We use essential cookies to keep the site running. Optional categories enable Spotify, SoundCloud, Mixcloud, hearthis.at and YouTube embeds, interactive maps by Mapbox, and error reports from your browser. Everything optional is off until you switch it on, and you can change your preferences at any time.
Last updated: August 6, 2026
We take the protection of your personal data seriously and handle it confidentially in accordance with applicable data protection laws and this privacy policy. Our website can generally be used without registering an account. However, certain features, in particular the creation of a user account, require the processing of personal data.
Names: Kenny Kunze-Oehme, Julia Weiske
Address: Wurzner Straße 9, 04315 Leipzig, Germany
Contact: info@artistspotter.com
When you access our website, technically necessary server log data is processed automatically and transmitted by your browser to the server. This includes, in particular:
01 Browser type and version
02 Operating system
03 Referrer URL
04 Host name of the accessing device
05 Date and time of the server request
06 Truncated IP address
This data is processed to ensure the secure and reliable operation of our website, to analyse errors and to improve our services. The data is not combined with other data sources. The legal basis for this processing is our legitimate interest pursuant to Art. 6(1)(f) GDPR.
These log data are automatically deleted by our service providers after a short period (currently: Vercel approx. 1 hour, Supabase approx. 1 day for API and database logs, and 1 hour for auth logs). These retention periods may change, for example if we switch to a different pricing plan with the respective providers.
Our website and the underlying application are operated with the support of external service providers that assist us with hosting, data storage and content delivery.
Vercel (Hosting). The provider is Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. Vercel provides the technical infrastructure for our website and processes technically necessary server log data (e.g. IP address, timestamp and requested URL). Vercel processes this data as our data processor pursuant to Art. 28 GDPR. The legal basis for this processing is our legitimate interest in the secure, reliable and high-performance provision of our online services pursuant to Art. 6(1)(f) GDPR. Personal data may be transferred to the United States. Vercel is certified under the EU-U.S. Data Privacy Framework.
Supabase (Database). The provider is Supabase, Inc., 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513. Account and profile data are stored and processed by Supabase as our data processor pursuant to Art. 28 GDPR in the region selected by us (Frankfurt am Main, Germany). The legal basis for this processing is Art. 6(1)(b) GDPR.
Sanity (Content Management). The provider is Sanity, Inc., 351 California Street, Suite 650, San Francisco, CA 94104, USA. We use Sanity to manage editorial content (e.g. blog posts). As a rule, no personal data of website visitors is processed through this service. Sanity acts as our data processor pursuant to Art. 28 GDPR. The legal basis for its use is our legitimate interest in efficient content management pursuant to Art. 6(1)(f) GDPR.
Analytics (Vercel Web Analytics & Speed Insights). We use Vercel Web Analytics and Vercel Speed Insights to analyse page views and loading times in aggregated form. Both services operate without the use of cookies. According to Vercel, no individual user identification or profiling takes place. The legal basis for this processing is our legitimate interest in ensuring and improving the technical operation of our website pursuant to Art. 6(1)(f) GDPR. According to Vercel, these services do not access information stored on users' devices within the meaning of Section 25 TDDDG, meaning that no consent is required.
So that we notice and fix technical faults, errors occurring on this website are reported automatically to an error diagnostics service. The provider is Functional Software, Inc. d/b/a Sentry, 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA. Sentry processes these data as a processor pursuant to Art. 28 GDPR. Processing takes place exclusively in the service's EU region, with its data centre in Frankfurt am Main, Germany.
What is reported. An error report contains the error description and the technical path through the program code (stack trace), the address of the page called, the request method, information about your browser and operating system, and the last steps before the error (such as page changes and network requests). From the address, we transmit only the route path, with artist usernames and collective or blog slugs replaced by placeholders, and a fixed list of non-sensitive parameters (genre, city, radius, page, language); all other parameters and the address fragment are replaced with "[Filtered]" before sending. We additionally strip email addresses and token-like strings from all text.
Signed-in users. If an error occurs on our server while you are signed in, your pseudonymous account identifier (a UUID) and your account role (artist, booker or collective) are attached to the report. This identifier allows us to contact you specifically about an error and to answer your requests under Art. 15 and Art. 17 GDPR for error reports as well. Errors that occur in your browser carry no account identifier.
