Privacy Policy
Effective Date: February 16, 2026
In Plain English: We collect minimal data. Your stage plots stay on your device. We use privacy-friendly analytics. You can delete your data anytime. We don't sell anything to anyone.
1. Introduction
This Privacy Policy describes how Gryphon Graham, operating as go·for·show ("we", "us", or "our"), collects, uses, and protects information when you use our website (goforshow.io) and applications, including stage·left, back·line, carnet, changeover, loadin, and settle·up (collectively, the "Services").
We are based in New York City, USA. For privacy inquiries, contact us at legal@goforshow.io.
2. Information We Collect
2.1 Information You Provide Directly
Email Address: When you purchase a Pro license or sign up for our mailing list, we collect your email address.
Payment Information: Payment processing is handled entirely by Stripe. We never see or store your credit card numbers, billing addresses, or other payment details. Stripe provides us with a confirmation of payment and a customer ID.
2.2 Information Stored Locally on Your Device
Application Data: Your stage plots, input lists, backline data, tour schedules, financial records, and all other content you create using our Services are stored locally in your browser using localStorage and IndexedDB. This data never leaves your device unless you explicitly export or share it.
Preferences and Settings: Your application preferences, language selection, theme choices, and license information are stored locally in your browser.
2.3 Analytics and Usage Data
We use analytics services to understand how our Services are used. This helps us improve the product and fix bugs.
| Service | Purpose | What's Collected |
|---|---|---|
| Plausible Analytics | Privacy-friendly usage analytics | Page views, referrers, device type (no personal data, no cookies) |
| Google Analytics (GA4) | Usage patterns and demographics | Anonymized usage data, approximate location (country/city level) |
Important: Plausible Analytics does not use cookies and does not collect any personally identifiable information. Google Analytics is configured to anonymize IP addresses and respect Do Not Track settings.
2.4 Error Monitoring
We use Sentry for error monitoring. When a JavaScript error occurs in the application, Sentry may collect:
- Error messages and stack traces
- Browser type and version
- Operating system
- Page URL where the error occurred
Sentry does not collect personal information or the content of your stage plots or application data.
2.5 Information We Do Not Collect
- Your name (unless you provide it in communications)
- Your stage plot data (it stays on your device)
- Your location (beyond country-level analytics)
- Your browsing history outside our site
- Any information from children under 13
3. How We Use Your Information
We use the information we collect for the following purposes:
- To process purchases: Your email is used to generate and deliver your license key
- To provide customer support: Responding to your questions and resolving issues
- To send product updates: If you subscribe to our mailing list (you can unsubscribe anytime)
- To improve our Services: Analytics help us understand what features are used and what needs improvement
- To prevent fraud: Verifying license keys and preventing abuse of our services
- To comply with legal obligations: Tax reporting, responding to lawful requests
4. Third-Party Services
We use trusted third-party services to operate our business. Each has their own privacy policy:
| Service | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|
| Stripe | Payment processing | Email, payment info | stripe.com/privacy |
| Supabase | Database (license storage) | Email, license keys | supabase.com/privacy |
| Vercel | Hosting and infrastructure | HTTP requests, IP addresses | vercel.com/legal/privacy-policy |
| SendGrid | Transactional emails | Email addresses | twilio.com/legal/privacy |
| Buttondown | Mailing list | Email addresses | buttondown.com/privacy |
| Plausible | Analytics | Anonymized usage data | plausible.io/privacy |
| Google Analytics | Analytics | Anonymized usage data | policies.google.com/privacy |
| Sentry | Error monitoring | Error data, browser info | sentry.io/privacy |
We do not sell, rent, or share your data with any other third parties.
5. Cookies and Local Storage
5.1 Essential Storage
Our applications use browser localStorage and IndexedDB to store your stage plots, settings, and license information. This is essential for the app to function and cannot be disabled without losing functionality.
5.2 Analytics Cookies
Google Analytics may set a first-party cookie (_ga) to distinguish unique users. This cookie does not contain personal information. You can opt out of Google Analytics by using the Google Analytics Opt-out Browser Add-on.
Plausible Analytics does not use cookies.
For more information, see our Cookie Policy.
6. Data Security
We take reasonable measures to protect your information:
- Encryption: All data transmitted between your browser and our servers is encrypted using HTTPS (TLS)
- Secure infrastructure: Our database (Supabase) uses encryption at rest and in transit
- Access controls: Only authorized personnel have access to our systems
- Regular security updates: We keep our dependencies and infrastructure up to date
However, no method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
For more information, see our Security page.
7. Data Retention
- License records: Retained as long as your license is active, or as required by law (e.g., tax purposes)
- Email list subscriptions: Retained until you unsubscribe
- Analytics data: Retained per each provider's default policy (typically 26 months for GA4, indefinitely for Plausible aggregated data)
- Error logs: Retained for 90 days in Sentry
- Local application data: Stored on your device until you clear your browser data or delete it manually
8. Your Rights
8.1 Rights Under GDPR (European Users)
If you are located in the European Union or European Economic Area, you have the following rights:
- Right to access: Request a copy of your personal data
- Right to rectification: Request correction of inaccurate data
- Right to erasure: Request deletion of your data ("right to be forgotten")
- Right to restrict processing: Request that we limit how we use your data
- Right to data portability: Request your data in a machine-readable format
- Right to object: Object to processing based on legitimate interests
- Right to withdraw consent: Withdraw consent where we rely on it
Legal basis for processing: We process your data based on (a) contract performance (providing the Services you purchased), (b) legitimate interests (improving our Services), and (c) consent (for analytics and marketing).
8.2 Rights Under CCPA (California Users)
If you are a California resident, you have the following rights under the California Consumer Privacy Act:
- Right to know: Request disclosure of what personal information we collect, use, and share
- Right to delete: Request deletion of your personal information
- Right to opt-out: Opt out of the "sale" of personal information (note: we do not sell personal information)
- Right to non-discrimination: We will not discriminate against you for exercising your rights
8.3 How to Exercise Your Rights
To exercise any of these rights, email us at legal@goforshow.io with:
- Your email address associated with your account
- A description of your request
- If applicable, proof of identity
We will respond within 30 days (or as required by applicable law).
9. International Data Transfers
We are based in the United States. If you access our Services from outside the US, your information may be transferred to, stored, and processed in the US where our servers and service providers are located.
By using our Services, you consent to the transfer of your information to the US and other jurisdictions that may have different data protection laws than your country.
For European users, we rely on Standard Contractual Clauses (SCCs) and other appropriate safeguards when transferring data outside the EEA.
10. Children's Privacy
Our Services are not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us at legal@goforshow.io. We will delete such information promptly.
11. Do Not Track Signals
Some browsers offer a "Do Not Track" (DNT) signal. Our analytics services respect DNT signals where technically feasible. Plausible Analytics does not track users at all. Google Analytics is configured to respect DNT signals.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do:
- We will update the "Effective Date" at the top of this page
- For significant changes, we will notify you via email (if we have your email address)
- Continued use of the Services after changes constitutes acceptance of the updated policy
We encourage you to review this Privacy Policy periodically.
13. Complaints and Regulatory Contact
If you have concerns about how we handle your data and are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority:
- EU/EEA residents: Contact your local supervisory authority (list of EU authorities)
- UK residents: Information Commissioner's Office (ICO) at ico.org.uk
- California residents: California Attorney General at oag.ca.gov/privacy
14. Contact Us
If you have questions about this Privacy Policy or how we handle your data:
Email: legal@goforshow.io
Operating as: go·for·show
Location: New York City, USA
We will respond to your inquiry within 30 days.