Privacy
What we collect, why we collect it, where it is kept and how to get rid of it. Written to be read rather than to be survived — if anything here is unclear, ask and we will fix the wording.
Last updated
Who this is about, and which of us is responsible
“We” is Urban Waves SRL, a company registered in Belgium at Avenue Château de Walzin 4, 1180 Uccle, under enterprise and VAT number BE 0717.595.706. EarlyGrooves is a trading name of that company — which is why a receipt or an invoice from us carries the company’s name and not the product’s.
EarlyGrooves is a tool for musicians, labels and their teams. There are two different kinds of person in it, and we hold a different responsibility for each.
If you have an EarlyGrooves account — an artist, a label, a manager — we decide what we do with your account data, so we are the controller of it and this notice describes our own handling.
If you are a fan on somebody’s mailing list, the artist or label you subscribed to decides what happens to your address. They are the controller; we run the machinery for them, which makes us their processor. We do not sell, rent or share those addresses, and we do not mail them for our own purposes. If you want to be removed from a list, the unsubscribe link in any message does it in one click, with no sign-in and no confirmation step. You can also write to us and we will pass it on.
Contact for anything on this page: privacy@earlygrooves.com.
What we hold
| What | Why |
|---|---|
| Your account | Email address, display name, handle, an optional bio and avatar, and a hashed password. Needed to have an account at all. |
| Sessions | A signed session so you stay logged in, and the date it was created. |
| Billing | Your plan, its status, and identifiers issued by Stripe. Card numbers never reach our servers — the payment form is Stripe’s and the card details go straight to them. |
| Your releases | Titles, artist names, artwork you upload, streaming links, tracklists and the text you write. This is the product. |
| Your subscribers | Each person’s email address, an optional name, when and how they joined, when they confirmed, and when they unsubscribed. Lists migrated from our previous platform also carry how many messages that person opened and clicked over the years. |
| What we sent | For each message: the address as it was at the time, whether it was delivered, and, if it failed, the receiving server’s own words for why. Kept so a send can resume without mailing anyone twice, and so a dead address is not tried forever. Links in a newsletter go through this site so that the first click on a message is recorded against it — a single timestamp, not a history: clicking twice records the same thing as clicking once, and which link was followed is not stored. It is how a creator can tell that a mailing arrived at all, since nothing here records whether a message was opened. The unsubscribe link is never routed this way. |
| Addresses that bounce | An address that a receiving mail server tells us no longer exists goes on a do-not-send list. It is kept as an address on its own, not attached to a person, which is what lets it survive a list being deleted and re-imported — the point being to stop mailing a mailbox that is gone. |
| Link page visits | See the next section. Deliberately the least we could record and still answer “how did this release do”. |
How we count visits, and what we do not keep
Fan link pages have no analytics cookie. There is nothing stored on a visitor’s device and nothing to agree to. What a visit records is:
- A one-day hash. The visitor’s IP address and browser string are hashed together under a secret that changes every day. Within a day it tells a returning visitor from a new one. Across days it tells us nothing, on purpose, and it cannot be turned back into an address.
- A country. Two letters, worked out from the IP address at the moment of the visit using a database on our own server. The IP address itself is never written down, here or anywhere else. No lookup leaves our machine.
- Where the visit came from — the site, not the page. We keep
instagram.comand throw away the rest of the address, because a full referrer can carry a search term or a session identifier and neither is any use for a figure that renders as a site name.
A creator’s own visits to their own pages are recorded and then excluded from their figures, so their numbers are about their audience rather than about them.
Advertising pixels, and the consent that gates them
A creator on a paid plan can connect a Meta, Google or TikTok advertising pixel to their own link pages, so that people who visited can be reached in a campaign they run. Those are the creator’s own advertising accounts and the creator’s own decision.
Nothing loads until the visitor agrees. Where a consent bar is required, the page shows one and the pixel is not merely held back from firing — the third-party script is not put on the page at all until the answer is yes. Declining leaves the page working exactly as it did.
