Privacy Policy
We collect only what we need to run the platform. We do not sell your data, we do not currently run advertising, and you can delete your account and all associated data at any time. We use Google Analytics 4 only after you give explicit consent through the cookie banner — never without it. This policy explains exactly what we collect, why, on what legal basis, and what you can do about it.
1. Introduction
Welcome to Band in Tour. Whether you are a band, a venue, a promoter or a music fan, the respect of your privacy is important to us.
This Privacy Policy describes how Band in Tour ("we", "us", "our") collects, uses and protects your personal data when you use our platform and services. It has been written in compliance with Regulation (EU) 2016/679 ("GDPR"), Directive 2002/58/EC ("ePrivacy"), Regulation (EU) 2022/2065 ("Digital Services Act" or "DSA") and applicable Italian data-protection law (D.lgs. 196/2003 as amended by D.lgs. 101/2018).
This policy applies to personal data collected through bandintour.com and any related pages or services operated by us. It does not apply to third-party websites you may reach through links on our platform.
2. Definitions
- Personal data: any information relating to an identified or identifiable natural person (name, email address, location, online identifier, etc.).
- Services: all features and functionalities made available through bandintour.com, including event discovery, profile management, the Live Music Club, the Live Music Club Agenda, the support and reporting system, and (when activated) the boost and membership system.
- User: any visitor or registered individual on the platform, including bands, venues, promoters and fans.
- Profile: the registered account and public page associated with a User on Band in Tour.
- Processing: any operation performed on personal data, whether automated or not, including collection, storage, use, disclosure and deletion.
- GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
- DSA: Regulation (EU) 2022/2065 of 19 October 2022 on a Single Market for Digital Services.
3. Data Controller
The data controller is IOCOS di G.C. (P.IVA 02758080804), with registered office at Via F. Baracca traversa De Salvo 15, 89123 Reggio Calabria, Italy. Band in Tour is developed under the Sunakoma project; legal responsibility for processing rests with IOCOS di G.C.
We are not required to appoint a Data Protection Officer (DPO): under Article 37 of the GDPR that obligation arises only where our core activities consist of large-scale, regular and systematic monitoring of individuals, or large-scale processing of special categories of data, or where we are a public authority — none of which applies to our processing. (Separately, for Digital Services Act purposes, Band in Tour qualifies as a micro/small enterprise online platform within the meaning of Article 19 of the DSA; that status concerns DSA transparency and moderation obligations, not the GDPR DPO requirement.) Our designated point of contact for privacy matters and for Member State authorities is:
- Privacy matters: privacy@bandintour.com
- Legal and authority requests: legal@bandintour.com
- Working language: English and Italian
4. Personal Data We Collect
The data we collect depends on how you use the platform.
4.1 All visitors
- Aggregate usage data (pages visited, time on site) derived from our own server logs.
- Analytics (Google Analytics 4) — only with your consent. If, and only if, you click "Accept all" in the cookie banner, we load Google Analytics 4, which collects aggregate usage data (pages visited, session duration, traffic sources, approximate location) through cookies. It is never loaded if you decline or before you choose, and you can withdraw consent at any time. Full details, including the provider and international transfers, are in our Cookie Policy.
- Technical data: browser type, device type, approximate country (derived from IP address). IP addresses are used only for rate limiting and anti-abuse and are automatically purged after 30 days.
- Data collected through cookies and local storage, as described in our Cookie Policy.
4.1.1 Third-party technical services
Two technical third-party services are already in use to make specific features work. They are not analytics or advertising services and run only when the relevant feature is used.
- hCaptcha (bot protection): used on registration, contact and report forms to distinguish humans from automated bots. Provided by Intuition Machines, Inc. (USA). When the widget loads it may set its own storage and processes your interaction with the challenge to assess whether you are human, as described in the hCaptcha Privacy Policy. Because the provider is established in the United States, this involves a transfer of data outside the EEA (see Section 6).
- Nominatim / OpenStreetMap (address geocoding): when you enter an address (for example registering a venue or creating an event), the address text is sent to Nominatim to obtain the map coordinates, so the location can be shown on the map. Operated by the OpenStreetMap Foundation (United Kingdom, covered by a European Commission adequacy decision). See the OpenStreetMap Foundation Privacy Policy.
4.2 Registered users (all roles)
- Required at registration: username (public alias), email address, password (stored as a bcrypt hash, never in plain text), role (band / venue / promoter), city.
- Optional profile data: display name, biography, profile photo, trailer or video link, genre tags, repertoire type, social media links.
