GDPR · CCPA · Dutch UAVG

Privacy Policy

Last updated: June 12, 2026

Your privacy matters deeply to us. This policy explains exactly what data we collect, why we collect it, and how you can control it.

1. Who We Are

Faith On Stage B.V. ("Faith On Stage", "we", "us", "our") is the data controller for personal data processed through the Faith On Stage platform. We are a company registered in the Netherlands operating a booking hub that connects Christian artists with churches, conferences, and ministries worldwide.

This Privacy Policy applies to all visitors, registered users, and others who access our website at faithonstage.com and related applications ("Platform"). It describes how we collect, use, store, and share personal information in accordance with the EU General Data Protection Regulation (GDPR), the Dutch Implementation Act (UAVG), and the California Consumer Privacy Act (CCPA) where applicable.

2. Data We Collect

We collect personal data in the following categories:

Account & Registration Data
  • Full name, stage name, or organisation name
  • Email address and password (hashed)
  • Phone number (optional)
  • Profile photo
  • User role (Artist or Organisation)
  • Country and city of operation
Profile & Platform Data
  • Artist: biography, genre tags, performance videos/audio, pricing, availability calendar
  • Organisation: church/ministry name, event history, booking preferences
  • Reviews and ratings given and received
  • Messages exchanged through our in-platform chat (Stream.io)
  • Verification documents (ID, professional credentials) — encrypted at rest
Transaction & Payment Data
  • Booking details, event dates, and agreed fees
  • Payment references and transaction IDs (via Stripe — we never store card details)
  • Stripe Connect account information for Artists
  • Invoice and payout history
Technical & Usage Data
  • IP address and approximate geolocation
  • Browser type, operating system, and device identifiers
  • Pages visited, features used, and time spent on Platform
  • Search queries within the Platform
  • Login timestamps and session data

3. How We Use Your Data

We use your personal data for the following purposes:

Platform operationTo create and manage your account, enable booking transactions, and deliver core Platform features.
Payment processingTo process payments, manage escrow, facilitate artist payouts via Stripe Connect, and issue invoices.
CommunicationTo send booking confirmations, dispute notifications, product updates, and transactional emails.
Safety & verificationTo verify artist identities, detect fraud, prevent abuse, and moderate content and reviews.
Customer supportTo respond to enquiries, process dispute claims, and resolve platform issues.
Service improvementTo analyse usage patterns, fix bugs, and develop new features (using aggregated, anonymised data where possible).
MarketingTo send newsletters and promotional content to users who have given explicit consent. You may opt out at any time.
Legal complianceTo comply with Dutch and EU law, tax obligations, and court orders.

Under the GDPR, we process your personal data on the following legal bases:

Contract performance (Art. 6(1)(b))Processing necessary to provide the Platform, facilitate bookings, and process payments.
Legitimate interests (Art. 6(1)(f))Fraud prevention, platform security, usage analytics, and improving our service.
Consent (Art. 6(1)(a))Marketing emails and non-essential cookies. You may withdraw consent at any time.
Legal obligation (Art. 6(1)(c))Tax reporting, anti-money laundering checks, and responding to legal requests.

5. Data Sharing

We do not sell your personal data. We share it only in the following circumstances:

  • With other Platform users as necessary for bookings (e.g., an Organisation sees an Artist's profile and contact details once a booking is confirmed, and vice versa).
  • With our sub-processors (listed in Section 6) who provide technical services under GDPR-compliant Data Processing Agreements.
  • With law enforcement or regulatory authorities when required by law, court order, or to protect the safety of our users.
  • With a successor entity in the event of a merger, acquisition, or sale of Faith On Stage assets. Users will be notified before data is transferred.
  • With professional advisors (lawyers, accountants) under strict confidentiality obligations.

