Privacy Policy
Effective date: August 2, 2026
Last updated: September 6, 2026
1. Who we are
OpenStageCall (“OpenStageCall,” “we,” “us”) operates the website at openstagecall.com (the “Service”). OpenStageCall is a website; we do not publish a mobile app.
The data controller responsible for your personal data is:
Suitcase Studios, LLC330 Changebridge Rd. STE 101
Pine Brook, NJ 07058
privacy@suitcasestudios.com
Note: OpenStageCall is operated from the United States and is aimed at events in the United States. We do not target the European Economic Area, the United Kingdom, or Switzerland, but visitors from those regions are asked for consent before any advertising or analytics cookies are set (see §5). An EU/UK representative under GDPR Article 27 will be appointed if and when we knowingly offer the Service to people in those regions.
2. What this Service is, and why that matters for your privacy
OpenStageCall helps people find, host, and perform at live events — open mics, jams, showcases, and similar. Much of what you create on OpenStageCall is public by design. Before you read the rest of this policy, understand these three things:
- Performer profiles (“Acts”), tours, and events are public web pages. They are visible to anyone on the internet, including people who are not signed in, and they can be indexed by search engines and shown as link previews on social media.
- Signing up to perform or attend an event is public. Your stage name appears on that event’s page with the list of performers and attendees who will be there.
- Voting is not public, but it is recorded (see §3.5).
If you do not want something associated with your name publicly, do not put it in a profile, act, tour, event, or signup.
3. What we collect
3.1 Information you give us when you create an account
- Email address and password, if you sign up directly. Passwords are stored only as a cryptographic hash; we never see or store your plaintext password.
- Google account information (name, email address, profile picture, Google account identifier, and the authentication tokens and scopes Google issues as part of the sign-in connection), if you sign in with Google. We refresh your name and picture from Google each time you sign in. We never receive your Google password.
- Display name and, optionally: a biography, a profile picture, your general location, your roles (performer, host, fan, and similar), the instruments you play, links to your social media and streaming profiles, and payment instructions for receiving tips (see §3.6).
3.2 Information you give us when you use the Service
- Acts: stage name, act type, hometown, description, photo, media links, song lists (originals and covers), optional PDF chord sheets, band member names, and tour information. Song pages and any chord sheets you attach to them are public and can be downloaded by visitors. If you provide a hometown, we store its approximate coordinates so the Act can be found by location searches.
- Events: name, date, time, venue, description, poster image, sign-up rules, equipment (“backline”) lists, live-stream configuration, and co-host assignments. If you save an event as a reusable template, we keep the template and its event details privately with your account until you delete the template or your account.
- Event signups: your stage name and act details as they appear on that event, plus jam requests, song requests, and equipment selections. If you request a song without an account, we also record a one-way fingerprint of your IP address alongside the request, so the same person cannot repeatedly request from the same performer within 24 hours. That fingerprint is not cleared on its own; it is deleted together with the event (see §7).
- Saved searches: a name you choose, together with the filters you saved under it — which can include a location and distance radius (see §3.3). Saved searches are private to your account: they are never shown on your public profile or to anyone else.
- Follows and Event RSVPs: a list of performers and tours you follow (private to your account), and a list of events you have signed up to perform at or indicated you will attend.
- Feedback and support requests: your name, email address, and whatever you write.
- Reports, appeals, and moderation: reports you submit, reports about your content or messages, the explanation supplied with a report, moderation decisions and replacement history, copyright-removal records, and any appeal or privacy-rights request you send us. We may withhold credentials and unrelated third-party contact details when providing a copy of these records to you.
- Images you upload (profile pictures, act photos, event posters). Images are stored on Cloudflare R2 and served publicly.
3.3 Location information
Location is the most sensitive category we handle, so we describe it separately.
- Event and venue locations. When you create an event, we store the venue’s address and coordinates. These are public information about a public event.
- Your approximate location for search. If you use location-based search or set a location on your profile, we store the coordinates you chose. If you save that search, those coordinates are kept as part of the saved search until you edit or delete it. You can change or remove this at any time.
