Last updated 4 September 2026
This policy explains what personal data Bandpit("we", "us") collects, why, and your rights over it. Bandpit is a web app that helps bands store songs, build setlists, play live in sync, and run a public band page. If you have questions, contact us at hello@bandpit.app.
To provide and secure the service, process subscriptions, respond to you, and improve Bandpit. Our legal bases (GDPR) are performing our contract with you, our legitimate interest in running and improving the service, and your consent where it applies. We do not sell your data or use it for advertising.
We share data only with providers that help us run the service:
Your data is stored in the EU (Stockholm). Some providers may process limited data elsewhere under appropriate safeguards.
We keep your data while your account is active. You can delete your account at any time from your account page, which removes your profile; bands where you are the only member are deleted with their content. A sole member can also delete one band from its Settings page without deleting their account. Band deletion removes the band's private and public content, while a written appearance on another event owner's gig remains as an unlinked lineup entry. Backups and logs age out on a rolling basis. The cookieless site traffic log expires after 45 days.
Under the GDPR you can access, correct, export, or delete your data, and object to or restrict certain processing. Account deletion is available directly in the app. You also have the right to complain to your data protection authority (in Finland, the Office of the Data Protection Ombudsman / Tietosuojavaltuutettu). To exercise any right, contact hello@bandpit.app.
If a band enables its public page, the information it puts there (name, bio, links, gigs, images) is intentionally public. Don't put anything there you don't want the world to see.
Feedback is linked to your account so only you and the Bandpit owner can follow it. The owner may publish a handling status and a reply to your private feedback page. If you select email updates when sending the message, Resend delivers those status or reply updates to your account email. You can leave that option off. Deleting your account also deletes the feedback linked to it.
Anyone can anonymously report a published artist or gig page for review. The report is visible only to the Bandpit owner and expires after 180 days. A one-way protected fingerprint made from the report and network address suppresses repeats without storing the raw address in the report. Because the form does not collect contact details, we cannot reply to its sender.
The owner may temporarily hide a band's public artist page, public gigs, EPK, calendar, directory presence, and artist cross-links while a concern is reviewed. This does not remove the private band room, songs, recordings, members, or billing. Moderation actions retain an internal audit record of the reason, owner account, and time.
Gig emails are optional and start only after you confirm your address. The band's editors can see and export the confirmed addresses and cities for their band, and may use them only for the gig updates you requested. Every message contains an unsubscribe link. Unsubscribing removes the subscription and its delivery records. Unconfirmed requests expire after 24 hours.
A one-off gig reminder also starts only after email confirmation. It sends only for the selected event, is not visible to the band or included in follower exports, and does not subscribe you to future artist or city messages. You can cancel it from the email. Its record expires after the event.
When you send a booking enquiry, its details are emailed to the band's chosen booking address so they can reply. The band's editors can also track its status and add an internal handling note in their private Bandpit workspace. We delete the enquiry and that note automatically after 30 days. A one-way hash of the sender address and network address limits repeated submissions; the raw network address is not stored in the enquiry record. Sending an enquiry does not subscribe you to marketing.
A band can send a single-use invitation to a venue contact so the venue can claim its page and approve linked events. The pending invitation stores the contact email and expires after 14 days. Claiming the page associates the signed-in account with that venue. Public contact details appear only when a venue owner enters them in the venue profile.
Rehearsal takes, demos and backing tracks attached to a song are available only to members of that band while its Pro access is active. Audio is stored in a private Cloudflare R2 bucket. Listening uses a short-lived signed address after Bandpit checks band membership. Deleting a recording removes its stored file, and deleting a sole-member band removes that band's audio records and files.
A Pro-band admin can deliberately save a setlist and its backing tracks to the browser's private local storage for offline stage use. The copy stays on that device, expires after seven days, and can be removed from the Live page. Refreshing it checks current band membership and Pro access again.
Bandpit is not intended for children under 16.
We'll update this page if our practices change and revise the date above.