Privacy Policy
Last updated: 13 June 2026
The protection of your data is important to us. In this policy we describe, in clear and understandable language, which personal data we process when you use Castashoot, for what purpose, on what legal basis, and what rights you have. It applies to the EU General Data Protection Regulation (GDPR) as well as the Swiss Federal Act on Data Protection (FADP).
1. Controller
The controller responsible for the data processing is:
tim3l3ss (sole proprietorship)
Owner: Timon Duodu
Libellenstrasse 15, 6004 Luzern, Switzerland
Email: support@castashoot.com
Website: castashoot.com
If you have any questions about data protection or wish to exercise your rights, you can contact us at any time using the email address listed above.
2. Which data we process
We only process the data we actually need to operate the platform:
- Account data: name, email address, encrypted password (hash), role (Brand or Talent), and your confirmation that you are at least 18 years old.
- Profile & portfolio data: profile picture, portfolio images, description (bio), skills, location, rates/prices, social media links.
- Content & usage data: listings you create, applications, reviews, as well as messages you exchange with other users via the platform’s built-in messaging feature.
- Payment data: If you take out a paid subscription, your payment data (e.g. credit card details) is processed exclusively by our payment service provider Stripe. We ourselves store no complete card data, only the subscription status, the plan, and a Stripe customer identifier.
- Technical data & cookies: technically necessary cookies for login and session, as well as your language setting. Server logs (e.g. IP address, time of access) are generated by our hosting providers to ensure secure operation.
3. Purposes and legal bases
We process your data for the following purposes on the following legal bases (Art. 6 GDPR):
- Provision of the platform (account, profile, listings, applications, messages): to perform the user agreement, Art. 6(1)(b) GDPR.
- Billing and payment processing of subscriptions: to perform the contract, Art. 6(1)(b) GDPR, and to comply with statutory retention and accounting obligations, Art. 6(1)(c) GDPR.
- Security, moderation and abuse prevention (e.g. reviewing content, preventing fraud): legitimate interest, Art. 6(1)(f) GDPR.
- Transactional emails (e.g. registration confirmation, password reset, notifications): to perform the contract, Art. 6(1)(b) GDPR.
- Consent-based processing (where required, e.g. non-essential cookies or newsletters): Art. 6(1)(a) GDPR. You can withdraw any consent you have given at any time with effect for the future.
4. Processors and service providers
We use carefully selected service providers who process data exclusively on our behalf and according to our instructions. Data processing agreements (Art. 28 GDPR) are in place with these service providers:
- Supabase: database, authentication and storage (incl. portfolio images). Hosting in the EU (Frankfurt region, Germany).
- Vercel: hosting and delivery of the web application.
- Stripe: payment processing for subscriptions. Stripe processes your payment data on its own responsibility in accordance with its own privacy policy.
- Resend: sending of transactional emails.
Insofar as data is transferred to third countries (e.g. the USA), we base this on appropriate safeguards such as the EU standard contractual clauses.
5. Retention period
We store your data for as long as your account exists and it is necessary for the purposes stated. After your account is deleted, your personal data will be deleted or anonymised. This does not apply to data that we are required to retain due to statutory retention obligations (in particular under tax and commercial law, e.g. invoices); such data is blocked for the duration of the statutory periods and then deleted.
6. Your rights
You have the following rights with regard to your personal data:
- Access to the data stored about you (Art. 15 GDPR);
- Rectification of inaccurate data (Art. 16 GDPR);
- Erasure of your data (Art. 17 GDPR);
- Restriction of processing (Art. 18 GDPR);
- Data portability in a common format (Art. 20 GDPR);
- Objection to processing based on legitimate interests (Art. 21 GDPR);
- Complaint to a supervisory authority. In Germany this is the respective competent state data protection authority; in Switzerland it is the Federal Data Protection and Information Commissioner (FDPIC).
You can trigger a data export as well as the deletion of your account at any time directly in your settings, or contact us by email.
7. Cookies
We only use technically necessary cookies (for login, session and language setting). There is no advertising tracking by third parties and no profiling for advertising purposes.
8. Data security
Data is transmitted in encrypted form (TLS/HTTPS). Passwords are stored exclusively as a hash. We take appropriate technical and organisational measures to protect your data against loss, misuse and unauthorised access.
9. Changes to this policy
We may update this privacy policy, for example if legal requirements or our services change. You will always find the current version on this page.
Template: please have a lawyer review before launch.