Last updated 2 August 2026
Privacy policy
This policy explains how VinylReach handles personal data when you use our music-promoter workspace, visit our public pages, or contact us.
Who is responsible
VinylReach is responsible for the account and service data described here. You can ask us about this policy or how your data is handled at the address below.
What we hold
We hold your account email and username; workspace records, contacts, notes, and settings; events, promoters, venues, artists, and contact evidence a Hunt discovers; request and support messages; session cookies needed to keep you signed in; and usage, token, and spend counters needed to run and protect the service. If you upload a profile picture for your record label, we hold that picture too until you remove it.
Signing in securely
If you set up a passkey, your device keeps the private key and we hold only the matching public key with a device label — a fingerprint or face check happens on your device, and that biometric data never reaches us. If you turn on an authenticator app, we hold its secret encrypted; recovery codes are stored only as hashed values and stop working once used. We also keep a tamper-evident record of security events on your account — sign-ins, second-factor prompts, password and email changes, and administrative actions such as suspending or restoring access. These records exist to protect the account, prove what happened, and meet our security duties, so they cannot be switched off while the account is open.
How and why we use it
We use this data to provide and secure your account and workspace, run Hunts, cross-reference and verify discovery evidence, manage contact and outreach work, deliver support, meter usage, prevent abuse, and improve reliability. Our legal basis depends on the activity and may be our contract with you, our legitimate interests in operating and securing VinylReach, a legal duty, or consent where we ask for it.
Emails we send you
VinylReach sends three kinds of email: transactional mail — sign-in codes, password resets, and security alerts — which keeps your account safe and is never optional; service mail — product announcements, service changes, and incident updates — which we send to existing accounts on the basis of our legitimate interests in keeping the service you use running and understood, and you can object at any time, which stops it without affecting transactional mail; and marketing mail — offers and upgrade news — which we send only if you opt in, at signup or later, and only for as long as your consent stands. To decide who receives a service or marketing email and when, we use signals already described elsewhere in this policy: how recently you logged in, your Hunt activity, and your plan tier. Every non-transactional email includes an unsubscribe link that is safe to use more than once — the first click stops that mail, and using it again changes nothing further. Transactional mail carries no unsubscribe link, because it cannot be switched off while your account is open.
Public-source discovery
VinylReach works by cross-referencing evidence across public sources. Events and promoter details from public listings are cross-referenced and verified before use. Verified public event evidence may enter a shared first-hunter library so the same fact can help more than one workspace; private notes, messages, and outreach stay scoped to the workspace.
Services that process data for us
Neon hosts our PostgreSQL database. Cloudflare serves and protects our public pages, so requests to VinylReach pass through it. IONOS delivers and receives our service email. We use Google for sign-in and optional Calendar sync, and Instagram or WhatsApp only when a workspace connects its own account. Each service receives only the data needed for that function. We may also disclose data when the law requires it or when needed to protect VinylReach and its users.
Optional connected accounts
A workspace chooses whether to connect Google Calendar, Instagram, or WhatsApp. A connection lets VinylReach exchange the data needed for the selected feature. Disconnecting stops new access but does not automatically erase records already saved in the workspace; use the in-app delete controls or contact support for that.
Royalty checking
When you ask us to check your catalogue, you give us the works you choose to enter — their titles, artists, and any ISRC, ISWC, or writer credits — and we check them against official public registries only on your request. We store the results in your workspace so you can act on them; we do not sell them and we do not share them with advertisers. The claim journey records only your own steps and the outcome of each check — never a payment or a private amount. This same on-request model — you ask, we check public sources, the results stay in your workspace, and nothing is sold — also covers any future checking of public set listings for where your music is played.
The writing assistant
Robin, our writing assistant, drafts outreach messages from your own workspace data and the voice you teach it. Each draft you request is metered and recorded in your workspace’s usage ledger, so you can see what was spent. We do not use your messages, contacts, or drafts to train any model, and we do not share them with other workspaces. The assistant is optional and can be turned off for your workspace.
Inbound replies
When someone you contacted answers through a private reply link, their reply threads into your workspace inbox. That link carries a token that we store only as a hashed value; it works once and expires after a limited time. A person replying this way needs no account with us — what we keep from them is the reply they send and basic delivery metadata, such as when it arrived, held in your workspace so you can continue the conversation.
No sale and no third-party ads
We do not sell personal data. We do not run third-party advertising, and we do not give advertisers your workspace data.
How long we keep data
We keep account and workspace data while the account is active and for as long as needed to provide the service, resolve support or security issues, and meet legal or accounting duties. In-app deletion and deletion requests are honoured. Limited backups or audit records may remain until they expire or are no longer needed for legal and security purposes.
Your data rights
UK data protection law may give you rights to access, correct, delete, restrict, or move your personal data, to object to some uses, and to withdraw consent. The right that applies depends on the circumstances. Use the in-app delete controls or contact support. You can also complain to the UK Information Commissioner’s Office at ico.org.uk.
Contact us
Email us with a privacy question or request. We may need to confirm your identity before changing or disclosing account data.
[email protected]