1. Scope
This policy describes how TapToCast ("we", "us") handles information in the Service operated at this domain, including preview/demo browsing and signed-in casting workflows.
2. Information we collect
Depending on how you use the Service, we may collect and store:
- Account details such as email, display name, selected roles, verification status, authentication identities, sessions, and consent records.
- Talent profile details, including headshots, reels, credits, skills, languages, availability, representation, links, and profile visibility settings.
- Casting workflow records, including role posts, submissions, selected media, notes, shortlists, board votes, comments, saved searches, saved talent, workflow requests, calendar holds, and organization memberships or invites.
- Uploaded media and metadata, including file name, content type, size, storage key, moderation status, and derivative processing state.
- Trust and safety records, including reports, moderation decisions, NDA/sides access receipts, audit events, IP hashes, user-agent strings, and abuse-prevention rate-limit keys.
3. Browser-local information
The Service uses your browser's localStorage to remember demo preferences and fallback sample state, including:
- A self-chosen display name and persona (actor / casting director), if you set one.
- Demo submissions, shortlists, board lanes, saved searches, and UI preferences.
To delete browser-only fallback data, clear your browser's site data for this domain. Signed-in workflow state is stored server-side so it can sync across devices, enforce permissions, support moderation, and maintain audit trails.
4. How we use information
- Provide account access, authentication, roles, and workspace membership.
- Show roles, submissions, profiles, reels, shortlists, casting boards, messages, and workflow status to authorized users.
- Queue transactional emails such as email verification, password reset, submission receipts, and moderation notices.
- Detect abuse, enforce safety policies, protect confidential sides, rate-limit sensitive actions, and investigate reports.
- Improve the Service using operational diagnostics and aggregate workflow signals. We do not use advertising pixels or sell personal data.
5. Information our infrastructure may see
The Service is delivered through Cloudflare Pages, Workers/Pages Functions, D1, KV, and R2. Cloudflare, acting as our processor, may process standard request metadata (IP address, user-agent, request path, response status, approximate region), account/workflow requests, stored database records, queued rate-limit keys, and uploaded media for hosting, security, abuse prevention, caching, storage, and DDoS protection. See Cloudflare's privacy notice at cloudflare.com/privacypolicy.
6. Children
The Service is not directed to children under 13. Profiles, media, or submissions involving minors must be managed by a parent, guardian, or authorized representative, and may be subject to additional safeguards. See Children's Privacy.
7. Your rights
Depending on your location, you may have rights to access, correct, delete, export, or object to certain processing of your personal information. Contact us using the email below to make a request. We may need to verify your identity before acting on account or media data. Some records may be retained where required for security, legal compliance, anti-abuse, audit, or dispute-resolution purposes.
- EU / UK (GDPR / UK GDPR): our lawful bases may include contract, legitimate interests, consent, and legal obligation, depending on the feature.
- California (CCPA / CPRA): we do not sell or share personal information. See Your Privacy Choices.
- Other US states (CO, VA, CT, UT, TX, etc.): equivalent rights apply.
8. Security
See our Security page. We use HTTPS, security headers, rate limits, cross-origin checks, password hashing, signed session cookies, role-based API authorization, media quotas, moderation queues, and audit trails to protect the Service.
9. International transfers
Cloudflare's global edge means account, workflow, request, and media data may be processed in multiple regions. Cloudflare relies on Standard Contractual Clauses and the EU-US Data Privacy Framework where applicable.
10. Changes
We will post any change here with a new "Last updated" date. Material changes take effect 14 days after posting.
11. Contact
Privacy questions: privacy@taptocast.com.