Home/Privacy Policy

Privacy Policy

Privacy policy for the processing of personal data pursuant to EU Regulation 2016/679 (GDPR).

Last updated: August 7, 2026

1

Data Controller

The data controller for personal data collected through the BandCalendar service is:

Name:
BandCalendar
Website:
www.bandcalendar.it

For any questions regarding the processing of personal data, you can contact us at [email protected].

2

Types of data collected

BandCalendar collects and processes the following categories of personal data, depending on the features used:

2.1 Registration and profile data

  • First and last name (or stage name / band name)
  • Email address
  • Password (stored in encrypted form — bcrypt hash, never in plaintext)
  • Profile photo (if uploaded voluntarily)
  • Team / band data

2.2 Data entered in the application

In the ordinary use of the service, the user independently enters data relating to their professional activity, including:

  • Client and contact data (name, phone, email, address)
  • Event information (date, location, event type, notes)
  • Collaborator and musician data (name, contact, fees)
  • Collaborator operational notification settings, unsubscribe/suppression preferences and minimal technical email logs
  • Documents, quotes and contracts
  • Setlists, repertoires and songs
  • Financial data (fees, payments, advances)
  • Photos and multimedia files uploaded by the user

BandCalendar acts solely as a data processor for all data relating to third parties (clients, collaborators) that the user enters in the platform. The user is the data controller for such data.

2.3 Operational emails to collaborators

If the team explicitly enables collaborator operational notifications, BandCalendar may send transactional emails to collaborators associated with an event or rehearsal. These emails contain only operational information visible in the public collaborator card, a link to that card and an unsubscribe link.

  • The feature is disabled by default and can be enabled only from team settings.
  • Emails do not include fees, payments, quotes, contracts, client administrative data or internal history.
  • BandCalendar does not use tracking pixels, per-collaborator open tracking, IP fingerprinting or attachments for these emails.
  • The user/team remains responsible for using collaborator email addresses on a lawful basis consistent with their relationship with those collaborators.

2.4 Location data (address, map pin, device GPS)

To calculate distances and show a map position for the team base or an event venue, BandCalendar may process:

  • Address text you type (street, number, postcode, city), stored with your team or event data
  • Geographic coordinates (latitude/longitude) obtained by geocoding that address via OpenStreetMap Nominatim, or set by you manually on the map, by pasting coordinates, or via a one-time browser geolocation request
  • A flag indicating whether the pin was set automatically from the address or fixed manually
  • Device location is requested only if you press “Use my location”: the browser asks for permission; we use the coordinates once to set the pin and do not track your movements over time.
  • Map tiles and public geocoding use OpenStreetMap / Nominatim services (third-party infrastructure). Do not enter secrets in the address field.
  • You can move or replace the pin at any time; clearing the address can clear the coordinates according to the product rules.

2.5 Usage and technical data

  • IP address and browser/device information (access logs)
  • Session tokens (JWT, stored in the browser)
  • Push notification tokens (if authorised by the user)
  • Aggregated navigation data (pages visited, features used)

2.6 Billing data

If a paid plan is activated, we will use certified third-party providers (Stripe, PayPal) for subscription management. BandCalendar does not directly store credit card or payment instrument data. We only receive transaction confirmations and billing data required for tax purposes (e.g., billing address).

2.7 Google Calendar data we access and use

Only after you explicitly connect Google Calendar, BandCalendar accesses the following data through the Google Calendar API:

  • OAuth access and refresh tokens and synchronization identifiers
  • The list of subscribed calendars and calendar metadata, such as IDs, names, colors and access roles
  • For calendars explicitly selected by the user, event titles, descriptions, dates, times, locations and statuses required for synchronization or the personal-calendar overlay

We use these data only to let you choose calendars, display personal events from calendars you select, create, update or delete BandCalendar events in the selected destination calendar, and import provider-side changes when bidirectional synchronization is enabled. We do not access other Google Account services or data.

OAuth tokens and synchronization identifiers are retained while the integration remains connected and are deleted when you disconnect Google Calendar; BandCalendar also requests revocation of the Google grant. Event content intentionally synchronized into BandCalendar remains subject to the service's standard retention and user deletion controls.

Google Calendar data is not used for advertising, profiling or AI training, and is not sold. It is not disclosed except to service providers acting on our behalf where strictly necessary to operate and secure BandCalendar.

BandCalendar's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy including the Limited Use requirements.

3

Purposes and legal basis for processing

PurposeLegal basis
Service provision (registration, access, core features)Performance of a contract — Art. 6.1.b GDPR
Subscription and payment managementPerformance of a contract — Art. 6.1.b GDPR
Tax and accounting obligationsLegal obligation — Art. 6.1.c GDPR
Sending transactional communications (confirmations, system notifications)Performance of a contract — Art. 6.1.b GDPR
Sending operational emails to event/rehearsal collaborators when enabled by the teamPerformance of a contract and service provision — Art. 6.1.b GDPR
Service security, fraud and abuse preventionLegitimate interest — Art. 6.1.f GDPR
Service improvement through aggregated usage analysisLegitimate interest — Art. 6.1.f GDPR
Promotional communications and newsletters (only with prior consent)Consent — Art. 6.1.a GDPR
In-app push notifications (only with prior consent)Consent — Art. 6.1.a GDPR
4

Processing methods

Processing is carried out using electronic and telecommunications tools. Data is stored on dedicated servers located in Italy, owned by the data controller. Access to data is protected by:

  • Password encryption with bcrypt algorithm
  • HTTPS/TLS connections for all data transfers
  • JWT session tokens with limited expiry
  • Access to production systems limited to authorised personnel
  • Encrypted daily backups stored separately
  • Network segmentation: database and storage not exposed to the Internet
5

Data retention

Personal data is retained for the time strictly necessary for the stated purposes:

Active account data

For the entire duration of the contractual relationship (as long as the account is active).

