Privacy Notice
Last updated: July 24, 2026
This page is maintained by TLiveHub to answer common privacy and data-handling questions about the TLiveHub service. It describes the practices of TLiveHub as an app owner and references platform capabilities we rely on; it is not an independent certification.
1. Who we are
This Privacy Notice describes how TLiveHub ("we", "us", "our") collects and processes personal data when you use tlivehub.com and the TLiveHub workspace. For personal data you provide when using the Service, TLiveHub acts as the data controller.
TLiveHub is a shared workspace for live production teams. The source of truth for your assets stays in your own storage (typically your Dropbox). We only administrate the workflow — draft versions, timestamped feedback, approvals, memberships, and notifications — and keep lightweight review copies to power the app. We do not own or claim rights over your master files.
2. Personal data we collect
- Account data — name, email address, sign-in identifiers (including Google, if you sign in with Google).
- Workspace content — event/setlist names, track names, ordering, comments and voice notes, approvals, membership roles, and light-weight audio previews and waveform data derived from the files you share with TLiveHub.
- Dropbox connection metadata — when you connect Dropbox, we store the connection's refresh token, your Dropbox account id, display name and email, and the specific folder path you point us at. We use this only to read/list the folder you selected and to mirror memberships you choose to share.
- Support and feedback messages — communications you send us in-app or by email.
- Usage and telemetry — pages visited, features used, playback events, sync events, and error logs.
- Device data — browser, operating system, and IP address.
- Billing data — handled by Paddle as our Merchant of Record (see section 5).
3. How we use your data
- Create and operate your account and workspace (contract performance);
- Sync content between your storage (Dropbox) and the TLiveHub workspace, and mirror memberships you enable (contract performance);
- Provide notifications, share links, and approval workflows (contract performance);
- Provide and improve the Service, including product analytics and error monitoring (legitimate interests);
- Prevent fraud and secure the Service (legitimate interests, legal obligation);
- Provide customer support (contract performance);
- Send service updates and, where permitted, product announcements (consent or legitimate interests — you can unsubscribe at any time).
4. What we don't do
- We don't sell your personal data.
- We don't use your workspace content (audio, comments, setlists) to train third-party AI models.
- We don't touch files in your Dropbox outside the folder you explicitly point TLiveHub at, and we do not write to your master files by default. Any destructive Dropbox operation is guarded server-side and requires an explicit user action.
- We don't require guests to create an account to view a share link.
5. How we share your data
We use a limited set of named subprocessors that process personal data on our behalf under contract, strictly to operate the Service:
- Supabase / Lovable Cloud — application database, authentication, storage of draft audio previews and waveform data, and edge runtime (EU/US regions).
- Cloudflare — CDN, DNS, and edge compute for tlivehub.com.
- Resend — transactional email delivery (invitations, notifications, service updates).
- Google — if you sign in with Google, Google shares your basic profile (name, email, avatar) with us to create your account.
- Dropbox — when you connect Dropbox, TLiveHub exchanges data with Dropbox on your behalf to list files, read draft versions, and (if you enable it) invite collaborators to the folder you selected. Your use of Dropbox is governed by Dropbox's own terms and privacy policy.
- Paddle (Merchant of Record) — we use Paddle.com as our reseller and Merchant of Record. Paddle processes your payment data, manages your subscription, handles invoicing and sales tax, and provides customer service for orders. See the Paddle Privacy Notice.
- Collaborators you invite — people you add to an event/setlist can see your display name, the content you contribute (tracks, comments, approvals), and activity within that workspace, according to their role (owner, editor, viewer) and their production role (music director, playback, lighting, etc.).
- Recipients of share links — anyone who has an active share link you generated can view the shared setlist and its draft audio while the link is valid; you can revoke links at any time.
- Professional advisers — legal, accounting, and similar advisers, where necessary.
- Authorities — where required by law or to protect our rights.
We do not add new subprocessors without updating this notice. If you require a Data Processing Agreement (DPA), contact us via the in-app support channel.
6. Legal bases
We process personal data on the basis of contract performance, our legitimate interests (running and improving the Service, security, fraud prevention), your consent where required (e.g. marketing emails, non-essential cookies), and compliance with legal obligations.
7. International transfers
Personal data may be transferred outside your country, including to the United States and other regions where our subprocessors operate. Where data leaves the UK or EEA, we rely on appropriate safeguards such as Standard Contractual Clauses or adequacy decisions.
8. Retention
We retain account data and workspace content for as long as your account is active. When you cancel or delete your account, we delete or anonymize your personal data within a reasonable period, except where we must keep it to comply with legal obligations (e.g. billing records), resolve disputes, or enforce agreements. Because your master files live in your own Dropbox, deleting your TLiveHub account does not delete anything in your Dropbox.
9. Your rights and self-serve controls
Subject to applicable law, you may have rights to access, correct, delete, restrict, or port your personal data, to object to processing, and to withdraw consent. Users in the UK or EEA have the right to lodge a complaint with their local data protection authority. We aim to respond to requests within one month.
You can exercise the most common rights directly inside the app:
- Access / portability — download a JSON export of your profile, memberships, comments, approvals, and notification preferences from Account → Your data.
- Erasure — request account deletion from Account → Your data. We process deletion within 30 days; during that window you can cancel the request. Shared workspace content you contributed (e.g. comments on other people's events) is anonymized rather than removed, to preserve the collaborators' history.
- Disconnect Dropbox and revoke share links at any time from inside the event.
- Notification preferences can be adjusted from Account → Email notifications.
10. Staff access
TLiveHub staff have technical access to the production database and storage because we operate the Service. Access to individual workspace content(event names, tracks, comments, draft audio) is restricted to what is necessary to (a) respond to a support request you initiated, (b) investigate a security incident, or (c) comply with a legal obligation. Aggregate, non-identifying analytics (usage totals, storage bytes, error rates) are used routinely to operate and improve the Service. We do not browse individual workspaces for any other purpose, and we do not use your workspace content to train models or share it with third parties for their own purposes.
11. Security
We implement technical and organizational measures appropriate to the risk, including encryption in transit, role-based access controls at the row level, audit logging, and server-side write-scoping for any destructive operation against connected storage. No system is perfectly secure; you are responsible for protecting your own account credentials and share links.
12. Cookies
We use essential cookies required to operate the Service (such as authentication and session cookies) and may use limited analytics to understand usage. You can manage cookies through your browser settings.
13. Children
TLiveHub is intended for professional use and is not directed to children under 16. We do not knowingly collect personal data from children.
14. Changes
We may update this Privacy Notice from time to time. Material changes will be surfaced in the app or by email where appropriate.
15. Contact
For privacy questions or to exercise your rights, contact us via the support channel inside the app. For payment and billing privacy questions, contact Paddle at paddle.net.