Privacy Policy
Last updated: August 2026
1. Introduction
This Privacy Policy describes how Rhythm Labs Pty Ltd (ABN 20 677 653 637) ("Staaage", "we", "us", "our") collects, uses, stores, and protects personal information through the stAAAge platform ("Platform").
StAAAge provides event management software used by organisations ("Organisations") to manage suppliers, vendors, artists, volunteers, and other participants ("Suppliers") for their events. This policy covers:
- Information we collect directly from Organisations and their team members
- Information collected from Suppliers through Organisation-created forms on the Platform
- How we handle and protect all personal information
We are committed to complying with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) and, where applicable, the EU General Data Protection Regulation (GDPR) and the UK GDPR.
2. Roles and Responsibilities
Staaage as Data Processor
When Organisations collect personal information from Suppliers via the Platform (application forms, document uploads, compliance materials), the Organisation is the data controller and Staaage acts as a data processor. We process this data solely on the Organisation's behalf and in accordance with their instructions.
Staaage as Data Controller
When we collect personal information directly from Organisations and their team members for account management, billing, and Platform operation, Staaage is the data controller.
3. Information We Collect
3.1 Organisation Account Information
- Contact name, email address, phone number
- Organisation name, ABN/ACN, business address
- Billing and payment information (processed by Stripe — we do not store card details)
- Team member names, email addresses, roles, and permissions
3.2 Supplier Information (collected on behalf of Organisations)
The specific information collected varies by Organisation and form configuration, but may include:
- Name, email address, phone number, postal address
- Business/trading name, ABN, insurance details
- Identification documents (e.g. photo ID, working with children checks)
- Professional qualifications and certifications
- Food safety certificates, liquor licences
- Product lists, menus, technical riders
- Photos, logos, biographies
- Bank account details (for refund or payment purposes)
- Emergency contact details
- Digital signatures on agreements
- Any other information the Organisation configures in their application forms
3.3 Usage Information
- Log data (IP address, browser type, pages visited, timestamps)
- Device information (operating system, screen resolution)
- Feature usage analytics (aggregated, non-identifying)
- Error logs and crash reports
3.4 Cookies and Similar Technologies
We use essential cookies for authentication, session management, security (CSRF protection), and user preferences (theme, timezone). We do not use third-party advertising or tracking cookies. We do not sell or share data with advertisers. See our Cookie Policy for details.
4. How We Use Information
4.1 Organisation Data
We use Organisation account information to:
- Provide, maintain, and improve the Platform
- Process payments and manage subscriptions
- Send transactional communications (invoices, payment confirmations, service notifications)
- Provide customer support
- Comply with legal obligations
4.2 Supplier Data
We process Supplier data solely to:
- Provide the Platform services to the Organisation
- Facilitate application submissions, advancing workflows, and compliance tracking
- Deliver transactional emails on behalf of the Organisation
- Generate documents (agreements, credentials) as configured by the Organisation
We do not:
- Use Supplier data for our own marketing purposes
- Sell, rent, or trade Supplier data to third parties
- Profile Suppliers for advertising purposes
- Access Supplier data except as necessary to provide the service or respond to support requests
4.3 Lawful Basis for Processing (GDPR)
Where the GDPR applies, we rely on the following lawful bases:
| Processing Activity | Lawful Basis (Article 6 GDPR) |
|---|---|
| Providing Platform services to Organisations | Performance of a contract (Art. 6(1)(b)) |
| Processing Supplier data on behalf of Organisations | Legitimate interest of the Organisation / controller instructions (Art. 6(1)(f) / Art. 28) |
| Sending transactional communications | Performance of a contract (Art. 6(1)(b)) |
| Billing and payment processing | Performance of a contract (Art. 6(1)(b)) |
| Security monitoring and fraud prevention | Legitimate interest (Art. 6(1)(f)) |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c)) |
| Aggregated usage analytics | Legitimate interest (Art. 6(1)(f)) |
5. Data Sharing and Disclosure
We share personal information only in the following circumstances:
| Recipient | Purpose |
|---|---|
| Google Cloud Platform | Infrastructure, hosting, database, file storage (data stored in Australia) |
| Firebase (Google) | Authentication, Cloud Functions (data stored in Australia) |
| SendGrid (Twilio) | Transactional email delivery |
| Stripe | Payment processing (card data only) |
| The Organisation | Supplier data is accessible to the Organisation that collected it |
| Law enforcement | Where required by law, court order, or legal process |
We will not disclose personal information to any other party without consent, except where required or permitted by law.
6. Data Storage and Security
6.1 Location
All Organisation Data and Supplier Data is stored on Google Cloud Platform infrastructure in the australia-southeast1 (Sydney) region, unless the Organisation requests an alternative region.
