StudioShift · Legal
Privacy
In effect from September 5, 2026
What StudioShift collects about you, why it needs it, who else handles it, and how to get a copy or have it deleted.
This document has not been reviewed by a lawyer. It was written to be clear and honest about how StudioShift actually works, and it is binding as written, but it has not had legal review. If anything here matters to a decision you are making, get your own advice.
StudioShift is a Canadian marketplace where dance studios find substitute dance teachers. It runs at shift.studiobeat.io. This page describes how it handles personal information under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA). It is written to be read, not to be survived.
What we collect
Only what the marketplace needs to work. Nothing is bought from data brokers and nothing is enriched from outside sources.
When you create an account
- Your email address and a password, held by our authentication system as a hash — we never see or store the password itself.
- Whether you are a studio or a teacher.
On your profile
- Your display name, and for a studio its business name, street address and phone number. Studio addresses and phone numbers are public on purpose: a studio is a retail business and people need to find it.
- A location pin (latitude and longitude) and, for teachers, how far you are willing to travel. This is what makes distance search work.
- For teachers: a biography, qualifications, teaching styles, availability, time off, and the rate you want.
- Photos and files you upload.
- For teachers: a vulnerable sector check attestation — whether you say you hold one, the date it was completed, when it expires, and which police service issued it. StudioShift records that claim. It does not verify it unless an operator has seen the document and marked it verified.
When you use the marketplace
- Job postings, applications, offers, counter-offers, bookings and their dates and times.
- Messages you send through the platform, and notes on applications. These are scanned automatically for phone numbers, email addresses and social handles, which are blocked before a booking exists — see the section on why below.
- Reviews you write and receive, and any reports or dispute cases you open.
- Notification preferences, and — if you turn on text messages — your phone number, whether it is verified, and the record of your consent.
When money moves
- The amounts on a booking: the rate, the fee split, sales tax, and what was paid or refunded. StudioShift stores these figures.
- Card numbers are never sent to StudioShift and are never stored by it. Payment card details go directly to Stripe.
- For teachers being paid out: an account with Stripe, which collects the identity and banking information it needs to pay you. StudioShift stores the identifier of that account and whether it is ready to receive money — not the banking details.
Automatically
- A session cookie, so you stay signed in. It is not advertising and it is not shared.
- Error and diagnostic logs from the app. Where a log is rate-limited by network address, the address is stored as a salted hash, not in the clear.
- When you sign an agreement, the date, the name you typed, your network address and your browser's user-agent string. That is what makes a signature evidence. It is never shown to another user.
Why we collect it
- To run the marketplace. A studio cannot find a teacher nearby without a location, and cannot book one without dates, a rate and a way to pay.
- To pay people. Bookings are charged and paid out through Stripe.
- To tell you when something happens on your own jobs, applications, offers and bookings. An offer is only worth having while the date is still open.
- To keep contact details on-platform until a booking exists. Public text and messages are scanned for phone numbers and email addresses. This protects both sides — a studio’s posting does not become a phone number scraped by anyone passing, and a teacher is not asked to hand out a mobile number to strangers.
- To keep the platform safe and honest — reviews, reports, dispute records, and the audit trail behind a payment.
- To fix the software, using error logs.
StudioShift does not sell personal information, does not share it for advertising, and does not use it to train machine-learning models.
What other people can see
- Teacher profiles and studio profiles are public, including the location pin, biography, qualifications, styles and rate. Assume anything you put on a profile can be read by anyone.
- A studio can see whether a teacher has declared a vulnerable sector check, and whether StudioShift has verified it. The wording is exact and never blurred: “Self-declared — not verified by StudioShift” means exactly that.
- Reviews are public once both sides have written one or the window closes.
- Messages are visible only to the two people in the conversation.
- Dispute cases are private. They never reach a public page and never appear in search.
- Your email address, your signature records, your notification settings and your payment details are never shown to another user.
Who else handles your information
StudioShift uses a small number of service providers. They act on our instructions, for the purposes below and no others. Each one is named because you are entitled to know who holds your information.
- Stripe — payments and payouts. Stripe receives the card details of a paying studio, the booking amount, and the identity and banking information a teacher provides to get paid. Stripe is the only party that sees a card number.
- Amazon Simple Email Service (AWS) — sends notification email. It receives your email address and the contents of the notification.
- Twilio — sends text messages, if you turn them on. It receives your phone number and the message.
- Google Places — used when a studio links its business listing so an address, opening hours and photos can be filled in. Google receives the search terms and the place identifier. Google’s photos are shown through StudioShift with attribution and are not copied into our storage.
- Vercel — hosts and serves the website.
- netcup — a German company whose server, located in the United States, runs our database and file storage.
- A feedback widget is loaded on every page so you can report a problem. It receives what you type into it and the page you were on.
Where your information is stored. The database and uploaded files sit on a server rented from netcup, a German company, but that server is physically located in the United States (Virginia). The website is served by Vercel, and Stripe, Amazon SES, Twilio and Google are United States companies. Your personal information is therefore stored and processed outside Canada, and while it is in another country it is subject to that country’s laws, including lawful access by its courts and authorities. There is no way to use this service without that being true, which is why it is stated here rather than buried.
How long we keep it
- Your profile and account: until you delete them.
- Bookings, payments, refunds and tax records: kept after an account is closed where Canadian tax and accounting law requires it. These records are about a transaction, not only about you.
- Agreement signatures: kept for as long as the account exists, because they are the evidence of what someone agreed to. They are deleted with the account.
- Error logs: short-lived, and cleared on a rolling basis.
Your rights — a copy of your data, corrections, and deletion
Under PIPEDA you can ask what we hold about you, ask for it, ask for it to be corrected, and ask for it to be deleted. All four are handled by email.
- See or correct it. Most of it is on your profile and you can edit it yourself at any time.
- Get a copy. Email privacy@studiobeat.io from the address on your account and ask for an export. You will get your profile, your jobs or applications, your bookings, your messages and your reviews in a machine-readable file, within 30 days.
- Delete your account. Email the same address and ask. Your profile, messages, applications and signature records are deleted. Records of completed transactions — what was charged, what was paid out, what tax was collected — are kept where the law requires, with your name removed from them wherever it is not needed to keep them intelligible. We will tell you exactly what was kept and why.
- Withdraw consent to notifications at any time in Settings, or by replying STOP to a text message.
If you are not satisfied with how a request was handled, you can complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca.
Security
Traffic is encrypted in transit. Every table in the database enforces row-level security, so a query runs as the person who made it and cannot reach another account’s rows. Payment card details never touch our systems. No system is perfect: if a breach creates a real risk of significant harm, we will tell affected people and the Privacy Commissioner, as PIPEDA requires.
Children
StudioShift accounts are for adults — studio operators and teachers. Do not create an account for anyone under 18. Students are never account holders and StudioShift does not collect information about the children in a class.
Changes to this page
When this page changes materially, the date at the top changes and account holders are told by email. Continuing to use StudioShift after that means the new version applies.
Contact
Privacy questions and requests: privacy@studiobeat.io.