Privacy Policy
Last updated: May 2026
1. Who we are
Mysttro is operated by Culina Bella Pty Ltd (ABN to be confirmed), trading as Mysttro. Our website is mysttro.com.
Mysttro is a daily operating system for commercial musical theatre productions. We provide tools for cast changes, notices, sign-ins, safety reporting, leave management, house seat requests, and more.
We are committed to handling your personal information in accordance with the Australian Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs).
Important distinction: Mysttro is a service provider. When a production company uses Mysttro to manage their team, that production company remains the data controller for employment-related information. We process that data on their behalf, under their instructions. This policy covers the data we collect and manage directly.
2. What information we collect
We collect the following types of personal information:
Account information
- Full name
- Email address
- Phone number
- Display name
- Profile photo
Production membership data
- Which productions you belong to
- Your role within each production (e.g. cast, crew, stage management)
- Department assignment
Attendance and sign-in data
- Sign-in and sign-out times for each call or performance
- Geofence location data (optional) — used only to verify you are near the venue when signing in. This data is checked in real time and is not stored.
Leave and scheduling data
- Leave request dates, type, and reason
- Schedule and call information
House seat requests
- Guest names submitted when requesting complimentary tickets
Safety and incident reports
- Details of injuries or incidents, including body parts affected, descriptions of what happened, and witness names
Communication data
- Notices and cast changes you create or receive
- Social posts (text and photos) shared within a production
- Policy acknowledgments
Technical data
- Push notification tokens (for delivering mobile and web notifications)
- Basic analytics data (page views, device type) collected by Vercel Analytics
3. How we collect your information
We collect personal information in the following ways:
- Directly from you — when you create an account, fill in your profile, submit a leave request, file a safety report, create a social post, or use any other feature that involves entering information.
- From your production company — when a company manager or stage manager adds you to a production roster and assigns your role.
- Automatically — when you use Mysttro, we collect basic analytics data (such as pages visited and device type) through Vercel Analytics. If you enable push notifications, we store the token needed to deliver those notifications.
- From authentication providers — if you sign in with Google, we receive your name and email address from Google. We do not receive or store your Google password.
4. Why we collect your information
We use your personal information for the following purposes:
| Purpose | Data used |
|---|---|
| Creating and managing your account | Name, email, phone, display name, profile photo |
| Managing production membership and access control | Production membership, role, department |
| Daily attendance tracking | Sign-in/out times, geofence location (real-time only) |
| Leave management | Leave request dates, type, reason |
| House seat ticket requests | Guest names |
| Workplace health and safety (WHS) compliance | Safety and incident report details |
| Production communication | Notices, cast changes, social posts |
| Delivering notifications | Push notification tokens, email address |
| Tracking policy acknowledgments | Acknowledgment records |
| Improving the service | Anonymous analytics data |
We do not use your personal information for marketing to third parties, and we do not sell your data.
5. Sensitive information
Under the Australian Privacy Act, certain types of information are classified as "sensitive information" and require your explicit consent before collection.
Mysttro collects sensitive information in one area: safety and incident reports. These reports may include health-related information such as injury details and affected body parts. This information is collected to meet workplace health and safety (WHS) obligations under Australian law.
We will always ask for your explicit consent before collecting sensitive information. You can choose not to provide it, though this may affect the ability to properly record and manage safety incidents.
We do not collect information about your racial or ethnic origin, political opinions, religious beliefs, sexual orientation, or criminal record.
6. How we store and protect your information
We take reasonable steps to protect your personal information from:
- Unauthorised access, modification, or disclosure
- Misuse, interference, and loss
Our security measures include:
- All data is encrypted in transit using TLS (HTTPS) and encrypted at rest in our database
- Our primary database is hosted by Supabase in the Sydney, Australia region
- Authentication is managed through Supabase Auth with support for email/password and Google OAuth
- Row-level security (RLS) policies ensure users can only access data they are authorised to see
- Access to production data is restricted to members of that production, with role-based permissions
No system is perfectly secure. If you become aware of any security issues, please contact us immediately at privacy@mysttro.com.
7. Who we share your information with
We do not sell your personal information. We share data only with the following categories of recipients, and only to the extent necessary to operate the service:
- Your production company — company managers and stage managers within your production can see your profile, attendance, leave requests, and other production-related information as part of managing the show.
- Other production members — depending on the feature, certain information (such as cast changes, notices, and social posts) is visible to other members of your production.
