Introduction
Tombstone Dash LLC ("we," "our," or "us") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, and safeguard your information when you use our websites and mobile applications, including our Casting Call app.
This policy complies with:
- Apple App Store Review Guidelines
- General Data Protection Regulation (GDPR)
- California Consumer Privacy Act (CCPA)
- Children's Online Privacy Protection Act (COPPA)
Information We Collect
Personal Information You Provide
When you use our Casting Call app or contact us, we may collect:
- Contact Information: Name, email address, phone number
- Professional Information: Role in entertainment industry, union status, experience level, company/agency affiliation
- Profile Data: Profile photos, demo reels, portfolio information, skills and experience
- Location Data: Current location (with your explicit permission) for casting call proximity matching
- Communication Data: Messages, feedback, support requests
- Preferences: Notification settings, casting type preferences, search filters
Automatically Collected Information
We automatically collect certain technical information to improve our services:
- Device Information: Device type, operating system version, app version, device identifiers
- Usage Analytics: Features used, time spent in app, interaction patterns, session duration
- Performance Data: Crash reports, error logs, response times, loading speeds
- Network Information: IP address, connection type (for security and optimization)
- App Diagnostics: Debug information to improve app functionality
Apple-Specific Data Collection
For iOS users, we may also collect:
- Apple ID Integration: Sign in with Apple data (name, email) when used
- Push Notifications: Device tokens for sending casting notifications
- App Store Data: Installation source, app version history
- iOS Features: Usage of iOS-specific features like Siri integration or Shortcuts
How We Use Your Information
Primary Service Delivery
- Casting Call Matching: Match you with relevant casting opportunities based on your profile and preferences
- Notifications: Send push notifications about new casting calls in your area and categories
- Profile Management: Maintain and display your professional profile to casting directors
- Location Services: Show casting calls near your location (only with your permission)
- Communication: Facilitate communication between talent and casting professionals
App Improvement and Analytics
- Performance Optimization: Analyze app usage to improve speed and functionality
- Feature Development: Understand which features are most valuable to users
- Bug Fixes: Identify and resolve technical issues
- Security: Monitor for suspicious activity and prevent fraud
Legal Bases for Processing (GDPR)
- Contract Performance: Processing necessary to provide casting call services
- Legitimate Interest: Improving our services and preventing fraud
- Consent: Location services, marketing communications, optional features
- Legal Obligation: Compliance with laws and regulations
Information Sharing and Disclosure
We Do Not Sell Your Data
We never sell, rent, or trade your personal information to third parties for marketing purposes. Your data is not for sale.
Limited Sharing Circumstances
We may share your information only in these specific circumstances:
- With Your Consent: When you explicitly agree to share your profile with casting directors or agencies
- Verified Casting Professionals: Your profile may be visible to verified casting directors and production companies
- Service Providers: Third-party providers who help us operate our services (under strict data protection agreements)
- Legal Requirements: When required by law, court order, or to protect our legal rights
- Business Transfers: In connection with a merger, acquisition, or sale of assets (with user notification)
- Safety and Security: To prevent fraud, protect safety, or investigate violations of our Terms of Service
Third-Party Services
We work with carefully selected third-party services:
- Cloud Storage: Secure cloud services for data backup and availability
- Analytics: Anonymous usage analytics to improve our services
- Push Notifications: Apple Push Notification Service (APNS) for iOS notifications
- Crash Reporting: Anonymous crash data to identify and fix bugs
Data Security and Protection
Security Measures
We implement comprehensive security measures to protect your personal information:
- Encryption: All data is encrypted in transit (TLS 1.3) and at rest (AES-256)
- Access Controls: Strict access limitations to authorized personnel only
- Authentication: Multi-factor authentication for all system access
- Regular Audits: Security assessments and vulnerability testing
- Secure Infrastructure: Industry-standard hosting with security monitoring
- Data Minimization: We collect only data necessary for app functionality
Data Retention
- Active Accounts: Data retained while your account is active and needed for services
- Inactive Accounts: Data automatically deleted after 24 months of inactivity
