Privacy Policy

This policy explains what information we collect when your organization uses our digital signage service, how that information is used, and the choices you have. It covers the dashboard you sign in to and the screens your organization pairs to it.

Information we collect

We collect the information needed to give you an account, keep your organization's data separate from every other organization's, and put your content on your screens. What that means in practice depends on how your organization uses the service, and the categories below describe each part of it.

Account information. When you create an account we collect:

  • your email address, which is how you sign in
  • a display name and a profile image, if you add them to your profile

Organization information. When you create or join an organization we record:

  • the organization's name
  • which accounts are members of it, the role each member holds, and whether that membership is active or suspended

Invitations. When someone is invited to an organization we record:

  • the email address the invitation was created for, which we hold whether or not that person ever creates an account
  • the role the invitation grants, when it expires, and whether it is still pending or has been accepted, revoked or expired

Content you upload. When a member of your organization uploads a file we store the file itself, along with:

  • its original filename and the name your organization gives it
  • its file type and size
  • its dimensions or duration, where those can be read from the file
  • which account uploaded it, and when

Screens and devices. When your organization pairs a device to a screen we record:

  • which device is paired to which screen, and when it was paired
  • the device's platform, model and app version, where the device reports them
  • when the device was last in contact with the service, and what it is currently showing

Billing information. If your organization takes a paid plan, its billing and payment details are entered on Stripe's checkout page rather than here, and Stripe processes them to take the payment. What comes back to us, and what we keep, is:

  • identifiers that link your organization to its customer and subscription records at Stripe
  • the country the subscription is billed in and the currency it is billed in, because the price depends on them
  • whether it is billed monthly or annually, what state it is in, and the dates of the period it is currently in
  • a record of whether each renewal payment succeeded or failed

We do not receive or store your full card number or its security code. Those are handled by Stripe. Some billing information does reach us, which is what the list above describes.

We do not collect location information from your screens or devices.

How we use this information

We use the information above to run the service, and specifically to:

  • sign you in and keep you signed in
  • show you only the organizations you belong to, and only what your role allows
  • store the content your organization uploads and deliver it to the screens it is published to
  • let a device prove it is the screen it claims to be before it receives any content
  • apply the limits that come with your organization's plan, such as how many screens it can pair or how much storage it can use
  • show your organization's owners and administrators who is a member, what is published, and which screens are online

The content your organization uploads is used to operate the service for your organization.

Service providers

We do not run our own data centres. We use service providers to operate the service, and each holds only what it needs for its part of it:

  • Supabase provides the database and the authentication that signs you in
  • a third-party object-storage provider holds the files your organization uploads
  • Stripe processes payments for paid plans, and handles the billing and payment details entered at its checkout
  • Resend delivers the email the service sends — an invitation, or a welcome message — and receives the address it is sent to and what that message says

Cookies and storage on your devices

When you sign in to the dashboard, our authentication provider sets a cookie in your browser that keeps you signed in as you move between pages. Signing out clears it. Without it you would have to enter your password on every page.

A screen is different from a browser. A paired screen keeps a local copy of the content it has been given, on the screen's own hardware, so that it keeps playing if the network drops. That local copy is cleared when the screen is unpaired.

Your choices

From the dashboard, depending on your role, you can:

  • change your display name
  • rename or delete the files your organization has uploaded
  • revoke an invitation that has not been accepted yet
  • suspend or remove a member of your organization
  • unpair a device from a screen, which clears the content stored on it

Deleting content

You can delete an uploaded file from the dashboard, and we remove it from storage. A file cannot be deleted while it is playing on a screen or is part of a playlist; remove it from those first, and it can then be deleted.

A record that the file existed and was deleted is kept, as is a record of which devices have been paired to your screens. These records are what let an organization see its own history.

Removing an entire account or an entire organization is not something the dashboard can do today.

Security

Some specific things we do:

  • access to your organization's data is checked by the database itself on every request, not only by the application, so a member of one organization cannot read another's
  • links used to upload or display a file are generated for that one purpose and stop working within minutes
  • the secret a screen uses to identify itself is stored only as a one-way hash, and so is an invitation link, so neither can be read back out of our database

No service can promise that nothing will ever go wrong. What we can say is what the mechanisms above actually do.

Children

This service is built for businesses and organizations, and accounts are intended to be created and used by adults in the course of their work. It is not directed to children, and we do not knowingly collect information from them.

Your organization and your data

If you use this service through your employer or another organization, that organization controls the account. Its owners and administrators decide who is a member, what role each member holds, and what content is stored and published. They can also remove your access.

That means questions about the information held in your organization's account are usually best raised with its owner or an administrator, who can see and change it directly.

Changes to this policy

As the service develops, this policy will change to describe what it actually does. The current version is always the one published on this page.