Privacy Policy

Last updated: June 08, 2026

This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.

We use Your Personal Data to provide and improve the Service. By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy.

As a Canadian operator, Our privacy practices are governed by the Personal Information Protection and Electronic Documents Act (PIPEDA) at the federal level and the British Columbia Personal Information Protection Act (PIPA) at the provincial level. These laws govern how We collect, use, and disclose personal information in the course of providing the Service.

Interpretation and Definitions

Interpretation

The words whose initial letters are capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.

Definitions

For the purposes of this Privacy Policy:

Account means a unique account created for You to access our Service or parts of our Service.

Affiliate means an entity that controls, is controlled by, or is under common control with a party, where "control" means ownership of 50% or more of the shares, equity interest or other securities entitled to vote for election of directors or other managing authority.

Company (referred to as either "the Company", "We", "Us" or "Our" in this Privacy Policy) refers to Grooveprint.

Cookies are small files that are placed on Your computer, mobile device or any other device by a website, containing the details of Your browsing history on that website among its many uses.

Country refers to: British Columbia, Canada.

Device means any device that can access the Service such as a computer, a cell phone or a digital tablet.

Personal Data (or "Personal Information") is any information that relates to an identified or identifiable individual. We use "Personal Data" and "Personal Information" interchangeably unless a law uses a specific term.

Service refers to the Website.

Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service or to assist the Company in analyzing how the Service is used.

Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).

Website refers to Grooveprint, accessible from https://grooveprint.app.

You means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.

Collecting and Using Your Personal Data

Types of Data Collected

Personal Data

While using Our Service, We may ask You to provide Us with certain personally identifiable information that can be used to contact or identify You. Personally identifiable information may include, but is not limited to:

  • Email address
  • Profile information (username, bio, and profile picture sourced from Google or Spotify)

Spotify Data

When You connect Your Spotify account, We access and store Your liked songs and associated artist data via the Spotify Web API. This data is used solely to match Your music library against our concert database. We store Your liked song data on an ongoing basis to provide the Service. We also store Spotify OAuth tokens (access and refresh tokens) securely to maintain Your Spotify connection. We do not access Your Spotify account for any other purpose. Your use of Spotify is also governed by Spotify's own Terms of Service and Privacy Policy.

Concert History Data

We store the concert history You build on the Service, including shows You have added, skipped, or reviewed. This data is associated with Your account and is used to display Your personal concert history and enable social features.

Social Data

If You use social features, We store Your friends list and friendship connections. Your profile information (username, bio, and concert history) may be visible to other users of the Service depending on Your profile visibility settings. You can control Your profile visibility in the Settings page.

Usage Data

Usage Data is collected automatically when using the Service.

Usage Data may include information such as Your Device's Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that You visit, the time and date of Your visit, the time spent on those pages, unique device identifiers and other diagnostic data.

When You access the Service by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device You use, Your mobile device's unique ID, the IP address of Your mobile device, Your mobile operating system, the type of mobile Internet browser You use, unique device identifiers and other diagnostic data.

Use of Your Personal Data

The Company may use Personal Data for the following purposes:

To provide and maintain our Service, including to monitor the usage of our Service.

To manage Your Account: to manage Your registration as a user of the Service. The Personal Data You provide can give You access to different functionalities of the Service that are available to You as a registered user.

To contact You: To contact You by email or other equivalent forms of electronic communication regarding updates or informative communications related to the functionalities or security of the Service.

To manage Your requests: To attend and manage Your requests to Us.

For business transfers: We may use Your Personal Data to evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of Our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which Personal Data held by Us about our Service users is among the assets transferred.

For other purposes: We may use Your information for other purposes, such as data analysis, identifying usage trends, and to evaluate and improve our Service, products, and your experience.

We may share Your Personal Data in the following situations:

With Service Providers: We may share Your Personal Data with Service Providers to monitor and analyze the use of our Service.

For business transfers: We may share or transfer Your Personal Data in connection with, or during negotiations of, any merger, sale of Company assets, financing, or acquisition of all or a portion of Our business to another company.

With Affiliates: We may share Your Personal Data with Our affiliates, in which case we will require those affiliates to honor this Privacy Policy.

With other users: When You share Personal Data or otherwise interact in the public areas with other users, such information may be viewed by all users and may be publicly distributed outside.

With Your consent: We may disclose Your Personal Data for any other purpose with Your consent.

Retention of Your Personal Data

The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use Your Personal Data to the extent necessary to comply with our legal obligations, resolve disputes, and enforce our legal agreements and policies.

We apply different retention periods to different categories of Personal Data based on the purpose of processing and legal obligations:

Account Information

Account and profile data (including Your email address, username, bio, concert history, Spotify library data, and friendship connections) is retained for the duration of Your account. Upon account deletion, this data is removed from Our active systems within 30 days. Residual copies in encrypted backups are permanently purged within 90 days of deletion.

Usage Data

Web performance and analytics data collected by Vercel (including IP addresses, page visit duration, and device identifiers) is retained in accordance with Vercel's data retention policies. Server-level access logs are retained for up to 90 days for security monitoring and troubleshooting.

We may retain Personal Data beyond the periods stated above where:

  • We are required by law to retain specific data.
  • Data is necessary to establish, exercise, or defend legal claims.
  • You ask Us to retain specific information.
  • Data exists in backup systems scheduled for routine deletion.

Transfer of Your Personal Data

Your information, including Personal Data, is processed at the Company's operating offices and in any other places where the parties involved in the processing are located. This information may be transferred to — and maintained on — computers located outside of Your state, province, country or other governmental jurisdiction where data protection laws may differ from those of Your jurisdiction.

The Company will take all steps reasonably necessary to ensure that Your data is treated securely and in accordance with this Privacy Policy and no transfer of Your Personal Data will take place to an organization or a country unless there are adequate controls in place.

The Service is operated from British Columbia, Canada. If You access the Service from outside Canada, You do so at Your own discretion and are responsible for compliance with any applicable local laws. The collection, use, and disclosure of Your Personal Data is governed by the laws of British Columbia and applicable Canadian federal law regardless of where You are located.

Your Privacy Rights

Under PIPEDA and BC's PIPA, You have the following rights with respect to Your Personal Data. We will respond to all privacy requests within 30 days of receipt.

Right of Access: You have the right to request a copy of the Personal Data We hold about You and to be informed of how it is used and disclosed. To request access, contact Us at artur@grooveprint.app.

Right to Correct: You have the right to request correction of inaccurate or incomplete Personal Data. You may update most account information directly in the Settings page. For other corrections, contact Us.

Right to Data Portability: You have the right to request an export of Your Personal Data in a structured, commonly used format. This includes Your concert history, profile information, and associated account data. To request a data export, contact Us at artur@grooveprint.app.

Right to Delete: You may delete Your account and all associated Personal Data at any time via the Delete Account option in the Settings page. Account deletion is permanent and cannot be undone. Upon deletion, Your data is removed from active systems within 30 days and purged from encrypted backups within 90 days.

Please note that We may need to retain certain information where We have a legal obligation or lawful basis to do so.

Disclosure of Your Personal Data

Business Transactions

If the Company is involved in a merger, acquisition or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred and becomes subject to a different Privacy Policy.

Law Enforcement

Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).

Other Legal Requirements

The Company may disclose Your Personal Data in the good faith belief that such action is necessary to:

  • Comply with a legal obligation
  • Protect and defend the rights or property of the Company
  • Prevent or investigate possible wrongdoing in connection with the Service
  • Protect the personal safety of users of the Service or the public
  • Protect against legal liability

Security of Your Personal Data

The security of Your Personal Data is important to Us, but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While We strive to use commercially reasonable means to protect Your Personal Data, We cannot guarantee its absolute security.

Children's Privacy

Our Service does not address anyone under the age of 16. We do not knowingly collect personally identifiable information from anyone under the age of 16. If You are a parent or guardian and You are aware that Your child has provided Us with Personal Data, please contact Us. If We become aware that We have collected Personal Data from anyone under the age of 16 without verification of parental consent, We take steps to remove that information from Our servers.

Links to Other Websites

Our Service may contain links to other websites that are not operated by Us. If You click on a third party link, You will be directed to that third party's site. We strongly advise You to review the Privacy Policy of every site You visit. We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.

Changes to this Privacy Policy

We may update Our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date at the top. You are advised to review this Privacy Policy periodically for any changes.

Third-Party Data Sources

Concert data on the Service is sourced from setlist.fm and is used under the Creative Commons CC BY-NC-SA 4.0 licence.

User authentication is provided via Google OAuth. When You sign in with Google, We receive Your email address from Google to create and manage Your account.

Your Personal Data is stored by Supabase, Inc., a third-party data hosting provider with servers located in the United States. By using the Service, You consent to the transfer of Your data to the United States for storage and processing.

The Service is hosted and delivered via Vercel, Inc., a web infrastructure provider with servers located in the United States. Vercel processes network request data, including IP addresses and performance metrics, as part of serving the Service to You. Vercel's privacy practices are described in Vercel's own Privacy Policy.

Transactional Communications

We may send transactional emails related to Your account, such as authentication confirmations and security notifications. We do not send marketing emails and You will not be subscribed to any mailing list by using the Service.

Cookies

We use only essential session cookies required for authentication and to keep You signed in to the Service. We do not use analytics, advertising, remarketing, or tracking cookies. You may disable cookies in Your browser settings, but doing so may prevent You from signing in to the Service.

Data Breach Notification

In the event of a data breach that poses a real risk of significant harm to You, We will notify You and the Office of the Privacy Commissioner of Canada as required under PIPEDA. Notification will be made without unreasonable delay and will describe the nature of the breach, the Personal Data involved, the steps We have taken to mitigate the harm, and the steps You can take to protect Yourself.

We maintain a record of all data breaches, including those that do not meet the threshold for notification, as required by law.

Contact Us

If you have any questions about this Privacy Policy, You can contact us by email at artur@grooveprint.app.