LEGAL
Privacy Policy
What Dubrate collects, why, and how to get it erased.
Last updated · 2026-07-29
1. Who we are
The data controller for personal information collected through the Dubrate marketplace is Showday Tickets Ltd.
Address for service: 66 Paul Street, London, EC2A 4NA, United Kingdom
Data Protection contact: privacy@dubrate.co.uk. We have not appointed a Data Protection Officer; UK GDPR Art. 37 does not require one for processing at this scale.
Information Commissioner's Office (ICO) registration: ZC191208
2. What we collect
2.1 Account data
- Email address — required for authentication and receipts.
- Display name — optional, visible on public DJ profile pages.
- Password — stored as a salted hash by Supabase Auth.
- Discord user ID — only if you choose to link your Discord account, so that your subscriber role can be applied and removed in our Discord server.
2.2 Transactional data
- Purchases (track ID, price, date).
- Wallet balance + transactions (top-ups, debits, refunds, expiry).
- Subscription tier, status, billing period, rolling credit balance.
- Stripe Customer ID (you, the buyer) and Stripe Connect Account ID (you, the artist).
2.3 Behavioural data
- Tracks you wishlisted, followed, played.
- Crates you created and tracks you added to them.
- Search queries (retained 30 days).
- Follow-verification results — if an artist gates a free download on a Spotify or YouTube follow and you choose to verify it, we ask that platform whether you follow them and store the answer (which platform, which campaign, the date). We do not store your listening history, your follow list, or the access token afterwards.
- Access logs with IP address, approximate location (country/city from your network provider), device and browser, and the pages you request — retained 90 days, for security, fraud and abuse detection.
2.4 Seller-only data
- KYC information collected and processed by Stripe Connect under Stripe's privacy policy. Dubrate does not store or have access to your KYC documents.
- Copyright attestation log: timestamp, IP, user-agent, and the exact wording you agreed to at upload time. Retained for the life of the track plus 7 years (HMRC + dispute window).
2.5 Download and anti-piracy data
Each paid MP3 you download is stamped with a unique identifier that ties that copy of the file to your account, so a copy shared without permission can be traced back to where it came from.
- The identifier itself, and the track, order and order line it belongs to. The identifier carries no information about you — it is a lookup key into our own records.
- One entry per time the download is issued: the date and time, a salted hash of your IP address (never the address itself) and your browser's user-agent string.
- Purpose: attributing a leaked file to the account it was issued to, so artists' copyright can be enforced. It is not used to profile you, to price anything, or for marketing. Lawful basis: legitimate interests (section 3) — you can object under Art. 21 by emailing privacy@dubrate.co.uk.
3. Why we collect it (lawful basis)
Under UK GDPR / Data Protection Act 2018:
- Contract — to fulfil your purchases, deliver downloads, manage subscriptions, pay sellers.
- Legitimate interest— to operate the platform, prevent fraud, improve features, and attribute leaked files to the account they were issued to so that artists' copyright can be enforced (section 2.5). Where we rely on legitimate interests you can object under Art. 21 and we will stop unless we can show compelling grounds to continue.
- Legal obligation — to comply with HMRC tax reporting, anti-money-laundering checks (via Stripe Connect), and DMCA/CDPA notice handling.
- Consent — for marketing emails, which you opt into separately and can withdraw at any time. We do not rely on consent for cookies because we set no non-essential ones (section 7).
4. Who we share it with
These are the processors that handle your data on our instructions:
- Supabase(Ireland / EU region) — hosting our database, auth, and storage. Any processing outside the UK is covered by the transfer terms in Supabase's data processing agreement (see section 8).
- Stripe — payments + Connect platform. Stripe processes your payment data; Dubrate never sees your card number.
- Resend (United States) — delivery of transactional email: order receipts, wallet top-up confirmations, campaign notices and the newsletter welcome. Resend receives your email address and the full content of the message we send you. See section 8 for the transfer position.
- Hetzner Cloud (Germany / EU) — hosts the web application servers.
- Sentry — error reporting. Personal data is scrubbed from error contexts.
These are not our processors. They act as controllers in their own right, under their own privacy notices — either because they are the merchant on the payment, or because you chose to connect an account:
- Apple and Google(United States) — if you top up your wallet inside the mobile app, the app store takes the payment and is the merchant on it, under its own terms and privacy notice. To credit your wallet we send the receipt the store issued back to that store to confirm it is genuine, and we keep the store's transaction reference so the same receipt cannot be credited twice. We do not send them your Dubrate email address or your library.
