Last updated 2026-08-18
This policy explains what personal data we collect when you use the StageOps system, what we use it for and what rights you have. StageOps is operated by a European Union company, so the EU General Data Protection Regulation (GDPR) — one of the strictest privacy laws in the world — applies to every customer, wherever you are located.
The controller of your personal data is MB Stagelab. For questions about data processing, write to ops@stageops.lt.
When a customer enters its own employees' or clients' data into the system, that company becomes the controller of that data, and StageOps acts as a data processor on its instructions. Use of the service itself is governed by the Terms of Service.
Registration data: company name, full name, email address, phone number. Needed to create the account and to contact you.
Sign-in data: email and password. The password is stored only as a cryptographic hash — we do not have it and cannot see it.
Usage data: last sign-in time, a log of actions in the system. Needed for security and support.
Payment data: we do not collect or store payment card details. They are processed by the payment service provider in its own systems; we receive only the payment confirmation and a customer identifier.
IP address: at registration only a cryptographic hash of the IP address is stored — it is used to prevent repeat trial registrations and does not allow the address itself to be reconstructed.
Performance of the contract — creating the account, providing the service, billing. Legitimate interest — system security, abuse prevention, support. Legal obligation — accounting and tax requirements.
We do not use the data for advertising and do not sell it to third parties.
To provide the service we rely on the following subprocessors. All of them process data under written contracts and only on our instructions. The maintained list, with processing locations and transfer mechanisms, is published at /subprocessors.
Stripe processes billing and payment data in accordance with Stripe's own terms and applicable law in order to provide payment services; data your team enters about its own staff and clients does not flow to Stripe.
We also use Google (Gmail) as a communications provider for the inbound support and legal correspondence sent to our address, where we act as controller of that correspondence. Google is not a subprocessor of the data you enter into the system: automatic notifications about activity in the system carry only a generic event and an internal reference — never names, contact details or message content — and we do not forward customer data from the system into that mailbox automatically.
We keep account data and the data entered into the system for as long as the subscription is active, and for another 60 days from the end of the last paid (or trial) subscription period — so you can come back without losing your work. After that it is deleted from our active production systems. Residual copies may persist in backups for a limited further period: they are kept isolated, are not used for ordinary operations or any other purpose, remain protected, and are deleted in the ordinary course of secure backup rotation; they are restored only for disaster recovery or where the law requires it.
The registration record (email, phone) is kept even after the account is deleted — it is needed so that the trial period is not granted repeatedly. Accounting documents are kept for the period required by law.
Records of subscription authorisations — who authorised a recurring charge, when, for what amount and under which version of these documents — are kept as evidence that the payment was agreed. They are retained for up to ten years from the authorisation, in line with the statutory limitation and accounting-retention periods we are subject to, and are then deleted by a scheduled clean-up. They are not kept indefinitely.
We use only essential cookies and browser storage — they are needed to keep your sign-in session alive. We use no analytics, advertising or tracking cookies, which is why there is no consent banner.
You have the right to access your data, to have it corrected or deleted, to restrict its processing, to object to processing and to data portability. Write to ops@stageops.lt — we reply within 30 days.
If you believe your data is being handled improperly, you have the right to lodge a complaint with the Lithuanian State Data Protection Inspectorate (vdai.lrv.lt).
Data is kept on servers located in the European Union. Access to each company's data is separated at the database level — a user from one company technically cannot see another company's data. The connection to the system is encrypted.
The primary database is hosted in the European Union — the AWS eu-central-1 region (Frankfurt, Germany), through Supabase. Some subprocessors may process or access data outside the EEA — for example, our edge-hosting provider operates a global network — and any such processing takes place under Chapter V GDPR safeguards, including European Commission adequacy decisions, the EU-U.S. Data Privacy Framework, or Standard Contractual Clauses. Details per provider are listed at /subprocessors.
The rights described in this policy — access, correction, deletion, restriction, objection and portability — are offered to all users regardless of location, including residents of the United States. We do not sell personal data.
Service provider