Final Stage · Legal
Last updated 14 August 2026
This addendum forms part of the Terms of Service and applies whenever Final Stage handles personal data belonging to your customers — the people who book, enquire or buy through the site we host for you.
For your customers' data, you are the controller and we are the processor. You decide what is collected and why; we only act on your instructions. Using the service is the instruction — building a booking form tells us to store bookings.
For your own account and billing data we are the controller, and the Privacy Policy governs it. That distinction is not decoration: the two sets of data are treated differently throughout.
| Category | Purpose |
|---|---|
| Bookings — name, email, phone, notes | Running the booking feature you enabled |
| Enquiries and contact messages | Delivering them to you and storing them in your dashboard |
| Intake and quote submissions, including typed signatures | Storing what was submitted and signed, with the form version |
| Store orders and customer details | Fulfilling orders placed through your site |
| Contacts you add or import | Your customer list |
| Uploaded images and files | Publishing them on your site or delivering them to buyers |
We process this data for the duration of your account and do not use it for our own purposes. We do not sell it, we do not market to your customers, and we do not use it to train any AI model.
We use the following, and only these. We will tell you before adding another.
| Subprocessor | Role |
|---|---|
| Cloudflare | Hosting, database, file storage, and the AI features |
| Stripe | Payments and subscriptions |
| Resend | Sending transactional email |
| Fonts on our pages; and, if you connect them, sign-in and Drive galleries | |
| GitHub | Storing the generated code for your site so it can be deployed and rebuilt |
| VirusTotal | Malware scanning of files uploaded as paid digital deliverables |
Passwords are stored using PBKDF2 hashing. Sessions use signed, HttpOnly, Secure cookies. Connected third-party credentials are encrypted at rest. Every database query for a site is scoped to that site, so one customer's data cannot be read through another's account. Uploaded files are checked by content rather than by the name or type the browser claims.
If one of your customers asks you for access to, correction of, or deletion of their data, you can usually do it yourself from your dashboard. Where you cannot, email us and we will help within a reasonable period. If such a request reaches us directly we will point them to you, because it is your relationship, not ours.
If we become aware of a breach affecting personal data we process for you, we will tell you without undue delay, with what we know and what we are doing about it. We will not decide on your behalf whether you need to notify anyone.
Deleting a project purges its data — bookings, enquiries, form submissions, orders and uploaded files — from our database and file storage. Deleting your account does the same for every project on it. Export anything you want to keep first.
Two honest caveats, the same ones in the Privacy Policy: backups and point-in-time database history exist so we can recover from a failure, and deleted data can persist there for a limited period before ageing out. Billing records are retained where we are required to keep them.
Data is stored on Cloudflare's infrastructure, which is distributed. Where a transfer out of your region requires a legal mechanism, the relevant subprocessor's standard contractual clauses apply — each of the companies above publishes its own.
Questions about this addendum, or to request a signed copy: [email protected].