Skip to content

ShowTiming

Privacy policy

How ShowTiming processes personal data for the hosted live-timing service (EU/France-oriented draft).

Last updated: 26 July 2026

1. Controller

Controller: [TO COMPLETE: legal name], trading as ShowTiming. Contact: [TO COMPLETE: email].

Publication director: Lucas Ait Madi. Draft — attorney review required. Target DSAR response time: 30 days.

2. What we process and why

Account & authentication: email, password hash (via Supabase Auth), display name — to create and secure your account (contract / pre-contract).

Events & rundown: event metadata, segments, live timing state, cue messages — to operate Control, Stage, and optional Broadcast (contract).

Stage / Broadcast access: tokenized read-only links you generate and can revoke — to share countdown views without operator accounts (contract / legitimate interest in secure handoff).

Billing: Stripe customer id, plan/license metadata, invoices handled by Stripe — we do not store full card numbers (contract / legal obligation for accounting).

Support / contact: messages you send via the contact form or email — to answer you (legitimate interest / pre-contract).

Admin operations: a restricted allowlist (ADMIN_EMAILS) may access cross-account operational stats for service stewardship (legitimate interest).

3. Recipients / processors

Supabase (Paris region) — authentication, database, realtime.

OVH SAS — website hosting.

Stripe — payments, Customer Portal, tax.

Transactional email for auth (confirm / reset) is sent through the configured Auth mail provider (confirm in docs/legal-founder-facts.md).

PostHog (EU) — product & marketing analytics, only if you consent.

We do not sell personal data.

4. Retention

Account data: kept while the account is active; deleted or anonymized after account closure subject to legal retention (billing).

Events / live state: kept while associated with an active account unless you delete them earlier.

License / billing records: retained as required for accounting and dispute handling.

Exact retention schedules: [TO COMPLETE with lawyer].

5. Transfers

Some processors may process data outside the EEA. Where that happens, we rely on their contractual safeguards (e.g. SCCs) in their DPA. Primary application data: Supabase, Paris region.

6. Your rights

Depending on applicable law (including GDPR), you may request access, rectification, erasure, restriction, portability, and objection.

To exercise rights, email [TO COMPLETE: legal email]. You may also lodge a complaint with your supervisory authority (in France: CNIL).

7. Cookies

See the Cookies page. Essentials always on; PostHog analytics only after consent via the banner.