Back

Privacy Policy

Last updated: 25 April 2026

1. Who we are

Production Deck ("we", "us", "our") provides film and video pre-production management software. This Privacy Policy explains how we collect, use, store, share and protect your personal information when you use our website and services (the "Service").

For the purposes of UK GDPR and the Data Protection Act 2018, we are the data controller of any personal data you provide to us.

2. Information we collect

We collect the following categories of information:

  • Account data — your email address, display name, password hash and authentication provider identifiers.
  • Profile data — optional information you add to your profile such as your nickname, avatar and bio.
  • Project content — projects, scripts, call sheets, budgets, schedules, contacts, mood boards, links and any other documents or data you create or upload.
  • Workspace data — workspace memberships, invites and collaborator relationships.
  • Billing data — subscription tier, billing status and payment metadata. Card details are processed by our payment provider and never stored on our servers.
  • Usage and technical data — IP address, browser type, device information, pages visited, referring URL and timestamps, collected via standard server logs and analytics.
  • Communications — support messages, feedback and conversations you initiate with us.

3. How we use your information

We use your personal data to:

  • Provide, maintain and improve the Service;
  • Authenticate you and secure your account;
  • Enable collaboration features (e.g. workspace members and project collaborators);
  • Process subscriptions, billing and refunds;
  • Respond to support requests and communicate service updates;
  • Detect, prevent and address fraud, abuse and security incidents;
  • Comply with legal obligations.

4. Legal bases for processing

We rely on the following legal bases under UK GDPR:

  • Contract — to provide the Service you have signed up for;
  • Legitimate interests — to secure the Service, prevent abuse and improve our product;
  • Consent — for optional analytics or marketing communications, where required;
  • Legal obligation — to comply with applicable law.

5. How we share your information

We do not sell your personal data. We share information only with:

  • Service providers processing data on our behalf (hosting, database, authentication, email, analytics, payment processing) under appropriate data processing agreements;
  • Workspace members and collaborators you have explicitly invited to your projects;
  • Authorities where we are legally required to disclose information.

6. International transfers

Some of our service providers are located outside the United Kingdom or European Economic Area. Where personal data is transferred outside these regions, we rely on appropriate safeguards such as the UK International Data Transfer Agreement or Standard Contractual Clauses approved by the European Commission.

7. Data retention

We retain your account and project data for as long as your account is active. When you delete a project or document it is moved to a 7-day soft-delete trash before being permanently removed. When you delete your account, we permanently remove your personal data within a reasonable period, except where we are required to retain it to comply with legal, accounting or regulatory obligations.

8. Security

We implement industry-standard technical and organisational measures to protect your data, including encryption in transit, row-level security on the database, scoped access tokens and least-privilege service credentials. However, no system is 100% secure and we cannot guarantee absolute security.

9. Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you;
  • Request correction of inaccurate data;
  • Request deletion of your data ("right to be forgotten");
  • Object to or restrict certain processing;
  • Request data portability;
  • Withdraw consent at any time, where processing is based on consent;
  • Lodge a complaint with the UK Information Commissioner's Office (ICO).

To exercise these rights, contact us via the Help & Support page.

10. Cookies

We use strictly necessary cookies to keep you signed in and remember your preferences. We may use limited analytics cookies to understand how the Service is used. You can control cookies through your browser settings.

11. Children

The Service is not intended for users under the age of 16 and we do not knowingly collect personal data from children.

12. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated via the Service or by email. The "Last updated" date at the top reflects the most recent revision.

13. Contact

For privacy questions or to exercise your rights, please reach out via our Help & Support page.