Privacy policy
Bandfolk depends on you posting video in which you are visible and audible. In practice that is sensitive material, even where the law does not classify it as a special category, so this policy is written to be understood rather than to be exhaustive.
1. Who is responsible for your data
The controller of your personal data in Bandfolk is:
IT GUY IO LLC1309 Coffeen Avenue STE 1200
Sheridan, Wyoming 82801
United States
IT GUY IO LLC is a company registered in the State of Wyoming in the United States. Its US federal Employer Identification Number (EIN) is 93-3223710. That is a United States tax identification number and is not equivalent to a European company registration number. Bandfolk is therefore not operated by a Nordic company, even though the service is aimed at musicians in the Nordics.
Contact for anything to do with personal data: support@it-guy.io.
2. Why the GDPR applies
Although we are established outside the EU, the General Data Protection Regulation applies to this processing in full. That follows from Article 3(2), because we deliberately offer the service to people in the EU and the EEA: we market in Swedish, Norwegian, Danish and Finnish, we price in Swedish kronor, and we address ourselves explicitly to musicians in the Nordics.
Representative in the Union under Article 27
Because we are established outside the EU and offer the service to people in the Union, we are required to designate a representative in the Union in writing. The representative's contact details are:
Tom Shibolli GreschlerÅsögatan 44
Stockholm
Sweden
support@it-guy.io
You can address the representative on any question about our processing of your personal data, and supervisory authorities may address the representative instead of us. The representative does not replace us as controller: you are equally welcome to write to us directly at support@it-guy.io, and you can always go to the supervisory authority in your own country as described in section 10.
3. What data we process
- Account data
- Your email address and the user identifier created when you sign in. Authentication is handled by Supabase Auth, with Google and Apple as the identity providers. We therefore handle no passwords at all: you prove who you are to Google or to Apple, and we receive an identifier and an email address back. If you use Apple's option to hide your email address, the address we hold is an Apple relay address rather than your real one, and anything we send you travels through Apple's relay.
- Profile data
- Your name or stage name, instruments, genres, city or region, level of experience, and any free text you write. You choose all of it and can change or remove it at any time.
- Video and audio
- The clips you upload, including picture and sound in which you are normally identifiable. A clip may also contain other people if you record with someone, and in that case it is your responsibility that they agreed to it. See the terms of service.
- Usage data
- Which profiles you showed interest in or swiped past, which matches came out of it, and when you were last active. This is what makes matching work and stops the same profile appearing over and over.
- Subscription data
- Whether you have an active subscription, when it renews and which store it came from. We do not take your payment and never see your card number. That stays with Apple and Google.
- Technical data
- Device type, operating system version, app version, IP address and technical logs. This is generated automatically when the app talks to our servers.
We do not use facial recognition. We do not analyse your clips biometrically, we build no face templates, and we do not use them to identify you or anyone else. The clips are shown to other users, and that is all.
We do not ask you for data that counts as a special category under Article 9 of the GDPR, such as health, ethnic origin or religious belief. A video can of course still reveal things like that about you. That is precisely why you decide what you post, and you can delete a clip whenever you want.
4. Why we process it, and on what legal basis
- To provide the service (Article 6(1)(b), contract)
- Creating and running your account, showing your profile and clips to other users, recording your swipes, creating matches, and granting access based on your subscription.
- For safety and to prevent abuse (Article 6(1)(f), legitimate interests)
- Detecting and stopping fraud, spam, harassment and account takeover, handling reports of objectionable content, and keeping technical logs. Our legitimate interest is keeping the service safe and usable, and we consider that it does not override your rights because the data involved is limited and kept briefly.
- To improve the service (Article 6(1)(f), legitimate interests)
- Understanding which features are used and where the app crashes, in aggregate. We do not sell data and we do not run advertising profiling.
- Where you have consented (Article 6(1)(a))
- Access to your device camera and microphone, and push notifications. You can withdraw consent at any time in your device settings, without affecting what has already been processed.
- To comply with the law (Article 6(1)(c))
- Responding to legitimate requests from authorities and meeting obligations that apply to us.
5. Where your data is stored and who we share it with
We never sell your personal data and we do not pass it to advertising networks. A small number of recipients do receive data. Some of them process it on our behalf as processors, others are independent controllers for their own part of the processing. We spell out which is which:
- Supabase
- Database and authentication, acting as our processor. Account data, profiles, swipes and matches are stored here. Sign-in runs through Supabase Auth, which also handles the connection to Google and Apple when you sign in with either of them. The project sits in an EU region, so the data is on servers inside the EU.
- Cloudflare R2
- Storage and delivery of your video clips. Clips are stored in an EU region.
