Not legal advice. This Privacy Policy should be reviewed by qualified counsel before reliance in a dispute.
Effective / last updated: 15 August 2026
Controller: BowlCast LLC (“BowlCast”, “we”, “us”, or “our”)
Contact: support@bowlcast.tv
This Privacy Policy explains how BowlCast collects, uses, stores, and shares personal information when you use the BowlCast live streaming platform, related websites, and on-premises edge software (the “Service”). It should be read with our Terms of Service.
1. Who we are
BowlCast LLC operates the BowlCast platform. For privacy requests, contact support@bowlcast.tv.
2. Scope and roles
This policy covers:
- The BowlCast web application and related services (including public pages such as live directory pages where applicable).
- Organisation and user administration features.
- YouTube channel connection via Google authorisation.
- Billing via Stripe.
- On-premises edge software used with your organisation (local processing may also occur on your hardware).
Venue footage and people on camera. Your organisation is responsible for camera footage and for individuals who appear in streams (patrons, staff, guests, minors). BowlCast processes account, organisation, and operational streaming metadata. Live video is primarily delivered to YouTube under your connected channel. This policy does not control how Google or YouTube process data under their own policies.
3. Personal data we collect
3.1 Account and profile
When you are invited and register, we collect information such as:
- Email address
- Name
- Password (stored in a secure, one-way form; we do not store plaintext passwords)
- Optional phone number
- Role within your organisation and account status
- Organisation association
- Last login and similar account activity indicators
BowlCast account sign-in is by email and password. We do not use Google Sign-In to authenticate BowlCast accounts.
3.2 Organisation information
For organisations we may store business profile details such as name, contact details, address, timezone, branding assets (for example logos), and settings needed to operate the tenant, including billing status and Stripe customer identifiers.
3.3 Billing and payments
When you subscribe, Stripe processes payments. We may store:
- Stripe customer, subscription, and invoice identifiers
- Plan/price references, amounts, currency, status, and invoice URLs or metadata mirrored for administration
We do not store full payment card numbers. Card data is handled by Stripe under Stripe’s terms and privacy policy.
3.4 Invites and password reset
We store invite and password-reset related information (such as the invitee email and short-lived reset credentials) so we can onboard users and help them regain access securely.
3.5 Authentication, cookies, and browser storage
To keep you signed in, route the application, and remember preferences, we use:
| Technology | Do we use it? | Purpose |
|---|---|---|
First-party cookie bowlcast_role | Yes | Essential routing / role indication for the application (not used as the primary sign-in credential store) |
| Local Storage / similar browser storage | Yes | Authentication/session information and certain UI preferences |
| Hosting / CDN / reverse-proxy cookies | Possibly | Essential delivery and security of the Service |
| Analytics cookies | No (current product) | We do not currently set first-party analytics cookies |
| Marketing / advertising cookies | No (current product) | We do not currently set advertising or marketing cookies |
Third-party sites you visit during Google authorisation (for example Google Account pages) may set their own cookies under Google’s policies. BowlCast does not control those cookies.
You can sign out through the application or clear site data in your browser. Blocking cookies may affect Google’s authorisation screens when connecting YouTube.
3.6 YouTube / Google authorisation (channel connect)
Google OAuth is used only to connect a YouTube channel—not to sign in to BowlCast. We request:
https://www.googleapis.com/auth/youtube.force-ssl
When an authorised user connects a channel, we may store:
- Channel identifiers and display name
- OAuth access and refresh tokens (stored securely) so we can perform authorised YouTube operations on your behalf
- Related authorisation metadata needed to keep the connection working
- Operational YouTube resource information created or managed through the Service (for example broadcasts and playlists)
3.7 Cameras, broadcasts, and playlists
We store operational data needed to run streaming, including camera connection details (which may include credentials, stored securely), broadcast and playlist metadata, schedules, visibility settings, actual start times and related status, and technical stream configuration. We do not operate BowlCast as the primary long-term archive of your live video file; live delivery is oriented to YouTube.
3.8 Edge devices
Where you use on-premises edge software, we may store device registration and health-related metadata. The edge device may also store credentials and stream state locally on your premises. You are responsible for securing that host.
3.9 Logs, public pages, and technical data
We may process technical logs such as IP addresses and request metadata to operate, secure, and troubleshoot the Service—including when visitors load public marketing or live pages. Sensitive fields (such as passwords and tokens) are protected in logging where practicable.
We do not currently operate first-party product analytics or marketing trackers in the application.
3.10 Communications
If you email support or submit feedback, we process the content of those communications. We send transactional email (invites, password reset, and similar service messages). We do not currently operate a separate marketing email list unless you later opt in to one we clearly offer.
4. How we use personal data
We use personal data to:
- Provide and secure the Service (including authentication and access control).
- Process subscriptions, invoices, and related billing administration with Stripe.
- Send invite and password-reset emails.
- Connect to YouTube and perform operations you have authorised.
- Schedule and operate live broadcasts and playlists.
- Operate edge connectivity and background processing required for streaming.
- Monitor reliability and investigate abuse or security incidents.
- Improve the Service (including using feedback you provide).
- Comply with law and enforce our Terms of Service.