What is explicitly not transmitted. We transmit no name, no email address, no IP address, no cookies, no request headers and no content you enter into forms — in particular no booking messages, reach-outs or reports. The website's console output is discarded entirely before sending. No session recording, performance tracing or profiling takes place.
No connection from your browser to Sentry. Error reports from the browser are sent to our own server and forwarded from there. Your browser establishes no connection to Sentry's servers; Sentry does not receive your IP address. In addition, we have enabled the setting in our account that prevents IP addresses from being stored.
Legal basis and consent. Errors occurring in your browser are reported only if you have switched on the “Error monitoring (Sentry)” category in the consent dialog. The legal basis is your consent under Art. 6(1)(a) GDPR. Until you consent, no error report leaves your browser; reports arising before your decision are discarded and not sent later. No information is stored on your device in the process and no information stored on it is accessed — in particular, no cookies are set.
Errors on our server. Errors occurring on our own server are reported regardless of your choice. Your device plays no part in them, so consent does not arise. The legal basis is our legitimate interest in a functioning and secure service under Art. 6(1)(f) GDPR (Recital 49). No usage profile is created, the data arises only when an error occurs, and what is transmitted is limited to what is technically necessary.
Withdrawal. You can withdraw your consent at any time with effect for the future by switching off the “Error monitoring (Sentry)” category under the “Cookie settings” link in the footer. That is the only route for it, and it takes effect immediately: from then on, no further error report leaves your browser. The lawfulness of processing carried out before withdrawal is unaffected.
Retention. Error reports are deleted automatically 30 days after they are received.
Right to object (server-side reports). You may object to the processing based on legitimate interest at any time on grounds relating to your particular situation (Art. 21(1) GDPR). There is no toggle for it, because that processing is not tied to your device. An informal message via our contact form or to the address given in the imprint is sufficient. Upon your objection, we delete the error reports attributable to your account and stop transmitting your account identifier in future.
Registration. When you create an Artist or Booker account, we process the information you provide (e.g. your name or artist name, email address, password, role, city, genres, links to streaming platforms, profile picture and biography) to the extent necessary to provide your account. Information you provide for your profile may be displayed on your public profile page. The legal basis for this processing is Art. 6(1)(b) GDPR.
Use of Profile Previews for Marketing Purposes. To promote our platform, we feature brief overview clips of the platform on our own social media channels (e.g., Instagram), in which profile previews of artists may be visible (e.g., profile picture, name or artist name, genre). This constitutes a cursory depiction of the platform interface rather than a targeted feature of individual artists. The legal basis is our legitimate interest in promoting our services under Art. 6(1)(f) GDPR. You have the right to object to this processing at any time for reasons arising from your particular situation (Art. 21(1) GDPR); to do so, please contact us informally at info@artistspotter.com.
Passwords and Authentication. Your password is never stored in plain text. Instead, it is stored as a secure hash using current industry standards. Authentication is provided through Supabase (Supabase, Inc.) acting as our data processor pursuant to Art. 28 GDPR. Your data is stored and processed by Supabase in the region selected by us (Frankfurt am Main, EU). We do not have access to your plain-text password.
We send emails to verify your email address and for security-related purposes (e.g. password resets). The legal basis for this processing is Art. 6(1)(b) GDPR.
Alternatively, you may sign in using Google or Apple. In this case, we do not receive your password, but only the profile information you authorize the respective provider to share for authentication purposes. The privacy policies of the respective provider also apply.
Login. Each time you sign in, we process your email address or user ID and the time of your login in order to authenticate your access and maintain your session using strictly necessary cookies and/or local storage. The legal basis for this processing is Art. 6(1)(b) and (f) GDPR as well as Section 25(2) No. 2 TDDDG.
Deletion. You may delete your account at any time via your dashboard. Your profile and associated profile data will be deleted or anonymized unless statutory retention obligations require otherwise.
You can view and edit your personal data at any time via your dashboard.
Several forms let you reach us or other members without holding an account: booking requests to artists, reach-outs to collectives, the general contact form, feedback, genre suggestions and the "Report a violation" form.
What data we process. Depending on the form, we process your name, your email address, a subject line and your message. The "Report a violation" form additionally processes the address (URL) of the reported content, a category and your description; giving your name is optional there, while we need your email address for follow-up questions. Mandatory fields are marked in each form.
Purposes and legal basis. We forward booking requests and collective reach-outs to the profile concerned and send you a confirmation; the legal basis is the performance of the service you requested pursuant to Art. 6(1)(b) GDPR. We also store booking requests and reach-outs in the inbox of the profile concerned so that the request can be handled there. Enquiries via the contact form, feedback and genre suggestions are processed to answer your request, on the basis of our legitimate interest in functioning communication pursuant to Art. 6(1)(f) GDPR. Reports submitted via the "Report a violation" form are processed so that we can review and, where appropriate, remove the reported content; the legal basis is our legitimate interest in a lawful platform pursuant to Art. 6(1)(f) GDPR.
Reports about third parties. A report inevitably also contains information about the reported person. We process this information solely in order to review the report. We inform the persons concerned in accordance with Art. 14 GDPR, insofar as this does not frustrate the review and no exemption applies. We do not disclose your identity as the reporting person on our own initiative.
Abuse prevention. All of the forms named above contain a field that is invisible to you (a honeypot) for spam protection. We also use your IP address — processed exclusively in hashed form — to check how many submissions originate from the same connection within 15 minutes (rate limit). We do not store your IP address itself; only a non-reversible hash value is stored. Blocked submissions are logged in the same non-reversible form so that we can detect patterns of abuse. The legal basis is our legitimate interest in forms that function and cannot be abused, pursuant to Art. 6(1)(f) GDPR.
Retention. Booking requests and reach-outs remain in the inbox of the profile concerned until that profile deletes them or the profile itself is deleted. Emails from the remaining forms are deleted once your request has been dealt with conclusively and no statutory retention obligations apply. Abuse-prevention logs are deleted after 90 days at the latest.
Delivery. All emails from these forms are sent via Resend — see the section "Email Delivery (Resend)".
You may alternatively sign in using "Sign in with Google" instead of creating an account manually. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google").
Data processing. When you click "Sign in with Google", your browser establishes a connection to Google's servers. If you choose to continue, we receive the profile information required for authentication via the OAuth authorization process, including your name, email address and profile picture, in order to create your account or sign you in. We have no control over Google's processing of your personal data.
Legal basis. The processing of the data provided by Google is carried out for the performance of the user agreement or to take steps prior to entering into a contract pursuant to Art. 6(1)(b) GDPR.
Transfer to third countries. Personal data may be transferred to the United States. Google LLC is certified under the EU-U.S. Data Privacy Framework (including the UK Extension and the Swiss-U.S. Data Privacy Framework). Where required, Google also relies on the European Commission's Standard Contractual Clauses.
For more information about how Google processes personal data, please visit: https://policies.google.com/privacy
Before the public launch, Artist Spotter is only accessible with an access code. You can sign up for early access on the coming-soon page.
What data we process. When you register, we process your name, optionally your artist name, your email address, and your consent. Providing this data is voluntary; without it, we cannot send you access. For spam and abuse prevention, we additionally use technical safeguards (honeypot, rate limiting via hashed IP).
Purposes & legal basis. We use your data solely to send you the beta access code and inform you about the launch — based on your consent (Art. 6(1)(a) GDPR). Spam prevention is based on our legitimate interest in a functional form (Art. 6(1)(f) GDPR). No automated decision-making or profiling takes place.
Double opt-in. After submitting the form, we send you a confirmation email; your registration only becomes valid once you click the link it contains (valid for 48 hours). If you don't confirm, the link expires and your data is not stored.
Storage period. We delete your registration data at the latest at the end of the beta phase or upon withdrawal of consent. If you create a user account during the beta phase, your registration data transfers into your account and is from that point subject to the deletion rules for account and profile data (see "Account and Profile Data" section), rather than the beta-phase deletion rule. We retain proof of your consent to the early access registration separately, for up to three years after the last email sent, in order to defend against legal claims.
