1. Introduction
This Privacy Policy explains how Tourmate360 ("we", "us", "our") collects, uses, stores, and protects personal data when you use the Tourmate360 platform (the "Service").
Tourmate360 is a SaaS platform for bands, venues, and music industry professionals used for tour management, booking coordination, and related communication.
We comply with the EU General Data Protection Regulation (GDPR) and applicable Spanish data protection laws.
2. Data Controller
Tourmate360 is the data controller for personal data processed under this Service.
Contact: support@tourmate360.com
Website: https://tourmate360.com
3. Personal Data We Collect
We collect the following categories of personal data:
3.1 Account Data
- Email address
- Full name
- Password (stored in encrypted form via Supabase)
- User type (band or venue)
- Account creation and login timestamps
3.2 Profile Data
Depending on account type:
Bands:
- Band name
- Genre
- Biography
- Location and address data
- Member count
- Social media links
- Press kit URL
- Images and photos
- Public contact details
- Subscription tier and status
Venues:
- Venue name
- Description
- Location, address, and GPS coordinates
- Capacity
- Equipment/backline information
- Social media links
- Images and photos
- Public contact details
- Subscription tier and status
3.3 Communication Data
- Messages sent via internal messaging system
- Interaction history between users
3.4 Technical Data
- IP address
- Approximate country derived from IP (country-level only, via our hosting provider Vercel; we do not use the browser Geolocation API for this)
- Browser type and Accept-Language preferences
- Device information
- Log data (access times, pages viewed, errors)
- Preference data stored in cookies (language and country settings — see Cookie Policy and section 10)
3.5 Payment Data
Payments are processed exclusively by Stripe. We do not store full credit card information.
We may receive:
- Payment status
- Subscription status
- Billing metadata
- Invoice information
4. Purpose of Processing
We process personal data to:
- Provide and operate the Service
- Create and manage user accounts
- Enable communication between users (bands and venues)
- Display public profiles
- Process subscriptions and payments
- Provide customer support
- Ensure platform security and prevent fraud
- Improve and maintain the Service
- Localize the Service (for example, default map center, country filters, and language preparation) based on approximate IP country and browser language preferences, or on preferences you set manually
5. Legal Basis for Processing (GDPR)
We process personal data based on:
- Contract performance (Art. 6(1)(b) GDPR)
- Legitimate interests (Art. 6(1)(f) GDPR) — including securing the Service and localizing maps, filters, and language defaults using approximate country and browser language signals
- Legal obligations (Art. 6(1)(c) GDPR)
- User consent where required (Art. 6(1)(a) GDPR)
You may change or clear country and language preferences in the Service at any time. You may also object to processing based on legitimate interests where applicable under GDPR (see section 13).
6. Data Sharing and Third Parties
We share personal data only when necessary with:
6.1 Service Providers
- Stripe (payment processing and billing)
- Supabase (authentication and database hosting)
- Vercel (hosting and deployment infrastructure)
- GoDaddy (domain services)
These providers act as data processors under GDPR.
7. Data Storage Location
Data is primarily stored in the European Union (EU), including Supabase infrastructure located in Frankfurt, Germany.
Some service providers may process data outside the EU. In such cases, appropriate safeguards (such as Standard Contractual Clauses) are used.
8. Public Profiles
Users may create public profiles that are visible to other users and visitors.
Public information may include:
- Name or stage name
- Profile images
- Biography
- Social media links
- Contact information designated as public
Users are responsible for information they choose to publish.
9. Messaging
The platform includes internal messaging between users.
Messages are stored to enable platform functionality and are not publicly visible.
We do not actively monitor private messages, but we may access them in case of:
- Abuse reports
- Legal obligations
- Platform security investigations
10. Cookies and Tracking Technologies
We use:
- Strictly necessary cookies for authentication, session management, security, and payments
- Functional preference cookies for language and country (including
tourmate-language,tm_preferred_language,tm_country, andtm_country_override)
Approximate country is derived from IP at the edge (Vercel). We do not request precise device location via the browser Geolocation API for localization.
We do not use advertising cookies or third-party marketing trackers at this stage.
Full details are set out in our Cookie Policy.
11. Data Retention
We retain personal data as long as:
- The account remains active
- It is necessary to provide the Service
- Required by law
Users may request deletion of their account at any time. When you delete your account, your subscription is cancelled immediately and your public profile, press kit, and events are taken offline so you are no longer discoverable. Your personal data is then retained for a 30-day grace period (to allow recovery of an accidental deletion) before it is permanently erased from our database. You may also request a machine-readable copy of your data ("Export Data") from your account settings.
12. Data Security
We implement appropriate technical and organizational measures to protect personal data, including:
- Encrypted authentication via Supabase
- Secure payment processing via Stripe
- Access control mechanisms
- HTTPS encryption
- Regular system monitoring
However, no system is completely secure.
13. User Rights Under GDPR
Users have the right to:
- Access their personal data
- Rectify inaccurate data
- Request deletion ("right to be forgotten")
- Restrict processing
- Data portability
- Object to processing
- Withdraw consent (where applicable)
Requests can be sent to: support@tourmate360.com
14. International Transfers
Where data is transferred outside the EU, we ensure appropriate safeguards such as:
- Standard Contractual Clauses (SCCs)
- Data processing agreements with providers
15. Third-Party Links and Services
The Service may contain links to third-party services, including accommodation booking providers (e.g., Stay22 affiliate links).
We are not responsible for:
- Third-party privacy practices
- Data processing by external providers
- Transactions conducted outside the platform
Users should review third-party privacy policies independently.
16. Children's Privacy
The Service is not intended for individuals under 18 years of age.
We do not knowingly collect personal data from minors.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time.
Updates will be posted on this page with a revised "Last Updated" date.
Continued use of the Service constitutes acceptance of changes.
18. Supervisory Authority
If you are in the European Economic Area and believe your data protection rights have been infringed, you may lodge a complaint with your local supervisory authority. For Spain, the supervisory authority is the Agencia Española de Protección de Datos (AEPD): https://www.aepd.es.
19. Contact
For questions regarding privacy or data protection: support@tourmate360.com