- Location data (venues): full address and GPS coordinates, used to display your venue on the map. This data is public.
- Session data: a JWT token stored in your browser's localStorage, used to authenticate your requests. It expires after 24 hours.
4.3 Event data (bands, venues, promoters)
- Event details you publish: band name, event type, date, venue, city, GPS coordinates, ticket link, and (Pro Members only) event flier image.
- Participation in events as a linked profile (band, venue or promoter role on an event).
- Availability dates you set on your calendar (visible to registered users in the Live Music Club; the Live Music Club Agenda is available to Pro Members only when that feature is activated).
4.4 Activity data (all registered users)
- Support actions ("heart") on events.
- Abuse reports submitted through the platform, including the reason text you provide.
- Membership status (free or Pro) and the date it was activated.
- Inputs and outputs of the transparent ranking algorithm (profile links, support votes, activity, boost tier where applicable, crowdfunding badge).
4.5 Interest and recommendation data
- City preferences: up to three cities you choose to follow (stored with display name and GPS coordinates).
- Genre preferences: musical genres you select from our standard list.
- Band type filter: whether you want to see local acts, touring bands, or international artists in your recommended feed.
- Recommendation history: the timestamp of your last visit to the "Recommended for you" section, used solely to compute the notification badge.
- Newsletter opt-in: your choice to receive the biweekly recommendation email. You can withdraw consent at any time from Profile > Settings.
All interest data is voluntary and can be deleted at any time from your Profile settings or by contacting us.
4.6 Membership and payment data (future)
Stripe is our designated payment provider for Pro Membership and Boost purchases. Payment processing is not yet active on the platform: no card or transaction data is currently collected. When payments go live, all card data will be handled directly by Stripe and will never transit through or be stored on our servers. We will retain only the record of the tier purchased, the associated event or subscription, the expiry date and the fiscal invoice data required by Italian tax law. This section will be updated, and where required additional consent collected, before the payment feature is activated.
4.7 Push notifications (future)
Browser push notifications are not yet active: no push data is collected today. When this feature is activated, enabling it will first require your browser's own native notification permission, which you must accept. If you do, we will store a push subscription endpoint provided by your browser, associated with your account, used solely to deliver the notifications you have asked for (such as nearby availability or events). You will be able to disable notifications at any time from your browser or your account settings. This section will be updated before the feature goes live.
4.8 Sponsorship and advertising (future)
We do not currently run advertising. Two future possibilities are anticipated here for transparency:
- Programmatic advertising (Google AdSense): if activated, contextual ads shown only to non-paying users (Pro Members would see no ads), loaded only after a renewed consent request. The cookie aspects are described in our Cookie Policy.
- Direct sponsored content: separately from programmatic advertising, we may host content or placements agreed directly with a sponsor (for example a musical-instrument brand or a festival). This is a direct commercial relationship, not third-party ad targeting. If and when we introduce it, we commit to clearly and prominently labelling such content as sponsored, so that its commercial nature is immediately recognisable, in line with Directive 2005/29/EC (as amended by the "Omnibus" Directive (EU) 2019/2161) and Article 26 of the DSA. The exact form is not yet decided and this Policy will be updated before any such content goes live.
5. Purposes and Legal Bases
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Creating and managing your account and profile | Contract performance (Art. 6.1.b) |
| Publishing and displaying events on the platform and map | Contract performance (Art. 6.1.b) |
| Authenticating your session securely (JWT) | Contract performance (Art. 6.1.b) |
| Sending service emails (account confirmation, event approval or rejection notifications) | Contract performance (Art. 6.1.b) |
| Processing boost and membership purchases and managing membership status (when activated) | Contract performance (Art. 6.1.b) |
| Displaying your availability to other users in the Live Music Club | Contract performance (Art. 6.1.b) |
| Operating the report/abuse mechanism and applying moderation decisions | Legal obligation (Art. 6.1.c — DSA Art. 16/17) and contract performance (Art. 6.1.b) |
| Anti-abuse, rate limiting and platform security | Legitimate interest (Art. 6.1.f) |
| Platform analytics and improvement (aggregated, anonymised data from our own server logs only) | Legitimate interest (Art. 6.1.f) |
| Analytics via Google Analytics 4 (only with your consent) | Consent (Art. 6.1.a) — withdrawable at any time; never loaded without consent |
| Bot protection on forms via hCaptcha (registration, contact, reports) | Legitimate interest in protecting the platform from bots, spam and abuse (Art. 6.1.f). Where the protected form is a necessary step to obtain a service you requested (e.g. registration), the related processing is also supported by contract performance (Art. 6.1.b). We have carried out a Legitimate Interest Assessment for this use of hCaptcha, available on request at privacy@bandintour.com |
| Geocoding addresses you enter, via Nominatim/OpenStreetMap, to display the location on the map | Contract performance (Art. 6.1.b) |
| Issuing fiscal invoices and complying with accounting obligations (when payments are activated) | Legal obligation (Art. 6.1.c — Italian fiscal law) |
| Responding to legal requests and managing disputes | Legal obligation (Art. 6.1.c) / Legitimate interest (Art. 6.1.f) |
| Providing personalised recommendations ("Recommended for you") based on your interest preferences | Consent (Art. 6.1.a) — interests are optional and can be removed at any time |
| Sending the biweekly recommendations newsletter and admin newsletters (if opted in) | Consent (Art. 6.1.a) — opt-out available in every email and in Profile > Settings |
| Optional marketing communications (if you explicitly opt in) | Consent (Art. 6.1.a) |
6. Recipients of Your Data
We do not sell, rent or share your personal data with third parties for commercial or marketing purposes. Our core hosting, database and email infrastructure is located within the European Economic Area. However, some third-party services we use are operated by providers outside the EEA: when you consent to Google Analytics 4, and when you interact with the hCaptcha anti-bot widget, data may be transferred outside the EEA. Such transfers take place under the safeguards required by Chapter V of the GDPR (such as standard contractual clauses or equivalent frameworks adopted by the provider); the specific mechanism for each provider is described in that provider's own privacy policy, linked below. We have carried out a Transfer Impact Assessment for these extra-EEA transfers, available on request at privacy@bandintour.com.
Your data may be disclosed to, or processed by, the following recipients:
- Internal team: authorised team members of IOCOS di G.C. and the Sunakoma development team who need access to operate and maintain the platform (development, support, moderation), under confidentiality obligations.
- Hosting and infrastructure: the EU-based servers and database services that store platform data operate as data processors under written agreements compliant with GDPR Art. 28.
- Email delivery: we use a transactional email service to send service notifications and newsletters. Only your email address and the content of the message are shared with that processor.
- Analytics (only if you consent): Google Ireland Limited (with Google LLC, USA, as possible sub-processor) processes Google Analytics 4 data, but only after you click "Accept all" in the cookie banner. This may involve a transfer outside the EEA under Chapter V GDPR safeguards. See Google's Privacy Policy.
- Bot protection: Intuition Machines, Inc. (hCaptcha, USA) processes your interaction with the anti-bot widget on protected forms. This involves a transfer outside the EEA under Chapter V GDPR safeguards. See the hCaptcha Privacy Policy.
- Geocoding: the OpenStreetMap Foundation (Nominatim, United Kingdom) receives the address text you enter in order to return map coordinates. The UK is covered by a European Commission adequacy decision. See the OpenStreetMap Foundation Privacy Policy.
- Payment provider (when activated): Stripe will act as an independent controller for card data and as a processor for invoice metadata. Until the payment feature is live, no data is transferred to Stripe.
- Other users: information you publish on your profile (name, alias, city, bio, genre, events, social links) is public and visible to all visitors. Availability dates are visible to registered users. Support actions are publicly counted.
- Legal authorities: we may disclose personal data if required by law, court order or a request from a competent authority (including DSA points of contact, judicial police, supervisory authorities), or to protect the rights and safety of the platform and its users.
7. Data Retention
- Account and profile data: retained while your account is active. Permanently deleted within 30 days of an account deletion request.
- Events: deleted events are soft-deleted and permanently removed from the database after 90 days.
- Uploaded images (avatar, event flier): deleted from our servers immediately when you replace or remove them. Event flier images are automatically deleted when the event date passes.
- IP and rate-limit logs: automatically purged after 30 days.
- Abuse reports and moderation records: retained for 12 months after the report is closed, to allow appeal and accountability under the DSA, then deleted.
- Internal admin audit logs: actions performed by platform administrators (such as content moderation decisions and access events) are logged for security and accountability purposes and automatically deleted after 12 months, in line with ENISA guidance and the NIS2 Directive (Directive (EU) 2022/2555).
- Payment and fiscal records (when activated): retained for the period required by Italian fiscal and accounting law (generally 10 years), in a restricted archive accessible only for tax, audit or legal-defence purposes.
- Availability dates: deleted when you remove them from your calendar, or when your account is deleted.
