Data Controller
The data controller for personal data collected through the BandCalendar service is:
- Name:
- BandCalendar
- Email:
- [email protected]
- Website:
- www.bandcalendar.it
For any questions regarding the processing of personal data, you can contact us at [email protected].
Types of data collected
BandCalendar collects and processes the following categories of personal data, depending on the features used:
2.1 Registration and profile data
- First and last name (or stage name / band name)
- Email address
- Password (stored in encrypted form — bcrypt hash, never in plaintext)
- Profile photo (if uploaded voluntarily)
- Team / band data
2.2 Data entered in the application
In the ordinary use of the service, the user independently enters data relating to their professional activity, including:
- Client and contact data (name, phone, email, address)
- Event information (date, location, event type, notes)
- Collaborator and musician data (name, contact, fees)
- Collaborator operational notification settings, unsubscribe/suppression preferences and minimal technical email logs
- Documents, quotes and contracts
- Setlists, repertoires and songs
- Financial data (fees, payments, advances)
- Photos and multimedia files uploaded by the user
BandCalendar acts solely as a data processor for all data relating to third parties (clients, collaborators) that the user enters in the platform. The user is the data controller for such data.
2.3 Operational emails to collaborators
If the team explicitly enables collaborator operational notifications, BandCalendar may send transactional emails to collaborators associated with an event or rehearsal. These emails contain only operational information visible in the public collaborator card, a link to that card and an unsubscribe link.
- The feature is disabled by default and can be enabled only from team settings.
- Emails do not include fees, payments, quotes, contracts, client administrative data or internal history.
- BandCalendar does not use tracking pixels, per-collaborator open tracking, IP fingerprinting or attachments for these emails.
- The user/team remains responsible for using collaborator email addresses on a lawful basis consistent with their relationship with those collaborators.
2.4 Location data (address, map pin, device GPS)
To calculate distances and show a map position for the team base or an event venue, BandCalendar may process:
- Address text you type (street, number, postcode, city), stored with your team or event data
- Geographic coordinates (latitude/longitude) obtained by geocoding that address via OpenStreetMap Nominatim, or set by you manually on the map, by pasting coordinates, or via a one-time browser geolocation request
- A flag indicating whether the pin was set automatically from the address or fixed manually
- Device location is requested only if you press “Use my location”: the browser asks for permission; we use the coordinates once to set the pin and do not track your movements over time.
- Map tiles and public geocoding use OpenStreetMap / Nominatim services (third-party infrastructure). Do not enter secrets in the address field.
- You can move or replace the pin at any time; clearing the address can clear the coordinates according to the product rules.
2.5 Usage and technical data
- IP address and browser/device information (access logs)
- Session tokens (JWT, stored in the browser)
- Push notification tokens (if authorised by the user)
- Aggregated navigation data (pages visited, features used)
2.6 Billing data
If a paid plan is activated, we will use certified third-party providers (Stripe, PayPal) for subscription management. BandCalendar does not directly store credit card or payment instrument data. We only receive transaction confirmations and billing data required for tax purposes (e.g., billing address).
2.7 Google Calendar data we access and use
Only after you explicitly connect Google Calendar, BandCalendar accesses the following data through the Google Calendar API:
- OAuth access and refresh tokens and synchronization identifiers
- The list of subscribed calendars and calendar metadata, such as IDs, names, colors and access roles
- For calendars explicitly selected by the user, event titles, descriptions, dates, times, locations and statuses required for synchronization or the personal-calendar overlay
We use these data only to let you choose calendars, display personal events from calendars you select, create, update or delete BandCalendar events in the selected destination calendar, and import provider-side changes when bidirectional synchronization is enabled. We do not access other Google Account services or data.
OAuth tokens and synchronization identifiers are retained while the integration remains connected and are deleted when you disconnect Google Calendar; BandCalendar also requests revocation of the Google grant. Event content intentionally synchronized into BandCalendar remains subject to the service's standard retention and user deletion controls.
Google Calendar data is not used for advertising, profiling or AI training, and is not sold. It is not disclosed except to service providers acting on our behalf where strictly necessary to operate and secure BandCalendar.
BandCalendar's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy including the Limited Use requirements.
Purposes and legal basis for processing
| Purpose | Legal basis |
|---|---|
| Service provision (registration, access, core features) | Performance of a contract — Art. 6.1.b GDPR |
| Subscription and payment management | Performance of a contract — Art. 6.1.b GDPR |
| Tax and accounting obligations | Legal obligation — Art. 6.1.c GDPR |
| Sending transactional communications (confirmations, system notifications) | Performance of a contract — Art. 6.1.b GDPR |
| Sending operational emails to event/rehearsal collaborators when enabled by the team | Performance of a contract and service provision — Art. 6.1.b GDPR |
| Service security, fraud and abuse prevention | Legitimate interest — Art. 6.1.f GDPR |
| Service improvement through aggregated usage analysis | Legitimate interest — Art. 6.1.f GDPR |
| Promotional communications and newsletters (only with prior consent) | Consent — Art. 6.1.a GDPR |
| In-app push notifications (only with prior consent) | Consent — Art. 6.1.a GDPR |
Processing methods
Processing is carried out using electronic and telecommunications tools. Data is stored on dedicated servers located in Italy, owned by the data controller. Access to data is protected by:
- Password encryption with bcrypt algorithm
- HTTPS/TLS connections for all data transfers
- JWT session tokens with limited expiry
- Access to production systems limited to authorised personnel
- Encrypted daily backups stored separately
- Network segmentation: database and storage not exposed to the Internet
Data retention
Personal data is retained for the time strictly necessary for the stated purposes:
Active account data
For the entire duration of the contractual relationship (as long as the account is active).