After account deletion

Data is deleted within 30 days of the deletion request, except where required by law.

Billing data

10 years from the transaction, in accordance with Italian tax obligations (D.P.R. 600/1973).

Access logs

Maximum 12 months, unless required for security activities or investigations.

Collaborator operational email logs

Recipient details and change summaries are retained for up to 180 days, then redacted or anonymised. Unsubscribe and suppression preferences are retained while necessary to respect the opt-out or prevent repeated delivery failures.

Uploaded files and documents

Deleted immediately upon deletion of the file by the user, or within 30 days of account deletion.

6

Disclosure to third parties

Personal data is not sold or transferred to third parties for commercial purposes. It may be disclosed only to the following parties, to the extent strictly necessary for service provision:

Stripe Inc.

Card payment processing

USA (SCCs GDPR)

PayPal Inc.

PayPal payment processing

USA (SCCs GDPR)

SMTP2GO

Sending transactional emails

Australia (SCCs GDPR)

Cloudflare Inc.

CDN, DDoS protection, HTTPS tunnel

USA (SCCs GDPR)

Google LLC

Google Calendar integration (only upon user request)

USA (SCCs GDPR)

All providers are subject to contractual confidentiality and security obligations compliant with the GDPR.

7

International transfers

Some providers listed in section 6 are located outside the European Union. In such cases, data transfer is carried out in compliance with the guarantees provided by Arts. 44-49 of the GDPR, in particular through:

  • Standard Contractual Clauses (SCCs) adopted by the European Commission
  • Adherence to certification programmes recognised by the European Commission
8

Your rights

As a data subject, you have the right to exercise the following rights at any time, pursuant to Arts. 15-22 of the GDPR:

Access (art. 15)

Obtain confirmation of processing and a copy of your personal data.

Rectification (art. 16)

Correct inaccurate data or complete incomplete data.

Erasure (art. 17)

Delete your account and all your data. You can do this directly from the app: Profile → Danger zone → Delete account permanently.

Restriction (art. 18)

Restrict the processing of your data in certain circumstances.

Portability (art. 20)

Export all your team data in JSON format. Available directly from the app: Settings → Backup → Download Backup.

Objection (art. 21)

Object to processing based on legitimate interest.

Withdrawal of consent

Withdraw consent at any time without affecting the lawfulness of prior processing.

Complaint to the Authority

Lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).

How account deletion works

Deletion is immediate and irreversible. The behaviour depends on the role:

  • Team owner: the team is dissolved, all members receive a notification email and are automatically moved to a new personal team (their accounts remain active and their data is preserved).
  • Invited member: the account is deleted along with all associated data.
  • Google OAuth users: no password is required, just confirm the intention.

How data export works

The team owner can download a complete archive of team data (events, clients, collaborators, fees, etc.) in JSON format directly from the app: Settings → Backup → Download Backup. The archive also includes collaborator notification settings, preferences and technical logs when present. Full public-link and unsubscribe tokens are not stored in plaintext and therefore are not exported. No need to contact us.

To request data in a different format, write to [email protected].

Newsletter

The BandCalendar newsletter is sent only to users who have given explicit consent via the subscription form on the website. We collect the email address, preferred language, and technical data (IP address and browser) for security and anti-spam purposes.

You can unsubscribe at any time by clicking the unsubscribe link at the bottom of every newsletter email, or by writing to [email protected]. Upon unsubscription, your data is retained for 30 days and then permanently deleted.

To exercise your rights, send a request to [email protected]. We will respond within 30 days, as required by the GDPR.

10

Minors

Under Art. 8 of the GDPR and Italian Legislative Decree 101/2018, the minimum age to independently consent to the processing of personal data for online services is 14 years in Italy. We do not knowingly collect personal data from children under 14.

Users aged 14 to 17 may use BandCalendar and all its features. To subscribe to a paid plan — which constitutes a contract with BandCalendar — parental or legal guardian authorisation is required.

If you are aware that a child under 14 has created an account, please contact us at [email protected] to proceed with immediate deletion.

11

Changes to this policy

We reserve the right to update this policy at any time, for example following regulatory changes or the introduction of new features. Significant changes will be communicated by email to the registered address or via notice in the application.

The date of the last update is always shown at the top of this page. Continued use of the service after publication of changes constitutes acceptance of those changes.

12

Contact us

For any questions, requests or reports regarding the processing of your personal data, you can contact us:

BandCalendar

You also have the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).

This policy has been drafted in compliance with EU Regulation 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018.