- Newsletter subscription record: retained while you remain subscribed; the proof of opt-in is kept for a further 12 months after unsubscription to demonstrate lawful processing.
8. Your Rights Under the GDPR
If you are located in the EU or EEA, you have the following rights regarding your personal data:
- Right to access: request a copy of the personal data we hold about you.
- Right to rectification: correct inaccurate or incomplete data. Most profile data can be updated directly from your account settings.
- Right to erasure ("right to be forgotten"): request the deletion of your personal data. You can delete your account directly from the platform settings.
- Right to restriction: request that we limit the processing of your data in certain circumstances.
- Right to data portability: receive a copy of your data in a structured, commonly used and machine-readable format. We currently do not offer an automated export tool; on written request to privacy@bandintour.com we will prepare and deliver your data within 30 days.
- Right to object: object to processing based on our legitimate interest.
- Right to withdraw consent: where processing is based on your consent (such as the recommendations newsletter or interest-based personalisation), you may withdraw it at any time and free of charge, without affecting the lawfulness of processing carried out prior to withdrawal.
- Right not to be subject to automated decision-making: we do not take decisions that produce legal or similarly significant effects based solely on automated processing. The ranking algorithm is transparent and does not exclude users from any feature.
To exercise any of these rights, contact us at privacy@bandintour.com. We will respond within 30 days. We may need to verify your identity before processing the request.
You have the right to lodge a complaint with the Italian Garante per la protezione dei dati personali (garanteprivacy.it) or with the supervisory authority of your country of residence.
9. Cookies and Local Storage
We use first-party essential technical cookies and local-storage items required to operate the platform (session management, CSRF protection, login token, consent preference). These are always active and exempt from consent. We also use Google Analytics 4, but only after you give explicit consent through the cookie banner — it is never loaded without your consent, and you can withdraw it at any time. We do not currently use advertising cookies.
For full details — including how Google Analytics 4 is loaded only on consent, the functional third-party services (hCaptcha, Nominatim/OpenStreetMap), and the planned future activation of Google AdSense and Web Push notifications — see our Cookie Policy.
10. Security
We apply appropriate technical and organisational measures to protect your personal data:
- Passwords are hashed using bcrypt and never stored in plain text.
- All communication between your browser and our servers is encrypted via HTTPS (TLS).
- Session tokens (JWT) are signed and expire after 24 hours.
- Uploaded files are validated for type and size before storage.
- Admin access to the platform is segregated and protected by separate authentication and audit logging.
- Rate limiting and input validation protect against brute force, injection and abuse.
No system is completely immune from risk. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Italian Garante within 72 hours and, where the risk is high, communicate the breach to affected users without undue delay, as required by GDPR Art. 33 and 34.
11. Minors
Band in Tour is not directed at minors. Under Article 8 of the GDPR the default age for a child to consent to information-society services is 16, which Member States may lower to no less than 13; Italy, through D.lgs. 101/2018, has set this threshold at 14 years. As a matter of our own policy we go beyond the Italian minimum and require users to be at least 16 years old to register on the platform. This is a voluntary editorial choice on our part, more restrictive than the Italian legal minimum, not a requirement imposed by Italian law. If we become aware that we have collected personal data from a person below this age without appropriate parental consent, we will delete it promptly. As required by Article 28 of the DSA, where minors do access the platform we apply appropriate and proportionate measures to ensure a high level of privacy, safety and security for them — including not directing advertising or profiling at users we know to be minors. If you believe a minor has registered on our platform, please contact us at privacy@bandintour.com.
12. Third-Party Links
Profiles on Band in Tour may contain links to external websites (social media, artist websites, streaming platforms, ticket vendors). We are not responsible for the privacy practices of those third-party services. We encourage you to read their privacy policies before sharing any personal data with them.
13. Changes to This Policy
We may update this Privacy Policy to reflect changes in the law, our services or our data practices. If we make material changes — including before activating Stripe payments, Google AdSense, Web Push notifications or direct sponsored content — we will notify registered users by email and update the version date at the top of this page. Continued use of the platform after the effective date of changes constitutes acceptance of the updated policy.
14. Contact
For any questions, requests or concerns regarding this Privacy Policy or your personal data:
- Privacy: privacy@bandintour.com
- Legal and authority requests: legal@bandintour.com
- Postal address: IOCOS di G.C., Via F. Baracca traversa De Salvo 15, 89123 Reggio Calabria, Italy
- Supervisory authority: Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Roma — garanteprivacy.it