Privacy Policy
In short
This policy is about what happens to your work and your details when you use CuePoints. It covers three things: our website, the application, and the cloud service behind it that handles your licence and, if you want it, project sync.
Here is what it comes down to.
Your projects are yours. Sync a project and the people who can read it are you and the people you have approved for it, not other customers. The support tools our staff work with cannot open a project, a cue or a marker. Neither can the organisation that pays for your seat: buying you a licence does not buy them your work.
We never see your card. Paddle is our reseller and merchant of record, which means the payment is between you and them. There is no card number anywhere in our database, and no field for one.
We collect what running the product needs. Your email address, your licence, the machines you sign in on, and the projects you choose to sync. No billing address, no invoices, no advertising, no tracking cookies. There is no cookie banner on our site because there is nothing to consent to.
Your account and your projects sit in the EU. The live database runs in Ireland.
You can have all of it deleted. Email us and we erase your account and everything attached to it. Your payment record stays with Paddle, who are required to keep it.
Keep your own copy of anything that matters. Cancelling a subscription stops your access rather than removing your work, and a project you keep syncing stays indefinitely. But a project left unsynced for 12 months is deleted, and we email you first. Our copy is there so you can reach your work from another machine, not to be your archive.
Your email inbox is the key to your account. Signing in sends a code there, so give that inbox the protection you would give a password.
The sections below are the policy itself, and go into detail on each of these.
1. Who we are
CuePoints is produced by Cue Point Technology Ltd, a company registered in England and Wales, company number 13279487, whose registered office is at Bruce Lodge, Bishopton Lane, Stratford upon Avon, Warwickshire, CV37 9QY, United Kingdom.
For the personal data described in this policy, we are the data controller. That means we decide what is collected and why, and we are answerable for it.
This policy covers our website, the CuePoints application, and the cloud service the application connects to for licensing, updates and optional project sharing.
You can reach us about anything in this policy at legal@cuepoints.com.
2. What we hold
2.1 When you visit our website
Server logs. Like every website, our hosting and download servers receive your IP address, browser type and the page you asked for. We use this to deliver the site, keep it secure and fix faults. We do not use it to build a picture of you, and we do not combine it with your CuePoints account.
Visitor numbers. We use Framer Analytics to count page visits. It sets no cookies and does not identify individual visitors. It tells us which pages are being read, not who read them.
We run no advertising or tracking of any kind on our website, and we do not profile visitors.
2.2 When you buy a licence
Payment is taken by Paddle as merchant of record. Paddle collects what it needs to take payment, including your card details and billing address, under its own privacy policy.
What reaches us is limited: your email address, Paddle's own customer and subscription references, the plan you bought, the subscription status, how many seats it covers, and the renewal and start dates. We hold no card number, no security code, no expiry date, no billing address, no tax identifier, and no invoices, amounts or receipts.
2.3 When you use CuePoints with an account
Your account. Your email address, which is also how you sign in, and a display name if you set one.
Your devices. One record per machine you sign in on: an identifier the application sends, a device label, the application version, release channel and platform, and when it was last seen. The label is the machine's own name, so on most computers it is whatever you or your IT department called it, which often includes a person's name. That means a device record can identify you, and we treat it as personal data rather than calling it anonymous.
Licence anchors. Values that tie a licence to a machine. Two of them are stored only as a one way keyed hash, using a key that is not kept in the database. A third, older fingerprint is stored exactly as the application sends it, because it is the value our licence abuse blocklist matches against.
Team licences. If you are on a team licence, we hold the organisation name, each member's email address and role, and the email addresses of seats that have been invited but not yet taken up.
Usage. One row per person per day recording how many times the application checked in and what type of licence it was. It records nothing about what you did in the application.
2.4 If you bought CuePoints before version 2
We hold a list of people who purchased an earlier version, so we can offer them an upgrade price. Each record is keyed on the email address and holds the date of the most recent purchase, the discount offered, and whether an offer has been sent.
