Privacy

Your data, in plain English.

Limelight Labs · Last updated 13 August 2026 · Hosted on Google Cloud

The short version We hold the data needed to run your show: your account, the messages you send, the schedules you're on, the files you upload, and any profile details your school or company asks you to add. Most of that data belongs to your Organisation - they decide what is held and we look after it for them. We host it on Google Cloud: our database and server-side functions live in the United Kingdom, while uploaded files are currently stored in Google's United States regions under UK-approved safeguards. We share it only with the third parties needed to operate the App. We never sell it. You can ask for a copy, a correction or a deletion at any time.

Introduction

This policy explains how Limelight Labs ("we", "us", "our") handles personal data in connection with the Limelight app and website. We wear two hats, and this policy is honest about which is which:

  • For account information, support enquiries, security, diagnostics and analytics, and feedback you choose to give us, we decide how and why the data is used - we are the data controller, and this policy is our transparency notice for that processing.
  • For the production data your Organisation manages through the app - cast and production profiles, schedules, messages, posts and uploaded files - your Organisation is the data controller and we act as its data processor under a Data Processing Agreement. For that data, your Organisation's own privacy information applies alongside this policy.

Each category in What data we collect below is marked to show which role we process it in.

Who we are

Limelight Labs is a trading name of Massingberd Investments Limited, a company registered in England and Wales (company number 15895057), 73 Massingberd Way, London, SW17 6AF. The app serves schools, academies, amateur dramatic societies, community theatre companies and similar production organisations.

We have not appointed a statutory Data Protection Officer (we have assessed that we are not required to), and we keep that under review. Our data protection contact is Dom Conte, dom@limelightlabs.co.uk.

What data we collect

  • Account information (we are controller) - your name, email address, password (hashed - we never see or store it in plain text), profile photo if you add one, and the Organisation and show(s) you belong to.
  • Support correspondence (we are controller) - the content of support enquiries you send us and the account details needed to answer them.
  • Diagnostic and usage data (we are controller) - crash reports and app performance data (such as load times), and in-app analytics showing which screens and features are used and the user's role. This tells us what to fix and improve; it is not used to build profiles of individual users.
  • Feedback, survey and interview responses (we are controller) - if you choose to take part in a feedback survey or interview, or send us suggestions, bug reports or feature requests, we collect what you tell us. Participation is always voluntary.
  • Device data (we are controller) - device model, operating system version, app version, a unique installation identifier and a push notification token.
  • Cast and production profile data (we are processor for your Organisation) - optional profile fields your Organisation chooses to use, which may include a short bio, costume measurements, phone number, date of birth, gender and emergency contact details. Your Organisation decides which of these fields are in use, and they are always optional for you to complete. If you provide someone else's details as an emergency contact, please make sure they are aware.
  • Content you provide (we are processor for your Organisation) - chat messages, newsfeed posts, comments, personal annotations and bookmarks, and any images, audio recordings or files you upload.
  • Device permissions - camera and photo library (profile photos and image uploads), microphone (audio uploads), Face ID / Touch ID (unlocking the app on your device only - your face or fingerprint data never leaves your device and is never available to us), and location (used only to display venue locations on a map). Each permission is used only if you grant it and only for the feature you invoke. The app does not collect or store your real-time location - venue locations shown on the map are addresses entered by your Organisation's administrators.

Special category and criminal offence data - not intended. The app provides no fields for special category data (such as information about health, racial or ethnic origin, political opinions, religious or philosophical beliefs, or sexual orientation) or for data about criminal convictions or offences, and it is not intended to be processed through the app. Please do not include it in free-text fields, messages or uploads. If it is included accidentally, we will work with your Organisation to restrict or delete it appropriately.

How we use your data, and our legal bases

Where we act as controller:

PurposeLegal basis
Creating and managing your account, signing you in, and providing the appContract (our Terms of Service)
Answering your support enquiriesContract; our legitimate interest in supporting users
Keeping the app secure and preventing fraud and abuseOur legitimate interest in protecting the platform and its users; legal obligation where applicable
Diagnostics and analytics - fixing crashes, improving performance, understanding which features are usedOur legitimate interest in operating and improving the app; consent where the law requires it for storing or accessing information on your device
Feedback, surveys and interviews - improving and developing our productsOur legitimate interest in developing the app; participation is always voluntary, and consent where we say so at the point of collection
Sending push notifications about rehearsals, messages and resourcesConsent (you can turn notifications off at any time in your device settings)
Complying with the lawLegal obligation

Any public use we make of feedback is anonymised and aggregated so that neither you nor your Organisation can be identified.

