable friend location sharing, we store only a city and country, not a coordinate history. Push notifications are optional and store a browser push-subscription endpoint. The Instrument Tuner and dBA/dBC Sound Meter request microphone permission only when you start them; captured audio is analysed locally in your browser and is not uploaded or stored by StageRage. The Sound Meter keeps derived LAeq measurement state only in this browser's IndexedDB. If you save a calibration, we store your numeric offset and a one-way hash of the browser microphone-processing signature in your account so the same input path can be restored; we do not store raw microphone IDs, labels, audio, or measurement history. Chat voice messages are recorded in your browser when you hold "talk" and are then uploaded to private storage visible only to members of that channel. Live voice channels relay your microphone audio in real time between members of the channel you belong to while you hold talk; the microphone stays muted otherwise and StageRage does not record, transcribe, or store live-room audio. Optional Bluetooth or USB push-to-talk accessories can be paired through an explicit browser device-permission step you start. The Loader Helper label scanner opens your camera only after you start a scan; QR/barcode labels are decoded in the browser and only the label token is sent to StageRage — scan video is not uploaded or stored.

3. How and why we use data

We use data to create and secure accounts; provide the platform and its planning, coordination, and gaming tools; publish and moderate community content; operate collaboration, notifications, subscriptions, customer support, exports, and integrations; prevent fraud, cheating, abuse, and security incidents; and improve the product through consent-based first-party analytics.

Our GDPR legal bases are performance of a contract (account, collaboration, paid features, and requested tools), consent (optional analytics, push notifications, location sharing, microphone and camera features, and optional profile features), legitimate interests (security, fraud prevention, service reliability, licence protection, moderation, fair play in games, and defending legal claims), and legal obligation where applicable (for example, accounting records).

We use automated safeguards, including rate limits, malware scanning, image safety checks, text-toxicity screening, and server-side recomputation of game scores from recorded replay events. These tools help flag or block abuse; they do not replace available human review through our reporting and contact channels.

4. Who receives data

We do not sell personal data or use it for behavioural advertising. Depending on the feature you use, data is shared with these recipients or processor categories:

  • Other users and the public: public profile fields and content you publish; tour and coordinator data with the owner, permitted members, and collaborators of the relevant workspace; game-room players see your display name, and leaderboards are publicly readable; and venue-related data with the relevant venue owner or administrator where the feature requires it.
  • Cloudflare: security/CDN services and Cloudflare R2 object storage — a public bucket for user-facing uploads and branding assets, and a separate private bucket for tour/coordinator files and voice messages that is only served to permitted workspace members. Uploaded review media can be publicly reachable when attached to public content.
  • Hetzner: EU application hosting and primary server infrastructure.
  • Creem: checkout, subscription, receipt, applicable sales-tax/VAT handling, and customer billing portal services for Stage Operations Pro. Creem receives the checkout and billing information needed to provide those services.
  • PayPal: legacy Stage Operations Pro subscriptions and one-time support payments. PayPal receives the account and transaction details needed to process the payment.
  • Resend: transactional email, including verification, password-reset, and account notices, and inbound processing of support replies you email us.
  • Sentry: error and limited performance monitoring. We configure Sentry not to automatically send PII and to remove request bodies, cookies, and authorization headers; session replay is disabled.
  • Google: Google OAuth when you select Google sign-in; Google Translate when you choose translation; Perspective API for text moderation; and Gemini when you submit content to an AI-powered assistant (see the AI bullet below). If an administrator expressly connects Google Search Console, we store an encrypted, read-only refresh token and the selected verified property to retrieve aggregated search-performance data for the admin dashboard. This does not grant access to Google account content or alter normal Google sign-in.
  • Google Fonts and jsDelivr: every page loads its webfonts from Google Fonts, which necessarily sees the requesting IP address. The LiveKit browser SDK and the face-blur detection library load from the jsDelivr CDN when you first use those features; the face-detection models themselves are served by StageRage.
  • LiveKit (voice relay): when you join a live voice channel, your encrypted microphone audio is relayed in real time through our LiveKit server and its TURN relay to the other connected members. StageRage does not record or store this audio.
  • AI text providers: Google Gemini is our primary assistant model; when it is unavailable, your submitted text may instead be sent to Groq, Cerebras, Mistral, or OpenRouter. These receive only the prompt needed to produce that single response.
  • Eventric (Master Tour): only when you choose to connect or import Master Tour information.
  • Maps, routing, weather and flight providers: OpenStreetMap map tiles are loaded directly by your browser (which exposes your IP to OpenStreetMap); Nominatim, Photon (Komoot), OpenRouteService (HeiGIT), and OSRM receive the place, route, or reverse-geocode query; Xweather and WeatherAPI.com receive the location needed for weather and alerts; and AirLabs, AeroDataBox, and AviationStack receive the flight number or date needed for flight status. We do not intentionally send your StageRage account email or name with those requests.

Some providers may process limited data outside the EU/EEA. Where a restricted transfer applies, we use an adequacy decision or appropriate safeguards required by applicable data-protection law.

5. Location, uploads, audio, and shared data

Location is optional. For the RF planner, GPS is rounded before reverse geocoding and is not saved as a coordinate history; the resulting city/country can be used for the coordination request. Map, search, route, and weather features send the location information required for the request to the provider named above.