This list exists only to run the introductory upgrade discount, and it has a closing date. The discount can be claimed up to and including 10 October 2026, and we delete the whole list immediately afterwards, not record by record but the entire thing, by a nightly job rather than a person remembering. Everybody on it is an existing customer of ours who bought an earlier version. It sits outside the CuePoints account system, so a record exists whether or not you ever created an app account. If you would rather not be on it at all, email legal@cuepoints.com and we will remove you straight away.
If you claim a discount, the discount is created at Paddle. That record carries the code and the percentage only: no email address, no purchase date, nothing identifying you. So when our copy goes on 10 October 2026, there is no second copy of the pairing left behind.
2.5 If you sync or share a project
Project sync stores your project as structured records rather than as a copy of your project file: cue markers and their notes, tracks, marker types, and references to media files by name. It also stores the project name and who created it. Audio and video files are not uploaded.
If you share a project, we also keep a change history for 90 days recording who changed which item and when. It does not store the old and new values, but it does store a short label taken from the item changed, which for a cue marker is its note text.
If you ask to join somebody's shared project, your email address is recorded on that request and shown to the project's owner so they can decide whether to admit you.
Your project data is encrypted on the way to us and where it is stored, but not from us. Everything travels over HTTPS, and the disks it sits on are encrypted by our hosting platform. The application holds no database password: it signs in with a short-lived token from your email code and talks to us through the same checked doors as everything else.
What we do not do is encrypt your data with a key that only you hold. That is a deliberate choice rather than a shortcut: syncing works by our server merging changes from your different machines, and it cannot merge what it cannot read. The consequence is that a project name or a cue note is readable by us if we go looking, which in this industry can mean a show, a client or a venue. Our support tools cannot open a project. One database administrator can, and that access is logged in full: every read, write and change to the structure, with who and when, kept for 7 days and reviewed weekly.
When we look, and when we do not. We access your project data only to solve a technical problem, and only as far as solving it needs. We do not browse it, search it or open it out of curiosity, and we do not act on or pass on anything we see while fixing something. A project can reveal an unannounced show or a client relationship, and what we see stays with the fault we were fixing.
2.6 If the application crashes
Crash reports carry no email address, no account identifier and no installation identifier. Before a report is stored it is cleaned on your machine and again on our servers to remove file paths, file names, email addresses and long random looking strings. The technical symbol names inside the stack trace are deliberately kept, because without them the report is unreadable.
If you type a note describing what you were doing, it is cleaned the same way, but prose you write is stored as you wrote it. Please keep names and confidential detail out of it.
2.7 Administrative records
We keep a record of licensing and seat events, and of administrative actions our staff take on accounts: what was done, when, who did it, and details of the action. A staff member looking an account up, rather than changing it, is not recorded. Where a project has been deleted through the account portal at accounts.cuepoints.com, this record keeps the project's name.
3. Why we process it, and our lawful basis
What we do | Data used | Lawful basis |
|---|---|---|
Provide the application and your licence | Account, licensing state, devices | Performance of a contract |
Run team licences and seats | Team account data | Performance of a contract |
Sync and share projects, at your choice | Project data, membership | Performance of a contract |
Take payment and manage subscriptions | Email, provider references | Performance of a contract |
Send transactional email (receipts, invitations, notices) | Email address | Performance of a contract |
Tell you about a security or stability problem affecting the service | Email address | Legitimate interests: you need to know, and it is not something you should have to opt in to |
Enforce licences and prevent abuse | Device records, licence anchors, blocklists | Legitimate interests: protecting our software from unlicensed use |
Diagnose crashes and faults | Crash reports | Legitimate interests: making the product work |
Keep the service secure and monitor for weaknesses | Account and system data | Legitimate interests: security of the service and its users |
Keep administrative records | Audit trail | Legitimate interests: accountability for administrative action |
Offer an upgrade price to earlier purchasers | Upgrade offer list | Legitimate interests: an offer to our own existing customers about a new version of the product they bought from us |
Deliver the website and downloads, keep them secure, fix faults | Server logs: IP address, browser type, page requested | Legitimate interests |
Count page visits | Framer Analytics, no cookies and no identification of individuals | Legitimate interests |
Non essential cookies | See section 4 | Consent |
Where we rely on legitimate interests, we have weighed our interest against your rights, and you can object at any time: see section 10.
