Legal
Privacy Policy
Last updated October 2, 2026
StudioSide is a tool that studios use to run their bookings, sessions, clients, invoices, and payments. This policy explains what we collect, why, who we share it with, and the choices you have. We wrote it in plain English on purpose.
Who we are
StudioSide is operated by StudioSide LLC (“StudioSide,” “we,” “us”). If you have a question about privacy or your data, email hello@studioside.app.
Two kinds of data
It helps to separate two things. First, your account data — the information about you and your studio. Second, your studio data — the information you put into StudioSide to run your business, which includes personal details about your own clients and team.
For your studio data, you are in charge. You decide what to add, you can export it at any time, and you can close your account, which deletes everything in it that StudioSide holds. We process it on your behalf to provide the service — we do not use it for our own purposes.
What we collect
- Account and studio details: your name, email, password (stored hashed, never in plain text), studio name, address, time zone, branding, and settings.
- Your clients and contacts: names, email addresses, phone numbers, company details, who pays for whom, outside crew you record, and any notes you choose to add.
- Files and photos you upload to a client or a note, and whatever they contain.
- Whether a client agreed to receive text messages, on client records made before 25 September 2026. StudioSide no longer asks for this and does not send text messages.
- Sessions and scheduling: bookings, rooms, times, gear, and the team assigned to each session.
- Your team: shifts, clock-in and clock-out times and breaks, availability and time off, and pay rates and amounts. If a studio turns on its location check for clocking in, the location of the device at clock-in and clock-out.
- Who arrived at the studio, if a studio uses check-in.
- Your booking portal, if a studio invites a client to it: the client’s email address, their sign-in, and the booking requests they send.
- Invoices and payments: line items, amounts, invoice status, and payment records.
- Quote approvals: when someone approves a quote online, the email address the studio named for approving it, when they opened it with the code we emailed them, the name they typed, the signature they drew, the consent wording they agreed to, when they signed, and the IP address and device (browser) they used. We keep a signed PDF copy of the quote and a fingerprint (hash) of it, and send that copy to them and to the studio. If they decline, any reason they choose to give.
- Payment details: handled by Stripe. Card numbers never reach our servers, and we store no part of one. Stripe’s own payments panel inside StudioSide can show a card’s last four digits.
- Connected accounts: if you connect Google Calendar, the calendar data needed to sync. The token that keeps the connection working is stored encrypted.
- Notifications: if you turn them on, the address your device uses to receive them.
- Basic technical data: sign-in and session cookies, plus standard server logs needed to keep the app secure and working.
- Visits to our public pages: which page, the site the visitor came from, their country, and a visitor tag that changes every day. No IP address or cookie is kept for this.
- How the product gets used: which pages are opened and which buttons and links are clicked, including the words on them, and masked recordings of app sessions in which text and anything you type is hidden.
- Crash reports and timings: what the app was doing when something broke, and how fast pages and the requests they make run. Reports from inside the app are tagged with your id and email. We remove the email addresses and phone numbers we can recognise from the text of error reports.
How we use it
- To run the product: show your schedule, create and send invoices, record payments, and keep each studio's data separate from every other studio's.
- To process payments through Stripe, including subscription billing and (if you turn it on) payments from your clients.
- To send messages you ask us to send, such as invoice emails and reminders.
- To keep the service secure, debug problems, and prevent abuse.
- To see which parts of the product actually get used, and to record crashes so we can fix them.
We do not sell your data. We do not use your studio data to train AI models unless your studio’s owner turns that on in Settings, and anything we use is anonymized first.
Who we share it with
We use a small set of trusted companies (“subprocessors”) to run StudioSide. Each receives only what it needs, and each is bound by its own privacy and security terms:
- Supabase — database, sign-in, and file storage.
- Vercel — application hosting, scheduled jobs, and page-view counts.
- Stripe — subscription billing and client card payments.
- Resend — transactional email.
- Google Calendar — one-way calendar sync, only if you connect a Google account.
- Google sign-in — signing in with a Google account, only if you choose to sign in with Google.
- Google Gemini — drafting help-centre answers from support tickets, only if you write to support and we turn your ticket into a published answer.
- Sentry — error monitoring.
- PostHog — product analytics and session replay.
- Mapbox — address and city lookup, and the map of your studio.
- OpenStreetMap — address lookup, when Mapbox isn’t set up or has no answer.
- Google Analytics — marketing-site visitor counts.
- Apple, Google, Microsoft and Mozilla push services — delivering notifications to your phone or computer, only if you turn on notifications on a device.
The full list, with what each one actually receives, is on our security page.
We may also share data if the law requires it, or to protect StudioSide, our users, or the public. If StudioSide is ever involved in a merger or acquisition, we will tell you before your data moves to a new owner.
Your clients' data and consent
When you add a client’s contact details or send them an email through StudioSide, you are responsible for having the right to do so. You should only message people who expect to hear from you, and you must honor any request to stop.
If you invite a client to your booking portal, they sign in with a link we email them, and the requests they send are stored with the rest of your studio’s data. We email them about their requests on your behalf.
Keeping and deleting data
We keep your data for as long as your account is open. You can export it to CSV at any time. If you cancel your plan, your data stays where it is, so you can export it or pick up where you left off if you come back. An owner can close the account in Settings: the studio disappears at once, billing stops at the end of the period already paid for, and 30 days later all its data is permanently deleted. Sign in within those 30 days to restore it. To delete everything at once, contact support at hello@studioside.app. Either way we keep only what we are legally required to keep (for example, basic billing records), and routine backups age out on their own.
Each studio’s history of changes — what changed, what it was before, when, and usually who changed it — is kept for twelve months and then removed automatically.
Your rights and choices
From inside the app you can see, correct, and export your data, archive a client, and close your account, which deletes your whole studio after 30 days. To ask about erasing one person’s record completely, or deleting your own login, email us at hello@studioside.app. Depending on where you live, you may have additional rights over your personal information; we will honor those requests.
How we protect it
Every studio’s data is separated at the database level, and our own code checks the rest. Data is encrypted in transit, passwords are stored hashed, and the Google Calendar connection token is encrypted at rest. No system is perfectly secure, but we take this seriously.
Cookies
We use cookies to sign you in and keep your session working, including remembering which studio you are viewing, and to remember display choices such as a collapsed sidebar. Our public marketing pages and the sign-in page also set Google Analytics cookies so we can count visits, and PostHog sets one across the site so we can see which pages get used. Our host, Vercel, counts page views without a cookie. If you sign in with Google, Google’s own sign-in script runs on the sign-in page. We do not use advertising or cross-site tracking cookies.
Where data is processed
StudioSide is operated from the United States, and your data is processed there. If you use StudioSide from outside the U.S., you understand that your data is handled in the U.S.
Children
StudioSide is a business tool and is not directed to anyone under 18.
Changes to this policy
If we make a meaningful change, we will update the date at the top and, where appropriate, let you know in the app or by email.
Contact
Questions? Email hello@studioside.app.