Where we act as processor, we use production data only to provide and support the app for your Organisation, on its instructions. Your Organisation is responsible for its own lawful basis for that data.

We never sell your personal data.

Who we share your data with

We use a small number of service providers (sub-processors) to run the app:

  • Google (Firebase / Google Cloud) - authentication, database, file storage, server-side functions, crash reporting and performance monitoring, and Android push notification delivery. ISO 27001 and SOC certified.
  • Stream (getstream.io) - real-time chat messaging within shows. SOC 2 Type II and ISO 27001 certified. UK/EEA data residency.
  • Apple - iOS push notification delivery (see International transfers).
  • Google Maps - displaying venue locations your Organisation's administrators have entered.

Members of your Organisation can see the information you contribute to its productions, in line with your role and the shows you belong to.

International transfers

Where your data lives:

  • The database is hosted in the United Kingdom (Google's London region).
  • Server-side functions run in the United Kingdom (Google's London region).
  • Uploaded files are currently stored, and processed, in Google's United States regions. This transfer is protected by Google LLC's certification under the UK Extension to the EU-US Data Privacy Framework (the "UK-US Data Bridge"), and the EU Standard Contractual Clauses and UK Addendum incorporated into Google's data processing terms apply as a fallback.
  • Chat messages are processed by Stream within the UK/EEA - no transfer arises.

Push notifications are delivered through Apple's and Google's global notification infrastructure. The data involved is your device's push token and the notification content, which may include a preview of a message. Payloads are encrypted in transit and held only transiently for delivery. If you would rather message content never appeared in notifications, you can turn off previews in your device's notification settings at any time.

All data is encrypted in transit (TLS 1.2 or above) and at rest.

How long we keep your data

We keep your data for as long as your account is active. If you delete your account, or ask us to, we delete your personal data within thirty days, except where we are required to keep it for legal reasons. Copies held in routine backups are purged on a rolling cycle of no more than thirty days. If you have contributed posts or comments to a show, your name is removed from them when your account is deleted; the content itself remains unless your Organisation asks us to remove it. Support and billing records are kept for up to six years, in line with UK limitation periods.

Your rights

Subject to applicable law, you have the right to access your personal data, have inaccurate data corrected, have your data deleted, restrict or object to processing, receive your data in a portable format, and withdraw consent where processing is based on it.

Who to contact depends on the data. For your account, support, diagnostics or feedback data, contact us at dom@limelightlabs.co.uk from your registered email address and we will respond within one calendar month. For cast and production profile data, messages, posts and uploads, your Organisation is the controller - contact your Organisation's administrator or data protection contact; if you send the request to us, we will pass it to your Organisation promptly.

You also have the right to complain to the Information Commissioner's Office (ico.org.uk).

Children

Organisations may only invite users under 18 where their agreement with us expressly permits it, and they are responsible for having appropriate safeguarding arrangements in place and for obtaining any parental or guardian consent required (including for users under 13) before the user signs in. We do not knowingly create accounts for children where these requirements have not been met.

Security

Data in transit is encrypted using TLS; data at rest is encrypted by our cloud provider as standard. Passwords are hashed and never stored in plain text. Access to data is controlled by role-based permissions enforced server-side, limited to what your role and shows require, and administrative access to our production systems is protected by multi-factor authentication and logged. Face ID / Touch ID runs entirely on your device.

For more on how role-based access works in practice, see our safeguarding brief.

Third-party links

The app may contain links to external resources (for example, learning materials). We are not responsible for the content or privacy practices of those third parties.

Changes to this policy

We update this policy from time to time. If we make material changes we will let you know through the app or by email, and the date at the top shows when it was last revised.

Contact us

Questions, requests or concerns: dom@limelightlabs.co.uk (data protection contact: Dom Conte). Please write from the email address registered to your account so we can verify it's you.