- Infrastructure and service providers — we use third-party services to host, operate, and improve Mysttro. These providers process data on our behalf and are listed in the next section.
We may also disclose your information if required by law, such as in response to a court order or to comply with WHS reporting obligations.
8. Cross-border data transfers
Under APP 8, we are required to tell you when your personal information is sent outside Australia. While our primary database is hosted in Australia, some of the services we use to operate Mysttro are based overseas.
| Service | Country | Purpose |
|---|---|---|
| Supabase | Australia (Sydney) | Database hosting and authentication |
| Vercel | United States (with Sydney edge network) | Web hosting and deployment |
| Resend | United States | Email delivery (e.g. notification emails) |
| Expo Push | United States | Mobile and web push notifications |
| Stripe | United States | Payment processing (planned) |
We take reasonable steps to ensure that overseas recipients handle your information in accordance with the Australian Privacy Principles. All providers listed above have their own privacy policies and data protection commitments.
9. Your rights
Under the Australian Privacy Principles, you have the following rights regarding your personal information:
Access (APP 12)
You can request access to the personal information we hold about you at any time. Much of your data is already visible to you directly within Mysttro (your profile, your sign-in history, your leave requests, etc.). For anything else, contact us and we will respond within 30 days.
Correction (APP 13)
If any of your personal information is inaccurate, incomplete, or out of date, you can update it directly in your Mysttro profile or ask us to correct it. We will make corrections promptly.
Deletion
You can request that we delete your account and personal information. We will action your request, subject to any legal obligations that require us to retain certain records (see the Data Retention section below). To request deletion, email privacy@mysttro.com.
Withdraw consent
Where we rely on your consent to process information (such as safety reports containing sensitive health data), you can withdraw that consent at any time. Withdrawing consent will not affect the lawfulness of processing that occurred before the withdrawal.
Push notifications
You can disable push notifications at any time through your browser or device settings. When you do so, your notification token is no longer used and will be cleaned up automatically.
10. Data retention
We keep your information for as long as it is needed to provide the service, or as required by law. Here is a summary of our retention periods:
| Data type | Retention period | Reason |
|---|---|---|
| Account information (name, email, phone, photo) | Duration of your account + 30 days | Account management; 30-day grace period for reactivation |
| Production membership and role | Duration of your membership in that production | Access control |
| Sign-in/out times | 7 years | Fair Work Act record-keeping requirements |
| Leave requests | 7 years | Fair Work Act record-keeping requirements |
| Geofence location | Not stored | Checked in real time only; never persisted |
| House seat requests | Duration of the production season | Ticket management |
| Safety and incident reports | Minimum 5 years; up to 30 years for health monitoring records | Work Health and Safety Act requirements |
| Notices and cast changes | Duration of the production | Production communication |
| Social posts | Until deleted by you or the production ends | User-generated content |
| Push notification tokens | Until you revoke notifications or the token expires | Notification delivery |
| Policy acknowledgments | Duration of the employment relationship | Compliance tracking |
When data reaches the end of its retention period, we delete or de-identify it.
12. Data breaches
We take data security seriously. In the event of a data breach that is likely to result in serious harm to any individual whose data is affected, we will:
- Take immediate steps to contain the breach and limit any damage
- Assess whether the breach is likely to result in serious harm
- Notify the Office of the Australian Information Commissioner (OAIC) and all affected individuals as soon as practicable, as required by the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act
- Keep a record of all data breaches, whether or not they meet the notification threshold
If you believe there has been a data breach involving your information, please contact us immediately at privacy@mysttro.com.
13. Changes to this policy
We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make significant changes, we will:
- Update the "Last updated" date at the top of this page
- Notify you through the Mysttro app or by email if the changes materially affect how we handle your information
We encourage you to review this page periodically to stay informed about how we protect your data.
14. How to contact us and make a complaint
If you have any questions about this privacy policy, want to access or correct your information, or wish to make a complaint about how we have handled your personal information, please contact us:
- Email: privacy@mysttro.com
- Entity: Culina Bella Pty Ltd trading as Mysttro
We will acknowledge your complaint within 7 days and aim to resolve it within 30 days. If we need more time, we will let you know why and give you an updated timeframe.
Escalation to the OAIC
If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
- Website: www.oaic.gov.au
- Phone: 1300 363 992
- Email: enquiries@oaic.gov.au