4. Cookies
A cookie is a small file a website stores in your browser. Some are needed for a site to work at all. Others are not, and those need your consent.
We set no cookies of our own. There are no advertising or tracking cookies on this website, and there is no cookie banner because there is nothing for you to consent to.
Cookies set by our payment provider. Our shop is run by Paddle, who act as our reseller and merchant of record. Paddle's code runs on our pages and sets a short-lived security cookie, lasting roughly 30 minutes, to tell real visitors apart from automated bots. When you open the checkout, Paddle sets further cookies needed to process your order. These are strictly necessary to run the shop and take payment, so we do not ask for consent for them.
Our visitor counting sets no cookies. Framer Analytics counts page visits without storing anything on your device and without identifying individual visitors.
You can delete cookies or block them in your browser settings, though blocking the payment provider's cookies will stop the checkout working.
The web pages we run for the CuePoints purchase flow and the version 2 upgrade offer set no cookies and contain no analytics, tracking or advertising code of any kind. We have verified that directly in their source.
5. Who else receives your data
We use a small number of suppliers. Listing a supplier here describes what it receives in practice. It is not a statement about its legal role.
Supplier | What it does | What it receives |
|---|---|---|
Supabase | Hosts our backend and database | All account data, and any project data you choose to sync |
Paddle.com Market Ltd | Reseller and merchant of record: payments, invoicing and tax | Your name, email address, billing address and payment details. It holds the payment details, we do not |
Paddle Retain | Subscription and billing analytics for Paddle | Subscription and billing data |
SMTP2GO (EU data centre, Amsterdam) | Sends our transactional email | The recipient's address and the message content. It keeps a record of what was sent for 35 days and then deletes it |
JetBrains YouTrack (Europe, Ireland) | Our issue tracker | Automated technical detail about crashes. No contact details |
Microsoft Azure | Runs the panel our support staff use, hosts our application downloads, and runs our security monitoring service | The staff panel handles the account, licence and subscription data our staff look up (West Europe). Request data when you download the application. The monitoring service itself receives no customer data (UK South) |
Framer B.V. (Netherlands) | Hosts and serves our website, and counts visits without cookies | Request data when you visit the site. No CuePoints account data |
We use no analytics, product telemetry, session replay, advertising or error tracking service in the CuePoints application or its backend. There is no Google Analytics, Segment, Sentry, Datadog or equivalent in it. The analytics described in section 4 is on our website only, and it never sees your project data or your account.
We will also disclose personal data where we are legally required to, or where it is necessary to establish, exercise or defend a legal claim.
We do not sell your personal data, we never have, and we do not share it with advertisers.
Security and stability notifications
If something goes wrong that affects your ability to work, or that affects the security of your data, we will email you about it. These are service messages rather than marketing, so there is no opt-out: an alert you can unsubscribe from is not much of an alert. We send them through the same transactional email provider as everything else, and we do not use them to tell you about anything we are selling.
An email address reaching another customer
There are three places where this happens:
On a join request, shown to the owner or admins of the project you asked to join.
On the member roster of a team licence, which every owner and admin of that organisation can see.
In the notice we send an organisation's owner when one of their members moves to their own subscription.
Team licences and your employer
We do not give your work to the organisation that pays for your seat. Paying for a licence buys the licence, not the projects made with it. If an employer asks us for a member's project data, we decline and point them back at the person who made it.
The reason is simple. What we hold is a mirror of the project files already on that person's own computer, kept so they can reach their work from another machine. It is not a separate company archive that we are holding on an employer's behalf, and we are not the right people to arbitrate who owns what. An organisation that needs work its staff produced should ask them for it, under its own IT and employment policies, where that question belongs.