- Your precise location during signup and search. We ask your device for its coordinates on the homepage to sort search results by distance, and whenever you sign up to perform, on any plan.
- Free plan and guest signups are location-checked. Signing up to perform on the free plan — whether as a guest (no account, stage name only) or with a free account — requires you to be at the venue on the day of the event, and we check server-side that you are within roughly 500 yards (about 460 meters) of it.
- Performer and Organizer subscribers are not location-checked, and can sign up for an event whenever and wherever they like — but we still collect and store the coordinates their device reports, the same as any other signup. We ask for it uniformly so every signup carries the same record, whether or not it was gated on location.
- We store the coordinates you submitted, not just the yes/no result, as a record of the signup in case of a later dispute about who signed up.
- We delete those coordinates when the event concludes, on every plan. The signup itself remains; the coordinates do not.
- We request location only at the moment you tap to sign up. We never track your location in the background.
- If you decline the location permission on the free plan or as a guest, you cannot sign up to perform — we cannot verify you are at the venue without it. Performer and Organizer subscribers can decline and sign up anyway, since their signup was never gated on location; we simply store no coordinates for that signup.
3.4 Information collected automatically
- Session information. When you sign in, we create a session record that includes your IP address and browser user-agent string, so you can stay signed in and so we can investigate suspicious sign-ins.
- Blocked sign-in attempts. If sign-in attempts against an account are automatically blocked for coming too fast, we record the email address attempted and a one-way fingerprint of the source (not the IP address itself) — this is what lets us investigate a suspicious pattern. We also retain the matched account identifier when the attempted email belongs to an account. If it matches, we email that account to say attempts were blocked, in case it wasn't them.
- Transactional email records. When the Service sends an email, we keep its recipient, subject, message content, delivery status, and timing so failed messages can be retried and support questions can be investigated.
- Search activity. We log searches performed on the Service — the search term, location, filters, distance radius, and view type — together with which events the search returned, so accounts with the Organizer paid plan can see how many searches found their events. These logs are retained for 12 months to support venue analytics. Search logs currently do not contain user identifiers.
- Page views. We count how many times each profile, act, tour and event page is viewed, so the person who owns that page can see how much interest it is attracting. We store only a running total per page per day: no identifier, no time of day, and nothing that links a view to a particular person or visit. Views by the owner of their own page are not counted.
- Google Analytics. The website uses Google Analytics to measure traffic and understand which pages people use. It sets its own cookies and reports your page visits, approximate location, device, and browser to Google. See How Google uses information from sites that use its services.
- Cookie-consent records. Enzuzo provides our cookie banner and preference center. It records the choices you make about analytics, advertising, and preference cookies, along with the time and jurisdiction information needed to document that choice. Enzuzo also receives the ordinary browser and network information needed to deliver the banner and maintain the consent record.
- Standard server logs kept by our hosting provider, Cloudflare, for security and reliability.
Advertising is a separate matter — see §5.
3.5 Voting
To stop the same person voting for the same act repeatedly in one day, we record a per-day fingerprint of each vote.
- If you are signed in, that fingerprint is your account ID.
- If you are not signed in, that fingerprint is a one-way hash of your IP address. Under EU law an IP address is personal data, so we are telling you plainly: anonymous voting derives a non-reversible fingerprint from your IP address and records it with the act you voted for and the date. We do not store the raw IP address in the vote record. These records are deleted within 48 hours.
- We do not publish who voted for whom. Vote counts are public; voter identities are not.
3.6 Payments and tips
We do not collect or store your card number, bank details, or any payment credentials.
Subscription payments are processed by Stripe, which handles your payment details under its own privacy policy. We receive only what we need to know that your subscription is active: an identifier, the plan, the status, and the renewal date.
Performers on the Performer or Organizer plan may add payment instructions to their profile — typically a link to a third-party service such as Venmo, PayPal, or Cash App. Accounts on the free plan cannot display payment instructions; see §4 of the Terms for what each plan includes.