- Legal Requirements: Some data may be retained longer for legal compliance
- User Deletion: You can request immediate account and data deletion
- Backup Data: Securely deleted from backups within 90 days
Your Privacy Rights and Controls
Universal Rights
Regardless of your location, you have these rights:
- Access: View and download your personal data
- Update: Correct or update your information
- Delete: Request deletion of your account and data
- Opt-Out: Unsubscribe from notifications and marketing
- Data Portability: Export your data in a standard format
GDPR Rights (EU Users)
- Right of Rectification: Correct inaccurate personal data
- Right to Erasure: Request deletion of personal data ("right to be forgotten")
- Right to Restrict Processing: Limit how we process your data
- Right to Object: Object to processing for legitimate interests or direct marketing
- Right to Withdraw Consent: Withdraw consent at any time
- Right to Lodge Complaints: File complaints with data protection authorities
CCPA Rights (California Users)
- Know: What personal information we collect, use, disclose, and sell
- Delete: Request deletion of personal information
- Opt-Out: Opt out of sale of personal information (we don't sell data)
- Non-Discrimination: Equal service regardless of privacy choices
- Authorized Agent: Designate someone to make requests on your behalf
How to Exercise Your Rights
To exercise any of these rights:
- In-App: Use the privacy settings in the Casting Call app
- Email: Contact us at privacy@tombstonedash.com
- Website: Use our contact form with "Privacy Request" as the subject
- Response Time: We'll respond within 30 days (1 month)
Apple App Store Compliance
App Store Guidelines Compliance
Our Casting Call app complies with Apple's App Store Review Guidelines regarding:
- Data Collection Transparency: Clear disclosure of all data collection practices in App Store privacy labels
- User Consent: Explicit consent required before collecting sensitive information
- Data Minimization: We collect only data essential for app functionality
- Third-Party Sharing: Transparent disclosure of any data sharing with third parties
- Children's Privacy: No data collection from users under 13
iOS Privacy Features
- App Tracking Transparency: We request explicit permission before tracking across apps
- Privacy Nutrition Labels: Accurate privacy disclosures in the App Store
- Sign in with Apple: Support for Apple's privacy-focused sign-in option
- Location Privacy: Clear prompts and controls for location access
- Camera/Photo Privacy: Permission requests for photo access when uploading profile images
Data Types and Linking (App Store Privacy Labels)
Data Linked to You:
- Contact Info (name, email, phone)
- User Content (profile photos, demo reels)
- Identifiers (account ID, device ID for notifications)
- Usage Data (app interactions, features used)
Data Not Linked to You:
- Diagnostics (anonymous crash reports, performance data)
- Analytics (anonymized usage patterns)
Children's Privacy (COPPA Compliance)
Our services are not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13.
Parental Controls
- Age Verification: Users must confirm they are 13 or older during registration
- Parental Consent: For users 13-17, we recommend parental supervision
- Immediate Removal: If we discover data from a child under 13, we immediately delete it
- Reporting: Parents can report underage accounts to privacy@tombstonedash.com
International Data Transfers
Your personal data may be transferred to and processed in countries other than your own. We ensure adequate protection through:
- Adequacy Decisions: Transfers to countries with adequate data protection laws
- Standard Contractual Clauses: EU-approved data transfer agreements
- Binding Corporate Rules: Internal data protection standards
- Certification Programs: Privacy Shield successor frameworks when applicable
Cookies and Tracking Technologies
Website Cookies
Our website uses minimal cookies:
- Essential Cookies: Required for basic website functionality
- Analytics Cookies: Anonymous usage analytics (with consent)
- Preference Cookies: Remember your settings and preferences
Mobile App Tracking
- Analytics: Anonymous app usage analytics for improvement
- Crash Reporting: Anonymous error reporting to fix bugs
- No Ad Tracking: We don't use advertising tracking or identifiers
- Push Notifications: Device tokens for casting call notifications (with permission)
Updates to This Privacy Policy
We may periodically update this Privacy Policy to reflect changes in our practices or legal requirements. When we make material changes:
- Email Notifications: We'll send email notifications to registered users
- In-App Notifications: Prominent notices in the Casting Call app
- Website Notice: Clear notice on our website homepage
- Effective Date: Changes become effective 30 days after posting
- Continued Use: Continued use of our services constitutes acceptance of updated terms
Contact Information and Data Protection Officer
For privacy-related questions, data requests, or concerns, please contact us: