Privacy Policy
We take the protection of your personal data seriously and handle it confidentially in accordance with applicable data protection laws and this privacy policy. Our website can generally be used without registering an account. However, certain features, in particular the creation of a user account, require the processing of personal data.
Responsible Parties
Names: Kenny Kunze-Oehme, Julia Weiske
Address: Wurzner Straße 9, 04315 Leipzig, Germany
Contact: info@artistspotter.com
What data we process
When you access our website, technically necessary server log data is processed automatically and transmitted by your browser to the server. This includes, in particular:
01 Browser type and version
02 Operating system
03 Referrer URL
04 Host name of the accessing device
05 Date and time of the server request
06 Truncated IP address
This data is processed to ensure the secure and reliable operation of our website, to analyse errors and to improve our services. The data is not combined with other data sources. The legal basis for this processing is our legitimate interest pursuant to Art. 6(1)(f) GDPR.
These log data are automatically deleted by our service providers after a short period (currently: Vercel approx. 1 hour, Supabase approx. 1 day for API and database logs, and 1 hour for auth logs). These retention periods may change, for example if we switch to a different pricing plan with the respective providers.
Hosting & Infrastructure
Our website and the underlying application are operated with the support of external service providers that assist us with hosting, data storage and content delivery.
Vercel (Hosting). The provider is Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. Vercel provides the technical infrastructure for our website and processes technically necessary server log data (e.g. IP address, timestamp and requested URL). Vercel processes this data as our data processor pursuant to Art. 28 GDPR. The legal basis for this processing is our legitimate interest in the secure, reliable and high-performance provision of our online services pursuant to Art. 6(1)(f) GDPR. Personal data may be transferred to the United States. Vercel is certified under the EU-U.S. Data Privacy Framework and, where required, also relies on the European Commission's Standard Contractual Clauses.
Supabase (Database). The provider is Supabase, Inc., 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513. Account and profile data are stored and processed by Supabase as our data processor pursuant to Art. 28 GDPR in the region selected by us (Frankfurt am Main, Germany). The legal basis for this processing is Art. 6(1)(b) GDPR.
Sanity (Content Management). The provider is Sanity, Inc., 351 California Street, Suite 650, San Francisco, CA 94104, USA. We use Sanity to manage editorial content (e.g. blog posts). As a rule, no personal data of website visitors is processed through this service. Sanity acts as our data processor pursuant to Art. 28 GDPR. The legal basis for its use is our legitimate interest in efficient content management pursuant to Art. 6(1)(f) GDPR.
Analytics (Vercel Web Analytics & Speed Insights). We use Vercel Web Analytics and Vercel Speed Insights to analyse page views and loading times in aggregated form. Both services operate without the use of cookies. According to Vercel, no individual user identification or profiling takes place. The legal basis for this processing is our legitimate interest in ensuring and improving the technical operation of our website pursuant to Art. 6(1)(f) GDPR. According to Vercel, these services do not access information stored on users' devices within the meaning of Section 25 TDDDG, meaning that no consent is required.
Account Registration, Login & Deletion
Registration. When you create an Artist or Booker account, we process the information you provide (e.g. your name or artist name, email address, password, role, city, genres, links to streaming platforms, profile picture and biography) to the extent necessary to provide your account. Information you provide for your profile may be displayed on your public profile page. The legal basis for this processing is Art. 6(1)(b) GDPR.
Passwords and Authentication. Your password is never stored in plain text. Instead, it is stored as a secure hash using current industry standards. Authentication is provided through Supabase (Supabase, Inc.) acting as our data processor pursuant to Art. 28 GDPR. Your data is stored and processed by Supabase in the region selected by us (Frankfurt am Main, EU). We do not have access to your plain-text password.
We send emails to verify your email address and for security-related purposes (e.g. password resets). The legal basis for this processing is Art. 6(1)(b) GDPR.
Alternatively, you may sign in using Google or Apple. In this case, we do not receive your password, but only the profile information you authorize the respective provider to share for authentication purposes. The privacy policies of the respective provider also apply.