- Discord (United States) — if you link your Discord account, we send Discord your Discord user ID and the role changes to apply to it, so that your subscriber role tracks your tier. Unlink at any time from your account settings; we delete the stored ID when you do.
- Spotify, and Google for YouTube — if an artist gates a free download on a follow and you choose to verify it, you sign in with that platform and we ask it a single question: do you follow this artist or channel. We keep the yes, and the access token is discarded at the end of the request. We do not read your library, playlists or watch history.
We do not sell your personal data. We do not share with advertisers.
5. Retention
- Financial records (orders, invoices, payouts): 6 years (HMRC requirement).
- Account data: until you delete your account + 30 days for finalising any pending operations.
- Search queries: 30 days.
- Access logs (IP, location, device, pages requested): 90 days.
- Copyright attestation log: life of track + 7 years (dispute retention).
- Download identifiers and the download log (section 2.5): kept for as long as your account exists. They are tied to your account in the database and are deleted with it. They are deliberately not deleted when a track is delisted or a download is revoked, because a file that leaks years later still has to be traceable to the copy it came from.
- Free-download follow verifications: kept for as long as the artist's campaign exists, and deleted with your account.
6. Your rights
Under UK GDPR you can:
- Access the personal data we hold about you.
- Correct anything that's wrong.
- Erase data we hold (subject to financial-records retention above).
- Export your data in a portable format.
- Object to or restrict processing.
- Withdraw consent (where consent is the lawful basis).
Request any of the above by emailing privacy@dubrate.co.uk. We respond within 30 days as required by UK GDPR Article 12.
If you're not satisfied with our response you have the right to complain to the Information Commissioner's Office (ico.org.uk).
7. Cookies
Every cookie Dubrate sets is strictly necessary — each one exists to sign you in or to stop a request being forged. They are all first-party and all HTTP-only, so page scripts cannot read them:
sb-ufxydkkprgjlovdqcjpr-auth-token(andsb-ufxydkkprgjlovdqcjpr-auth-token.0,sb-ufxydkkprgjlovdqcjpr-auth-token.1when the value is too long for one cookie) — your signed-in session, set by Supabase Auth. Expires 30 days after your last token refresh, or when you sign out.pw_recovery— set only when you follow a password-reset link, so the reset page can tell a recovery session from an ordinary one. Lasts 15 minutes.dc_oauth_nonce— set only while you are linking a Discord account, to prove the request coming back from Discord is the one you started. Lasts 10 minutes and is deleted on return.fd_oauth_nonce— the same protection while you verify a Spotify or YouTube follow for a free download. Lasts 10 minutes and is deleted on return.sb-ufxydkkprgjlovdqcjpr-auth-token-code-verifier— set when you sign up, request a magic link, or request a password reset. It holds the one-time verifier that proves the link you clicked belongs to the request you made (PKCE), so someone else's link cannot be used to sign in as you. It is deleted as soon as you use the link, and when you sign out. If you never use it, it is overwritten the next time you ask for one of those links, and otherwise expires 30 days after it is set.
We set no analytics, advertising, tracking or other non-essential cookies, so there is no consent banner and nothing for you to opt in or out of. We store nothing in your browser's local or session storage either. Paying is done on Stripe's own hosted checkout pages: any cookie set there is Stripe's, on Stripe's domain, under Stripe's privacy notice. If we ever add analytics, a PECR-compliant banner that asks first will ship before the first analytics cookie is set — not after.
8. International transfers
All primary processing happens in EU/UK regions. Where data is transferred to a processor outside the UK — including Resend and Sentry, both in the United States — we rely on the transfer mechanism in that processor's own data processing agreement: the ICO's International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses. The EU Standard Contractual Clauses alone are not a valid UK transfer mechanism, so we do not rely on them.
Apple, Google, Discord and Spotify are different: they are not our processors (section 4). Data reaches Apple or Google in the United States when we check an in-app top-up receipt with the store that issued it, and reaches Discord, Spotify or Google (YouTube) because you chose to connect that account. Those transfers happen under their own notices and their own safeguards, not ours.
You can ask for a copy of the safeguards that apply to a particular transfer by emailing privacy@dubrate.co.uk.
9. Children
Dubrate is not directed at children under 16. We do not knowingly collect personal data from children. If you believe we have, email privacy@dubrate.co.uk and we'll erase it.
10. Changes
We'll notify you of any material change at least 30 days in advance via email.