Privacy Policy
Last updated:
1. Introduction
BeatCheck (“we”, “our”, “us”) is committed to protecting your personal data. This Privacy Policy explains what data we collect, why we collect it, and your rights under UK GDPR and the Data Protection Act 2018.
This page contains placeholder content. It will be replaced with Termly-generated copy before public launch.
2. Data We Collect
- Account information: name, email address, encrypted password hash
- Release metadata you enter (title, artist name, genre, ISRC, etc.)
- Files you upload (cover art, audio, Spotify Canvas videos)
- Usage data: pages visited, features used, error events
- Payment information processed by Paddle (we never see raw card data)
- Support messages you send us
3. Legal Basis for Processing
We process your data under the following lawful bases: contractual necessity (to provide the BeatCheck service), legitimate interests (security, abuse prevention, service improvement), and your consent (for optional analytics and marketing cookies).
4. Data Retention
We retain your account data for the duration of your account plus 30 days after deletion (grace period for recovery). Release files are deleted when you permanently remove them. Backup exports are retained for 90 days.
5. Your Rights
Under UK GDPR you have the right to: access, rectify, erase, restrict, port, and object to processing of your personal data. To exercise any right, email us at privacy@beatcheck.app.
6. Third-Party Services
- Appwrite Cloud — backend infrastructure (EU region)
- Vercel — hosting and edge functions
- Resend — transactional email
- Paddle — payment processing
- PostHog (EU) — product analytics (anonymised user IDs only)
- Sentry — error monitoring (user ID only, no email)
7. Contact
Data controller: [Your Name / Company], [Address]. privacy@beatcheck.app