Privacy Policy

Last updated: June 9, 2026

1. Who We Are and Who This Policy Covers

PromoFuse ("we", "us") is a platform that lets music creators ("Creators") build download gates and smart links for their releases. This policy explains how we handle personal data for two groups of people:

  • Creators — artists, DJs, and labels with a PromoFuse account.
  • Fans — visitors who use a Creator's public gate or smart link page.

2. Controller and Processor Roles

For Creator account data and the aggregate analytics we need to run the platform, PromoFuse is the data controller.

For fan data collected through a Creator's gate (emails, names, consent records, and gate analytics), the Creator whose gate you visited is the data controller and PromoFuse acts as their data processor. We process that data on the Creator's instructions and make it available to them, including via CSV export. If you are a fan and want your data deleted or want to know how a specific artist uses it, the quickest route is to contact that artist — but you can always contact us at [email protected] and we will help.

3. Data We Collect

Creator account data

  • Email address and password (passwords are hashed by our authentication provider, Supabase; we never see them in plain text).
  • Profile data you provide: artist name, genre, and social media links.
  • Subscription plan and billing status (see "Payments" below).
  • Files, artwork, titles, and descriptions you upload for your campaigns.

Fan gate data

  • If a gate includes an email step: the email address and optional name you submit, whether you ticked the consent checkbox, and a timestamp of that consent.
  • A record of which gate steps you completed (for example "followed on SoundCloud"), linked to a visitor ID.
  • A randomly generated visitor ID stored in your browser's localStorage (key dg_visitor_id) so the gate remembers your progress. It is not derived from your identity.

Analytics events

When you view or interact with a gate or smart link page, we log events that include:

  • Approximate location (country and city), derived from your IP address using a third-party IP geolocation service. The IP address itself is used transiently for this lookup and is not stored in the event record.
  • Your browser's user agent string and the referring page.
  • UTM campaign parameters present in the link you clicked (utm_source, utm_medium, utm_campaign, utm_term, utm_content).
  • The event type (page view, action click, email submitted, download) and your visitor ID.

Connected streaming accounts (fans)

  • If you connect your SoundCloud account to complete gate steps, SoundCloud access and refresh tokens are stored as cookies in your own browser so the actions you approved (follow, like, repost) can be performed. They are not stored in our database.
  • If you complete a Spotify pre-save (where offered), we store the Spotify access and refresh tokens you authorised, along with your pre-save, so the release can be saved to your library on release day.
  • We only act on these accounts to perform the specific actions you requested.

Payments

Payments for paid plans are processed by Stripe. Your card details go directly to Stripe and are never stored on our servers; we keep only your subscription status and plan. Stripe's processing is described in its own privacy policy.

4. How We Use Data

  • To operate gates and smart links: remembering step progress, verifying completion, and delivering downloads.
  • To give Creators analytics about their campaigns (views, conversions, locations, traffic sources).
  • To make fan data (email, name, consent status) available to the Creator who ran the gate, as their processor.
  • To manage accounts, subscriptions, and billing.
  • To secure the Service, prevent abuse, and debug problems.

We do not sell personal data, and we do not use fan emails for our own marketing.

5. Legal Bases (GDPR)

  • Consent — fan email marketing consent collected via the gate checkbox, connecting a streaming account, and analytics or advertising cookies where your jurisdiction requires consent for them.
  • Contract — providing the Service to Creators, delivering a download a fan has unlocked.
  • Legitimate interests — campaign analytics, service security, and abuse prevention.
  • Legal obligation — tax and accounting records relating to payments.

6. Where Data Is Stored and Who Processes It

We use a small set of service providers (sub-processors) to run PromoFuse:

  • Supabase — database and authentication (account data, fan gate data, analytics events).
  • Cloudflare R2 — storage of files Creators upload; downloads are delivered via short-lived signed URLs.
  • Vercel — application hosting and privacy-friendly, cookieless web analytics.
  • Google (Analytics and Ads) — measures how visitors find and sign up for PromoFuse, and whether an advertisement led to a subscription. Loaded only on our marketing and dashboard pages, never on public gate or smart link pages, and only where permitted by your cookie choice.
  • Stripe — payment processing for subscriptions.
  • IP geolocation provider — converts IP addresses to approximate location (country/city) for gate analytics.
  • SoundCloud and Spotify APIs — perform the gate actions fans authorise on their own accounts.