6.2 Security Measures
- Encryption at rest: All data stored in Firestore and Cloud Storage is encrypted at rest using AES-256
- Encryption in transit: All communications use TLS 1.2 or higher
- Authentication: Firebase Authentication with secure password hashing; support for multi-factor authentication
- Access controls: Role-based access with granular permissions per team member, scoped by supplier type and site
- Audit logging: Administrative actions are logged for accountability
- Infrastructure security: Google Cloud's SOC 2 Type II, ISO 27001, and ISO 27017 certified infrastructure
6.3 Breach Notification
In the event of a confirmed data breach that is likely to result in serious harm, we will:
- Notify affected Organisations without undue delay (and within 72 hours where GDPR applies, per Article 33)
- Provide details of the nature of the breach, the data affected, and steps being taken
- Cooperate with the Organisation in meeting their notification obligations
- Report to the Office of the Australian Information Commissioner (OAIC) where required by the Notifiable Data Breaches scheme
- Where GDPR applies, assist the Organisation in notifying the relevant supervisory authority and affected data subjects (Articles 33–34)
7. International Data Transfers
7.1. Organisation Data is primarily stored in Australia. However, some sub-processors (e.g. SendGrid) may process data in other jurisdictions, including the United States.
7.2. Where data is transferred outside Australia or the EEA, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) as approved by the European Commission (for GDPR transfers)
- Sub-processors' adherence to recognised security frameworks (SOC 2, ISO 27001)
- Contractual data processing agreements with all sub-processors
- Supplementary measures where required by Schrems II guidance
8. Data Retention
8.1 Active Subscriptions
Organisation Data is retained for the duration of the active subscription and for 28 days after termination or cancellation to allow for data export.
8.2 Payment Failure
| Period | Data Status |
|---|---|
| Days 1–28 | Fully accessible (grace period) |
| Days 29–90 | Read-only access; data retained |
| Days 91–365 | Data archived; accessible upon request to support@staaage.com |
| After 12 months | Data permanently deleted |
8.3 Supplier Data
Supplier data submitted through the Platform is retained as part of the Organisation's data and follows the same retention schedule. Organisations may delete individual Supplier records at any time during an active subscription.
8.4 Account and Billing Records
We retain Organisation account information and billing records for 7 years after account closure, as required by Australian taxation law.
8.5 GDPR Data Minimisation
Where GDPR applies, we apply data minimisation principles (Article 5(1)(c)). Personal data is retained only as long as necessary for the purposes for which it was collected. Organisations are encouraged to regularly review and delete Supplier data that is no longer required.
9. Your Rights
9.1 Australian Privacy Act
Under the Australian Privacy Principles, individuals have the right to:
- Access personal information we hold about them
- Correct inaccurate, incomplete, or out-of-date personal information
- Complain to us or the OAIC about a breach of privacy
9.2 GDPR Rights (where applicable)
Where the GDPR applies, individuals additionally have the right to:
- Access — obtain confirmation of whether personal data is being processed and request a copy (Article 15)
- Rectification — correct inaccurate personal data (Article 16)
- Erasure — request deletion of personal data ("right to be forgotten") where no overriding legal basis exists (Article 17)
- Restriction — request restricted processing in certain circumstances (Article 18)
- Data portability — receive personal data in a structured, commonly used, machine-readable format (Article 20)
- Object — object to processing based on legitimate interests (Article 21)
- Automated decision-making — not be subject to solely automated decisions with legal or significant effects (Article 22). Note: Staaage does not use automated decision-making or profiling.
- Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing (Article 7(3))
9.3 How to Exercise Rights
Suppliers should direct data access, correction, or deletion requests to the Organisation that collected their data. The Organisation is the data controller and is responsible for responding to these requests. Staaage will assist the Organisation where necessary.
Organisation team members may contact us directly at support@staaage.com.
9.4 Response Time
We aim to respond to all privacy requests within 30 days. Where GDPR applies, we will respond within one month as required by Article 12(3), with the possibility of a two-month extension for complex requests (with prior notification).
9.5 Right to Lodge a Complaint
Australia: You may lodge a complaint with the Office of the Australian Information Commissioner (OAIC).
EU/EEA: You have the right to lodge a complaint with your local supervisory authority under Article 77 GDPR. A list of supervisory authorities is available at edpb.europa.eu.
10. Children's Privacy
The Platform is not directed at individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without parental consent, we will take steps to delete that information.
Organisations that collect information from individuals under 18 (e.g. young volunteers) are responsible for obtaining appropriate parental or guardian consent.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will:
- Post the updated policy on our website with a new "Last updated" date
- Notify Organisations of material changes via email at least 30 days before they take effect
12. Contact Us
If you have questions, concerns, or complaints about this Privacy Policy or our handling of personal information: