Legal

Privacy Policy

Last updated: 5 June 2026 · Operator: Gosling Productions (ABN 50 767 719 891), Melbourne, Victoria, Australia · Contact: [email protected]

This Privacy Policy explains how the EasyStagecraft Suite ("EasyStagecraft", "the Suite", "we", "us", "our") collects, uses, stores, discloses and protects personal information when you use our websites and browser-based applications — including EasyOrchestra, EasyInventory, EasyScheduler, EasyRisk, the ESC Course platform, and related services.

We are bound by the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs). The Suite is designed around data minimisation: we collect as little personal information as possible to run the service, and we never sell your data or use it to train AI models.

On this page

  1. What we collect
  2. How & where it's stored
  3. Schools, students & minors
  4. Cookies & sessions
  5. Retention & deletion
  6. Third parties / sub-processors
  7. Cross-border disclosure
  8. Your rights (APPs)
  9. Data breaches
  10. Changes to this policy
  11. Contact us

1What we collect

We deliberately keep the personal-information surface small. In normal use, the only personal information we hold about you is your email address, which we use as your account identifier and to send you transactional email.

InformationCollected?Why
Email addressYes — your account identifierSign-in (magic-link / password), billing receipts, transactional email
Password (optional)Only if you set oneFaster returning sign-in. Stored only as a salted PBKDF2-SHA256 hash, never in plain text, never logged
Stripe customer ID (paid plans)YesA reference linking your account to your subscription. The underlying billing record lives at Stripe — see §6
Payment / card detailsNoCard data is entered directly into Stripe at checkout. It never touches our systems
Production content you createYes — stored to run the appStage layouts, inventory items (and any photos you take of set, props or costumes), schedules, risk records. This is operational content, not personal profiling data
Student names / student recordsNot required, not collected by defaultSee §3
Government identifiers (TFN, USI, Medicare)NoWe never collect or accept these
Technical / log dataLimitedSign-in events, security audit logs, and IP address at sign-in (for fraud/security). Aggregate, privacy-preserving traffic stats via Cloudflare Web Analytics — no third-party ad trackers, no fingerprinting

You may use an alias or relay email address (for example Apple Hide My Email) if you prefer. We do not require your real name, role, or organisation to use the product.

2How & where your information is stored

EasyStagecraft is built entirely on the Cloudflare platform. Your account data and the production content you create are stored in Cloudflare KV (an encrypted key-value store) and served through Cloudflare Pages and Cloudflare Workers. For Australian users, traffic is served from Cloudflare's Australian edge locations (Sydney, Melbourne, Perth) by default.

3Schools, students & minors

EasyStagecraft is used by schools, and we take the safety of student data seriously. The Suite is a teacher-and-crew production tool, not a student information system.

Our position on student data EasyStagecraft does not require, request, or collect student personal information by default. No student names, student photos, health, accessibility, or behavioural data are needed to use the product. We do not profile students, we show no advertising, and we never use customer data to train AI or machine-learning models.

Where a school is the "APP entity" responsible for student data, EasyStagecraft acts in support of the school's own privacy obligations — including supplying technical detail to help the school meet its Notifiable Data Breach obligations if ever required (see §9).

4Cookies & sessions

We use the minimum storage needed to keep you signed in and the app working:

5Data retention & deletion on request

We keep your information only for as long as we need it to provide the service:

6Third parties / sub-processors

We share personal information only with the small set of service providers needed to run EasyStagecraft. We do not sell your data, and we do not disclose it for advertising.

ProviderWhat it doesWhat it sees
Cloudflare, Inc.Hosting, storage (Pages, Workers, KV), edge delivery, securityYour email and the content you store
Stripe, Inc. / Stripe Payments Australia Pty LtdSubscription billing & paymentsYour email and payment method (card data never touches our systems)
Google (Gmail / Workspace API)Sends our transactional email (sign-in links, receipts, account & refund notices)Your email address and the content of that transactional email

We may also disclose personal information where required by law, to comply with a valid legal request, or to protect the rights, safety and security of our users or the service. If we ever add a new provider that processes customer-identifiable data, we will update this policy and our published sub-processor list before activation.

7Cross-border disclosure (APP 8)

Our providers operate global infrastructure, so some information may be stored or processed outside Australia (Cloudflare KV is globally replicated for reliability; Stripe and Google operate internationally). Each of these providers maintains recognised security and privacy attestations (such as SOC 2, ISO 27001, ISO 27701, and — for Stripe — PCI DSS Level 1) that provide protection substantially equivalent to the APPs. By using the Suite you acknowledge this cross-border handling. If your organisation requires Australia-only data residency, contact us and we can discuss Cloudflare regional configuration.

8Your rights under the Australian Privacy Principles

9Data breaches

We maintain security monitoring and an incident-response runbook. If a data breach occurs that is likely to result in serious harm, we will comply with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth) — assessing the breach and notifying the OAIC and affected individuals as required. Where the breach affects data a school also holds (such as a teacher's account email), we will support the school's own notification obligations with technical detail. We aim to notify affected account holders promptly after becoming aware of a confirmed breach affecting their data.

10Changes to this policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the current version. If we make a material change — for example, adding a new category of data collection or a new sub-processor that handles personal information — we will notify active account holders by email before it takes effect. Continued use of the Suite after an update means you accept the revised policy.

11Contact us

For any privacy question, access/correction/deletion request, or complaint:

See also our Terms of Service.