Privacy Policy

Last updated: April 2026

1. Who We Are

Banded is a social gig diary app that lets you log, rate, and share the live music events you attend. Banded is operated from the United Kingdom.

If you have any questions about this policy or your data, contact us at hello@banded.uk.

2. What Data We Collect

2.1 Account Data

When you create an account we collect:

2.2 Gig Diary Data

When you log a gig we collect:

2.3 Social Data

2.4 Wishlist and Events Data

2.5 Photos and Camera Data

2.6 Notification Data

2.7 Location Data

2.8 Calendar Data

2.9 Top Four

2.10 Analytics Data

We use Mixpanel to understand how people use Banded so we can improve the app. Mixpanel collects:

Analytics data is processed on Mixpanel's EU servers. We do not use analytics data for advertising or share it with third parties.

3. What We Do Not Collect

Banded does not collect:

4. Legal Basis for Processing (UK GDPR)

We process your personal data under the following legal bases:

Data Legal Basis
Account data, gig diary data, social data, wishlist data Contract performance — necessary to provide the Banded service you signed up for
Photos and camera data Contract performance — core feature of logging gigs
Push notifications and device token Consent — you choose to enable notifications via the iOS permission prompt; you can revoke this at any time in device settings
Location data Consent — you choose to grant location access via the iOS permission prompt; you can revoke this at any time in device settings
Calendar access Consent — you choose to grant calendar access; you can revoke this at any time
Analytics data Legitimate interest — to understand how the app is used and improve the experience; processed on EU servers

5. How We Use Your Data

6. Third-Party Services

Banded uses the following third-party services. For each service, we describe what data (if any) is shared and why.

6.1 Supabase

Purpose: Database, user authentication, and file storage (photos and avatars).

Data shared: All user data described in this policy is stored in Supabase. Authentication tokens (JWT) are managed by Supabase.

Location: Supabase infrastructure may be hosted in the EU or US. See Section 9 (International Data Transfers) below.

Supabase Privacy Policy

6.2 Ticketmaster Discovery API

Purpose: To search for upcoming events, retrieve event details, and fetch artist images.

Data shared: Search parameters only — artist name, city or approximate location coordinates, date range, and genre filters. No account data or personal information is sent to Ticketmaster.

Ticketmaster Privacy Policy

6.3 MusicBrainz

Purpose: To look up artist metadata such as biography, origin, genres, and active years.

Data shared: Artist name or MusicBrainz ID only. No user data is sent.

MusicBrainz Privacy Policy

6.4 Setlist.fm

Purpose: To retrieve recent setlists for artists to help pre-fill gig logs.

Data shared: Artist name and performance date only. No user data is sent.

Setlist.fm Terms of Use

6.5 Fanart.tv

Purpose: Fallback source for artist images when Ticketmaster images are unavailable.

Data shared: MusicBrainz artist ID only. No user data is sent.

Fanart.tv Terms of Service

6.6 Wikidata and Wikimedia Commons

Purpose: Fallback source for artist images.

Data shared: Wikidata entity ID only. No user data is sent.

Wikimedia Privacy Policy

6.7 Mixpanel

Purpose: Product analytics — to understand how users interact with Banded so we can improve the app experience.

Data shared: Your user ID (UUID), username, display name, and city. Mixpanel also collects automatic interaction events (app opens, screen views). No gig diary content, photos, or social data is sent to Mixpanel.

Location: Data is sent to Mixpanel's EU servers (api-eu.mixpanel.com).

Mixpanel Privacy Policy

6.8 Apple Services

7. Data Retention

We retain your data for as long as your account is active and you continue to use Banded.

8. Your Rights Under UK GDPR

As a user in the United Kingdom, you have the following rights regarding your personal data:

To exercise any of these rights, email us at hello@banded.uk. We will respond within one month as required by law. If your request is complex, we may extend this by a further two months and will let you know.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection.

9. International Data Transfers

Banded uses Supabase as its backend infrastructure provider. Supabase may process and store data on servers located outside the United Kingdom, including in the United States and the European Union.

Where data is transferred outside the UK, we ensure appropriate safeguards are in place, including:

Third-party music data services (Ticketmaster, MusicBrainz, Setlist.fm, Fanart.tv, Wikimedia) may process API requests on servers located worldwide. However, no personal user data is sent to these services — only search parameters such as artist names, locations, and dates.

10. Children's Privacy

Banded is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has created an account, please contact us at hello@banded.uk and we will promptly delete the account and associated data.

11. Apple App Store Privacy Disclosures

In accordance with Apple's App Store requirements, here is a summary of the data Banded collects and its purpose:

Category Collected Purpose
Contact Info (email) Yes Authentication, account recovery
Identifiers (user ID) Yes App functionality
Identifiers (device ID) Yes Push notifications (APNs token)
User Content (photos, reviews, ratings) Yes App functionality
Location (coarse) Yes Nearby event discovery
Health & Fitness No
Financial Info No
Sensitive Info No
Contacts No
Browsing History No
Search History No
Usage Data (app interactions) Yes Analytics (Mixpanel)
Diagnostics No

Banded does not use any data for tracking purposes as defined by Apple. We do not share your data with data brokers or use it for advertising.

12. Data Security

We take reasonable measures to protect your personal data:

13. Changes to This Policy

We may update this privacy policy from time to time. If we make material changes, we will notify you by:

We encourage you to review this page periodically.

14. Contact Us

If you have any questions, concerns, or requests regarding this privacy policy or your personal data, please contact us:

Email: hello@banded.uk