Back

Privacy policy

Last updated: 8 September 2026

Who we are

BandFound (“we”, “us”) is the service at bandfound.com. We help musicians share repertoire, find people nearby, form bands, and connect with venues.

For GDPR, the data controller is the operator of BandFound. Privacy requests: privacy@bandfound.com.

What we collect

When you create an account we store:

  • Email address, and a hashed password if you sign up with email
  • Sign-in identifiers from Google or Apple if you use those buttons
  • Profile details you add: nickname and/or real name, city, state, ZIP, optional street address, instruments and skill level, optional birthday (we show age, not the date), bio, and whether you use BandFound as a musician, jam organizer, or venue
  • Songs, playlists, bands, venues, gigs, jam posts, and photos you upload
  • Messages, group chats, band inquiries, blocks, reports, and notification settings
  • Members-only forum posts, replies, and category requests (these are not shown to people who are not signed in)
  • First-party views on profiles, jam posts, band pages, and venue listings. Pro members can see aggregate analytics for pages they own. When a signed-in member views a profile, that member's display name and profile link may appear to the profile owner; signed-out visits remain anonymous
  • Pro membership status and store or PayPal payment references if you buy Pro
  • Referral codes and which new accounts signed up from a member's invite link

We do not collect live GPS. A ZIP or postal code is turned into a city centroid for nearby search. Musicians and jam organizers can add a city, state, and an optional street address. Venue listings require a street address. If you post a jam, you can also add a place name, directions, or a street address — that text is stored because you chose to share it.

Setlist photos, PDFs, and spreadsheets are processed on your device. Only the song rows you confirm are sent to our servers. Google Drive picker tokens stay in your browser. Photos you attach to a jam are stored so other people can see the post.

If you paste a public Spotify playlist link, we read the public playlist page to list tracks. We do not store your Spotify password or connect a Spotify account.

Why we use it

We use your data only to run BandFound:

  • Contract — create your account, keep your repertoire and bands, send messages, show nearby matches, and (if you have Pro) show you view analytics for pages you own
  • Legitimate interests — keep the service safe (rate limits, spam holds, reviewing reported messages)
  • Legal obligation — keep records we must keep if a law requires it
  • Consent — optional email we send if you keep message or nearby-jam alerts on, plus password reset and address verification

We do not sell your data. We do not use it for advertising.

Cookies

We use a signed, HttpOnly session cookie so you stay signed in. If you open a referral link, we also store a short-lived HttpOnly cookie so we can credit the person who invited you when you create an account. Those cookies are necessary for the site to work. We do not use advertising or tracking cookies, and we do not run third-party analytics pixels.

Who we share with

We share data only when needed to run the service:

  • Hosting and email providers that process data on our instructions
  • Google or Apple, if you choose to sign in with them
  • PayPal, Google Play, or the App Store, if you buy Pro through them
  • Other BandFound users, for the profile, songs, bands, and venues you make visible
  • Signed-in members, for forum threads and replies you post in the private forums
  • Administrators, to keep the service safe: they can review reports, manage accounts, and temporarily view the site as your account when investigating a problem

We may disclose data if required by law or to protect people from serious harm.

How long we keep it

We keep your account data while your account is open. If you ask us to delete it, we remove or irreversibly anonymize it unless we must keep a limited record (for example a ban related to abuse, or a legal hold).

Session cookies expire when the session ends or you sign out.

Where it is processed

BandFound may run on servers outside your country, including outside the European Economic Area. When we transfer personal data internationally we use appropriate safeguards, such as Standard Contractual Clauses with our processors, or another mechanism the GDPR allows.

Your rights

If GDPR or UK GDPR applies to you, you can ask us to:

  • Access a copy of your personal data
  • Correct inaccurate data
  • Delete your data
  • Restrict or object to certain processing
  • Receive data you provided in a portable format
  • Withdraw consent where we rely on consent (this does not affect past use)

Email privacy@bandfound.com from the address on your account. We may need to confirm it is you. We will respond within one month.

You can also complain to your local data protection authority. In the EU that is your national supervisory authority; in the UK it is the ICO.

Children

BandFound is for people 16 and older. We do not knowingly collect personal data from children under 16. If you think a child has an account, contact us and we will delete it.

Security

Sessions use HttpOnly cookies. We use rate limits and security headers. Payments for Pro go through PayPal on the website, Google Play on Android, or the App Store on iOS. No method is perfect; please use a unique password.

Changes

If we change this policy in a material way, we will update the date above and, when appropriate, notify you by email or a notice in the app.