Privacy Policy
Effective date: 2 September 2026
1. Introduction
This Privacy Policy explains how PerformerDesk ("we", "us", "our"), a company based in the United Kingdom, collects, uses, stores, and protects personal data when you use our platform and services.
We are committed to protecting your privacy in accordance with the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws.
2. Data Controller and Processor Roles
For platform users (performers): PerformerDesk is the data controller for your account data, business data, and technical data.
For end-client data: When you collect personal data from your clients via enquiry forms, intake forms, invoices, or contracts, you are the data controller for that data. PerformerDesk acts as a data processor, processing client data on your behalf and in accordance with your instructions through the platform.
3. Data We Collect
3.1 Account Data
When you create an account, we collect:
- Full name and email address
- Password (stored as a cryptographic hash — we never store your actual password)
- Phone number
- Business name, address, and website
- Performer/business type
3.2 Business Data
Data you create while using the Service:
- Client records (names, contact details, addresses)
- Enquiries, events, and booking details
- Invoices, payments, and financial records
- Contracts and documents
- Venue information and notes
- Bank account details for display on invoices
- Email and SMS templates
3.3 Client Data (on your behalf)
Data your clients provide through enquiry forms, intake forms, booking flows, and invoice payments:
- Names, email addresses, phone numbers, and addresses
- Event details and messages
- Typed signature names and agreement confirmations
- Payment references (card data is handled entirely by Stripe and never touches our servers)
3.4 Technical Data
- IP address and approximate geographic location (country, derived from IP for currency defaults)
- Browser type, device information, and operating system
- Pages visited and actions taken within the Service
- Cookies (see Section 8 below)
3.5 Analytics Data
- Page views and navigation patterns (Vercel Analytics, Google Analytics)
- Session recordings and interaction heatmaps (Microsoft Clarity)
- Conversion tracking (Meta Pixel)
4. How We Use Your Data
- Provide the Service: Store and process your business data, send transactional emails, enable payment processing
- Authentication: Verify your identity and manage account access
- Payments: Process subscription billing and facilitate client invoice payments via Stripe
- Communications: Send transactional emails via Resend and optional SMS via Twilio on your behalf
- AI features: Process your chat messages, business context, and (when enabled) CRM data through OpenAI to provide AI assistant responses
- Security: Detect and prevent fraud, spam, and abuse using Cloudflare Turnstile, spam scoring, and rate limiting
- Analytics: Understand usage patterns to improve the Service
- Support: Respond to your queries and troubleshoot issues
5. AI Data Processing
When you use the AI assistant ("Ask Sarah"), the following data is transmitted to OpenAI for processing:
- Your chat messages (up to 20 per conversation)
- Your business name, currency, and performer type
- Your first name and current page location within the app
- Images you upload for analysis (Expert plan)
- When CRM access is enabled: event titles, dates, statuses, client names, and venue details (read-only)
OpenAI processes this data under their API data usage policy. Data sent via the API is not used to train OpenAI's models. AI responses are generated content and may not be accurate.
Knowledge base documents you upload are converted to vector embeddings via OpenAI and stored in our database for retrieval.
6. Third-Party Services
We share data with the following third-party services as necessary to provide the Service:
| Service | Purpose | Data shared |
|---|---|---|
| Supabase | Database, authentication, storage | All account and business data |
| Vercel | Hosting, analytics, geo-detection | IP address, page views |
| Stripe | Subscription billing, client payments (Connect) | Email, payment details, invoice metadata |
| OpenAI | AI chat, text embeddings, image analysis | Chat messages, business context (see Section 5) |
| Resend | Transactional and bulk email delivery | Recipient email, email content |
| Twilio | SMS notifications (optional) | Phone number, message content |
| Maps/Places (address lookup), Calendar sync, Analytics | Address queries, calendar events, page views | |
| Meta / Facebook | Pixel conversion tracking, Lead Ads integration | Page views, signup events, lead form data |
| Microsoft Clarity | Session recording and behaviour analytics | Anonymised interaction data |
| Cloudflare | Turnstile bot protection | Browser signals for bot detection |
7. Data Storage and Security
- Data is stored in a PostgreSQL database hosted by Supabase
- Sensitive credentials (API keys, OAuth tokens) are encrypted at rest using AES-256-GCM
- Passwords are cryptographically hashed by Supabase Auth (bcrypt)
- Card payment data is handled entirely by Stripe (PCI DSS Level 1 compliant) and is never stored on our servers
- Row Level Security (RLS) is enforced at the database level to isolate workspace data
- Optional two-factor authentication (2FA/TOTP) is available for all accounts
- Bank account details provided for invoice display are stored in the database without application-level encryption
- All data in transit is encrypted via TLS/HTTPS
8. Cookies
| Cookie | Purpose | Duration |
|---|---|---|
| Supabase auth | Authentication session | Session |
| pd_session_start | Maximum session length (7 days) | 7 days |
| pd_last_activity | Idle timeout detection (24 hours) | 24 hours |
| pd_region | Country detection for currency defaults | Session |
| pdrefr | Referral/affiliate tracking | 30 days |
| Google Analytics (_ga, _gid) | Usage analytics | Up to 2 years |
| Meta Pixel (_fbp) | Conversion tracking | 90 days |
| Clarity (_clck, _clsk) | Session recording | Up to 1 year |
9. Data Retention
- Account and business data is retained for as long as your account is active
- Upon account deletion, your data is removed within 30 days
- Backup copies may persist in automated database backups per Supabase's retention policy
- Analytics data is retained according to each third-party provider's own retention policies
- Email delivery logs are retained by Resend per their data retention policy
10. Your Rights
UK and EU Residents (UK GDPR / EU GDPR)
You have the right to:
- Access — Request a copy of the personal data we hold about you
- Rectification — Request correction of inaccurate data
- Erasure — Request deletion of your data ("right to be forgotten")
- Portability — Receive your data in a structured, machine-readable format
- Restriction — Request that we limit processing of your data
- Objection — Object to processing based on legitimate interests or direct marketing
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) in the UK or the relevant supervisory authority in your EU member state.
California Residents (CCPA)
You have the right to know what personal information we collect, to request deletion, and to opt out of the sale of personal information. We do not sell personal information.
Exercising Your Rights
To exercise any of your rights, please contact us at privacy@performerdesk.com. We will respond within 30 days.
11. Children
The Service is not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 18, we will take steps to delete it promptly.
12. International Data Transfers
Your data may be processed in countries outside the UK and EEA, including the United States, where our third-party service providers (Supabase, Vercel, Stripe, OpenAI) operate. Where data is transferred internationally, we rely on appropriate safeguards such as standard contractual clauses (SCCs), adequacy decisions, or the service provider's own compliance frameworks.
13. Changes to This Policy
We may update this Privacy Policy from time to time. The effective date at the top of this page indicates when the policy was last revised. For material changes, we will notify you via email or a prominent notice within the Service.
14. Contact Us
For any privacy-related questions or requests, please contact us:
- Email: privacy@performerdesk.com
- General enquiries: support@performerdesk.com