Some of these providers process data outside the EEA. Where they do, transfers rely on safeguards such as the EU Standard Contractual Clauses or an adequacy decision.

7. Cookies and Local Storage

  • dg_visitor_id (localStorage) — random visitor ID that remembers your gate progress.
  • Supabase authentication cookies — keep Creators signed in to the dashboard.
  • sc_access_token, sc_refresh_token and related sc_* cookies — set only if a fan connects SoundCloud, used to perform the actions they approved.
  • Vercel Analytics — cookieless; it does not set cookies or track you across sites.
  • pf_attr — records which advertisement, search or link first brought you to promofuse.app, so we can tell which marketing actually works. Set only when you arrive with campaign parameters, kept 90 days, and never overwritten by a later visit. It holds no name, email or other identifying detail.
  • pf_consent (localStorage) — remembers your answer to the cookie banner.
  • Google Analytics and Google Ads cookies (for example _ga, _gcl_au) — set on our marketing and dashboard pages to measure signups and advertising performance. These are advertising and analytics cookies.

Public gate pages and smart links set no analytics or advertising cookies at all. If you are a fan who arrived from an artist's link, nothing in this section beyond the visitor ID and any SoundCloud tokens applies to you.

In the UK, EEA and Switzerland the Google analytics and advertising cookies are disabled until you accept them, and declining changes nothing about how the site works. Elsewhere they are enabled by default. You can change your mind at any time by clearing your browser's site data for promofuse.app, which also clears the visitor ID — the only effect of that is that gates forget your progress.

8. Data Retention

  • Creator account data is kept while the account exists and deleted or anonymised after account deletion, except records we must keep for legal reasons.
  • Fan gate data and analytics events are kept while the related campaign and Creator account exist. Deleting a campaign deletes its fan actions and events.
  • Download tokens are single-use and expire shortly after they are issued.
  • SoundCloud token cookies expire from the fan's browser automatically; Spotify pre-save tokens are kept only as long as needed to complete the pre-save.

9. Your Rights

If you are in the EEA, the UK, or another jurisdiction with similar laws, you have the right to:

  • Access the personal data we hold about you and receive a copy in a portable format.
  • Correct inaccurate data.
  • Have your data erased ("right to be forgotten").
  • Restrict or object to certain processing, including processing based on legitimate interests.
  • Withdraw consent at any time — for example, unsubscribe from a Creator's emails — without affecting processing that happened before withdrawal.
  • Complain to your local data protection supervisory authority.

Creators can exercise these rights through their dashboard or by contacting us. Fans can contact the Creator who ran the gate (the controller of their data) or contact us directly at [email protected]; where we act as processor we will assist or forward the request to the Creator.

10. Sharing of Data

  • Fan data collected through a gate is shared with the Creator who ran that gate — that is the purpose of the product, and gates disclose this at the point of collection.
  • Data is shared with the service providers listed in section 6, only as needed to run the Service.
  • We may disclose data where required by law or to protect the rights, safety, or property of PromoFuse, our users, or others.
  • If PromoFuse is involved in a merger or acquisition, data may transfer to the successor, subject to this policy.

11. Security

We protect data with measures including encrypted connections (HTTPS), hashed passwords, row-level security on all database tables, single-use expiring download tokens, and short-lived signed URLs for file delivery. No system is perfectly secure; if a breach affects your personal data we will notify you and the relevant authorities as required by law.

12. Children

The Service is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact us and we will delete it.

13. Changes to This Policy

We may update this policy as the Service evolves. We will post the new version here and update the "Last updated" date; for material changes affecting Creators we will also give notice by email or in the dashboard.

14. Contact

For any privacy question or to exercise your rights, contact us at [email protected].