# Soundportal — Privacy Policy

**Last updated: June 2026**
**Status: Beta / Free Service**

---

## 1. What Data We Collect

### Account Creation
- **Email address** (via Google OAuth)
- **Full name** (from Google profile)
- **Username** (you create, publicly visible)
- **Role** (Label Owner, A&R Manager, or Producer)

### Portal & Submission Data
- **Portal information:** name, description, genres, submission settings
- **Track metadata:** artist name, track title, BPM, genres, submission type
- **SoundCloud URLs** (links to external tracks, not files)
- **Producer contact:** email, username
- **Access logs:** who viewed which portal, when

### Technical Data
- **IP address** (for security, stored briefly)
- **Device info** (browser type, OS)
- **Login history** (timestamps, authentication method)
- **SoundCloud player analytics** (SoundCloud's data, not ours)

---

## 2. How We Use Your Data

✅ **To operate Soundportal:**
- Create and manage your account
- Show submissions to the right people
- Notify label owners of new tracks
- Enable private portal access

✅ **For security & legal compliance:**
- Detect unauthorized access
- Respond to copyright/DMCA claims
- Comply with Dutch/EU law
- Prevent abuse and fraud

✅ **NOT for:**
- ❌ Selling to third parties
- ❌ Marketing emails (unless you opt-in)
- ❌ Building ML models on your data
- ❌ Sharing with advertisers

---

## 3. Who We Share Data With

**Supabase (Data Processor):**
- Hosts our database (Ireland/EU)
- Encrypted in transit and at rest
- Signed Data Processing Agreement

**Google (OAuth Provider):**
- Verifies your identity only
- Doesn't share login with us beyond email

**No one else** gets your data unless:
- You publicly share your portal (producer sees label info)
- Legal requirement (court order, GDPR request)
- Copyright claim (we share contact info with claimant)

---

## 4. How Long We Keep Data

- **Active accounts:** kept as long as you use Soundportal
- **Deleted accounts:** anonymized after 30 days
- **Deleted portals/submissions:** archived for 90 days (legal/DMCA), then deleted
- **Login history:** 90 days
- **IP logs:** 30 days

---

## 5. Your Rights (GDPR/AVG)

You can request anytime:
- ✅ **Access:** Export all your data
- ✅ **Deletion:** Remove your account completely
- ✅ **Correction:** Fix wrong info
- ✅ **Portability:** Get data in machine-readable format

**Email:** mickstots@gmail.com with subject "Data Request"
**Response time:** 30 days maximum

---

## 6. Security Measures

We implement:
- ✅ SSL/TLS encryption (all traffic)
- ✅ OAuth 2.0 authentication (no passwords stored)
- ✅ Row-level security (users see only their own data)
- ✅ Secure Supabase (enterprise-grade)
- ✅ No public databases
- ✅ Regular security audits

**But:** No system is 100% secure. See Terms of Service for liability limits.

---

## 7. Cookies & Tracking

**Session cookies only:**
- `sb-session` = Supabase authentication token
- `sb-refresh-token` = Keep you logged in
- Deleted when you log out

**No tracking cookies:**
- ❌ No Google Analytics
- ❌ No behavioral tracking
- ❌ No retargeting ads

**SoundCloud player:**
- SoundCloud sets own cookies (see SoundCloud privacy policy)

---

## 8. Beta Service Notice

Soundportal is **beta software**. This means:
- Data retention policies may change
- We may modify how we store/process data
- We'll notify you of major changes
- Privacy practices will evolve

---

## 9. Changes to This Policy

We may update this anytime. We'll notify you of major changes via email.

---

## 10. Contact

**Data Protection Officer / Privacy Questions:**
- Email: mickstots@gmail.com
- Subject: "Privacy Question"

**Dutch Authority:**
- Autoriteit Persoonsgegevens (AP)
- https://www.autoriteitpersoonsgegevens.nl

---

**Last updated: June 2026**
