Last updated: 26 July 2026
ShowTiming
Privacy policy
How ShowTiming processes personal data for the hosted live-timing service (EU/France-oriented draft).
1. Controller
Controller: [TO COMPLETE: legal name], trading as ShowTiming. Contact: [TO COMPLETE: email].
Publication director: Lucas Ait Madi. Draft — attorney review required. Target DSAR response time: 30 days.
2. What we process and why
Account & authentication: email, password hash (via Supabase Auth), display name — to create and secure your account (contract / pre-contract).
Events & rundown: event metadata, segments, live timing state, cue messages — to operate Control, Stage, and optional Broadcast (contract).
Stage / Broadcast access: tokenized read-only links you generate and can revoke — to share countdown views without operator accounts (contract / legitimate interest in secure handoff).
Billing: Stripe customer id, plan/license metadata, invoices handled by Stripe — we do not store full card numbers (contract / legal obligation for accounting).
Support / contact: messages you send via the contact form or email — to answer you (legitimate interest / pre-contract).
Admin operations: a restricted allowlist (ADMIN_EMAILS) may access cross-account operational stats for service stewardship (legitimate interest).
3. Recipients / processors
Supabase (Paris region) — authentication, database, realtime.
OVH SAS — website hosting.
Stripe — payments, Customer Portal, tax.
Transactional email for auth (confirm / reset) is sent through the configured Auth mail provider (confirm in docs/legal-founder-facts.md).
PostHog (EU) — product & marketing analytics, only if you consent.
We do not sell personal data.
4. Retention
Account data: kept while the account is active; deleted or anonymized after account closure subject to legal retention (billing).
Events / live state: kept while associated with an active account unless you delete them earlier.
License / billing records: retained as required for accounting and dispute handling.
Exact retention schedules: [TO COMPLETE with lawyer].
5. Transfers
Some processors may process data outside the EEA. Where that happens, we rely on their contractual safeguards (e.g. SCCs) in their DPA. Primary application data: Supabase, Paris region.
6. Your rights
Depending on applicable law (including GDPR), you may request access, rectification, erasure, restriction, portability, and objection.
To exercise rights, email [TO COMPLETE: legal email]. You may also lodge a complaint with your supervisory authority (in France: CNIL).
7. Cookies
See the Cookies page. Essentials always on; PostHog analytics only after consent via the banner.