This applies whoever asks and however the request is framed, including after somebody has left.
6. Where your data is held
Everything we hold about you is processed inside the United Kingdom or the European Economic Area, with one exception noted below.
Your account, your projects, and the backups of both: Supabase, in Ireland.
The panel our support staff use: Microsoft Azure, in the Netherlands.
The email we send you: SMTP2GO, from its EU data centre in Amsterdam, with inbound servers in London and Frankfurt.
Crash reports: JetBrains YouTrack, in Ireland. JetBrains states that application data is always processed in that region and never leaves it without our permission.
Your payment relationship: Paddle.com Market Ltd, a UK company.
Our website: Framer B.V., a Netherlands company.
Our security monitoring: the United Kingdom. It holds no customer data of its own.
UK law treats that group as offering equivalent protection, so data moves within it freely and nothing further is needed.
The exception. Framer says in its own privacy policy that it may transfer website visitor data to the United States. That is visits to our website, not your account and not your work. For that, and for anything that ever processes outside the group in future, we rely on the safeguards in the supplier's data processing agreement, which is the contract that carries UK standards across the border. Ask us and we will tell you which supplier and which safeguard.
We do not offer a contractual data residency guarantee, and if we ever moved region we would update this policy.
7. How long we keep it
Data | How long |
|---|---|
Server logs (website and downloads) | Kept by our hosting providers under their own terms. We do not set a period ourselves |
Crash report notes | Erased after 12 months |
Crash reports | Deleted after 24 months |
Shared project change history | Deleted after 90 days |
Rate limiting counters | Cleared nightly |
Unclaimed seat invitations | Removed once the seat is reconciled |
Upgrade offer records | The whole list deleted on 10 October 2026, when the campaign closes, by a nightly job |
Synced project data and project names | Deleted after 12 months without a sync. Syncing the project resets the clock, so a project you still use is never at risk. We email the owner before anything goes |
Everything else, including your account, team membership, device records, usage counters and the administrative audit trail | No automatic deletion. Kept until somebody deletes it. |
Cancelling a subscription stops your access. It does not delete your data. Your account and your synced projects stay where they are, so if you cancel between productions and come back later, your work is still waiting. One caveat now applies: a cancelled account cannot sync, so its projects will reach 12 months of inactivity and be deleted. We email the owner before that happens. If you would rather it was not, ask us to erase it and we will.
Project data has a deletion date; your account does not. A project that has not been synced for 12 months is deleted, and syncing it starts the 12 months again, so work you are still using is never at risk. We email the project's owner before it happens rather than letting work disappear quietly.
This policy starts on 3 September 2026. For a project that was already dormant before that date, the 12 months runs from then, so nothing is deleted before September 2027.
Your account, your team membership and your device records have no set deletion date. They stay until you or we remove them. Whatever the periods say, keep your own copy of anything that matters: our copy is there so you can reach your work from another machine, not to be your archive.
8. Security
All traffic between the application, the web portal and our backend is encrypted using HTTPS. Separation between customers is enforced by the database itself rather than by application code remembering to filter, so a query returns only the rows your account is entitled to see.
Encryption of data at rest comes from our hosting platform rather than from anything we built.
A monitoring service we build and run ourselves tests the live service from outside, on a recurring schedule, checking that no customer data can be read without signing in and that one customer cannot reach another's records. We also run an in-house suite of attack tests against a copy of the system before changes ship.
If you are assessing CuePoints for an organisation and need more than this, ask us at legal@cuepoints.com for our security overview. It is a fuller document written for people whose job is to find the gaps, and it sets out our controls, our suppliers and our limitations in detail.
Signing in does not use a password. We send a one time code, or a single use link for the web portal, so control of your email inbox is what proves your identity. We do not currently offer multi-factor authentication, which means the security of your email account is effectively the security of your CuePoints account.
9. Automated decisions
We make no decisions about you by automated means alone.
