Privacy Policy
Last updated: August 20, 2026
Who we are
STHO (STHO GLOBAL LTD, Office 2712, Unit D11, floor 27, Addax Port Office Tower, Tamouh, Al Reem Island, Abu Dhabi, United Arab Emirates — Abu Dhabi Global Market commercial licence 24938, tax registration number 105054063000001) operates the STHO platform — thestho.com, api.thestho.com and the STHO mobile app — connecting venues and artists for booking and settlement. STHO is the data controller for the personal data described in this policy.
Contact: privacy@thestho.com
Postal address: Office 2712, Unit D11, floor 27, Addax Port Office Tower, Tamouh, Al Reem Island, Abu Dhabi, United Arab Emirates. Telephone: +971 58 575 7662. Privacy contact: privacy@thestho.com. STHO is established outside the European Union, so it has designated Ophélie Serre as its representative in the Union under Article 27 GDPR [OPERATIONAL: Member State of establishment; contact address].
What we collect
Depending on how you use STHO, we collect:
- Account data: Name, email address, phone number, password (stored as a one-way hash), preferred language, and role (artist, artist manager, venue manager, admin).
- Onboarding and profile data: Artist profiles (bio, genres, media, social links, availability, equipment), venue profiles (venue details, address, capacity, programming), identity and legal documents you submit for validation, and nationality where it is required for payout or tax purposes.
- Booking and financial data: Booking requests, negotiation history, offers, confirmations, reviews, invoices, payout records, ledger entries and payment records.
- Communications: Transactional messages we send you (email, WhatsApp verification codes) and your notification preferences.
- Technical data: Authentication events, security audit records (timestamps, IP address, device and user-agent details) and error diagnostics.
- Prospect data (you may not have an account): If you are a performing artist or a venue, we may hold limited professional contact data gathered from public sources — name, stage name, public contact details and links to public work — in order to invite you to the platform. See "Prospecting" below.
Why, and on what legal basis
We process personal data only where we have a legal basis for it:
- To provide the service — creating your account, verifying your identity, matching, booking, invoicing and payouts (contract, Art. 6(1)(b)).
- To meet legal obligations — bookkeeping, tax and responding to lawful requests (legal obligation, Art. 6(1)(c)).
- To keep the platform secure — authentication, fraud and abuse prevention, audit logging and error monitoring (legitimate interests, Art. 6(1)(f)).
- To send you marketing, only if you opted in (consent, Art. 6(1)(a)) — withdrawable at any time in your notification settings or through the unsubscribe link in any marketing message.
- Prospecting from public sources (legitimate interests, Art. 6(1)(f)) — you can object at any time, and we will delete your data and suppress re-collection.
Prospecting
If you are a performing artist or a venue and have no account with us, we may still hold limited professional contact data about you, gathered from public sources, so that we can invite you to the platform. We rely on our legitimate interest in building a professional marketplace, and we hold professional contact details only.
You can object at any time by writing to privacy@thestho.com. On objection we delete the record and suppress re-collection, so the same details are not gathered again. Prospect data we hold is reviewed for continued relevance at least every 24 months.
AI-assisted features
Some features use AI providers (OpenAI, Tavily) as processors: we generate artist press kits from your own profile at your request, and we produce market research and programming drafts for venues. Outputs are drafts, reviewed by people before they are used.
No automated decision producing legal or similarly significant effects is made about you (Art. 22). We minimise the personal data included in these requests, and our providers are contractually barred from using it to train their models.
Who receives your data
Service providers acting on our instructions under data processing agreements:
- Hosting and storage (DigitalOcean, EU region).
- Phone verification (Twilio / WhatsApp).
- Transactional email (Resend).
- Error monitoring (Sentry).
- AI processing (OpenAI, Tavily).
- Address lookup and mapping (Google Maps Platform — when you type an address, the text is sent to Google to suggest completions).
- Code and build infrastructure (GitHub — no user data).
Venue and artist counterparties see the role-scoped information they need in order to negotiate and fulfil a booking. We disclose data to authorities where the law requires it. We never sell personal data.
International transfers
Your data is stored in the EU. Some providers process data in the United States; those transfers rely on the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. Copies of the safeguards are available on request at privacy@thestho.com.
How long we keep it
We keep personal data only for as long as we need it:
- Account and profile data: For the life of your account, and deleted or anonymised within 30 days of a deletion request.
- Booking and financial records: Retained for the statutory commercial and tax period (ten years from the end of the financial year, under UAE law) in a form that is no longer linked to your live profile.
- Security logs: Up to 12 months.
- Prospect data: Deleted on objection, and reviewed for continued relevance at least every 24 months.
- Backups: Encrypted, and aged out within 30 days.
Your rights
Over the personal data we hold about you, you have the right to:
- Access it, and obtain a copy.
- Have it corrected when it is inaccurate or incomplete.
- Have it erased.
- Have its processing restricted.
- Receive it in a portable, machine-readable format.
- Object to its processing — including an absolute right to object to direct marketing.
You can export your data and delete your account yourself, in the app, under Settings → Privacy. Deletion takes effect after a 30-day grace period during which you can change your mind. After that your account is anonymised or removed entirely, and the records we must keep by law are retained in a form no longer linked to you.
Otherwise, or if you have no account, write to privacy@thestho.com. We respond within one month. You may also complain to the data protection supervisory authority of the country you live or work in: STHO has no establishment in the European Union, so no single lead authority handles it — each national authority is competent for the people in its own territory.
Cookies
We use only strictly necessary first-party cookies, for signing in and keeping your session secure. We set no advertising or analytics cookies and no third-party trackers, so there is no consent pop-up to click.
Our Cookie Notice lists every cookie and browser storage entry we use, what each one is for and how long it lasts.
Children
The platform is for professional use by adults: you must be at least 18 years old to hold an account, as set out in the eligibility clause of our Terms of Service. STHO is not directed at children and we do not knowingly collect their personal data.
Changes to this policy
We will notify you of material changes in the app or by email, and the current version and its date always appear on this page. When a material change is published we ask you to accept the new version, so that the record of what you agreed to stays accurate.
Contact
For any question about this policy, or to exercise any of the rights above, contact our privacy team:
Email: privacy@thestho.com
We respond to requests within one month (Art. 12(3)).
Version 2026-08-20 — this is the identifier recorded with your acceptance of this policy.