Withdrawal. You can withdraw your consent at any time with future effect, informally by emailing info@artistspotter.com; every email we send also includes an unsubscribe link. We will delete your registration data without delay after withdrawal.
Right to complain. You also have the right to lodge a complaint with a competent data protection supervisory authority regarding the processing of your personal data (Art. 13(2)(d) GDPR). See also the "Your Rights" section below.
Sending. Confirmation emails and access/launch emails are sent via Resend — see "Email Delivery (Resend)".
We use Resend to send transactional emails, such as registration confirmations, password reset emails and notifications about new messages. The provider is Resend, Inc., 2261 Market Street #5401, San Francisco, CA 94114, USA. For this purpose, your email address and the respective email content are transmitted to and processed by Resend for delivery.
Legal basis. The processing is carried out for the performance of the user agreement pursuant to Art. 6(1)(b) GDPR.
Transfer to third countries. Resend processes and stores data in the United States. Resend, Inc. is certified under the EU-U.S. Data Privacy Framework (including the UK Extension). Where required, Resend also relies on the European Commission's Standard Contractual Clauses under its Data Processing Addendum.
Storage period. Resend stores delivery data for a limited period for delivery and logging purposes, after which it is automatically deleted. Details on the retention period can be found in Resend's privacy policy at resend.com/legal/privacy-policy.
We use the following technically necessary cookies and local storage elements: a cookie that remembers the beta access code you entered (session duration, deleted when you close your browser), three cookies that secure the Instagram login process (each valid for 10 minutes), a cookie that maintains your login session (until logout or expiry of the session token), and two local storage elements for your cookie consent decision and your theme selection (each stored indefinitely until deletion or withdrawal). The legal basis in each case is § 25(2) No. 2 TDDDG. We do not use tracking or marketing cookies.
Artists can embed audio content from SoundCloud, Mixcloud, hearthis.at and Spotify on their profile (player widgets, embeds, or directly loaded audio streams). This content is only loaded after you have actively given your consent (so-called two-click solution). The legal basis is your consent under Art. 6(1)(a) GDPR and § 25(1) TDDDG; you can withdraw it at any time with future effect.
SoundCloud. The provider is SoundCloud Global Limited & Co. KG, Rheinsberger Str. 76/77, 10115 Berlin, Germany. When a SoundCloud player is loaded, your browser establishes a direct connection to SoundCloud's servers; this may involve, among other things, the transmission of your IP address. Details: soundcloud.com/pages/privacy.
Mixcloud. The provider is Mixcloud Limited, Unit #2255, 275 New North Road, London N1 7AA, United Kingdom. When a Mixcloud player is loaded, your browser establishes a direct connection to Mixcloud's servers; this may involve, among other things, the transmission of your IP address. Details: mixcloud.com/privacy.
hearthis.at. The provider is Benedikt Groß, hearthis.at, Annaberger Strasse 282, 09125 Chemnitz, Germany. Unlike the other providers, no player is embedded: when a hearthis.at track is played, your browser loads the audio stream and the waveform data directly from hearthis.at's servers; this may involve, among other things, the transmission of your IP address. hearthis.at sets no cookies through our site. Details: hearthis.at/datenschutz.
Spotify. The provider is Spotify AB, Regeringsgatan 19, 111 53 Stockholm, Sweden. When a Spotify embed is loaded, your browser connects directly to Spotify's servers, which may process, among other things, your IP address and device information. Details: spotify.com/legal/privacy-policy.
Transfer to third countries. A transfer of your data to the USA or other third countries cannot be ruled out. The providers rely on the Standard Contractual Clauses of the European Commission for this. We have no influence on the type and scope of processing carried out by these providers.
Artist and collective profiles may embed YouTube videos. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; its parent company is Google LLC, USA. This may involve a transfer of personal data to the USA.
We do not load videos automatically. As long as you have not granted consent for media embeds and then pressed the play button, nothing is loaded from Google (not even preview images). Preview images are served from our own server.
Only when you start the video is a connection to www.youtube-nocookie.com established, transmitting your IP address and technical data about your device to Google. YouTube's "privacy-enhanced mode", which we use, means according to Google that your viewing is not used to personalise content outside of YouTube. It does not mean that no data at all is stored once the video has started.
