Privacy Policy

Last updated: June 11, 2026

This Privacy Policy explains how bandleader.app ("Bandleader," "we," "us," or "our") collects, uses, shares, and protects information when you use our website and admin application (the "Service"). By using the Service, you agree to the collection and use of information as described in this policy.

1. Who We Are

Bandleader.app is a tool for musicians and band leaders ("Band Admins") to run live shows, manage gigs and rehearsals, and let their audiences make song requests, sign up for karaoke, and tip the band.

2. Information We Collect

2.1 Account & Band Information

When a Band Admin creates an account, we collect information such as an email address, band/client name, and authentication credentials (managed via Firebase Authentication).

2.2 Band Member Data

Band Admins may invite other members (musicians, subs) to their band. We store each member's email address, display name, role (admin, member, sub), and scheduling-related data they provide, such as rehearsal/gig RSVPs.

2.3 Audience Interaction Data

Audience members interacting with a band's public gig page may submit song requests, karaoke sign-ups, names, and feedback/ratings. Where tipping is enabled, payments are processed by Stripe — we do not store full payment card numbers ourselves. To recognize a returning audience member's device across a show (e.g., for karaoke queue position or "top singers" stats), we store a randomly generated, non-personally-identifying device identifier in the visitor's browser (localStorage).

2.4 Content You Create

This includes setlists, song catalogs ("repertoire"), gig and rehearsal details, venue information, custom song properties, and similar content that Band Admins and members create within the Service.

2.5 Google Calendar Data (Optional)

If a band member chooses to connect their Google Calendar from the Availability page, we request access to the following Google API scopes:

  • Calendar Events (https://www.googleapis.com/auth/calendar.events) — used to create, update, and delete calendar events that correspond to that member's gigs and rehearsals, so they automatically appear on their personal calendar.
  • Calendar Free/Busy (https://www.googleapis.com/auth/calendar.freebusy) — used to read free/busy availability windows so the Service can flag potential scheduling conflicts with a member's existing personal calendar events.

We do not read the titles, descriptions, attendees, or other details of a member's existing personal calendar events — only their free/busy status, and the events that Bandleader itself creates for gigs/rehearsals. Calendar access tokens are stored securely and are accessible only to server-side processes; they are never exposed to the browser or to other band members.

A member can disconnect their Google Calendar at any time from the Availability page within the app, or by visiting their Google Account permissions page and revoking access. Disconnecting deletes the stored tokens and stops any further calendar sync.

Limited Use of Google user data. Data obtained through the Google Calendar scopes above is used only to provide the calendar-sync and availability-conflict features described in this section, and is not used for any other purpose. In particular:

  • Google user data is never used to train, develop, or improve any artificial intelligence or machine learning models, including the AI features used elsewhere in the Service (e.g., setlist or song-catalog assistance).
  • Google user data is never used for advertising, and is never sold, rented, or transferred to third parties or data brokers.
  • No human reviews Google user data except: (a) with the affected user's affirmative consent for a specific support request; (b) where necessary for security purposes, such as investigating abuse or a security incident; (c) to comply with applicable law; or (d) where the data has been aggregated and anonymized.

2.6 Usage & Device Information

We may collect standard technical information such as browser type, device type, and pages visited, to operate, secure, and improve the Service.

3. How We Use Information

  • To provide, operate, and maintain the Service (gig management, song requests, karaoke, tipping, scheduling).
  • To sync gig and rehearsal events to a connected member's personal Google Calendar and surface availability conflicts, if that feature is enabled.
  • To process payments and tips via Stripe.
  • To communicate with Band Admins about their account and the Service.
  • To maintain security, prevent abuse, and debug issues.
  • To generate aggregate statistics for Band Admins (e.g., earnings, song popularity, audience engagement).

We do not sell personal information, and we do not use Google user data for advertising or serving ads of any kind. Bandleader's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

4. How We Share Information

We share information only in the following circumstances:

  • Within a band: Band Admins can see information submitted by their band's members and audience (e.g., rehearsal RSVPs, song requests, earnings).
  • Service providers: We use third-party infrastructure providers, including Google Firebase (authentication, database, hosting) and Stripe (payment processing), to operate the Service. These providers process data on our behalf under their own privacy and security commitments.
  • Google Calendar: Calendar event data is sent only to Google, on behalf of the member who connected their account, to create/update/delete events on their own calendar.
  • Legal requirements: If required to comply with applicable law, regulation, legal process, or governmental request.

We do not sell or rent personal information to third parties.

5. Data Retention

We retain account and band data for as long as the account is active. Google Calendar tokens are retained until a member disconnects their calendar or deletes their account, at which point they are deleted. Audience device identifiers persist only in the audience member's own browser storage and can be cleared by clearing browser data.

6. Data Security

We use industry-standard tools (Firebase Authentication, Firestore security rules, and server-side-only access to sensitive tokens) to protect data against unauthorized access. No method of transmission or storage is 100% secure, but we work to protect your information using commercially reasonable safeguards.

7. Your Choices & Rights

  • You may request access to, correction of, or deletion of your personal information by contacting us (see below).
  • Band members can disconnect their Google Calendar at any time, as described in Section 2.5.
  • Band Admins can remove members or audience-submitted content from their band's data.

8. Children's Privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will post any changes on this page and update the "Last updated" date above.

10. Contact Us

If you have questions about this Privacy Policy or wish to exercise any of the rights described above, please contact us at [email protected].