Login. Each time you sign in, we process your email address or user ID and the time of your login in order to authenticate your access and maintain your session using strictly necessary cookies and/or local storage. The legal basis for this processing is Art. 6(1)(b) and (f) GDPR as well as Section 25(2) No. 2 TDDDG.
Deletion. You may delete your account at any time via your dashboard. Your profile and associated profile data will be deleted or anonymized unless statutory retention obligations require otherwise.
You can view and edit your personal data at any time via your dashboard.
Contact, booking and report forms
Several forms let you reach us or other members without holding an account: booking requests to artists, reach-outs to collectives, the general contact form, feedback, genre suggestions and the "Report a violation" form.
What data we process. Depending on the form, we process your name, your email address, a subject line and your message. The "Report a violation" form additionally processes the address (URL) of the reported content, a category and your description; giving your name is optional there, while we need your email address for follow-up questions. Mandatory fields are marked in each form.
Purposes and legal basis. We forward booking requests and collective reach-outs to the profile concerned and send you a confirmation; the legal basis is the performance of the service you requested pursuant to Art. 6(1)(b) GDPR. We also store booking requests and reach-outs in the inbox of the profile concerned so that the request can be handled there. Enquiries via the contact form, feedback and genre suggestions are processed to answer your request, on the basis of our legitimate interest in functioning communication pursuant to Art. 6(1)(f) GDPR. Reports submitted via the "Report a violation" form are processed so that we can review and, where appropriate, remove the reported content; the legal basis is our legitimate interest in a lawful platform pursuant to Art. 6(1)(f) GDPR.
Reports about third parties. A report inevitably also contains information about the reported person. We process this information solely in order to review the report. We inform the persons concerned in accordance with Art. 14 GDPR, insofar as this does not frustrate the review and no exemption applies. We do not disclose your identity as the reporting person on our own initiative.
Abuse prevention. All of the forms named above contain a field that is invisible to you (a honeypot) for spam protection. We also use your IP address — processed exclusively in hashed form — to check how many submissions originate from the same connection within 15 minutes (rate limit). We do not store your IP address itself; only a non-reversible hash value is stored. Blocked submissions are logged in the same non-reversible form so that we can detect patterns of abuse. The legal basis is our legitimate interest in forms that function and cannot be abused, pursuant to Art. 6(1)(f) GDPR.
Retention. Booking requests and reach-outs remain in the inbox of the profile concerned until that profile deletes them or the profile itself is deleted. Emails from the remaining forms are deleted once your request has been dealt with conclusively and no statutory retention obligations apply. Abuse-prevention logs are deleted after 90 days at the latest.
Delivery. All emails from these forms are sent via Resend — see the section "Email Delivery (Resend)".
Sign in with Google
You may alternatively sign in using "Sign in with Google" instead of creating an account manually. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google").
Data processing. When you click "Sign in with Google", your browser establishes a connection to Google's servers. If you choose to continue, we receive the profile information required for authentication via the OAuth authorization process, including your name, email address and profile picture, in order to create your account or sign you in. We have no control over Google's processing of your personal data.
Legal basis. The processing of the data provided by Google is carried out for the performance of the user agreement or to take steps prior to entering into a contract pursuant to Art. 6(1)(b) GDPR.
Transfer to third countries. Personal data may be transferred to the United States. Google LLC is certified under the EU-U.S. Data Privacy Framework (including the UK Extension and the Swiss-U.S. Data Privacy Framework). Where required, Google also relies on the European Commission's Standard Contractual Clauses.
For more information about how Google processes personal data, please visit: https://policies.google.com/privacy
Early Access Registration (Beta)
Before the public launch, Artist Spotter is only accessible with an access code. You can sign up for early access on the coming-soon page.
What data we process. When you register, we process your name, optionally your artist name, your email address, and your consent. Providing this data is voluntary; without it, we cannot send you access. For spam and abuse prevention, we additionally use technical safeguards (honeypot, rate limiting via hashed IP).
