Your Privacy Matters: This Privacy Policy explains how we collect, use, and protect your information when you use GrooveHouse.
1. Information We Collect
1.1 Information You Provide
When you create an account and use GrooveHouse, we collect:
- Username and email address (for account creation)
- Profile information (display name, bio, social media links)
- SoundCloud track URLs you submit to competitions
- Voting data (which competitions you voted in and which tracks you voted for)
- Support requests and communications with us
1.2 Automatically Collected Information
When you use our Service, we automatically collect:
- Browser type and version
- IP address and general location (city/region level)
- Pages visited and features used
- Date and time of your visits
- Device information (type, operating system)
1.3 Third-Party Data
We access limited public information from SoundCloud when you submit tracks, including:
- Track title and artist name
- Track thumbnail/artwork
- Play count statistics (publicly available data)
2. How We Use Your Information
We use your information to:
- Provide and maintain the GrooveHouse Service
- Process competition entries and voting
- Calculate leaderboards and determine winners
- Send you important updates about competitions
- Respond to your support requests
- Improve our Service and develop new features
- Prevent fraud and ensure fair competition
- Comply with legal obligations
3. Data Storage and Security
Your data is stored securely using industry-standard practices:
- Database: We use Supabase (a PostgreSQL database) with encryption at rest and in transit
- Authentication: Passwords are hashed and never stored in plain text
- File Storage: Profile pictures are stored in Supabase Storage with public access controls
- Access Control: Row-level security ensures users can only access their own private data
While we implement strong security measures, no system is 100% secure. We cannot guarantee absolute security of your data.
4. Third-Party Services & Data Processors
We use the following third-party services to provide our Service:
4.1 Supabase (Database & Storage)
Data Stored: User profiles, competitions, tracks, votes, comments, profile pictures
Location: USA (cloud infrastructure)
Compliance: GDPR-compliant and SOC 2 Type II certified
Learn more: Supabase Privacy Policy
4.2 Netlify (Hosting)
Data Stored: Access logs, bandwidth usage, CDN data
Location: Global CDN with data centers worldwide
Compliance: GDPR-compliant
Learn more: Netlify Privacy Policy
4.3 FormSubmit (Contact Form)
Data Stored: Support requests sent via email. We do not control FormSubmit's data retention policies.
4.4 SoundCloud (Third-Party Integration)
When you submit a track, we access publicly available SoundCloud data through their oEmbed API. We do not store your SoundCloud credentials.
Data Accessed: Track title, artist name, thumbnail, play counts (public data only).
5. Cookies and Tracking
We use essential cookies for:
- Keeping you logged in
- Remembering your preferences
- Ensuring security and preventing fraud
We do NOT use tracking cookies or third-party advertising cookies.
6. Data Sharing and Disclosure
We do NOT sell your personal information. We may share your data only in these situations:
- Public Profile: Your username, display name, and submitted tracks are publicly visible
- Service Providers: With third-party services like Supabase and FormSubmit
- Legal Requirements: If required by law or to protect our legal rights
- Business Transfer: In case of a merger, acquisition, or sale of assets
7. Your Rights (GDPR & Data Protection)
Under GDPR and other privacy laws, you have the following rights:
- Right to Access: Request a copy of all personal data we hold about you
- Right to Correction: Update inaccurate or incomplete data in your profile
- Right to Deletion (Right to be Forgotten): Request permanent deletion of your account and all associated data
- Right to Data Portability: Receive your data in a machine-readable format (JSON)
- Right to Object: Object to processing of your data for certain purposes
- Right to Restriction: Request we limit how we use your data
- Right to Withdraw Consent: Withdraw consent for data processing at any time
7.1 Right to be Forgotten
You can request complete deletion of your account and all associated data by contacting us via our support page. We will:
- Delete your user profile and account credentials
- Delete all competitions you created
- Delete all tracks you submitted
- Delete all votes you cast
- Delete all comments you posted
- Delete your profile picture from storage
Timeline: Account deletion requests are processed within 30 days.
Note: Some data may be retained in backup systems for up to 90 days for technical reasons, but will not be accessible or used.
7.2 How to Exercise Your Rights
To exercise any of these rights, contact us via our support page. We will respond within 30 days.
8. Children's Privacy (COPPA & GDPR-K)
Age Requirement: GrooveHouse is intended for users aged 13 years or older.
We comply with:
- COPPA (Children's Online Privacy Protection Act): US law protecting children under 13
- GDPR-K: EU data protection for minors
We do not knowingly collect data from children under 13. If you believe we have inadvertently collected information from a child under 13, contact us immediately via our support page and we will delete the account within 24 hours.
9. International Users
GrooveHouse is based in the United States. If you access our Service from outside the US, your data may be transferred to and stored in the United States. By using our Service, you consent to this transfer.
For users in the European Economic Area (EEA), we comply with GDPR requirements. For California residents, we comply with the California Consumer Privacy Act (CCPA).
10. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. If you delete your account, we will delete your personal data within 30 days, except where we must retain data for legal or regulatory reasons.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We'll notify you of significant changes by posting a notice on the Service or sending an email. The "Last Updated" date at the top indicates when changes were last made.
12. Contact Us
If you have questions or concerns about this Privacy Policy, please contact us via GrooveHouse Support.