Data Processing Agreement
Plain-language summary. Full executable DPA available on request via support.
Roles
RedSquare (the "Processor") processes personal data on behalf of you, the customer (the "Controller"), to deliver the marketplace service. You decide why and how the data is processed; we provide the platform that does it.
Categories of personal data
- Account profile: name, email, role, login history.
- Screen metadata: screen name, address, photos, operating hours, pricing.
- Bookings & payments: booking IDs, line items, amounts, refunds, Stripe Connect identifiers.
- Telemetry: per-play logs (booking_id, started_at, status), device heartbeats, support tickets.
Processing purposes
- Operating the marketplace (matching advertisers to screens).
- Billing and remittance via Stripe Connect direct charges.
- Computing earnings analytics and reliability scores.
- Notifying you of operational events (offline screens, refunds).
- Honoring legal retention obligations (tax records, KYC).
Security measures
- TLS 1.2+ in transit; encryption at rest for the Supabase Postgres database and Stripe-side records.
- Row-level security on all tables holding personal data; service role used only by audited edge functions.
- Audit log of administrative access (Plan D1) retained for one year.
- Annual penetration test of the public surface; vulnerability triage SLA documented in our security policy.
Sub-processors
We disclose the third parties that touch personal data on our Sub-processors page. You are notified of additions ≥30 days before they take effect.
Data subject rights
You can self-serve right-to-portability (download every record we hold about you) and right-to-erasure (delete personal fields, retaining legally required financial records) from /account/privacy.
International transfers
Personal data is stored in the United States. EU/UK data subjects are protected by Standard Contractual Clauses (incorporated by reference into the executable DPA).
Breach notification
We notify affected controllers within 72 hours of becoming aware of a personal-data breach, with the information required under GDPR Article 33.