OpenStageCall does not process tips, hold tip money, or take any percentage of a tip. When you tip a performer, you leave OpenStageCall and transact directly with that performer through a service we do not operate. We never see the amount, the parties, or whether a tip happened at all. Any dispute about a tip is between you and the performer, governed by the terms of whichever payment service you used.
Note that a performer’s payment instructions are displayed publicly on their profile and on event pages.
3.7 What we do not collect
We do not knowingly collect: government identification numbers, financial account numbers, biometric data, precise background location, health information, or the special categories of data defined in GDPR Article 9 (racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation). Please do not put such information into free-text fields like biographies or event descriptions.
4. Why we use your data, and our legal basis
For users in the EU, UK, and other regions with similar laws, we rely on the following legal bases under GDPR Article 6:
| What we do | Why | Legal basis |
|---|---|---|
| Create and maintain your account | To give you the Service you asked for | Contract (Art. 6(1)(b)) |
| Publish your profile, acts, tours, and events | This is the core function of the Service | Contract (Art. 6(1)(b)) |
| Verify presence at the venue for guest signup | To prevent people signing up as performers they are not | Legitimate interests (Art. 6(1)(f)) — preventing impersonation and abuse |
| Send you notifications about events, follows, and votes | To operate the features you enabled | Contract (Art. 6(1)(b)) |
| Send service and security emails | To run the Service safely | Contract; legitimate interests |
| Record votes with a per-day fingerprint | To prevent ballot stuffing | Legitimate interests (Art. 6(1)(f)) — integrity of a voting feature |
| Log searches | To understand what people look for and improve results | Legitimate interests (Art. 6(1)(f)) |
| Count profile, act, tour and event page views | To show the page's owner how much interest it attracts | Legitimate interests (Art. 6(1)(f)) |
| Measure site traffic with Google Analytics | To understand how the Service is used and improve it | Legitimate interests (Art. 6(1)(f)); consent where required |
| Moderate content and act on reports | To keep the Service safe and lawful | Legitimate interests (Art. 6(1)(f)); legal obligation where applicable |
| Show advertising to free-plan users | To fund a free tier | Consent, where required (see §5) |
| Process subscription payments | To provide a paid plan you purchased | Contract (Art. 6(1)(b)) |
| Keep records of moderation decisions | To handle appeals and repeat abuse | Legitimate interests (Art. 6(1)(f)) |
Where we rely on legitimate interests, you have the right to object — see §8.
5. Advertising
The free plan shows advertising served by Google AdSense. Google may use cookies and similar technologies to serve and measure ads, including personalized ads, subject to Google’s own policies. See policies.google.com/technologies/partner-sites.
Third-party vendors, including Google, may use cookies to serve ads based on a visitor's prior visits to OpenStageCall or other websites. You can control personalized advertising through Google Ads Settings. You can also learn about opting out of participating third-party vendors at aboutads.info.
Paid subscribers see no advertising from us. Both the Performer and Organizer plans are ad-free.
Nothing in those categories loads until you allow it. Our Enzuzo consent manager asks for your consent before any advertising or analytics cookie is set, and we apply that rule to every visitor rather than only where the law requires it. You can decline or change your choice at any time, and declining does not limit your use of the Service.
Everyone can turn personalized advertising off, wherever they live. The Your Privacy Choices link in the footer of every page opens Enzuzo's preference center. You can allow or decline analytics and marketing separately, and your choice is remembered.
Our Cookie Policy explains these categories and displays the cookies identified by Enzuzo's site scanner.
We honor Global Privacy Control (GPC). If your browser or an extension sends a GPC signal, we treat it as a standing request not to share your data for personalized advertising: advertising and analytics cookies stay off automatically, you do not have to do anything else, and we honor it even if an older choice stored on your device said otherwise.
6. Who we share your data with
We do not sell your personal data. Nobody pays us for it, and we have never offered it for sale.
