This document is a draft. Highlighted values are not yet filled in.
This Privacy Policy explains how MySetlist ("we", "us") collects, uses and protects your personal data when you use mysetlist.app (the "Service"), including the website, the web application, the MySetlist Desktop Audio Bridge, and the MySetlist Song Sections Exporter device for Ableton Live. A note on the Song Sections Exporter. This is a Max for Live device that runs entirely inside Ableton Live on your own computer. It reads your arrangement and writes a JSON file to your local disk. It does not connect to our servers, does not send us any data, and does not require an account. We receive nothing from it unless you choose to upload the exported file to your MySetlist account yourself. We are the data controller for this processing under the General Data Protection Regulation (GDPR). Contact details
We are not required to appoint a Data Protection Officer. For any privacy question, use the email address above.
When you create an account we process your email address, your password (stored only as a salted hash — we never see it), your display name, and an optional profile picture. MySetlist accounts use email and password only. We do not offer sign-in through Facebook, Google, Apple or any other social or identity provider, so no data about you is exchanged with those companies when you register or log in.
If you take a paid plan we process your plan type, subscription status, billing period and invoice history. Payments themselves are handled by Stripe. We never receive or store your full card number. For invoicing and EU VAT purposes we (or Stripe on our behalf) process your name, billing address, country and, where applicable, VAT number.
The Service is built to store the material you put into it: artist and band profiles, setlists, songs, audio stems, sheet music, lyrics, notes, song section data and any images you upload. You can also record rights and copyright information alongside your songs — for example composer and lyricist credits, publisher, rights holder, PRO or collecting society affiliation, ISRC or ISWC codes, and licensing notes. This information often names real people, so it counts as personal data where those people are identifiable. You are responsible for having a proper basis to record details about third parties such as co-writers, and for keeping that information accurate. Content you upload may contain personal data in other ways too — band member names, or a photograph. You decide what you upload. Your content is private to your account and the accounts you explicitly grant access to. We do not use your audio, sheet music or setlists to train machine learning models, and we do not sell or license it.
When you use the Service we automatically process your IP address, browser type and version, operating system, device type, timestamps of requests, pages and features used, and error and diagnostic logs. Our hosting provider and Cloudflare also log this data for security and abuse prevention.
If you email us or submit a support request, we process the content of that message and any attachments you send.
Purpose Legal basis (GDPR Art. 6)
Creating and managing your account; Performance of a contract (Art. 6(1)(b)) providing the Service
Storing, streaming and syncing your Performance of a contract (Art. 6(1)(b)) content
Processing payments, subscriptions and Performance of a contract (Art. 6(1)(b)) and legal invoices obligation (Art. 6(1)(c))
Retaining invoices and tax records Legal obligation — Dutch tax law (Art. 6(1)(c))
Service, security and outage emails Performance of a contract (Art. 6(1)(b))
Securing the Service, preventing abuse Legitimate interests (Art. 6(1)(f)) — keeping the and fraud, debugging Service available and secure
Handling support requests Performance of a contract / legitimate interests (Art.
Aggregated, cookieless website statistics Legitimate interests (Art. 6(1)(f)) — understanding
Marketing emails to people who are not Your consent (Art. 6(1)(a)) customers
Where we rely on consent, you can withdraw it at any time. Withdrawal does not affect processing that took place before you withdrew.
We do not use advertising, tracking or profiling cookies. We do not use the Facebook (Meta) Pixel, Google Analytics, or any other cross-site advertising technology. We do not build advertising profiles and we do not track you across other websites. The only cookies and browser storage we use are strictly necessary for the Service to function. Under Article 11.7a(3) of the Dutch Telecommunications Act these are exempt from the consent requirement, which is why you will not see a cookie banner.
