Privacy Policy
Last updated: 15 March 2026
1. Introduction
Castora ("we", "us", "our") operates the Castora platform at getcastora.com and app.getcastora.com. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our services.
By using Castora, you agree to the collection and use of information in accordance with this policy. If you do not agree with this policy, please do not use our services.
2. Information We Collect
2.1 Information you provide
- Account information — name, email address, and password when you create an account.
- Organisation details — organisation name, team member information, and role assignments.
- Audition content — audition briefs, scripts, reference materials, and other files you upload.
- Submission content — self-tape videos, headshots, CVs, and other materials submitted by performers.
- Reviews and scores — scorecard ratings, comments, verdicts, and discussion content.
- Payment information — billing details processed through our payment provider (Stripe). We do not store full credit card numbers on our servers.
- Communications — messages you send through our contact form or support channels.
2.2 Information collected automatically
- Usage data — pages visited, features used, actions taken within the platform.
- Device information — browser type, operating system, device type, and screen resolution.
- Log data — IP address, access times, referring URLs, and error logs.
- Cookies — see Section 7 below for details on our cookie usage.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services.
- Process audition submissions and facilitate the review workflow.
- Send transactional emails (account confirmations, submission notifications, review alerts).
- Process payments and manage subscriptions.
- Respond to support requests and communications.
- Analyse usage patterns to improve the platform experience.
- Detect, prevent, and address technical issues and security threats.
- Comply with legal obligations.
We do not sell your personal information to third parties. We do not use your audition content or submission materials for any purpose other than providing our services to you.
4. Data Storage and Security
Your data is stored securely using industry-standard practices:
- Application data — stored in Supabase-hosted PostgreSQL databases with encryption at rest.
- Media files — video, audio, and document files are stored in Wasabi cloud storage with server-side encryption.
- Data in transit — all data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher.
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
5. Third-Party Services
We use the following third-party services to operate Castora:
- Supabase — database hosting and authentication services.
- Wasabi — cloud object storage for media files.
- Stripe — payment processing. Stripe's privacy policy applies to payment data they process.
- EmailIt — transactional email delivery.
Each of these providers has their own privacy policies governing their handling of your data. We have data processing agreements in place with each provider where applicable.
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide our services. Specifically:
- Account data — retained until you delete your account.
- Audition and submission content — retained for the duration of your subscription. Deleted content may be retained in backups for up to 30 days.
- Payment records — retained as required by applicable tax and accounting regulations.
- Log data — retained for up to 12 months for security and debugging purposes.
When you delete your account, we will delete or anonymise your personal data within 30 days, except where we are required by law to retain it.
7. Cookies
Castora uses cookies and similar technologies to:
- Essential cookies — maintain your session and authentication state. These are necessary for the platform to function.
- Preference cookies — remember your settings and preferences (e.g., theme, notification preferences).
- Analytics cookies — understand how you use the platform so we can improve it. These are anonymised and do not track you across other websites.
You can control cookie preferences through your browser settings. Disabling essential cookies may prevent you from using certain features of the platform.
8. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Correction — request correction of inaccurate or incomplete personal data.
- Deletion — request deletion of your personal data, subject to legal retention requirements.
- Portability — request a copy of your data in a structured, machine-readable format.
- Objection — object to processing of your personal data for specific purposes.
- Restriction — request restriction of processing in certain circumstances.
To exercise any of these rights, please contact us at privacy@getcastora.com. We will respond to your request within 30 days.
9. Children's Privacy
Castora is not intended for use by children under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
10. International Data Transfers
Your data may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for any international transfers of personal data, including standard contractual clauses where required.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page and updating the "Last updated" date. Your continued use of Castora after changes are posted constitutes acceptance of the updated policy.
12. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
- Email: privacy@getcastora.com
- Contact form: getcastora.com/contact