Consent and legal basis. The legal basis is your consent under Art. 6(1)(a) GDPR. You can withdraw it at any time via the cookie settings.
Transfer to third countries. Google LLC is certified under the EU-U.S. Data Privacy Framework (including the UK Extension and the Swiss-U.S. Data Privacy Framework). Where necessary, Google also relies on the Standard Contractual Clauses of the European Commission. For more information, see Google's privacy policy at policies.google.com/privacy.
Artists and collectives can link their own Instagram profile and display posts on their profile page. This feature is provided through the Instagram APIs. The provider is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland ("Meta").
Artist connection process. If you link your Instagram profile, you will be redirected to Instagram and log in there. Through the authorization process (OAuth), you grant us permission to retrieve public profile information and media content via the Instagram API and display it on your profile. Only the data you explicitly approve during authorization is processed; we never access passwords or private messages. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR. You can revoke the connection at any time via your dashboard or in your Instagram settings under "Apps and Websites".
What we store for this. For an existing connection we store your Instagram username, your Instagram account ID and the access token. The access token is stored encrypted (AES-256-GCM) and is never displayed or disclosed. When you revoke the connection, we delete this information.
Data processing when a profile is viewed. Posts are retrieved by our server via the Instagram API, and the associated images are delivered through our own image service. When you view a profile, your browser therefore does not establish a connection to Meta's servers; Meta receives neither your IP address nor information about your browser when you view a profile, and no Meta cookies are set. For this reason, no consent is required in order to display the posts.
Transfers to third countries. For the server-side retrieval of posts, a transfer to the United States and other third countries cannot be excluded. Meta relies on the European Commission's standard contractual clauses. More information: privacycenter.instagram.com/policy.
We use the Mapbox mapping service to display maps, for example to show event locations and artist locations. The provider is Mapbox, Inc., 1133 15th St NW, Suite 825, Washington, DC 20005-1047, USA.
Data processing. After you have given your consent, your browser establishes a direct connection to Mapbox's servers when a map is loaded. In this process, Mapbox may process your IP address, information about your browser and device, usage and log data, and—if location services are enabled—your approximate location. We have no influence over the nature and scope of the data processing carried out by Mapbox.
Legal basis. The processing is based on your consent pursuant to Art. 6(1)(a) GDPR.
Transfer to third countries. Personal data may be transferred to the United States. Mapbox, Inc. is certified under the EU-U.S. Data Privacy Framework (including the UK Extension and the Swiss-U.S. Data Privacy Framework). Where required, Mapbox also relies on the European Commission's Standard Contractual Clauses.
For more information about how Mapbox processes personal data, please visit: https://www.mapbox.com/legal/privacy
We store personal data only for as long as it is necessary for the respective purpose or as long as statutory retention obligations apply. Account and profile data are stored until you delete your account. Booking requests and reach-outs remain in the inbox of the profile concerned until that profile deletes them. Server log data is deleted automatically by our service providers after a short period (see "What data we process"). Abuse-prevention logs are deleted after 90 days at the latest. Records of consent are kept for up to three years after the last email sent to you. Error diagnostics reports are deleted after 30 days.
The recipients of your data are exclusively the service providers named in this policy, acting for us as data processors (hosting, database, email delivery, content management), and — in the case of published profiles — the public, to the extent described. Your data is neither transferred for advertising purposes nor sold.
Automated decision-making. No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.
Minors. Our service is directed at persons aged 16 and over. We do not knowingly collect data from children under 16. Should we become aware of such data, we will delete it.
You have the right to obtain, free of charge, information about the personal data we store about you, as well as the right to rectification, erasure, restriction of processing and data portability, subject to the applicable legal requirements. Where processing is based on Art. 6(1)(f) GDPR, you also have the right to object to such processing.
If you wish to exercise your rights or have any questions regarding data protection, you may contact us at any time using the contact details provided above.
You also have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data (Art. 77 GDPR). The authority competent for us is the Saxon Data Protection Commissioner (Der Sächsische Datenschutzbeauftragte), Devrientstraße 5, 01067 Dresden, Germany.