5. Google user data — Limited Use
Regarding Google user data obtained through OAuth / YouTube APIs:
- We do not sell Google user data.
- We do not use Google user data for advertising.
- We use Google user data only to perform user-authorised YouTube operations and related Service functionality (for example, managing live broadcasts, streams, and playlists for the connected channel).
We strive to comply with the Google API Services User Data Policy, including Limited Use requirements applicable to our permissions.
You may disconnect a channel in BowlCast (we attempt to revoke access with Google and remove stored tokens) or revoke access in Google Account permissions. If you revoke only in Google settings, also disconnect in BowlCast so tokens are cleared on our side.
6. Legal bases (where GDPR/UK GDPR or similar applies)
Where those laws apply, we typically rely on performance of a contract, legitimate interests (security, service reliability, and product improvement), and consent (for example Google authorisation grants). Exact bases for each processing activity should be confirmed with counsel for your markets.
7. Sharing and processors
We share data with categories of recipients such as:
| Recipient | Role |
|---|---|
| Stripe | Payment processing, subscriptions, invoices, and related fraud/prevention tooling Stripe provides |
| Google / YouTube | Authorisation and YouTube API operations you approve |
| Email delivery providers (SMTP) | Transactional email (invites, password reset) |
| Infrastructure / hosting providers | Hosting and operating the Service |
| Your organisation’s administrators | User and organisation administration within the tenant |
We do not sell personal information.
Exact hosting region depends on our production configuration and subprocessors. We do not claim a specific region or security certification (such as SOC 2 or ISO) in this policy.
8. International transfers
Personal data may be processed in facilities used by us and our subprocessors, which may be outside your country of residence. Where required, we use appropriate safeguards for such transfers.
9. Security
We use industry-standard practices to protect accounts, credentials, and tokens, including secure password storage, encryption of sensitive secrets at rest where applicable, role-based access controls, and encrypted transport (HTTPS) in production. Customer-managed edge hosts and local networks remain your responsibility.
No method of transmission or storage is perfectly secure. Security measures reduce risk but cannot eliminate it.
Security incidents
If we become aware of a security incident affecting personal data or Service integrity, we intend to contain and investigate, remediate where feasible, and notify affected customers and regulators when legally required.
Report vulnerabilities to support@bowlcast.tv. Do not access data that is not yours or disrupt availability while testing.
10. Retention
| Data | Retention (summary) |
|---|---|
| User accounts | Until an authorised administrator deletes the user, or supported offboarding completes |
| Disabled / deactivated users | Retained until deleted |
| Organisation profile and settings | For the life of the organisation |
| Invites | Until used, expired, or removed |
| Billing identifiers and invoice records | As needed for billing, accounting, disputes, and legal obligations |
| Signed-in session data | Limited period while signed in, or until sign-out |
| Password-reset credentials | Short-lived; expire if unused |
| OAuth tokens and channel identifiers | Until the YouTube channel is disconnected |
| Broadcasts, playlists, cameras, edge records | Until deleted in the product or organisation data is removed |
| Local edge data | On your premises until cleared or wiped |
| Logs | According to hosting and logging configuration |
| Backups | May retain copies of deleted data until backup retention expires |
| Temporary caches / queues | Short-lived by design |
Broadcast and similar content data are generally not auto-purged on a schedule. We may retain data longer when required by law, dispute, or security investigation.
11. Account deletion and offboarding
Current product behaviour:
| Capability | Status |
|---|---|
| Self-serve “delete my account” for the logged-in user | Not available |
| Organisation admin deletes a member | Available, with restrictions (admins cannot delete themselves or the primary admin through that flow) |
| Deactivate / reactivate a member | Available (access disabled; data retained until deleted) |
| Disconnect YouTube channel (revoke access and remove tokens) | Available for authorised roles |
| Delete broadcasts / playlists | Available |
| Full organisation wipe as self-serve | Not available |
Member delete removes that user account; it does not by itself remove organisation-scoped resources (channels, broadcasts, cameras, edge devices).
Cancelling a subscription does not automatically delete organisation data.
To request deletion assistance or organisation offboarding beyond in-product tools, email support@bowlcast.tv with your account email, organisation name, and what you need (member removal, channel disconnect confirmation, content deletion, or full offboarding). We will respond on a best-effort basis. YouTube-side content remains on YouTube unless deleted there or through BowlCast actions that update YouTube. Backups and logs may lag behind in-product deletes.
12. Your rights
Depending on your location, you may have rights to access, correct, delete, or export personal data, or to object to or restrict certain processing. To exercise rights, contact support@bowlcast.tv. We will respond on a best-effort basis, subject to the product limitations above and applicable law (including Australian privacy requirements where they apply).
13. Children
The Service is directed at organisations and adult operators (18+) of venues and events. It is not directed at children. We do not knowingly collect personal information from children for BowlCast accounts.
14. Changes
We may update this Privacy Policy. Material changes will be notified by email or in-product notice where practicable. Continued use after the effective date constitutes acceptance of the updated policy where permitted by law.
15. Contact
Privacy requests: support@bowlcast.tv
Related: Terms of Service
External references: