Privacy Policy
Last updated: 02 Sep 2025
Who we are: TuneGate (Soothing Soundwave) (“TuneGate”, “we”, “us”, “our”)
Contact: office@soothingsoundwave.com
1) What we collect
- Submission data: email address, the Spotify track URL you submit, the playlist you listened on, the target playlist you choose, your IP address, the listening mode (premium/free), timestamps, and submission status (new/accepted/denied).
- Captcha: hCaptcha may process your IP address, device/browser details and a challenge response to prevent abuse.
- Playback/auth (when applicable): if you connect Spotify, we receive an access token to enable playback and read basic account info (e.g., whether the account is Premium). We do not store your Spotify password.
- Logs: limited technical logs (e.g., mail delivery logs, hCaptcha verification logs) for reliability and security.
- Admin data: if you email us or we email you about a submission, we process that correspondence.
We do not collect payment data. We do not sell personal data.
2) How we use data
- To operate the gating flow (listen → unlock → submit) and manage your submission.
- To verify you’re human (hCaptcha) and prevent abuse.
- To send transactional emails (submission received / accepted / not accepted) and admin notifications about new submissions.
- To troubleshoot, secure our service, and improve reliability.
3) Legal bases (EEA/UK users)
- Performance of a contract: processing needed to receive and evaluate your submission.
- Legitimate interests: prevent abuse, ensure security and service quality.
- Consent: where required (e.g., hCaptcha challenge, optional marketing if ever added).
4) Sharing & third parties
We share data only with service providers that help us run TuneGate:
- Spotify — playback in the official Spotify player or via approved SDKs; subject to Spotify’s Terms and Privacy Policy.
- hCaptcha — bot protection (privacy‑first CAPTCHA).
- Email delivery/hosting — SMTP or email provider to send transactional emails; web hosting for our app and databases.
These providers act as processors on our behalf where applicable. We do not sell or trade your data.
5) Cookies & tracking
We use only what’s necessary to run the app (session/security cookies). No advertising trackers. hCaptcha may set cookies strictly to detect abuse.
6) Retention
- Submissions: kept while your track is under review and for up to 24 months thereafter (or longer if needed for legitimate business/legal reasons).
- Captcha & server logs: typically 30–90 days.
- Emails: operational copies in sent/received mailboxes per our normal retention.
You can request deletion (see Your rights).
7) Security
We use reasonable technical and organizational measures (TLS encryption, access controls, least‑privilege, prepared statements) to protect your data. No method is 100% secure.
8) Your rights
Depending on your location, you may have the right to access, correct, delete, object to or restrict processing, and port your data. To exercise these rights, contact office@soothingsoundwave.com. We will verify your request and respond as required by law.
9) International transfers
If data is processed outside your country (e.g., by our providers), we rely on appropriate safeguards (such as Standard Contractual Clauses) where required.
10) Children
TuneGate is not intended for children under 16. We do not knowingly collect data from children. If you believe a child has provided data, contact us to delete it.
11) Changes
We may update this Policy from time to time. The “Last updated” date shows the latest revision. Significant changes will be posted in the app.
12) Contact
If you have questions or requests about this Policy, email office@soothingsoundwave.com.