We do share it for advertising, in the specific sense California law means by “sharing.” The AdSense advertising described in §5 is personalized by default, and allowing an advertising partner to set cookies that build a profile of you across different websites counts as sharing for cross-context behavioral advertising — even though no money changes hands for your data. We would rather say that plainly than claim we do not share and then carve out the one place where we do. You can stop it at any time, from anywhere: use Your Privacy Choices in the footer, or send a Global Privacy Control signal. See §5 and §8.3.
We share data with the following categories of service providers, who process it on our behalf:
| Provider | What it handles | Where |
|---|---|---|
| Cloudflare | Hosting, database (D1), image storage (R2), network security | Global |
| Google — Sign-In | Authentication, if you choose to sign in with Google | US / global |
| Google — Maps & Places | Venue/location lookup and autocomplete for profiles, acts, tours, events, and searches | US / global |
| Google — Analytics | Traffic measurement on the website | US / global |
| Google — AdSense | Advertising on the website | US / global |
| Enzuzo | Cookie-consent banner, preference center, and consent records | Canada / global |
| Stripe | Subscription payments | US / global |
| Resend | Sending transactional emails (confirmations, password resets, etc.) | US / global |
We may also disclose data when required by law, to enforce our Terms, or to protect the rights and safety of our users or the public.
If OpenStageCall is ever acquired or merged, personal data may transfer as part of that transaction; we will give notice before your data becomes subject to a different privacy policy.
Media embedded in event and performer pages. Event and performer pages may contain media embedded by their creators — video (YouTube, Vimeo, Twitch), music (Spotify, Apple Music, SoundCloud, Bandcamp, Audiomack, Mixcloud), or social feeds (Facebook). Loading those embeds contacts those platforms directly from your browser, and they may set their own cookies or collect data about your visit. We do not control those platforms or their practices — see their privacy policies for details. Additionally, placeholder images for events or performers with missing photos are loaded from third-party image services and do not contain your personal data.
7. How long we keep your data
| Data | Retention |
|---|---|
| Account and profile | Until you delete your account, then deleted (see §8.1) |
| Events | 365 days after the event date, then deleted automatically |
| Performer signups | Deleted together with their event |
| Guest song-request fingerprint (§3.2) | Not cleared separately — deleted together with the event, up to 365 days |
| Signup coordinates (§3.3) | Deleted when the event concludes, on every plan |
| Notifications | 365 days after being created, then deleted automatically |
| Search logs | 12 months after being logged, then deleted automatically |
| Saved searches | Until you delete the saved search, or your account (see §8.1) |
| Saved event templates | Until you delete the template, or your account (see §8.1) |
| Page view counts (profile, act, tour, event) | 365 days after being recorded, then deleted automatically — sooner if the page they count is deleted first (event page counts specifically are deleted together with their event) |
| Session records (including IP address) | 30 days of inactivity, or until you sign out — a session you keep using stays alive on a rolling basis |
| Blocked sign-in attempt records | 90 days after being recorded, then deleted automatically |
| Vote records (including anonymous voter IP) | Within 48 hours |
| Support and feedback messages | 12 months |
| Sent-email records | 12 months |
| Subscription records | 6 months after the subscription ends |
| Moderation records (reports, decisions, strikes) | Retained while your account is active — see below; deleted together with your account (see §8.1) |
| Banned email and enforcement audit record (for-cause account removal only) | Retained indefinitely — see below |
| Appeal and privacy-rights request records | Retained indefinitely, as a record that we met our response-time commitment |
About backups. The deletion periods above describe removal from the live Service. Cloudflare D1 keeps automatic point-in-time recovery history, so database rows deleted from the live database may remain recoverable in that protected history for up to 30 additional days before expiring automatically. Deleted R2 images are removed from storage immediately, although a previously cached copy may remain available through the Service for up to five minutes. Backup history is used only for disaster recovery, not for ordinary product access.
Why we keep moderation records while your account is active. We keep records of reports, moderation decisions, and enforcement actions for as long as your account exists, without a fixed end date, so that we can recognize repeat abuse, respond to appeals, and defend our decisions. These records do not outlive your account: deleting your account deletes them too, along with the rest of your personal data. If you believe a moderation record about you should be erased sooner, contact us and we will weigh your request against those interests, as GDPR requires.