Camera and microphone access are optional browser permissions. You can refuse them without losing access to unrelated parts of the service and can revoke a grant at any time in your browser or device settings. A browser permission policy allowing StageRage to request a device does not activate the device or bypass the browser's permission prompt. Chat voice messages you send become personal data visible to every member of that channel, and live-voice audio is audible to everyone connected to the channel while you hold talk — be mindful of what you record or say, and check local rules about recording conversations.

We process uploads to create supported image/PDF formats and scan them for malicious or prohibited content. Review photos have faces detected and blurred in your browser before upload, with a server-side blur applied as a safety net. Do not upload personal data about others unless you have a lawful basis and the necessary permissions. Do not put booking codes, passport data, health data, access codes, or other sensitive data into public reviews, comments, pins, or shared documents.

Tour and coordinator owners are responsible for ensuring they have an appropriate basis to add crew, guests, travel, accommodation, equipment, or other third-party information to a shared workspace.

Public venue, event, news, feature, games, and help pages may be crawled and indexed by search engines and AI services in accordance with our robots policy; when such pages are published or changed, their public URLs may be submitted to IndexNow so search and AI engines can discover them quickly. We do not make account areas, private workspaces, private files, private API responses, or authenticated user data public for crawling.

6. Cookies, local storage, and offline cache

We use essential browser storage to operate and secure the app. This includes a secure HttpOnly server-session cookie (up to seven days while your account session remains valid), short-lived OAuth and administrator Search Console proof cookies when you explicitly use those flows, a sidebar display-preference cookie, a signed Pro-tool license token with its random install identifier kept in this browser's IndexedDB, and locally stored consent, language, date/time, measurement, and safety-recovery preferences. Authentication and security storage are required to keep a requested account session and security controls working and cannot be disabled while using them.

If you consent to product analytics, we store stagerage_analytics_id, stagerage_analytics_consent, stagerage_cookie_consent, and a consent-version marker in browser storage. The identifier is converted to a different server-side pseudonym each UTC day. Event and venue audience analytics use that same rotating pseudonym plus opaque server HMACs, as does news audience analytics; creators and verified venue owners can see aggregate counts only, never a visitor list. Refusing or withdrawing consent removes the analytics identifier and stops future analytics events. A previously stored choice is not treated as consent when we add a new analytics purpose; we ask again. StageRage has no advertising, marketing-cookie, or third-party analytics category. You can change this choice at any time through the Cookie Settings control in the footer or in Privacy Settings.

Our service worker caches application files and limited public venue data for offline use. It does not cache authenticated API responses. After an authorised user opens a Tour Plan or Coordinator while online, StageRage may automatically keep an encrypted, account-scoped, read-only browser replica of the operational data and private files that user is permitted to access, subject to device storage limits. This replica contains no password, session cookie, API key, request header, or queued action; it is used only after a genuine network failure and is cleared on logout or when a different account is verified in that browser. Offline loader scans queue only label tokens on the device until they can be verified. On a shared device, always log out and clear StageRage site data/browser storage when you finish. Google Translate may set googtrans only after you choose a non-English translation.

7. Retention and account deletion

  • Account and private workspace data are retained while the account remains active or as needed to provide the service.
  • When you delete an account, we delete the account and connected sessions, notifications, friendships, owned tours, map pins, and certain account records; public reviews and messages are de-identified where they need to remain as community or tour history. Review media attached to your account is cleared and R2 deletion is attempted. Game rooms and server-verified leaderboard entries keep the display-name snapshot recorded when they were set; contact us if you want your name or identifier removed from games records.
  • Chat voice messages are kept with their channel history until deleted in the app or removed with the workspace; live-voice audio is never stored at all (only a transient 12-second talk-floor lock exists in server memory).
  • Flight records are configured to expire after arrival and hotel records 14 days after checkout. Consent-based analytics events expire after 90 days; event, venue, news, and general daily pseudonymous analytics counts expire after 24 months. Event, venue, and news lifetime totals contain no visitor identifier and are removed when their event, venue, or article is deleted.
  • Payment, tax, security, audit, error, dispute, and backup records may be retained for longer where reasonably necessary for security, legal obligations, accounting, or the establishment, exercise, or defence of legal claims. Backups age out through the normal backup rotation rather than being edited individually.

You can delete or withdraw private drafts, tool records, and uploads where the relevant feature provides a delete control. For any data you cannot remove yourself, contact us using the address below.

8. Your rights

Subject to applicable law, you can request access, correction, erasure, restriction, objection, and portability. You can withdraw consent at any time for analytics, location sharing, notifications, and optional profile features; this does not affect processing already carried out. Contact [email protected] to exercise a right or ask a question.

You may also complain to your local data-protection authority. In Slovenia, the authority is the Information Commissioner (Informacijski pooblaščenec): ip-rs.si.

9. Changes and contact

We may update this policy when the product or applicable law changes. The date above shows the latest version. For privacy questions, requests, or concerns, contact Sebastjan Zavrl s.p., MGLightning, Podreča 126, 4211 Mavčiče, Slovenia, at [email protected].