- RevenueCat
- Manages subscription status against the stores so the app knows whether you have access. RevenueCat is a United States company and part of that processing takes place in the US. We send a user identifier and subscription status, not your clips.
- Google and Apple, as sign-in identity providers
- Bandfolk offers sign-in with Google and sign-in with Apple, and no other way in. Choose Google and Google learns that you are signing in to Bandfolk; choose Apple and Apple learns the same. Each of them then passes us a user identifier and an email address, and your password stays with them. Personal data moves in both directions, and Google and Apple are independent controllers for what happens inside their own systems under their own privacy policies. Both are United States companies, so that part of the processing takes place partly in the US. Apple's hide my email feature means the address we receive may be an Apple relay address rather than your real one.
- Apple App Store and Google Play
- They sell the subscription, take the payment and handle receipts and refunds. They are independent controllers for their own processing of you as their customer, and their own privacy policies govern that part.
Other users see your profile and your clips. That is the entire point of the service, but it also means you should only post things you are comfortable with a musician you have never met watching.
We may also disclose data where we are legally required to, or where it is necessary to establish, exercise or defend legal claims.
6. International transfers
The data is stored in the EU, but it is accessible to us as controller in the United States. In practice that means personal data can be transferred to, or read from, the US, a country outside the EU and the EEA. We would rather say so plainly than describe the storage location and stay quiet about the access.
The safeguard we rely on for those transfers is:
[TRANSFER MECHANISM: STANDARD CONTRACTUAL CLAUSES NOT YET IN PLACE]
For as long as the field above is not filled in, that mechanism is not formally in place. We would rather claim too little here than too much. If you want to know exactly where this stands at the time you are reading, email support@it-guy.io and we will answer straight.
7. How long we keep your data
- Account, profile and video clips
- For as long as you have an account. When you delete it, the data is removed on the timetable set out on the delete account and data page.
- Backups
- Deleted data can remain in encrypted backups for up to 90 days before those backups are overwritten. They are used for nothing other than disaster recovery.
- Technical and security logs
- No longer than 12 months.
- Reports of objectionable content and moderation decisions
- Up to 24 months after the decision, so that we can show how a report was handled, deal with an appeal against it and defend legal claims.
- Support correspondence
- Up to 24 months after the case is closed.
8. Your rights under the GDPR
You have the following rights, and exercising them is free:
- Access. Find out whether we process data about you and get a copy of it (Article 15).
- Rectification. Have inaccurate data corrected and incomplete data completed (Article 16).
- Erasure. Have your data deleted, often called the right to be forgotten (Article 17). See delete account and data.
- Restriction. Ask us to restrict processing while, for example, an objection is being looked into (Article 18).
- Portability. Receive the data you gave us in a structured, commonly used, machine-readable format, and have it transmitted to someone else where that is technically feasible (Article 20).
- Objection. Object to processing based on legitimate interests, on grounds relating to your particular situation (Article 21).
- Withdraw consent. Withdraw a consent at any time, without affecting the lawfulness of processing before you did (Article 7(3)).
- Automated decision-making. We make no decisions about you based solely on automated processing that produce legal effects for you (Article 22).
Send your request to support@it-guy.io. We respond within one month. If the request is complex we may extend that by two further months, and if so we will tell you why within the first month. We may need you to confirm your identity, for example by writing from the address the account is registered to, so that we do not hand your data to the wrong person.
9. Children
Bandfolk is a service for working musicians and is intended for people aged 18 or over. We do not knowingly collect data about children. If you believe a child has created an account, contact support@it-guy.io and we will remove it.
10. Your right to complain to a supervisory authority
If you think we are handling your personal data wrongly, we would like you to come to us first. But you always have the right to lodge a complaint with the data protection authority in the EU or EEA country where you live, where you work, or where you believe the infringement took place.
In Sweden that is Integritetsskyddsmyndigheten (IMY), imy.se. If you live elsewhere it is the authority there: Datatilsynet in Norway, Datatilsynet in Denmark, and Tietosuojavaltuutetun toimisto in Finland.
11. Cookies and this website
The bandfolk.art website sets no cookies, runs no analytics, loads no third-party fonts or scripts, and does not track you. It is a set of static pages. The ordinary server logs at our web host may contain your IP address for a short period, which is normal for all web traffic.
12. Changes to this policy
If we change this policy we update the date at the top. For material changes we will tell you in the app or by email before they take effect.
13. Contact
Data protection questions, requests and complaints: support@it-guy.io.
IT GUY IO LLC1309 Coffeen Avenue STE 1200
Sheridan, Wyoming 82801
United States
We have not appointed a data protection officer, because our processing does not meet the criteria in Article 37. These questions are handled directly by us at the address above.