1. Who We Are (Data Controller)
1/15This Privacy Policy applies to our music social networking platform (the "Service"). We act as the Data Controller for all personal data processed through the Service.
As a Data Controller, we are registered under the UK Data Protection Act 2018 and comply with the UK General Data Protection Regulation (UK GDPR). We have appointed a Data Protection Officer (DPO) who can be contacted through the details in Section 14.
Our lawful bases for processing your data are: (a) contract performance - to provide the Service you signed up for; (b) legitimate interests - to operate and improve the platform; (c) consent - for optional features such as location sharing and non-essential cookies; and (d) legal obligation - when required by law.
2. What Data We Collect
2/152.1 Account & Identity Data
- Full name and email address (required for registration)
- Username and display name (publicly visible)
- Password (stored as a one-way cryptographic hash - we never store your raw password)
- Profile photo (optional, publicly visible if provided)
- Short biography (optional, publicly visible)
- Social media profile links (optional, publicly visible)
- Phone number (optional, used only for account recovery - never publicly displayed)
- Artist verification documents including government-issued ID (retained securely, used only for verification purposes)
2.2 Content & Activity Data
- Posts, comments, reactions, and media you publish
- Fandoms you create or join
- Accounts you follow or friend
- Posts you save or like
- Direct messages you send or receive
- Notifications generated by your activity
2.3 Location Data (opt-in only)
- If you choose to tag a post with your location, we store the coordinates you provide
- If you use the Near Me feature, your approximate location is used server-side to filter posts - we do not store this session location permanently
- IP-based approximate location may be used server-side as a fallback for Near Me - this is not stored beyond the request
2.4 Technical & Usage Data
- IP address (held in server logs for up to 30 days for security purposes)
- Browser type and version
- Device type and operating system
- Pages viewed and features used
- Timestamps of logins and key actions
- Error reports and diagnostic data
3. Data We Do Not Collect
3/15We are committed to data minimisation. We do not collect:
- Financial or payment card information
- Health or biometric data
- Government ID numbers beyond what is necessary for artist verification
- Your contacts, calendar, or other device data
- Precise GPS location without your explicit, per-request consent
- Data from children under 13 - if we become aware a user is under 13, we will delete their account
4. How We Use Your Data
4/15We use your personal data only for the purposes described below and will not repurpose it without notifying you and, where required, obtaining fresh consent.
- To create and manage your account and profile
- To deliver and personalise the core Service features (feed, fandoms, messaging)
- To verify artist accounts and prevent impersonation
- To send transactional emails: email verification, password reset, and important account notices
- To detect, investigate, and prevent abuse, fraud, and security incidents
- To comply with legal obligations including law enforcement requests made in accordance with UK law
- To improve the platform through anonymised or aggregated analytics (only with your consent)
We do not use your data for automated decision-making or profiling that has legal or similarly significant effects on you.
5. Third-Party Services & Data Sharing
5/155.1 Services We Use
- Cloudflare R2 (media storage) - your uploaded images and files are stored on Cloudflare's infrastructure. Cloudflare acts as a processor under our instruction.
- Resend (transactional email) - your email address is shared with Resend only to deliver emails you trigger (e.g. verification, password reset). Resend does not use your data for their own marketing.
- Google Maps & Geocoding API (events and location features) - when you use map or location features, your browser communicates with Google's servers. Google's Privacy Policy applies to that data.
- ipapi.co (IP geolocation, fallback) - your IP address is sent to ipapi.co server-side when the Near Me fallback is used. No persistent storage occurs.
- Neon (PostgreSQL database hosting) - your data is stored in Neon's hosted database infrastructure within the EU/UK. Neon acts as a data processor.
5.2 What We Do Not Do
- We do not sell your personal data to any third party
- We do not share your data with advertisers
- We do not allow third parties to use your data for their own independent purposes
- We do not transfer your data outside the UK/EEA without appropriate safeguards such as Standard Contractual Clauses
6. Publicly Visible Data
6/15The following information is visible to all users of the platform, including unauthenticated visitors:
- Your username and display name
- Your profile photo and biography
- Posts, comments, and reactions you make
- Fandoms you have created
- Social media links you choose to add
- Your verified artist status (if applicable)
- Approximate location of a post, if you explicitly tagged it
The following information is never publicly exposed:
- Your email address
- Your phone number
- Precise GPS coordinates of posts (exact coordinates are never returned to other users in API responses)
- Your private messages
- Your password or any authentication tokens
- Your IP address
- Artist verification documents
7. Location Data
7/15Location features are entirely optional. We obtain your explicit consent before accessing location in any form.
