Legal

Privacy Policy

Last updated

This policy explains what data Sheencast collects across the marketing site, the admin console, and paired screens, how it is used, and the controls you have over it.

Information we collect

Account & organization data

When you or a teammate create or are invited to an account, we store the email address used to sign in, your display name (if provided), your role within an organization, and the organizations you belong to. Sign-in is by password or one-time magic link. We never see or store your password.

Screen & device telemetry

Each paired screen produces operational telemetry for the Device Health view. No additional tracking runs on the screen. For every screen we keep a single current-state snapshot of:

These are low-sensitivity operational facts. They contain no IP address and no location.

IP address & location — opt-in only

The following are captured only when an organization admin enables “Collect IP address & location” in Admin → Settings → Organization (default off):

Precise coordinates, city, and postal code are deliberately never stored. Turning the option off stops capture immediately and scrubs any already-captured masked IP, country, and region from every device in the organization.

Usage & playback analytics

To provide proof-of-play reporting we record which content played on which screen and when, along with impression counts, playback completion, and error events. This is tied to your organization and its screens, not to individual viewers of a display.

Diagnostic & error logs

Players and services emit logs used to diagnose faults. Personal data is scrubbed from error and crash reports before they leave our systems. A full IP address is retained in a separate security audit log for events such as sign-in, pairing, and settings changes, under that log’s own retention.

Cookies & local storage

We use the minimum needed to run the product: an authentication session for the admin console, and small local-storage values for preferences (such as your light/dark theme) and player state. We do not use third-party advertising or cross-site tracking cookies.

How we use data

How data is shared

We do not sell personal data. We share it only with the service providers that run the platform on our behalf (“sub-processors”), each acting under contract and only as needed to provide their function. Those categories are: cloud infrastructure providers, managed database and authentication providers, application monitoring providers, email delivery providers, and a payment provider that acts as merchant of record for paid plans.

Customers who need the specific providers named — for a vendor or security review — can request the current list by contacting us.

Separately from those sub-processors, a few parts of the dashboard load resources directly from third parties in your browser, which means those parties see the request. We list them because they are not acting on our behalf and are not covered by the paragraph above:

Screens themselves load YouTube, Vimeo and Google Slides content directly from those services when you schedule it, for the same reason.

We may also disclose data where required by law or to protect the rights and safety of our users and the service.

Data retention

We keep operational and diagnostic records only as long as they are useful for running the service — at most 90 days, and in most cases far less. Security audit records, which log events such as sign-in, pairing and settings changes, are kept for up to one year. For Device Health we keep the most recent value for each screen plus an hourly history for up to 14 days, used to show storage and memory trends and to investigate a fault reported after the fact. Both are deleted when the screen is deleted.

The records that make up your account and its reporting history — your organization, users, screens, content, and playback analytics — are retained for as long as your account remains open, or as needed to meet legal obligations. When an organization is deleted, its data is deleted with it.

Security

Data is encrypted in transit, and access is scoped to your organization so that one organization cannot read another’s data. No system is perfectly secure, but we work to protect data using industry-standard measures.

Your choices and controls

We describe here what you can actually do today, rather than listing rights in the abstract:

We do not sell or share your personal information, and we do not use it for advertising or cross-site tracking.

Where data is processed

Sheencast is operated from the United States and your data is processed there by us and by the service providers listed above.

Children

Sheencast is a business product and is not directed to children, and we do not knowingly collect personal data from them.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected by an updated effective date, and where appropriate we will notify account admins.

Contact

Questions or requests about this policy or your data — including a copy or deletion of your account data, or the names of the providers listed above — reach us at support@sheencast.com. We aim to respond promptly.