♪ BandSharp Song & gig management for bands
עב Back to the site
Legal

Privacy Policy - BandSharp

Last updated: 2026-09-17

This page explains what BandSharp holds, why, who can see it and for how long. There are two kinds of people here and the rules differ: people who signed up and use the app, and venue contacts - people who never signed up to us at all, whose details a band added to the shared venue list. Section 4 is about them.

1. What we hold about a user

The account itself holds very little: an email address, a display name, the reading language you chose, and created/updated timestamps. If you signed up with a password, the password itself is not stored - a bcrypt hash of it is, and it cannot be turned back into the password. Your band membership is stored too: which band, what role, and the name on that band's roster.

We hold no phone number, no address, no date of birth and no payment details. BandSharp has no checkout and no card processing - card details do not pass through us, are not stored by us and are never seen by us, for the simple reason that there is nowhere in the product to enter them.

When you appear to other users - who added a venue to the shared list, who uploaded a file, who confirmed a gig - only your first name is shown. Your full name stays on your own record and is shown to you on your own account screen. Your email address is not shown to other users.

2. Signing in, sessions and tracking

There are two ways in: email and password, or “Sign in with Google”. With Google, your browser loads a script from accounts.google.com and hands us an identity token; we request no permissions on your Google account at all - not your mail, not your calendar, not your files - and read only the email address, the name and the profile picture from it.

After signing in we issue a server-signed session token valid for 30 days. It is kept in your browser's localStorage, alongside your language preference. We use no cookies at all - not a session cookie, not a preference cookie, not an advertising cookie. That is also why this site has no cookie consent banner: there is nothing to ask consent for.

BandSharp runs no measurement or tracking of any kind. No Google Analytics, no Facebook pixel, no Hotjar, no error-reporting tool, no ad network. Our web server logs requests as any web server does - IP address, time, and the page asked for - and those logs are kept for 14 days and then deleted. Neither these documents nor the site loads any third-party script, other than the fonts from Google Fonts.

3. Your band's content

Songs, lyrics, chords, notes, setlists, gigs, the band's own venues, events and each player's personal preferences all belong to the band. They are not public, they are not shared with other bands, and we do not use them for anything else: we will not sell them, rent them, or train models on them. We access them only for support you asked for, for maintenance, or where the law requires it.

Audio recordings live both on the device and with us, so a player installing the app on a new device finds them there. They are stored per band, and every request for an audio file requires a signed-in member of that band. The one exception is a share link you created yourself - see section 7.

4. Venue contacts - data about people who are not BandSharp users

The shared venue list is the only place in BandSharp that holds information about a person who never signed up to us and agreed to nothing. A band adding a venue may fill in three fields that are a particular person's personal data: the contact's name, their phone number and their email address. Alongside them sit the venue's own details - name, area, city, address, capacity, entry type, genre, deal type, terms, links and notes.

Why it exists: so that a band can find a venue and approach it without every band rebuilding the same list. What is meant is professional contact details - the phone and email a person gives out for their work booking a venue - and not private ones. The screen says so explicitly before anything is added.

Who can see it: only a signed-in user, from a band that has the shared-venue module, and only after they have read and accepted the notice shown in the app. The list is never public. It has no public address, no share link, no token, no export endpoint and no anonymous view - anyone not signed in is refused before a single row is read, and so is anyone signed in who has not accepted the notice. Search engines cannot reach it at all.

How a person asks for their details to come down. Write to privacy@bandsharp.com with the venue's name and your own. You do not need an account, you do not need to be a customer, and you do not need to give a reason. We clear the three fields from the record, and we also delete the entries in that record's change history that still hold the old value - without that the deletion would be partial, because the history keeps previous values. We answer within a reasonable time, and in any case within the period the law sets. Any band member who can see the record can also clear those fields themselves, as an ordinary edit.

What we cannot do, said plainly: once a band has seen a detail, no deletion of ours removes it from their own notebook. We can take it out of our list and out of its history, and no further than that.

5. The list is community-edited, and a contribution carries a name

Every venue somebody adds, and every correction somebody makes, is visible to all the bands with access to the list. Each record shows who added it and who last edited it - by first name and date - and every change is recorded in that record's change log, field by field, with the previous value and the new one. The log is visible to the same people who can see the record, and it exists so a mistake can be corrected and a value deleted in error can be put back.

A user is shown this explanation before their first read of the list, not after, and chooses there whether they also contribute to it or only use it. We record which wording they accepted, when, on behalf of which band, and which browser was used. When the wording changes, we ask again.

6. The files you upload, and the link that sends them

A band's press kit - documents, images, whatever you upload - is stored on our server, per band. To send it to a venue you create a link: an address containing a 144-bit random token that cannot be guessed and cannot be reached without being given. The link serves only the files chosen into it, and only from the band that created it.

The link expires on its own - six months by default - and can be revoked instantly at any time, taking effect on the next read. When a file is deleted, the bytes are removed from disk and not only the database row, and any link that pointed at it stops serving it in the same instant.

Every opening of a link is recorded so the band can see the materials were opened: the time, the browser type, and a shortened IP address with its precise identity removed. We do not tell the band who opened it, because we do not know: a mail client's preview, a company's security scanner, a forwarded message, and the booker themselves all look the same.

7. The link that shares songs with a stand-in

When a band sends songs to a stand-in player, a read-only link is created with a 144-bit random token. It expires on its own after a number of days the band sets, can be revoked instantly, and is limited to one device: the first device to open it is bound to it, and any other is refused until the band's manager releases the binding.

On that device we keep a random identifier the browser generates, and the browser type, so the limit can be enforced. No IP address is stored. If the band entered the stand-in's email address in order to send them the link, it is kept with the link so the band knows who it went to.

8. Email - what leaves us and what does not

Outreach to a venue from the venue list is written in your own mail client and does not pass through us. BandSharp composes the letter, opens it in your own program with the recipient, subject and body already filled in, and from there it is your mail, from your address. We hold no copy and do not have the recipient.

Mail we do send: a welcome message, an invitation to join a band (carrying a one-time password for someone who has no account yet), a share link sent to a stand-in, and notices that an archive is about to be deleted. All of these go out from our own mail server, running on the same machine, and do not pass through an external mailing service.

Two paths do go through Google, and it is right to say so plainly: an invitation to a rehearsal or event sent to band members with a calendar file attached, and outreach to a venue sent from the gig screen by pressing “send”. Both go out through the Gmail interface from an ESK account, unless the band has set a sender address we hold a mailbox for - in which case they leave from our own mail server. In both cases the content of the message is what you wrote.

We send no marketing email from the app, and no address given to us for another purpose is on any list of ours.

9. Leaving a band - the archive

A player who leaves a band, or is removed from one, does not lose what they themselves put in. The songs they added, their recordings and their personal preferences move to a private archive of their own, which only they can see. The archive is kept for 182 days and then deleted.

Before the deletion three notices are sent: about a month ahead, about a week ahead, and a day ahead. Each says what will be deleted, when, and what to do to keep it. An archive we never managed to give notice of is not deleted - it is held aside and flagged for a person, because deletion without warning is not a retention policy, it is a loss.

10. Sub-processors, and where the data sits

Data is stored in Frankfurt, Germany - inside the EU. It is a single server: the site, the app, the database, the press-kit files, the recordings and the mail server all run on it.

Two suppliers are involved in running the service, and these are they:

  • Hostinger International Ltd - hosting for the server everything runs on.
  • Google - “Sign in with Google” for those who choose it, and the two mail paths described in section 8. On those two paths the message you wrote and the recipients' addresses do pass through Google, because that is what sending through it means. Beyond that, no content of your band's reaches Google - not songs, not recordings, not setlists, and not the venue list.
  • There is no payment processor, because there is no payment inside the product. There is no CDN, no external object storage, and no third-party library loaded from the network into the app.

11. How long we keep things

  • Account and band data - for as long as the account is active.
  • A leaver's archive - 182 days, after three notices.
  • A press-kit link - six months by default, revocable instantly. A song-share link - a number of days the band sets.
  • Web-server logs (IP address, time, page) - 14 days.
  • Backups - the database is backed up nightly, encrypted, kept for seven days, and a copy is pulled off the server. Something deleted is gone from the backups within those seven days.

12. Your rights

For anything to do with privacy: privacy@bandsharp.com. That address is open to people with no account too - especially a venue contact asking for their details to come down (section 4).

  • To see what we hold about you.
  • To have inaccurate information corrected.
  • To delete your account and what is in it.
  • To receive a copy of your band's content in a format readable elsewhere.
  • To object to any use of your information and to be told what is done with it.

13. Security, and a security incident

Traffic is encrypted end to end - the site and the app run over HTTPS only. The database is not exposed to the internet, and the application server itself listens only inside the machine, behind the web server. Passwords are stored as a bcrypt hash and nothing else. Backups are encrypted.

If a security incident affects your data we will tell you without undue delay: what we know, what we did, and what we recommend you do.

14. Changes to this document

If we change something material - what is collected, who can see it, or how long it is kept - we will say so in the app before the change takes effect. The date at the top of the page is the date this wording applies from.

ESK Marketing Services Ltd, company no. 516791738 · 5 Haasis St, Rishon LeZion 7549316, Israel · hello@bandsharp.com

♪ BandSharp
Privacy Policy Terms of Service hello@bandsharp.com
© 2026 BandSharp · made with love for live music