Data we collect
·Account data — your name, email address and a password (stored only as a secure hash by our authentication provider).
·Workspace & project data — the company details, gear, crew roles, budgets, projects and calendar information you enter.
·Billing data — handled by Stripe. We store only a Stripe customer reference and your current plan/subscription status; we never see or store full card details.
·Operational logs — minimal technical logs needed to run and secure the Service. We do not run third-party advertising or cross-site behavioural tracking.
·Product analytics— to understand which features are used and improve the Service, we record a small set of in-app events (e.g. "project created", "PDF generated") via PostHog on its EU Cloud. This is cookieless and pseudonymous: it is keyed only to an internal account identifier — never your name or email — with no IP address stored, no cookies set, and no recording of the content you enter. We attach a small, fixed set of non-identifyingaccount-state properties to that identifier (your top plan tier, how many workspaces you're in, your role on your current workspace, and your signup date) so we can build aggregate funnels and cohort analysis. Because it sets no cookies and is strictly necessary-adjacent and non-intrusive, no consent banner is required; deleting your account severs the link to you.
·Website analytics (cookies)— our public marketing website uses PostHog (EU Cloud) with cookies to measure traffic, referral sources and conversion. This is strictly opt-in: nothing is stored on your device and no analytics request is made until you accept the cookie banner. You can withdraw consent at any time via "Cookie settings" in the site footer.
·Joining a website visit to a signup— if (and only if) you accepted the cookie banner and then follow a link from this website into the app, we pass along the random website visitor identifier the banner already created, once, in the link. It lets us see that a signup followed from, say, the pricing page, instead of counting one person as two. No personal data is passed — only that random identifier — it is not stored on the app's domain, and it is discarded when you close the tab. If you declined cookies there is no identifier to pass and nothing happens.
·Session-aware navigation cookie — when you are signed in to the app we set a small slatewise_signed_in cookie scoped to our domain. It carries a single boolean and no personal data — it lets the marketing website show you a direct link back to your workspace instead of the generic sign-in/sign-up buttons. It is cleared automatically when you sign out.
·Crew shoot-day reminders (email)— when a producer chooses to send shoot-day reminders from a project's calendar, we email the assigned crew members an .ics calendar attachment via Resend(EU region). The email contains the freelancer's name, the project + workspace name, and the shoot day details (date, call time, location, role). The producer's email is set as the Reply-To so questions reach a human. Sending is always a manual, explicit click — never automatic, and never for marketing.
·Product & onboarding emails — as part of getting you set up, we send occasional product updates, tips, and a personal check-in from the founder a couple of days after you sign up. We rely on legitimate interest(Art. 6(1)(f)) for these low-frequency, non-promotional messages to our own signed-up users; the imposition is minimal and you can opt out at any time, two ways: a one-click unsubscribe link in every such email (handled by our email provider, Resend), and an "Email preferences" toggle in your account settings. Either stops all product / onboarding emails immediately and has no effect on essential service notices (Terms, Privacy, security), which are always sent.
·Push notifications— if you enable notifications on a device, we store that device's push token (via Google Firebase Cloud Messaging, the same provider that runs our database) so we can alert you about your shoots — bookings, schedule changes, and next-day reminders. This only happens after you explicitly turn it on, on the basis of your consent (Art. 6(1)(a)). Turn it off any time from your account settings or your browser/OS; the token is removed and deleting your account erases it.
·Service notices (email) — we maintain a list of signed-up account emails in Resend (EU region) so we can email you about material changes to the service: updates to these Terms, the Privacy Policy, our list of sub-processors (with at least 30 days' notice), security incidents, and planned downtime. These notices are part of delivering the service to you (contractual basis) and are not marketing — we do not send product updates or promotional emails via this channel without separate opt-in consent. Deleting your account removes your email from this list.