The short version
We hold the data needed to run your show: your account, the messages you send, the schedules you're on, the files you upload, and any profile details your school or company asks you to add. Most of that data belongs to your Organisation - they decide what is held and we look after it for them. We host it on Google Cloud, with data held in the United Kingdom. We share it only with the third parties needed to operate the App. We never sell it. You can ask for a copy, a correction or a deletion at any time.
Introduction
This privacy policy explains how Limelight Labs ("we", "us", "our") collects, uses and protects personal data when you use the Limelight mobile application and related services (the "App"). Our role depends on the data. For some data we are the data controller, meaning we decide how and why it is processed - this covers your account and login details, diagnostic and crash data, billing and support enquiries. For the data your Organisation asks us to hold so it can run its productions - such as cast profiles, schedules, messages and uploaded resources - your Organisation is the data controller and we act as its data processor, processing that data only on its instructions. This policy covers both roles.
If you have any questions about this policy or your data, please contact us at dom@limelightlabs.co.uk.
Who we are
Limelight Labs is a trading name of Massingberd Investments Limited, a company registered in England and Wales (company number 15895057) whose registered office is at 73 Massingberd Way, London, England, SW17 6AF. The App is invite only and is provided to schools, academies, amateur dramatic societies, community theatre companies and similar production organisations (each an "Organisation"). Where an Organisation has invited you to use the App, that Organisation is the data controller for the personal data it asks us to hold on its behalf - for example cast profiles, rehearsal schedules, messages and uploaded resources - and we act as that Organisation's data processor for it under a Data Processing Agreement, handling it only on the Organisation's documented instructions.
What data we collect
We collect and process the following categories of personal data. Some of this we hold as controller; much of it - in particular your cast profile and the content of your show - we hold as processor on behalf of your Organisation.
- Account information - name, email address, password (stored securely and hashed by our authentication provider), profile photo, a short bio and the Organisation and show(s) you belong to.
- Cast and production profile data - where your Organisation uses these features, your profile may also include your phone number, date of birth, gender, emergency contact details (name, phone number and relationship), costume measurements (such as height, chest, waist, hips, inseam, head circumference and shoe size) and any special requirements. This supports real production needs such as casting, costume fitting and duty of care. It is optional and is held on behalf of, and under the instructions of, your Organisation.
- Health information (special category data) - some Organisations choose to record medical conditions and allergies so they can keep performers safe during rehearsals and performances. This is special category data under data protection law. It is entirely optional, and where it is collected it is held on behalf of your Organisation, which is responsible for obtaining the appropriate lawful basis (normally the explicit consent of the performer, or of a parent or guardian for performers under 18).
- Content you provide - chat messages, newsfeed posts, comments, personal annotations and bookmarks, and any images, audio recordings or files you upload.
- Diagnostic and usage data - crash reports and app performance data (such as load times), used to keep the App stable and fix bugs. Where in-app analytics are enabled in future, this may also include which screens and features are used.
- Device data - device model, operating system version, app version, a unique installation identifier and a push notification token.
- Device permissions - camera, microphone, photo library, Face ID / Touch ID and location access, used only when you grant permission on your device and only for the feature you invoke.
Other than the medical information described above, which an Organisation may choose to record, please do not upload special category data such as political, religious or biometric information through the App.
How we use your data
We use your personal data for the following purposes:
- Providing and operating the App, including authenticating you, showing you your Organisation's content and enabling communication within your show.
- Sending you push notifications about rehearsals, new resources and messages, where you have enabled them.
- Keeping the App secure, investigating suspected misuse and preventing fraud.
- Understanding how the App is used so we can improve it and fix bugs.
- Responding to your enquiries and providing customer support.
- Complying with our legal obligations.
For data we hold as processor on behalf of your Organisation, we only use it to provide and support the App for that Organisation and act on its documented instructions - we do not use it for our own purposes.
Legal bases for processing
Under UK and EU data protection law, we rely on the following legal bases:
- Contract - to provide the App to you under our Terms of Service.
- Legitimate interests - to operate, secure and improve the App, and to communicate with our users.
- Consent - for optional features such as push notifications, camera, microphone, photo library and location access. You can withdraw consent at any time in your phone's Settings.
- Explicit consent - for any health information (such as medical conditions or allergies) your Organisation chooses to record. Your Organisation is responsible for obtaining this consent.
- Legal obligation - where we are required to process your data to comply with the law.
Where we act as processor, your Organisation (as controller) is responsible for establishing the lawful basis for the data it asks us to hold.
Who we share your data with
We share your personal data only with trusted service providers who help us deliver the App:
- Google (Firebase) - authentication, database (Cloud Firestore), file storage, cloud functions, crash reporting (Crashlytics), performance monitoring and push notification delivery (Firebase Cloud Messaging). Data is processed by Google Cloud, which holds ISO 27001 and SOC 1/2/3 certification among others, in Google's UK / EEA regions.
- Stream (getstream.io) - real-time chat messaging within shows. Stream processes message content and related metadata on our behalf, and is SOC 2 Type II and ISO 27001 certified.
- Apple - delivery of push notifications via the Apple Push Notification service.
- Google Maps - to display venue locations on a map, if your Organisation has added venue addresses.
We also share your data with your Organisation (for example your school or drama society), so teachers, directors and organisation admins can see the data you contribute to a production. We never sell your personal data.
International transfers
Your data is processed in the United Kingdom (and, for some services, the European Economic Area, which benefits from UK adequacy). Some limited processing may still involve a transfer outside the UK / EEA - for example, push notifications are delivered via Apple's global infrastructure. Where that happens, we rely on appropriate safeguards, including the UK International Data Transfer Addendum and EU Standard Contractual Clauses, to ensure your data continues to be protected to UK / EU standards.
How long we keep your data
We keep your personal data for as long as your account is active, plus a reasonable period thereafter to comply with our legal obligations, resolve disputes and enforce our agreements. When your Organisation deletes your account, or when you ask us to delete your account, we will remove your personal data within thirty days, except where we are required to keep it for legal reasons.
Your rights
Subject to local law, you have the right to:
- Access the personal data we hold about you.
- Ask us to correct inaccurate or incomplete data.
- Ask us to delete your data (the right to be forgotten).
- Restrict or object to our processing of your data.
- Receive a copy of your data in a portable format.
- Withdraw consent where we rely on it.
- Lodge a complaint with a data protection authority. In the UK this is the Information Commissioner's Office (ico.org.uk).
To exercise any of these rights, email dom@limelightlabs.co.uk from the address on your account. We aim to respond within one calendar month.
Children
Limelight is often used by performers under the age of 18. Where an Organisation invites users under 13, that Organisation must obtain appropriate parental or guardian consent before the user signs in. We do not knowingly create accounts for children under 13 without such consent. If you believe a child has an account without appropriate consent, please contact us and we will remove the account.
Security
We take the security of your data seriously. Data in transit is encrypted using TLS. Data at rest is encrypted by our cloud providers. Access to data is controlled by role-based permissions and is limited to authorised personnel of Limelight Labs and your Organisation. Passwords are hashed and never stored in plain text.
For more on how role-based access works in practice, see our safeguarding brief.
Third-party links
The App may contain links to third-party websites or resources. We are not responsible for the content or privacy practices of those third parties. Please review their privacy policies before providing them with personal data.
Changes to this policy
We may update this policy from time to time. If we make material changes, we will let you know through the App or by email. The "Last updated" date at the top of this page shows when the policy was last revised.