Why we keep a banned email address. If we remove your account for violating our content policies, we keep the email address you used so that address cannot simply sign up again. The enforcement audit record also keeps the reason, the date, and which administrator imposed or later lifted the ban. The rest of your account data is deleted. This does not apply if you delete your own account: it is only for removals we initiate for a policy violation. If you believe this was a mistake, contact us and we will weigh your request against our interest in enforcing the removal, as GDPR requires.
8. Your rights
8.1 Deleting your account
You can delete your account from your profile settings. When you do:
- Personal data attached to your account is deleted from the live Service, including moderation records, subject to the temporary backup history described in §7. The independently retained appeal/privacy-rights request records and blocked sign-in attempt records described in §7 follow their own retention periods instead; they are not owned by or deleted with the account.
- Your acts are removed, and your profile becomes inaccessible.
- Any upcoming event with an eligible co-host is transferred to that co-host, who is notified and becomes responsible for it. An upcoming event with no eligible co-host is cancelled, and everyone holding a slot or attending is notified. Cancelled listings stay visible, no longer attributed to you, so the people who were counting on them find out.
- Past events you organized remain as a record of what happened, no longer attributed to you, until they age out under §7.
- A concluded performance signup that includes an approved jam participant may remain with that event as a historical record. We sever its account and Act identifiers, but the snapshotted stage name and performer photo may remain public with the event until that event ages out under §7.
8.2 Your privacy rights
You have the right to:
- Access — get a copy of the personal data we hold about you.
- Rectification — correct data that is wrong or incomplete.
- Erasure — have your data deleted by deleting your account (see §8.1).
- Portability — receive data you gave us in a machine-readable format.
- Object — object to processing we base on legitimate interests, including our search-logging and page-view-counting activities.
To exercise any of these rights, contact privacy@suitcasestudios.com. We will respond within 30 days — for an access request, that means providing your data in a standard format.
8.3 Rights under California law (CCPA/CPRA)
California residents have the right to know what personal information we collect, to delete it, to correct it, to opt out of its sale or sharing, and to be free from discrimination for exercising those rights.
We do not sell personal information. We do share it for cross-context behavioral advertising in the sense described in §6 — that is what personalized AdSense advertising is. You can opt out in either of two ways, and both work whether or not you have an account:
- Use the Your Privacy Choices link in the footer of any page and choose Decline.
- Turn on Global Privacy Control in a browser or extension that supports it. We detect and honor it automatically, and it overrides any earlier choice stored on your device.
Exercising either of these changes nothing else about your use of the Service. To make any other request, contact privacy@suitcasestudios.com.
8.4 International transfers
We are based in the United States and our providers operate globally, so your data may be processed outside your home country.
9. Security
We protect your data with encryption in transit (HTTPS), hashed password storage, server-side authorization checks, and access controls limiting administrative access to a small number of people. No system is perfectly secure, and we cannot guarantee absolute security.
If there is a breach, we will tell you. If personal data we hold is lost or exposed in a way that creates a real risk to you, we will notify you — by email to the address on your account, and by a notice in the Service — without undue delay once we have established what happened and who is affected, and in any event within the deadline set by the law where you live. That notice will say what data was involved, what we have done about it, and what you can do to protect yourself. Where the law requires it we will also notify the relevant regulator; for users in the EEA or the UK that means within 72 hours of becoming aware of the breach, as GDPR Article 33 requires.
10. Children
The Service is not directed to children. You must be at least 16 years old to create an account. We do not knowingly collect personal data from children below that age. If you believe a child has given us personal data, contact us and we will delete it.
Live events often take place in venues with their own age restrictions. OpenStageCall does not verify or enforce venue age policies.
11. Changes to this policy
We will post any changes here and update the “Last updated” date. If the changes are significant, we will give notice in the Service before they take effect.
12. Contact
privacy@suitcasestudios.comSuitcase Studios, LLC
330 Changebridge Rd. STE 101
Pine Brook, NJ 07058
See also our Terms of Service.