Privacy Policy

Effective date: 2 September 2026

1. Introduction

This Privacy Policy explains how PerformerDesk ("we", "us", "our"), a company based in the United Kingdom, collects, uses, stores, and protects personal data when you use our platform and services.

We are committed to protecting your privacy in accordance with the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws.

2. Data Controller and Processor Roles

For platform users (performers): PerformerDesk is the data controller for your account data, business data, and technical data.

For end-client data: When you collect personal data from your clients via enquiry forms, intake forms, invoices, or contracts, you are the data controller for that data. PerformerDesk acts as a data processor, processing client data on your behalf and in accordance with your instructions through the platform.

3. Data We Collect

3.1 Account Data

When you create an account, we collect:

  • Full name and email address
  • Password (stored as a cryptographic hash — we never store your actual password)
  • Phone number
  • Business name, address, and website
  • Performer/business type

3.2 Business Data

Data you create while using the Service:

  • Client records (names, contact details, addresses)
  • Enquiries, events, and booking details
  • Invoices, payments, and financial records
  • Contracts and documents
  • Venue information and notes
  • Bank account details for display on invoices
  • Email and SMS templates

3.3 Client Data (on your behalf)

Data your clients provide through enquiry forms, intake forms, booking flows, and invoice payments:

  • Names, email addresses, phone numbers, and addresses
  • Event details and messages
  • Typed signature names and agreement confirmations
  • Payment references (card data is handled entirely by Stripe and never touches our servers)

3.4 Technical Data

  • IP address and approximate geographic location (country, derived from IP for currency defaults)
  • Browser type, device information, and operating system
  • Pages visited and actions taken within the Service
  • Cookies (see Section 8 below)

3.5 Analytics Data

  • Page views and navigation patterns (Vercel Analytics, Google Analytics)
  • Session recordings and interaction heatmaps (Microsoft Clarity)
  • Conversion tracking (Meta Pixel)

4. How We Use Your Data

  • Provide the Service: Store and process your business data, send transactional emails, enable payment processing
  • Authentication: Verify your identity and manage account access
  • Payments: Process subscription billing and facilitate client invoice payments via Stripe
  • Communications: Send transactional emails via Resend and optional SMS via Twilio on your behalf
  • AI features: Process your chat messages, business context, and (when enabled) CRM data through OpenAI to provide AI assistant responses
  • Security: Detect and prevent fraud, spam, and abuse using Cloudflare Turnstile, spam scoring, and rate limiting
  • Analytics: Understand usage patterns to improve the Service
  • Support: Respond to your queries and troubleshoot issues

5. AI Data Processing

When you use the AI assistant ("Ask Sarah"), the following data is transmitted to OpenAI for processing:

  • Your chat messages (up to 20 per conversation)
  • Your business name, currency, and performer type
  • Your first name and current page location within the app
  • Images you upload for analysis (Expert plan)
  • When CRM access is enabled: event titles, dates, statuses, client names, and venue details (read-only)

OpenAI processes this data under their API data usage policy. Data sent via the API is not used to train OpenAI's models. AI responses are generated content and may not be accurate.

Knowledge base documents you upload are converted to vector embeddings via OpenAI and stored in our database for retrieval.

6. Third-Party Services

We share data with the following third-party services as necessary to provide the Service:

ServicePurposeData shared
SupabaseDatabase, authentication, storageAll account and business data
VercelHosting, analytics, geo-detectionIP address, page views
StripeSubscription billing, client payments (Connect)Email, payment details, invoice metadata
OpenAIAI chat, text embeddings, image analysisChat messages, business context (see Section 5)
ResendTransactional and bulk email deliveryRecipient email, email content
TwilioSMS notifications (optional)Phone number, message content
GoogleMaps/Places (address lookup), Calendar sync, AnalyticsAddress queries, calendar events, page views
Meta / FacebookPixel conversion tracking, Lead Ads integrationPage views, signup events, lead form data
Microsoft ClaritySession recording and behaviour analyticsAnonymised interaction data
CloudflareTurnstile bot protectionBrowser signals for bot detection

7. Data Storage and Security

  • Data is stored in a PostgreSQL database hosted by Supabase
  • Sensitive credentials (API keys, OAuth tokens) are encrypted at rest using AES-256-GCM
  • Passwords are cryptographically hashed by Supabase Auth (bcrypt)
  • Card payment data is handled entirely by Stripe (PCI DSS Level 1 compliant) and is never stored on our servers
  • Row Level Security (RLS) is enforced at the database level to isolate workspace data
  • Optional two-factor authentication (2FA/TOTP) is available for all accounts
  • Bank account details provided for invoice display are stored in the database without application-level encryption
  • All data in transit is encrypted via TLS/HTTPS

8. Cookies

CookiePurposeDuration
Supabase authAuthentication sessionSession
pd_session_startMaximum session length (7 days)7 days
pd_last_activityIdle timeout detection (24 hours)24 hours
pd_regionCountry detection for currency defaultsSession
pdrefrReferral/affiliate tracking30 days
Google Analytics (_ga, _gid)Usage analyticsUp to 2 years
Meta Pixel (_fbp)Conversion tracking90 days
Clarity (_clck, _clsk)Session recordingUp to 1 year

9. Data Retention

  • Account and business data is retained for as long as your account is active
  • Upon account deletion, your data is removed within 30 days
  • Backup copies may persist in automated database backups per Supabase's retention policy
  • Analytics data is retained according to each third-party provider's own retention policies
  • Email delivery logs are retained by Resend per their data retention policy

10. Your Rights

UK and EU Residents (UK GDPR / EU GDPR)

You have the right to:

  • Access — Request a copy of the personal data we hold about you
  • Rectification — Request correction of inaccurate data
  • Erasure — Request deletion of your data ("right to be forgotten")
  • Portability — Receive your data in a structured, machine-readable format
  • Restriction — Request that we limit processing of your data
  • Objection — Object to processing based on legitimate interests or direct marketing

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) in the UK or the relevant supervisory authority in your EU member state.

California Residents (CCPA)

You have the right to know what personal information we collect, to request deletion, and to opt out of the sale of personal information. We do not sell personal information.

Exercising Your Rights

To exercise any of your rights, please contact us at privacy@performerdesk.com. We will respond within 30 days.

11. Children

The Service is not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 18, we will take steps to delete it promptly.

12. International Data Transfers

Your data may be processed in countries outside the UK and EEA, including the United States, where our third-party service providers (Supabase, Vercel, Stripe, OpenAI) operate. Where data is transferred internationally, we rely on appropriate safeguards such as standard contractual clauses (SCCs), adequacy decisions, or the service provider's own compliance frameworks.

13. Changes to This Policy

We may update this Privacy Policy from time to time. The effective date at the top of this page indicates when the policy was last revised. For material changes, we will notify you via email or a prominent notice within the Service.

14. Contact Us

For any privacy-related questions or requests, please contact us: