Effective date: 2026-09-04
Version: 1.0 (see the change log at the end)
Published at: linebooth.com
Service provider: an individual seller (name not yet published) · بائع فرد (الاسم غير منشور بعد) — an individual working under a Freelance Certificate. Certificate number: not yet published — registration details will be published here. Address: not yet published — registration details will be published here.
Contact: support@linebooth.com (a phone number will be published here; email is the monitored channel)
This page is kept up to date as our suppliers change. The version published at linebooth.com is always the current one, and it prevails over any copy you have saved or printed.
The marks used on this page.
To run Linebooth we rely on a small number of outside companies — for example the company that hosts the website, the company that stores the database, and the company that provides the AI features. Some of them can access personal data belonging to you.
This page lists those companies, what each one does for us, what kinds of personal data each one can access, and where each one hosts that data.
We publish it so that:
Our responsibility does not move. Using these companies does not transfer our responsibility to them. The seller — an individual seller (name not yet published) — remains responsible to you for the personal data handled on our behalf. We choose each company, we instruct it, and we keep it under review.
Who else sees your data. We do not disclose your personal data to anyone outside the companies listed on this page, and then only as far as is needed to provide the service shown next to that company. We may also disclose data where a Saudi authority or a court requires it.
Cookies and identifiers. Several companies in the table below handle device or session identifiers, request logs and email-delivery records. For the scope of our use of cookies and similar identifiers, see the cookie section of our Privacy Policy at linebooth.com (this disclosure is required by Article 6 of the Implementing Regulations of the E-Commerce Law).
Please read this section before you subscribe.
Policy issued by the Saudi Data and Artificial Intelligence Authority (SDAIA) requires the personal data of minors to be stored and processed inside the Kingdom. Our systems store data outside the Kingdom, so we cannot lawfully serve minors.
For that reason Linebooth is available only to people aged 18 or over. The sign-in screen and the checkout screen each ask you to confirm that you are 18 or over before they will go any further, and the date and time of that confirmation is recorded.
Under the Civil Transactions Law the age of majority is 18, and a subscription taken by a person under 18 does not validly bind that person. If we learn that an account belongs to someone under 18, we close the account, refund in full everything collected for it, and delete that person's personal data from our systems and from the companies listed on this page.
How to read the table
| Vendor | Role / service provided | Categories of personal data accessed | Hosting region / country | Vendor's data-processing agreement or privacy terms |
|---|---|---|---|---|
| Cloudflare, Inc. — Pages, and the content delivery network that goes with it | Hosts linebooth.com and app.linebooth.com and delivers the pages and the app files to your browser, from a server close to you. | IP address; browser and device information; technical request logs (which page was requested, when, and whether it succeeded). | United States company; global edge network. Not inside the Kingdom. | cloudflare.com/cloudflare-customer-dpa |
| Cloudflare, Inc. — Workers | Runs our small backend: the sign-in link, the free rehearsal days, the entitlement answer that tells your device whether the paid Studio features are unlocked, and the receiver for Paddle's payment notifications. | Email address; the irreversible hashes of your sign-in link and session; subscription status and dates; IP address, for rate limiting only. | United States company; global edge network. Not inside the Kingdom. | cloudflare.com/cloudflare-customer-dpa |
| Cloudflare, Inc. — Workers KV | Fast store for the entitlement record, and the store that holds our verbatim copy of every payment notification Paddle sends us. | Entitlement records keyed by an irreversible hash of your email address, with no address in them. In the verbatim notification copy: the billing name, billing address and billing email you gave Paddle — see section 5A. | United States company; global edge network. Not inside the Kingdom. | cloudflare.com/cloudflare-customer-dpa |
| Cloudflare, Inc. — D1 database | Our queryable records: customers, sign-in sessions and links, subscriptions, free rehearsal days, entitlements, payment events, discount codes and their attribution, a log of which service email was sent to whom, anonymous funnel counters, and account-deletion requests. | Email address (erased when a deletion request is executed); the irreversible hash of it; subscription, rehearsal-day and payment records; the timestamps of your consents. | United States company; global edge network. Not inside the Kingdom. | cloudflare.com/cloudflare-customer-dpa |
| Cloudflare, Inc. — R2 storage | Holds the nightly backup of the database and the entitlement store, so that a paying customer cannot lose access to what they paid for. | A copy of the three rows above. | United States company. Not inside the Kingdom. | cloudflare.com/cloudflare-customer-dpa |
| Paddle.com Market Ltd | Merchant of record. Paddle is the seller for the payment itself: it runs the checkout, takes your card details in its own fields, collects the money, handles tax, issues your receipt, and runs the customer portal where you manage your card, your invoices and your cancellation. | Cardholder name; billing email; billing address and country; card type and the last four digits; payment, renewal and refund history. Card details are entered directly into Paddle's own fields — Linebooth never receives, sees or stores a card number, its expiry date or its security code, and holds no payment token. | Registered in the United Kingdom. Not inside the Kingdom. | paddle.com/legal/dpa |
| Resend (Plus Five Five, Inc.) | Sends our service emails: the one-time sign-in link, the rehearsal-days notice, a gift notice, and the acknowledgement of an account-deletion request. It sends nothing else, and it sends no marketing unless you have separately opted in. | Email address; the content of the message sent to you; delivery records. | United States company. Not inside the Kingdom. | resend.com/legal/dpa |
| Cloudflare Web Analytics | Counts page views so we can see whether the site and the app are working. | No personal data. It sets no cookie, stores no identifier on your device, and cannot follow you to another website or build a profile of you. That is why we chose it, and why this site has no cookie-consent banner. | United States company; global edge network. | cloudflare.com/cloudflare-customer-dpa |
| {{AI_VENDOR}} — not currently used | Would provide the AI script-conversion feature inside the app. No AI provider is connected today, and the feature does not send anything anywhere. This page and the Privacy Policy will name the provider before it does. | Nothing today. When it is connected: only the text you choose to send to an AI feature, plus a technical request identifier. | [TO BE COMPLETED — region / country] | [TO BE COMPLETED — link] |
| Authentication provider — not used | We use no outside sign-in company. Sign-in is a one-time link our own Worker sends and verifies; there is no password anywhere in the system. | Nothing. There is no such company. | — | — |
| Error-tracking provider — not currently used | Would record technical errors so we can fix crashes. We run no error-reporting tool today. If we add one, this page changes first, and we will not use a tool that cannot be configured to leave the contents of your scripts out of a report. | Nothing today. | — | — |
Every payment notification Paddle sends us is stored in our own systems exactly as it arrives, without editing or trimming. Such a notification can contain the billing name, billing address and billing email address you gave Paddle.
We do that for two reasons, and we would rather state them plainly than let you assume the record is anonymous:
What this means when you ask us to delete your account. Your email address is erased from the customer record, every sign-in session and outstanding sign-in link is destroyed, and nothing in the account joins you to the payment record any more. The payment record itself stays, with the billing details Paddle sent, for as long as the law requires a seller to keep it. An account that never paid us anything leaves nothing behind but an irreversible hash and the fact that the free rehearsal days were used. The Privacy Policy at linebooth.com sets this out in full.
Each company keeps personal data only for as long as it needs it to provide its service to us. The retention periods that apply to your data are set out in our Privacy Policy at linebooth.com.
When we stop using a company on this list, or replace it, we will require it to delete or return the personal data it holds for us, and we will record the change in the change log at the end of this page.
The scripts you paste or type into Linebooth are not stored by any company on this list. They are held in your own browser's storage, on your own device, and there is no cloud sync. The same is true of every take you record: the audio is written to your browser's storage and the finished file is assembled and exported on your device.
So there is nothing here for us to disclose, hand over or lose in a breach of our systems — and nothing for us to restore for you either. Delete a script or a project from inside the app at any time, and export the work you want to keep before you clear your browser storage.
The one exception is the AI script-conversion feature: if it is switched on, the text you choose to send to it goes to the AI provider named in the table above. That feature is not connected to any provider today.
We update this page first. Except in the urgent cases described below, we update this page before a new company starts handling personal data, and we raise the version number and record the date of the change in the change log.
Notice. Where it is practical, we aim to email registered subscribers before a new company starts handling personal data, and we may also post the change at linebooth.com.
Urgent changes. If we have to move quickly — for example because a company stops operating, or for a security reason — we may make the change first and tell you afterwards, with the reason.
How to raise a concern. Email support@linebooth.com with "Sub-processor" in the subject line, telling us which company concerns you and why. We will look into it and reply. We cannot run the service without the companies listed here, so if you are not comfortable with a company on this list you can cancel your subscription. Cancellation, and any refund, are dealt with in the Terms of Service at linebooth.com, together with your statutory withdrawal right under Article 13(1) of the E-Commerce Law.
These notices are not marketing. Messages about this list are service messages about your account. We only send marketing messages if you have separately opted in beforehand (Article 25 of the PDPL). You can withdraw that consent at any time, as easily as you gave it (Article 12 of the Implementing Regulations), and we stop sending immediately. Every marketing email we send is marked clearly as advertising and carries a way to unsubscribe (Article 10 of the Implementing Regulations of the E-Commerce Law).
Your rights. You can ask us to tell you how your personal data is being used, ask what personal data we hold about you, ask for a copy of it, ask us to correct it, and ask us to destroy it. Where our processing is based on your consent, you can withdraw that consent at any time, as easily as you gave it. Write to support@linebooth.com. We answer within 30 days, and where we need more time we may extend once by a further 30 days.
Security incidents. If personal data is leaked, damaged, destroyed, altered, or accessed without authorisation, and the incident could harm the data, harm you, or conflict with your rights, we notify the Saudi Data and Artificial Intelligence Authority (SDAIA) within 72 hours of becoming aware of it. Where the incident may cause you damage, we also notify you without undue delay. Separately, we notify the Ministry of Commerce within 3 days of becoming aware of it.
Complaints. This is our complaints procedure, and it is the same procedure referred to in our other legal pages:
| Version | Date | What changed |
|---|---|---|
| 1.0 | 2026-09-04 | First publication. |
| 1.1 | 2026-09-04 | The list replaced with the companies actually engaged: Cloudflare (Pages, Workers, Workers KV, D1, R2 and Web Analytics), Paddle.com Market Ltd as merchant of record, and Resend for service email. Recorded that scripts and recordings are never stored by any of them (section 6), that no authentication company, error-tracking company or AI provider is used today, and — in the new section 5A — that our verbatim copy of Paddle's payment notifications keeps the billing identity, including after an account is deleted. |
This page is published in Arabic and English. The two versions were prepared to say the same thing. For customers in the Kingdom of Saudi Arabia, the Arabic version governs if there is any difference between them.
This page and the service are governed by the laws of the Kingdom of Saudi Arabia. Payment, cancellation and refund terms are in the Terms of Service at linebooth.com.
Closed since version 1.1 — the four [OWNER TO CONFIRM] points are resolved and the sentences that carried them now state the fact: the 18-or-over confirmation is live on both the sign-in and the checkout screen and its timestamp is recorded; scripts and recordings are never stored on a server; the payment integration is Paddle as merchant of record, with card details entered only in Paddle's own fields; deleting a script inside the app is what removes it, because we never had a copy.
This page must still not be published while any of the following is outstanding:
tools/identity.json; filling them in there and re-running tools/apply-identity.js updates every page.