Stage That Room

Privacy

Photo privacy, explained plainly.

We collect what the staging service needs, keep customer media private, and do not sell personal information.

Updated September 7, 2026. Stage That Room operates from British Columbia, Canada. Privacy requests may be sent to support@stagethatroom.com.

What we collect

  • Temporary authentication identifiers used to protect the three-preview allowance, plus account information such as name, email address, authentication records, and support messages when you create or use an account.
  • Listing labels, source photos, staging selections, prompts derived from those selections, generated results, and generation status.
  • Checkout email, transaction identifiers, purchased credits, amounts, currency, and payment status. Stripe handles card details; Stage That Room does not store full card numbers.
  • Security and technical information such as timestamps, request identifiers, IP-derived logs, and error diagnostics needed to operate and protect the service.

How we use it

We use this information to enforce the preview allowance, authenticate accounts, store private projects, process requested staging jobs, reserve guest purchases to the Stripe Checkout email, deliver and reconcile credits after verified claim, prevent abuse, troubleshoot failures, respond to support, maintain financial records, and comply with law. We do not use customer listing photos to train Stage That Room models or for advertising without separate, explicit consent.

Processors and international transfers

Supabase provides authentication, database, and private media storage; Vercel hosts the application; OpenAI processes source images and staging instructions through its API to create staged results; Google (Gemini API) sorts listing photos into rooms from small thumbnails and, when a design keeps changing the room, may create a replacement design from the source image; Stripe processes payments; and Cloudflare provides domain, DNS, and anti-abuse verification services. These providers may process information outside your province or country under their own security, legal, and retention obligations.

OpenAI processing is subject to its API data controls, including applicable abuse-monitoring retention, and Google processing to the Gemini API terms. We do not promise zero retention by the image providers. Earlier generations used fal.ai and its model provider; those historical requests remain subject to the terms and retention settings applicable when they were processed.

Retention

  • Source photos and staged results remain in private account storage until permanently deleted or removed following a verified deletion request. Moving a set to Trash hides it from the active workspace but does not permanently delete its photos; it can be restored.
  • After a verified deletion request, customer media will be removed from active systems within 30 days and from routine backups within 90 days, unless a legal hold or active dispute requires longer retention.
  • Account profile data is kept while the account is active and then follows the same 30/90-day deletion schedule.
  • Billing, tax, fraud, and transaction records may be retained for six years after the end of the year they relate to, or longer if law, an audit, chargeback, or dispute requires it.
  • De-identified aggregate operational statistics may be retained when they can no longer reasonably identify a customer or property.

Security

Customer tables use owner-scoped access controls and media is stored in private buckets. Privileged keys stay on the server, downloads use time-limited signed links, and payment webhooks are signature-verified. No online service can promise absolute security.

Your choices

You may request access, correction, export, or deletion of your account information and media by emailing support@stagethatroom.com. We will verify requests using account information before acting. Some transaction or security records cannot be deleted immediately when retention is legally required.

Cookies and analytics

The current service uses essential authentication and security storage. It does not currently run behavioural advertising or third-party marketing analytics. This notice will be updated before adding non-essential tracking.