Last updated: July 9, 2026
Account data (name, email, hashed password), the content you upload (statements, artwork, documents), campaign analytics (link clicks, referrers), and — when you connect them — data from services you authorize, like Spotify artist stats.
When a fan subscribes on your campaign pages, we store their email with a consent record, on your behalf. Artists control this data; we process it. Spotify pre-save is not connected on this deployment: pre-save buttons collect a notify-me address instead, and no Spotify token is requested, stored or processed.
We don't sell personal data. We don't use your uploads to train AI models. We don't read fan tokens for anything beyond the save and the consented email.
We use Render (hosting), Resend (email delivery), and public music APIs (Spotify, Deezer, iTunes, Odesli, MusicBrainz, Bandsintown) to provide features you invoke. Each receives only what's needed for that feature.
We use a single session cookie to keep you signed in. No advertising trackers.
Your data stays while your account is active. Ask us to delete your account and we remove your data within 30 days, except records we must keep by law.
Depending on where you live (GDPR, CCPA), you can request access, correction, export, or deletion of your personal data — email us and we'll handle it.
Passwords are hashed, fan tokens are encrypted, and data lives on access-controlled infrastructure. No system is perfect; we'll notify affected users of any breach as required by law.
Privacy questions and requests: team.summitarts@gmail.com.