Our systems do watch for patterns consistent with one licence being used across many machines, and they raise a flag when they see one. That part is automatic. What follows is not. A person reviews the flag and decides, and nothing is blocked on the strength of the flag by itself.
If we conclude a licence is being used outside its terms, our End User Licence Agreement gives you 14 days to put it right before we deactivate. So there is a human decision and a notice period between the flag and any loss of access, and there is somebody to argue with throughout. If you think we have it wrong, email legal@cuepoints.com.
We do not profile you for marketing, and we make no automated decisions about you anywhere else in the service.
10. Your rights
Under UK data protection law you have the right to be informed, the right of access, the right to rectification, the right to erasure, the right to restrict processing, the right to data portability, the right to object, and the right to withdraw consent where we rely on it.
To exercise any of them, email legal@cuepoints.com. We will acknowledge your request the day it arrives and answer within one month. If a request is genuinely complex and needs longer, we will tell you so, and why, inside that first month.
Because erasure requests are destructive and cannot be undone, we will ask you to confirm the request from the email address registered on the account before we act. That step protects you from somebody else asking us to delete your work.
Erasure is carried out by a person using a purpose-built tool, not by a script somebody retypes each time. It runs in two steps: the first counts exactly what would go and changes nothing, and the second will only proceed against those same numbers. It is all or nothing, so there is no state where you are half erased.
Backups. Erasing your data removes it from the live database straight away. Copies can still exist in our hosting provider's automatic backups for up to 7 days, after which they roll off on their own. That is the longest any copy of erased data survives. We do not use those backups to bring back data somebody asked us to erase. If we ever had to restore one after a serious failure, we would re-run the erasure afterwards.
Three honest points about it:
It is a request to us, not a button in the product. We do not currently offer self-service account deletion.
Some records survive, where we have a lawful reason to keep them, such as a record needed to prevent licence abuse or to defend a legal claim. Where that applies we will tell you what was kept and why.
Your payment records sit with Paddle, who took your payment as merchant of record and who must keep a record of the sale for a statutory period. We will pass your request on, but that part is theirs to answer, not ours.
Getting a copy of your data
Your project work is yours to take at any time, without asking us. CuePoints exports cue lists and project data in over ten formats from inside the application, so your work is never locked up here and you do not need our permission or our timescale to get it out.
For the personal data we hold about you, which is your account, your licence and subscription state, your device records and your usage counters, email legal@cuepoints.com and we will send you a copy in a common machine-readable format.
If you created a shared project, you can delete its cloud copy yourself from the account portal, one project at a time. The copy on your own machine is untouched.
11. Children
CuePoints is professional software for live production and broadcast. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, email legal@cuepoints.com and we will delete it.
12. Special categories of data
We do not seek or intentionally process special category data, which means data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning a person's sex life or sexual orientation.
We cannot control what a customer types into a project name or a cue note, so please do not put such information there.
13. Changes to this policy
We will update this policy when what we do changes. Where a change materially affects how we handle your data, we will tell account holders by email rather than relying on you noticing. The version and date at the top always show which version is current.
14. If something goes wrong
If personal data we hold is lost, exposed or accessed by somebody who should not have it, and that is likely to put you at real risk, we will tell you without undue delay. We will say what happened, what data was involved, what we have done about it, and what you should do.
Where the law requires it, we will also report the breach to the Information Commissioner's Office within 72 hours of becoming aware of it.
We would rather tell you about something that turns out to be minor than leave you to find out from somewhere else.
15. Complaints
If you are unhappy with how we have handled your personal data, please tell us first at legal@cuepoints.com so we have the chance to put it right.
You also have the right to complain to the Information Commissioner's Office, the UK's supervisory authority for data protection. Their contact details are on their website at ico.org.uk. Complaining to us first does not affect that right.
16. Contact
Cue Point Technology Ltd
Bruce Lodge, Bishopton Lane
Stratford upon Avon
Warwickshire CV37 9QY
United Kingdom
This policy is valid as of 3 September 2026. It replaces the Privacy and Cookie Policy of 7 April 2021.