stagetile
PrivacyTermsCookies

Privacy

Last updated: 2026-08-07

Short version

StageTile hosts a public profile page for you. We keep only the data you give us plus what we need to run the service. We don't sell your data. We don't run behavioural tracking. Our analytics (Umami) are cookieless and aggregate-only.

Who is responsible

StageTile is operated by Angel J. Haro (the "operator"). Questions about your data or this policy go to privacy@stagetile.com.

What we collect and why

  • Account + login: email and unique ID from your OAuth provider (Google or GitHub). Legal basis: contract and pre-contractual measures (GDPR Art. 6(1)(b)). StageTile never sees or stores your OAuth provider password.
  • Profile content: handle, display name, bio, services, links, page settings, uploaded photos. You enter this; we store it. Legal basis: contract.
  • Cookies: four first-party functional cookies (session, security token, theme, and page-address memory). No tracking. Details in the Cookie Policy. Legal basis: GDPR Art. 6(1)(f) legitimate interest + ePrivacy Art. 5(3) strictly necessary exemption.
  • Aggregate analytics: Umami in cookieless mode records anonymous daily counts and rough device/country buckets for the operator's dashboard. No individual tracking, no user IDs, no cross-site profiles. Legal basis: Art. 6(1)(f) legitimate interest.
  • Error and security logs: Sentry captures server errors. StageTile scrubs provider IDs, slugs, Stripe IDs, URL query strings, cookies, request bodies, and headers before sending — see the operator's Sentry configuration for the complete rule set. Legal basis: Art. 6(1)(f) legitimate interest in reliability and security.
  • Billing (when paid plans launch): Stripe processes payments. StageTile stores only the Stripe customer and subscription IDs it needs to link your account. No card data touches StageTile. Legal basis: contract.

Sub-processors

StageTile relies on the following service providers:

  • Stripe — billing (US; activated at paid-plan launch).
  • MinIO — object storage for photos, hosted on the operator's VPS.
  • Sentry — error + performance monitoring.
  • Umami — cookieless aggregate analytics, same-origin proxied.
  • Google and GitHub — OAuth login providers.
  • Operator's VPS host — server + database hosting.

StageTile does not sell personal data. StageTile does not share data with advertising networks.

International transfers

Where a sub-processor is located outside your jurisdiction, transfers rely on the sub-processor's applicable data-transfer mechanism (e.g., EU-US Data Privacy Framework, Standard Contractual Clauses, or adequacy decisions) as published by that sub-processor. MinIO runs on the operator's VPS (operator-controlled jurisdiction — infrastructure-level transfer is the operator's VPS jurisdiction).

How long we keep your data

StageTile keeps your data until you delete your account. There is no automatic purge on inactivity. If you delete your account, StageTile removes your profile, services, links, and page settings promptly and requests deletion of your stored photos; if any photo deletion fails we are alerted and follow up on the remainder. It cancels and deletes your Stripe customer record (when billing is live) and retires your page handle; in rare failure cases the handle may become claimable again. The sign-in identity record linking your StageTile account to your Google or GitHub login is deleted as part of the same operation. Active sign-in sessions are revoked on a best-effort basis; any that cannot be reached at deletion time expire within 7 days. Anonymized security-log entries (sign-in events with your account identifier removed; only truncated IP and event metadata remain) are retained for security monitoring and cannot be linked back to you. Some billing records may survive where tax or audit law requires, disclosed at paid-plan launch.

Your rights (EU / UK / similar jurisdictions)

  • Access and rectification: your dashboard shows and edits everything we hold about your profile.
  • Erasure (GDPR Art. 17): the "Delete account" button in dashboard settings removes your data without undue delay, well inside the one month the regulation allows.
  • Data portability (GDPR Art. 20): the "Export my data" button returns a JSON file with your profile, services, links, page settings, and stable public URLs to your uploaded photos (the same URLs rendered on your public profile page).
  • Objection, restriction, automated decision-making: email privacy@stagetile.com. StageTile does not perform automated decision-making.
  • Complaint: you can lodge a complaint with your local data-protection authority. EU users can find theirs at edpb.europa.eu.

Security

StageTile uses HTTPS everywhere, Spring Security with OAuth2/OIDC, CSRF protection via a double-submit cookie, per-IP rate limits on authenticated endpoints, Session cookies with SameSite=Lax, and a Content Security Policy with strict-dynamic script loading.

Changes

StageTile updates this policy as the service evolves. Material changes get an in-app notice or an email before they take effect.

StageTile -- a single, fast link for everything you do.

PrivacyTermsCookiesAbuse