The answer is remembered in your browser’s own storage under eg-ad-consent. It never reaches us, and it exists only so the same question is not asked on every page.
Cookies and browser storage
We use no advertising or analytics cookies of our own. The full list of what we set:
| Name | What it does |
|---|---|
| Session | Keeps you signed in. Strictly necessary; there is no site without it. |
eg-pending-verification | Remembers which address you are in the middle of confirming, so the “check your email” screen can name it. Short-lived. |
eg-catalog-view | Remembers whether you last used the grid or the list. |
eg_view_as | Set only for an administrator looking at an account to answer a support question, and only ever read-only. |
| Browser storage | Your light or dark preference, and the advertising answer above. Both stay in your browser. |
Who else sees any of it
| Who | What they get, and what for |
|---|---|
| OVH | Our servers and our database. They host it; they do not use it. See “Where it is kept” below. |
| Stripe | Payments, subscriptions and invoices. They receive your card details directly and we never do. |
| Resend | Account email only — confirming an address, resetting a password. They see the recipient and the message. |
| Our own mail server | Everything sent to a fan — newsletters, release announcements, confirmations. It is our machine, so no third party is involved in it. |
| Anthropic | Only if a creator asks the product to draft social copy, and only the release details they asked it about. It is off in every deployment today, and there is a plain template behind it that needs no model. |
| Meta, Google, TikTok | Only on a link page whose creator configured a pixel, and only after the visitor agrees. See above. |
Nobody else. We do not sell personal data, we do not share subscriber lists between creators, and there is no advertising network reading this site.
Where it is kept
Our servers and our database are run by OVH in Montréal, Canada. Uploaded artwork and outgoing mail are on the same machines.
That means personal data from the EU and the UK is transferred outside them. The European Commission has decided that Canada offers adequate protection for personal data handled by commercial organisations, which is the basis this transfer rests on. Stripe and Resend are US companies and handle transfers under their own published safeguards.
How long we keep it
We do not run an automatic deletion schedule. We would rather say that plainly than publish a number we do not actually enforce.
What that means in practice:
- Your account and everything in it stays until you delete it. Deleting your account really deletes it — releases, subscribers, statistics and the record of what was sent to whom.
- A subscriber you remove is removed. If their address had bounced, the address itself stays on the do-not-send list, because the point of that list is to stop mail going to a mailbox that no longer exists.
- Invoices are kept for as long as tax law requires, which is longer than anything else here and is not ours to shorten.
What you can ask us for
If you are in the EU or the UK you have the rights the GDPR gives you: to see what we hold, to correct it, to have it deleted, to take it elsewhere, and to object to particular uses. They apply wherever you are, because it is easier for everyone if we do not run two standards.
- Delete your account. In your settings, and it is a real deletion rather than a flag.
- Export your subscribers. On the subscribers page, as a file you can take anywhere.
- A copy of everything else. In your settings, under Your data, as a single file. It names every table it counts rather than copies — the ones holding other people’s addresses — and why. If you want those too, or anything the file does not answer, email privacy@earlygrooves.com and we will reply within 30 days.
- Stop receiving a creator’s mail. The unsubscribe link in any message. One click, no sign-in.
If you think we have handled your data badly, tell us first — and you can complain to the data protection authority where you live, whatever we say.
Security, briefly
Passwords are hashed and never stored in a form anyone can read. Traffic is over HTTPS. Mail we send is signed, so a receiving server can tell it really came from us. Access to the servers is limited to the people who run them.
No system is perfect. If you find something wrong with ours, please write to privacy@earlygrooves.com before telling anyone else, and we will take it seriously and quickly.
Age
EarlyGrooves is a tool for people releasing music commercially and is not aimed at children. We do not knowingly hold data about anyone under 16; if you believe we do, tell us and we will remove it.
If this changes
The date at the top is the date this was last revised. If we change something that materially affects you — a new recipient of your data, a new purpose — we will tell account holders by email rather than quietly editing the page.
See also our terms and the API documentation.