IndieThis← Back to home

Legal

Privacy Policy

Last Updated: April 2026

1. Information We Collect

Account Information: Name, email address, password (hashed), profile photo, artist/stage name, genre, city/location, bio, social media links, phone number (for studios). If you sign up via Google or Facebook, we receive your name, email, and profile photo from those services.

Payment Information: Billing details are processed by Stripe. We do not store credit card numbers, bank account details, or payment credentials on our servers. Stripe Connect account information is stored for users who set up payouts (DJs, producers, affiliates).

Content You Upload: Music files, cover art, videos, canvas videos, merch designs, sample packs, session files, documents, and any other files you upload to the Platform.

Audio Data: When you upload audio, we automatically analyze it to extract acoustic fingerprints, BPM, musical key, and audio features (energy, danceability, valence, acousticness, instrumentalness, speechiness, liveness, loudness). This data is used for platform features and stored alongside your content.

Usage Data: Pages visited, features used, tracks played, searches performed, buttons clicked, AI tools used, time spent on pages, device type, browser type, IP address, referring URLs.

Communication Data: Email campaigns sent, SMS broadcasts sent, fan contacts, booking inquiries, intake form submissions, invoice communications.

Transaction Data: Purchases, sales, subscriptions, PPU charges, merch orders, beat licenses, fan funding transactions, DJ earnings, affiliate commissions, withdrawal history.

2. How We Use Your Information

We use your information to: operate and maintain your account; process payments and payouts; provide AI-powered tools and services; display your public profile and content; send transactional emails (receipts, confirmations, notifications); send marketing emails you opted into; run platform agents that provide recommendations and alerts; calculate quality scores and rankings for the explore page; match artists with producers, collaborators, and opportunities; detect and prevent fraud, abuse, and terms violations; analyze platform usage to improve features; generate anonymized aggregate analytics.

3. Information We Share

Public Information: Your artist name, bio, genre, city, social links, profile photo, track titles, cover art, and merch listings are publicly visible on your profile page. Play counts and "Picked by DJs" badges are publicly visible.

With Service Providers: We share data with third-party services that help operate the Platform: Stripe (payment processing), Brevo (email and SMS), Printful (merch fulfillment), Uploadthing and AWS S3 (file storage), Supabase (database), Vercel (hosting), ACRCloud (audio fingerprinting), AudD (content recognition), Anthropic Claude (AI text generation), fal.ai (AI image and video generation), Replicate (vocal removal, transcription), PostHog (analytics and error tracking).

With Buyers: When someone purchases your music, merch, or beats, they receive your artist name, track/product information, and download access. For self-fulfilled merch orders, buyers receive shipping updates from you.

With Studios: When you submit an intake form or booking request, the studio receives the information you provided in the form.

With DJs: DJs can see tracks in their crates and public track information. DJs do not see which artists have opted into DJ discovery attribution or the attribution percentage.

We Do Not Sell Your Data. We do not sell, rent, or trade your personal information to third parties for their marketing purposes.

4. Data Storage and Security

Your data is stored on servers operated by Supabase (PostgreSQL database) and AWS (file storage) in the United States. We use encryption in transit (HTTPS/TLS) and follow security best practices. Passwords are hashed using bcrypt and never stored in plain text. OAuth users (Google, Facebook) do not have passwords stored. While we take reasonable measures to protect your data, no method of electronic storage is 100% secure.

5. Your Rights and Choices

Access and Download: You can access your account data through your dashboard at any time. You can download your uploaded content at any time.

Update: You can update your profile information, bio, social links, and settings through your dashboard.

Delete: You can request account deletion by contacting us at info@indiethis.com. Upon deletion, your public page will be taken offline, your content will be removed within 30 days, and your personal data will be purged from our systems except where retention is required by law or for completed transactions.

Email Opt-Out: You can unsubscribe from marketing emails using the unsubscribe link in any email. Transactional emails (receipts, security alerts, payment notifications) cannot be opted out of while you have an active account.

SMS Opt-Out: Reply STOP to any SMS message to unsubscribe from SMS communications.

6. Cookies and Tracking

We use cookies and similar technologies for: session management (keeping you logged in), DJ attribution tracking (30-day attribution cookies), analytics (PostHog), preference storage (popup dismissals, settings). We do not use third-party advertising cookies. We do not display ads on the Platform.

7. Children's Privacy

IndieThis is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If we learn that we have collected data from a user under 18, we will delete that information promptly.

8. California Residents (CCPA)

If you are a California resident, you have the right to: know what personal information we collect and how it is used; request deletion of your personal information; opt out of the sale of personal information (we do not sell your data); not be discriminated against for exercising your privacy rights. To exercise these rights, contact us at info@indiethis.com.

9. International Users

IndieThis is operated in the United States. If you access the Platform from outside the US, your data will be transferred to and processed in the United States. By using the Platform, you consent to this transfer.

10. Data Retention

We retain your account data for as long as your account is active. After account deletion, personal data is purged within 30 days except: transaction records (retained for 7 years for tax and legal compliance), anonymized analytics data (retained indefinitely), content involved in completed purchases (retained for buyer access).

11. Third-Party Links

The Platform may contain links to external websites (Spotify, Apple Music, Instagram, TikTok, YouTube, etc.). We are not responsible for the privacy practices of external sites. Review their privacy policies before sharing information with them.

12. Facebook Data

If you sign up or log in with Facebook, we receive your name, email, and profile photo. We use this only for account creation and profile display. You can request deletion of your Facebook-connected data at any time. We provide a data deletion callback endpoint as required by Meta's platform policies.

13. Changes to This Policy

We may update this Privacy Policy at any time. Material changes will be communicated via email and in-app notification. The "Last Updated" date at the top reflects the most recent revision.

14. Contact

For privacy questions or data requests, contact us at info@indiethis.com.

Clear Ear Corp
Chicago, Illinois