Purposes & legal basis. We use your data solely to send you the beta access code and inform you about the launch — based on your consent (Art. 6(1)(a) GDPR). Spam prevention is based on our legitimate interest in a functional form (Art. 6(1)(f) GDPR). No automated decision-making or profiling takes place.
Double opt-in. After submitting the form, we send you a confirmation email; your registration only becomes valid once you click the link it contains (valid for 48 hours). If you don't confirm, the link expires and your data is not stored.
Storage period. We delete your data at the latest at the end of the beta phase or upon withdrawal of consent. We retain proof of your consent for up to three years after the last email sent, in order to defend against legal claims.
Withdrawal. You can withdraw your consent at any time with future effect, informally by emailing info@artistspotter.com; every email we send also includes an unsubscribe link. We will delete your registration data without delay after withdrawal.
Right to complain. You also have the right to lodge a complaint with a competent data protection supervisory authority regarding the processing of your personal data (Art. 13(2)(d) GDPR). See also the "Your Rights" section below.
Sending. Confirmation emails and access/launch emails are sent via Resend — see "Email Delivery (Resend)".
Email Delivery (Resend)
We use Resend to send transactional emails, such as registration confirmations, password reset emails and notifications about new messages. The provider is Resend, Inc., 2261 Market Street #5401, San Francisco, CA 94114, USA. For this purpose, your email address and the respective email content are transmitted to and processed by Resend for delivery.
Legal basis. The processing is carried out for the performance of the user agreement pursuant to Art. 6(1)(b) GDPR.
Transfer to third countries. Resend processes and stores data in the United States. Resend, Inc. is certified under the EU-U.S. Data Privacy Framework (including the UK Extension). Where required, Resend also relies on the European Commission's Standard Contractual Clauses under its Data Processing Addendum.
Cookies & local storage
We use the following technically necessary cookies and local storage elements: a cookie that remembers the beta access code you entered (session duration, deleted when you close your browser), three cookies that secure the Instagram login process (each valid for 10 minutes), a cookie that maintains your login session (until logout or expiry of the session token), and two local storage elements for your cookie consent decision and your theme selection (each stored indefinitely until deletion or withdrawal). The legal basis in each case is § 25(2) No. 2 TDDDG. We do not use tracking or marketing cookies.
Third-Party Embedded Content
Artists can embed audio content from SoundCloud and Spotify on their profile (player widgets/embeds). This content is only loaded after you have actively given your consent (so-called two-click solution). The legal basis is your consent under Art. 6(1)(a) GDPR and § 25(1) TDDDG; you can withdraw it at any time with future effect.
SoundCloud. The provider is SoundCloud Global Limited & Co. KG, Rheinsberger Str. 76/77, 10115 Berlin, Germany. When a SoundCloud player is loaded, your browser establishes a direct connection to SoundCloud's servers; this may involve, among other things, the transmission of your IP address. Details: soundcloud.com/pages/privacy.
Spotify. The provider is Spotify AB, Regeringsgatan 19, 111 53 Stockholm, Sweden. When a Spotify embed is loaded, your browser connects directly to Spotify's servers, which may process, among other things, your IP address and device information. Details: spotify.com/legal/privacy-policy.
Transfer to third countries. A transfer of your data to the USA or other third countries cannot be ruled out. The providers rely on the Standard Contractual Clauses of the European Commission for this. We have no influence on the type and scope of processing carried out by these providers.
YouTube Integration
Artist and collective profiles may embed YouTube videos. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; its parent company is Google LLC, USA. This may involve a transfer of personal data to the USA.
We do not load videos automatically. As long as you have not granted consent for media embeds and then pressed the play button, nothing is loaded from Google (not even preview images). Preview images are served from our own server.
Only when you start the video is a connection to www.youtube-nocookie.com established, transmitting your IP address and technical data about your device to Google. YouTube's "privacy-enhanced mode", which we use, means according to Google that your viewing is not used to personalise content outside of YouTube. It does not mean that no data at all is stored once the video has started.