After account deletion
Data is deleted within 30 days of the deletion request, except where required by law.
Billing data
10 years from the transaction, in accordance with Italian tax obligations (D.P.R. 600/1973).
Access logs
Maximum 12 months, unless required for security activities or investigations.
Collaborator operational email logs
Recipient details and change summaries are retained for up to 180 days, then redacted or anonymised. Unsubscribe and suppression preferences are retained while necessary to respect the opt-out or prevent repeated delivery failures.
Uploaded files and documents
Deleted immediately upon deletion of the file by the user, or within 30 days of account deletion.
Disclosure to third parties
Personal data is not sold or transferred to third parties for commercial purposes. It may be disclosed only to the following parties, to the extent strictly necessary for service provision:
Stripe Inc.
Card payment processing
USA (SCCs GDPR)
PayPal Inc.
PayPal payment processing
USA (SCCs GDPR)
SMTP2GO
Sending transactional emails
Australia (SCCs GDPR)
Cloudflare Inc.
CDN, DDoS protection, HTTPS tunnel
USA (SCCs GDPR)
Google LLC
Google Calendar integration (only upon user request)
USA (SCCs GDPR)
All providers are subject to contractual confidentiality and security obligations compliant with the GDPR.
International transfers
Some providers listed in section 6 are located outside the European Union. In such cases, data transfer is carried out in compliance with the guarantees provided by Arts. 44-49 of the GDPR, in particular through:
- Standard Contractual Clauses (SCCs) adopted by the European Commission
- Adherence to certification programmes recognised by the European Commission
Your rights
As a data subject, you have the right to exercise the following rights at any time, pursuant to Arts. 15-22 of the GDPR:
Access (art. 15)
Obtain confirmation of processing and a copy of your personal data.
Rectification (art. 16)
Correct inaccurate data or complete incomplete data.
Erasure (art. 17)
Delete your account and all your data. You can do this directly from the app: Profile → Danger zone → Delete account permanently.
Restriction (art. 18)
Restrict the processing of your data in certain circumstances.
Portability (art. 20)
Export all your team data in JSON format. Available directly from the app: Settings → Backup → Download Backup.
Objection (art. 21)
Object to processing based on legitimate interest.
Withdrawal of consent
Withdraw consent at any time without affecting the lawfulness of prior processing.
Complaint to the Authority
Lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).
How account deletion works
Deletion is immediate and irreversible. The behaviour depends on the role:
- Team owner: the team is dissolved, all members receive a notification email and are automatically moved to a new personal team (their accounts remain active and their data is preserved).
- Invited member: the account is deleted along with all associated data.
- Google OAuth users: no password is required, just confirm the intention.
How data export works
The team owner can download a complete archive of team data (events, clients, collaborators, fees, etc.) in JSON format directly from the app: Settings → Backup → Download Backup. The archive also includes collaborator notification settings, preferences and technical logs when present. Full public-link and unsubscribe tokens are not stored in plaintext and therefore are not exported. No need to contact us.
To request data in a different format, write to [email protected].
Newsletter
The BandCalendar newsletter is sent only to users who have given explicit consent via the subscription form on the website. We collect the email address, preferred language, and technical data (IP address and browser) for security and anti-spam purposes.
You can unsubscribe at any time by clicking the unsubscribe link at the bottom of every newsletter email, or by writing to [email protected]. Upon unsubscription, your data is retained for 30 days and then permanently deleted.
To exercise your rights, send a request to [email protected]. We will respond within 30 days, as required by the GDPR.
Minors
Under Art. 8 of the GDPR and Italian Legislative Decree 101/2018, the minimum age to independently consent to the processing of personal data for online services is 14 years in Italy. We do not knowingly collect personal data from children under 14.
Users aged 14 to 17 may use BandCalendar and all its features. To subscribe to a paid plan — which constitutes a contract with BandCalendar — parental or legal guardian authorisation is required.
If you are aware that a child under 14 has created an account, please contact us at [email protected] to proceed with immediate deletion.
Changes to this policy
We reserve the right to update this policy at any time, for example following regulatory changes or the introduction of new features. Significant changes will be communicated by email to the registered address or via notice in the application.
The date of the last update is always shown at the top of this page. Continued use of the service after publication of changes constitutes acceptance of those changes.
Contact us
For any questions, requests or reports regarding the processing of your personal data, you can contact us:
BandCalendar
E-mail: [email protected]
Website: www.bandcalendar.it
You also have the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it).
This policy has been drafted in compliance with EU Regulation 2016/679 (GDPR) and Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018.