- Post tagging: if you tag a post with a location, the approximate area (not precise coordinates) is displayed to other users. Precise coordinates are stored server-side only for the Near Me distance calculation and are never returned to other clients.
- Near Me: your location is used only for the current session to filter posts within your chosen radius. It is not stored beyond the request.
- IP fallback: a city-level estimate from your IP address may be used as a fallback for Near Me - this is not stored beyond the request.
You can revoke location permission at any time through your browser settings. Previously tagged posts can be deleted from your profile.
9. Data Retention
9/15We retain your personal data only for as long as necessary for the purposes described in this policy, or as required by law.
- Account data: retained for the duration of your account plus 30 days after deletion to allow recovery
- Posts and comments: deleted immediately when you delete them; copies may remain in backups for up to 90 days
- Messages: retained until you or the other participant deletes the conversation
- Security logs (IP, login timestamps): retained for up to 12 months for fraud and security purposes
- Artist verification documents: retained for up to 2 years after verification decision, then securely destroyed
- Email and server logs: retained for up to 30 days
- Backups: retained for up to 90 days in encrypted form
10. Your Rights Under UK GDPR
10/15As a data subject under UK GDPR and the Data Protection Act 2018, you have the following rights:
- Right of access: you can request a copy of all personal data we hold about you (available via Settings > Export my data)
- Right to rectification: you can correct inaccurate data at any time through your profile settings
- Right to erasure ('right to be forgotten'): you can request deletion of your account and all associated data through Settings > Delete account
- Right to restriction: you can request that we restrict processing of your data in certain circumstances
- Right to data portability: you can download your data in a machine-readable format via Settings > Export my data
- Right to object: you can object to processing based on legitimate interests
- Rights related to automated decision-making: we do not use your data for solely automated decisions with significant effects
- Right to withdraw consent: where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of prior processing
To exercise any of these rights, contact us via the details in Section 14. We will respond within one calendar month as required by UK GDPR. If you are unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
11. Children's Privacy
11/15Our Service is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13.
If you are a parent or guardian and believe that your child has provided us with personal data without your consent, please contact us immediately. We will take steps to delete such data promptly.
Users between the ages of 13 and 17 may use the Service with parental consent. We encourage parents to monitor their children's online activity.
12. Security Measures
12/15We implement industry-standard technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction.
- Passwords are hashed using a strong cryptographic algorithm (Argon2) - we never store plain-text passwords
- All data in transit is protected with TLS encryption
- Database access is restricted to authorised server-side code only
- Authentication tokens are signed and time-limited
- Admin access is separately controlled and logged
- Regular security reviews and dependency audits
Despite our best efforts, no security measure is perfect. In the event of a data breach that is likely to result in a high risk to your rights and freedoms, we will notify you and the ICO within 72 hours as required by UK GDPR.
13. Changes to This Policy
13/15We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make significant changes, we will:
- Update the Last updated date at the top of this page
- Display a prominent notice within the platform
- Send an email notification to your registered email address
Your continued use of the platform after changes take effect constitutes acceptance of the revised policy. If you do not agree to the updated policy, you must stop using the Service and may request account deletion.
14. Contact & Data Protection Officer
14/15For all privacy-related enquiries, rights requests, or complaints, please contact us through the platform's support system or the email address on our website.
You can also contact our Data Protection Officer (DPO) directly via the same channels, clearly marking your message as 'For the attention of the DPO'.
We aim to respond to all requests within 30 days. For complex requests, we may extend this period by a further two months, in which case we will inform you within the first 30 days.
If you are not satisfied with our response, or believe we are processing your data unlawfully, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- ICO website: ico.org.uk
- ICO helpline: 0303 123 1113
- ICO postal address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
15. International Transfers
15/15We primarily store and process your data within the UK and European Economic Area (EEA). Where we use third-party service providers located outside the UK/EEA, we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses (SCCs) approved by the UK ICO
- Adequacy decisions recognising equivalent data protection standards
- Binding Corporate Rules where applicable
A list of the countries where our processors operate is available on request.
Information Commissioner's Office (ICO)
You have the right to lodge a complaint with the ICO if you believe we are not handling your data lawfully. ico.org.uk · 0303 123 1113
Questions about your privacy?
Contact us or our DPO through the platform. We respond within 30 days as required by UK GDPR.
This policy was last updated on 22 September 2026. It is governed by the laws of England and Wales.