Consent and legal basis. The legal basis is your consent under Art. 6(1)(a) GDPR. You can withdraw it at any time via the cookie settings.
Transfer to third countries. Google LLC is certified under the EU-U.S. Data Privacy Framework (including the UK Extension and the Swiss-U.S. Data Privacy Framework). Where necessary, Google also relies on the Standard Contractual Clauses of the European Commission.
Instagram integration
Artists and collectives can link their own Instagram profile and display posts on their profile page. This feature is provided through the Instagram APIs. The provider is Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland ("Meta").
Artist connection process. If you link your Instagram profile, you will be redirected to Instagram and log in there. Through the authorization process (OAuth), you grant us permission to retrieve public profile information and media content via the Instagram API and display it on your profile. Only the data you explicitly approve during authorization is processed; we never access passwords or private messages. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR. You can revoke the connection at any time via your dashboard or in your Instagram settings under "Apps and Websites".
What we store for this. For an existing connection we store your Instagram username, your Instagram account ID and the access token. The access token is stored encrypted (AES-256-GCM) and is never displayed or disclosed. When you revoke the connection, we delete this information.
Data processing when a profile is viewed. Posts are retrieved by our server via the Instagram API, and the associated images are delivered through our own image service. When you view a profile, your browser therefore does not establish a connection to Meta's servers; Meta receives neither your IP address nor information about your browser when you view a profile, and no Meta cookies are set. For this reason, no consent is required in order to display the posts.
Transfers to third countries. For the server-side retrieval of posts, a transfer to the United States and other third countries cannot be excluded. Meta relies on the European Commission's standard contractual clauses. More information: privacycenter.instagram.com/policy.
Mapbox
We use the Mapbox mapping service to display maps, for example to show event locations and artist locations. The provider is Mapbox, Inc., 1133 15th St NW, Suite 825, Washington, DC 20005-1047, USA.
Data processing. After you have given your consent, your browser establishes a direct connection to Mapbox's servers when a map is loaded. In this process, Mapbox may process your IP address, information about your browser and device, usage and log data, and—if location services are enabled—your approximate location. We have no influence over the nature and scope of the data processing carried out by Mapbox.
Legal basis. The processing is based on your consent pursuant to Art. 6(1)(a) GDPR.
Transfer to third countries. Personal data may be transferred to the United States. Mapbox, Inc. is certified under the EU-U.S. Data Privacy Framework (including the UK Extension and the Swiss-U.S. Data Privacy Framework). Where required, Mapbox also relies on the European Commission's Standard Contractual Clauses.
For more information about how Mapbox processes personal data, please visit: https://www.mapbox.com/legal/privacy
Retention and recipients at a glance
We store personal data only for as long as it is necessary for the respective purpose or as long as statutory retention obligations apply. Account and profile data are stored until you delete your account. Booking requests and reach-outs remain in the inbox of the profile concerned until that profile deletes them. Server log data is deleted automatically by our service providers after a short period (see "What data we process"). Abuse-prevention logs are deleted after 90 days at the latest. Records of consent are kept for up to three years after the last email sent to you.
The recipients of your data are exclusively the service providers named in this policy, acting for us as data processors (hosting, database, email delivery, content management), and — in the case of published profiles — the public, to the extent described. Your data is neither transferred for advertising purposes nor sold.
Automated decision-making. No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.
Minors. Our service is directed at persons aged 16 and over. We do not knowingly collect data from children under 16. Should we become aware of such data, we will delete it.
Your rights
You have the right to obtain, free of charge, information about the personal data we store about you, as well as the right to rectification, erasure, restriction of processing and data portability, subject to the applicable legal requirements. Where processing is based on Art. 6(1)(f) GDPR, you also have the right to object to such processing.
If you wish to exercise your rights or have any questions regarding data protection, you may contact us at any time using the contact details provided above.
You also have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data (Art. 77 GDPR). The authority competent for us is the Saxon Data Protection Commissioner (Der Sächsische Datenschutzbeauftragte), Devrientstraße 5, 01067 Dresden, Germany.