Name / purpose Set by What it does Retention
Authentication MySetlist Keeps you logged in Session / until session (Supabase) logout or
Security token MySetlist Protects against cross-site request Session
Player and interface MySetlist Remembers volume, mute/solo, active Local storage, state artist, and which browser tab is until cleared
__cf_bm Cloudflare Distinguishes real visitors from bots; 30 minutes
cf_clearance Cloudflare Records that a security challenge was Up to 1 year
__stripe_mid , Stripe Fraud detection during payment. Only 1 year / 30 __stripe_sid set on our billing and checkout pages, minutes
None of these are used for advertising or to profile you. You can clear this data at any time through your browser settings. If you do, you will be logged out and your player preferences will reset. Website statistics [We use [PLAUSIBLE / UMAMI] to understand how many people visit the site and which pages they use. It is privacy-friendly and cookieless: it sets no cookies, does not use browser fingerprinting, does not track you across sites, and does not store your IP address. All statistics are aggregated and cannot be traced back to an individual visitor.] (Delete this section if analytics are not yet deployed.)
We do not sell your personal data. We do not share it with advertisers, data brokers, or any third party for their own marketing purposes. We do use a small number of service providers ("processors") to run the Service. They act only on our instructions and are bound by data processing agreements. They may not use your data for their own purposes.
Provider Role Location
Supabase Authentication and user account database [EU region — CONFIRM YOUR
Cloudflare CDN, DNS, DDoS protection, and R2 Global CDN; R2 bucket in
TransIP Server hosting (VPS) The Netherlands
Stripe Payment processing, subscription billing, Ireland / United States
[EMAIL Transactional email (confirmations, [REGION] PROVIDER] password resets)
We may also disclose personal data where we are legally required to do so — for example in response to a valid order from a competent authority — or where necessary to establish, exercise or defend legal claims. If MySetlist is sold or merged, your data may transfer to the acquiring party. We will notify you before that happens and you will be able to delete your account first.
Our servers and primary storage are in the European Union. Some providers listed above (Stripe, Cloudflare) may process data outside the EEA, including in the United States. Where that happens, the transfer is covered by the European Commission's Standard Contractual Clauses, and — for providers certified under it — the EU-US Data Privacy Framework, together with additional technical measures such as encryption in transit and at rest. You can request a copy of the relevant safeguards from us at the address in §12.
Data Retention
Account data For as long as your account is active
Uploaded content (stems, setlists, sheet Until you delete it, or 30 days after account deletion music)
Backups Rolling backups retained for [30] days, then
Invoices and tax records 7 years (Dutch Tax Administration requirement)
Server and security logs [90] days
Support correspondence 2 years after the request is closed
When you delete your account, we delete your account data and content from our active systems within 30 days. Data in encrypted backups is removed as those backups rotate out.
We protect your data with encryption in transit (TLS) and at rest, hashed passwords, access controls limiting who can reach production systems, signed and time-limited URLs for audio file access, and regular patching of our servers and dependencies. No system is perfectly secure. If a data breach occurs that is likely to result in a high risk to your rights and freedoms, we will notify you and the Dutch Data Protection Authority as required by Articles 33 and 34 GDPR.
Under the GDPR you have the right to:
You can exercise most of these directly in your account settings, including exporting your setlists and content and deleting your account. For anything else, email us at [PRIVACY@MYSETLIST.APP]. We respond within one month, and will tell you if we need to extend that in a complex case. If you are not satisfied with our response, you can complain to the Dutch Data Protection Authority: Autoriteit Persoonsgegevens Postbus 93374, 2509 AJ Den Haag https://www.autoriteitpersoonsgegevens.nl If you live in another EU country, you may also complain to your local supervisory authority.
We do not use automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you.
The Service is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
We may update this Privacy Policy as the Service changes. The date at the top shows when it was last revised. If we make material changes, we will notify you by email or through a notice in the app before those changes take effect.
Questions about this policy or about your data: [LEGAL ENTITY NAME] [STREET ADDRESS] [POSTCODE] [CITY], The Netherlands Email: [PRIVACY@MYSETLIST.APP] KvK: [KVK NUMBER]