1. What data we collect
When you use Musiome, we may collect the following personal data:
- Email address β provided during registration or OAuth login.
- Display name β provided during registration or imported from your OAuth provider.
- Avatar image β uploaded by you or imported from your OAuth provider.
- IP address β recorded in session data for security purposes.
- Uploaded content β audio files, images, and other media you upload to your profile.
- Subscription metadata β plan tier, subscription status, and transaction identifiers processed by our payment provider.
2. Why we collect it
We collect personal data solely for the purposes below. The legal basis is performance of a contract (Art. 6(1)(b) GDPR) for account operation, and our legitimate interests (Art. 6(1)(f) GDPR) for security.
- Account operation β to create and maintain your Musiome account and authenticate you.
- Artist profiles β to display your public profile, tracks, videos, events, and press kit.
- Payment processing β to manage subscription purchases and payouts via our payment provider.
- Security β to detect and prevent fraud and abuse.
3. Third-party processors
We share your data with the following sub-processors only to the extent necessary to provide the service:
VercelApplication hosting and file storage (Vercel Blob)
Privacy policy4. Cookies
Musiome uses essential session cookies only. These cookies are strictly necessary to keep you signed in and to protect against cross-site request forgery. We do not use advertising cookies, analytics cookies, or any third-party tracking cookies.
5. Data retention
- Session data β expires automatically when your session ends or after a period of inactivity.
- Account data β retained for as long as you have an active account. You may request deletion at any time (see Section 6).
- Payment records β retained as required by applicable accounting and tax law, even after account deletion.
6. Your rights under GDPR
If you are located in the European Economic Area, you have the following rights regarding your personal data:
- Right of access β obtain a copy of the personal data we hold about you.
- Right to rectification β correct inaccurate or incomplete data.
- Right to erasure β request deletion of your account and associated data.
- Right to data portability β receive your data in a structured, machine-readable format.
- Right to object β object to processing based on legitimate interests.
You can exercise these rights from your account settings page, where you can export or delete your account. For requests that cannot be fulfilled in-app, contact us at the address in Section 7.
8. Supervisory authority
If you believe we are processing your personal data unlawfully, you have the right to lodge a complaint with the competent supervisory authority. In the Czech Republic this is:
ΓΕad pro ochranu osobnΓch ΓΊdajΕ― (ΓOOΓ)
Pplk. Sochora 27, 170 00 Prague 7, Czech Republic
www.uoou.cz