6. Sub-processors & Third-Party Services

We use the following trusted third-party services to operate the Platform. Each is bound by a Data Processing Agreement (DPA):

ProviderPurposeLocation
SupabaseDatabase, authentication, file storageAWS eu-west-1 (Ireland)
StripePayment processing & escrowUSA (SCCs in place)
Stream.ioReal-time chat & messagingUSA (SCCs in place)
VercelCloud hosting & CDNEU edge nodes
ResendTransactional email deliveryUSA (SCCs in place)
Google AnalyticsWebsite analytics (anonymised)USA (SCCs in place)

7. Data Retention

Active account dataFor the lifetime of your account
Booking & transaction records7 years after event (Dutch tax law requirement)
Identity verification documentsDeleted within 30 days of verification approval or rejection
Chat messages2 years, then automatically deleted
Review contentRetained as long as both accounts exist
Data after account closure12 months, then permanently deleted
Anonymised analytics dataIndefinitely (not personal data)

8. Your Rights

Regardless of where you are located, you have the following rights regarding your personal data:

Right to Access
Request a copy of all personal data we hold about you.
Right to Rectification
Correct inaccurate or incomplete personal data.
Right to Erasure
Request deletion of your data ("right to be forgotten").
Right to Portability
Receive your data in a machine-readable format.
Right to Object
Object to processing based on legitimate interests or for marketing.
Right to Restriction
Limit how we use your data in certain circumstances.

To exercise any of these rights, email privacy@faithonstage.com with the subject line "Data Rights Request" and your registered email address. We will respond within 30 days. We may request identity verification before processing your request.

9. EU / EEA Resident Rights

As a Dutch company, we are subject to GDPR. EU/EEA residents have all rights listed in Section 8, plus the right to lodge a complaint with a supervisory authority:

Dutch supervisory authorityAutoriteit Persoonsgegevens (AP) — autoriteitpersoonsgegevens.nl
EU ODR platformec.europa.eu/consumers/odr

Where we transfer data outside the EEA (e.g. to Stripe or Stream in the USA), we use Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate protection.

10. Cookies & Tracking

We use the following types of cookies:

EssentialSession token, CSRF protection, auth stateNot required
FunctionalLanguage preferences, dashboard layoutNot required
AnalyticsGoogle Analytics (anonymised page views)Required — opt-in
MarketingRetargeting pixels, ad conversion trackingRequired — opt-in

You can manage cookie preferences via your browser settings or our cookie consent banner. Disabling essential cookies may affect Platform functionality.

11. Children's Privacy

The Platform is intended for users aged 18 and older. We do not knowingly collect personal data from anyone under the age of 18. If we become aware that we have collected data from a minor, we will delete it immediately.

If you are a church or ministry that involves children in events and collects children's data through Platform bookings, you are the data controller for that data. You are responsible for obtaining any necessary parental consents in compliance with applicable law.

12. Security

We implement industry-standard security measures to protect your personal data, including:

  • TLS encryption for all data in transit
  • AES-256 encryption for sensitive data at rest (including verification documents)
  • Hashed passwords using bcrypt — we never store plain-text passwords
  • Row-level security (RLS) on our database so users can only access their own data
  • Regular security audits and penetration testing
  • Strict access controls — only authorised Faith On Stage staff can access user data

Despite these measures, no system is 100% secure. In the event of a data breach, we will notify affected users and the Dutch Autoriteit Persoonsgegevens (AP) within 72 hours as required by GDPR.

13. International Data Transfers

Our primary data infrastructure is hosted in the EU (Ireland via AWS eu-west-1). However, some of our sub-processors operate outside the EEA. Whenever we transfer data internationally, we ensure at least one of the following safeguards applies:

  • An adequacy decision by the European Commission for the destination country.
  • Standard Contractual Clauses (SCCs) approved by the European Commission.
  • The recipient is certified under an approved code of conduct or certification mechanism.

You may request a copy of the relevant safeguards by emailing privacy@faithonstage.com.

14. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email (to your registered address) and display a prominent notice on the Platform at least 30 days before the changes take effect.

Your continued use of the Platform after the effective date constitutes acceptance of the updated policy. If you do not agree, please close your account before the effective date.

15. Contact & Data Protection Officer

Faith On Stage B.V. — Data Controller
Privacy enquiriesprivacy@faithonstage.com
Data Rights Requestsprivacy@faithonstage.com (subject: "Data Rights Request")
General contactinfo@faithonstage.com
Dutch supervisory authorityautoriteitpersoonsgegevens.nl
Note on DPO: As you grow, Dutch law may require you to appoint a formal Data Protection Officer (DPO) — see our advisory below.
Disclaimer: This Privacy Policy has been prepared for general informational purposes based on current applicable law. Faith On Stage recommends consulting a qualified privacy lawyer to ensure full compliance with GDPR and applicable national law before launch.