Alpha Privacy Policy

Privacy Policy

Last updated: May 18, 2026

Ghostlight (“we”, “us”, “our”) is operated from British Columbia, Canada. This Privacy Policy describes what personal information we collect through Ghostlight and its Theatre Manager application (the “Service”), how we use it, and the choices you have. We aim to comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and British Columbia’s Personal Information Protection Act (PIPA).

The Service is currently in invite-only alpha. Our practices may evolve as we move toward general availability; we will update this Policy and notify you of material changes.

1. Information we collect

We collect information in three ways:

a) Information you provide

  • Account details: email address, password (stored as a salted hash, never in plain text), display name, and your acknowledgement that you are at least 19 years old and accept our Terms.
  • Actor profile: headshots, resumes, audition videos, demo reels, biographical details (pronouns, age range, height, hair colour, build), union affiliation, and contact information you choose to add.
  • Audition submissions: the materials you submit to a call, any selected roles, and any notes or scheduling responses you provide.
  • Production data (company accounts): productions, roles, schedules, talent roster entries, reviews, ratings, notes, and uploaded production files (scripts, music, blocking, etc.).
  • Support and feedback: messages you send us by email or through the Service.

b) Information collected automatically

  • Activity logs: actions you take in the Service (sign-in, file uploads, permission changes, etc.), with timestamps. These are used for security and audit purposes.
  • Technical data: IP address, browser user agent, approximate location derived from IP, and basic device characteristics. We use IP addresses for rate-limiting authentication endpoints to defend against brute-force attacks, and to log failed-login attempts on your account.
  • Cookies: we set an HTTP-only session cookie when you sign in, and PostHog sets a first-party cookie to recognise your browser across visits. We do not use third-party advertising cookies.
  • Product analytics and session replay: we use PostHog to record which pages and features you use, errors the Service throws, and a replay of your on-screen interactions, so we can find and fix broken or confusing flows. Replays mask all on-screen text and everything you type into form fields. We use this only to operate and improve the Service, never to sell or advertise to you.

c) Information from third parties

If a theatre company invites you to join its team or a talent roster, we may receive your name and email from that company in order to send the invitation.

2. How we use your information

  • provide, operate, and improve the Service;
  • route audition submissions to the recipient theatre company;
  • authenticate you, secure your account, and detect abuse;
  • send transactional emails — verification, password resets, callbacks, offers, scheduling updates, and important notices about the Service;
  • respond to your support requests and gather pilot feedback;
  • comply with legal obligations and enforce our Terms.

We do not sell your personal information. We do not use the Service to serve third-party advertising.

3. Who can see your information

Theatre companies you submit to see the audition materials and profile information you choose to share with that submission, along with any reviewer notes their team adds internally.

Members of a company team can see productions, submissions, roster entries, and shared files for that company. Per-team-member permission controls and personal notes are described in our product documentation.

We share with service providers (sub-processors) that help us run the Service, under contractual confidentiality and security obligations:

  • Supabase — managed Postgres database and file storage.
  • Vercel — application hosting and edge delivery.
  • Resend — transactional email delivery (verification, password reset, audition notifications).
  • Upstash — Redis-backed rate limiting.
  • PostHog — product analytics, session replay, and error tracking, used to diagnose and fix problems in the Service.
  • Stripe — payment processing for pilot companies who opt in to billed services. Card details are handled by Stripe and never stored by us.

Some of these providers may store or process data outside Canada, including in the United States and the European Union. Where that’s the case, your information may be subject to the laws of those jurisdictions, including lawful access by foreign authorities.

We may also disclose information if required by law, in response to valid legal process, to protect our rights or the safety of users, or in connection with a corporate transaction (with notice to you where practicable and required).

4. Retention

We retain your information for as long as your account is active and as needed to provide the Service.

  • Account closure: when you delete your account, we mark the record deleted, disable sign-in, release your email address so it can be reused, and set your actor profile to private so it no longer appears in our directory or at its shareable link. Closing your account does not by itself erase the underlying data: your profile details, headshots, resumes, and past audition submissions are retained in our database. Audition submissions you sent to a theatre company also remain visible to that company unless they delete them on their end, since they form part of the company’s casting record.
  • Erasure on request: we do not currently run an automated purge. If you want your information deleted rather than deactivated, email us (see “Your rights” below) and we will remove it manually.
  • Activity logs and security records: retained for audit, security, and incident response for as long as we have a business or legal reason to keep them. We do not currently apply an automatic expiry to these records.
  • Backups: residual copies may persist in encrypted backups for a limited period after deletion.

We would rather describe this accurately than aspirationally: the text above reflects what the Service does today, not what we intend to build. We will update it as our deletion tooling matures; if you have questions about a specific data type, please reach out.

5. Your rights

You have the right to access, correct, or request deletion of your personal information. You may also withdraw consent for optional processing (subject to the consequences of doing so, such as no longer being able to use the Service).

Many of these rights can be exercised directly in the Service — you can update your profile, change your password, or close your account from your settings. For anything that you can’t do yourself, email hello@ghostlight.tech and we’ll respond within a reasonable timeframe (and within any statutory deadline).

If you believe we are not handling your information appropriately, you can contact the Office of the Privacy Commissioner of Canada or the Office of the Information and Privacy Commissioner for British Columbia.

6. Security

We use industry-standard measures to protect your information — encryption in transit (HTTPS), password hashing, HTTP-only session cookies, rate limiting on authentication endpoints, and account lockout after repeated failed login attempts. No system is perfectly secure, however, and because the Service is in alpha you should treat the Service as you would any pre-release software.

Suspect a security issue? Please report it to hello@ghostlight.tech.

7. Children

The Service is intended for users 19 years of age or older(the age of majority in British Columbia). We do not knowingly collect personal information from anyone under 19. If you become aware that someone under 19 has provided us with personal information, please contact us and we will take steps to delete it.

8. Changes to this Policy

We may update this Policy from time to time. Material changes will be communicated through the Service or by email before they take effect. The “Last updated” date at the top of this Policy reflects the most recent revision.

9. Contact

Privacy questions, access or deletion requests, or feedback on this Policy: hello@ghostlight.tech.