Riff Circle

Privacy Policy

Operator: [LEGAL ENTITY NAME — e.g. Riff Circle LLC], a Florida limited liability company (“Riff Circle,” “we,” “us”).

Effective date: [EFFECTIVE DATE] · Last updated: [LAST UPDATED DATE] · Contact: privacy@riffcircle.com

This policy explains what Riff Circle collects, why, who we share it with, and what you can do about it. Riff Circle is intended for users in the United States and for people 18 and older. If you use Riff Circle from outside the United States, you consent to your information being processed in the United States, where privacy laws may differ from those where you live.

The short version: we do not sell your personal information, we do not run advertising or cross-site tracking, and we do not use your content to train AI models. Riff Circle is a discovery platform, so some of what you add is designed to be seen by others — Section 5 explains exactly what, and how to turn it off.

1. Information you give us

  • Account. Your email address and name (first, middle, last). If you register with a password we store it only as a salted hash, never in readable form, and we check it against public breach data using a partial hash (see Section 6). If you sign in with Google we receive your Google profile, including your profile photo. We record an 18+ attestation and your acceptance of the Terms, with the date and time of each — we do not collect your date of birth. If you set up two-factor authentication we store the secret and your backup codes; these are never returned to your browser.
  • Profile. Bio, profile and cover images, social links (Bluesky, X/ Twitter, TikTok, SoundCloud), instruments and skill levels, genres, gig and lesson rates, availability flags, travel distance, theme and avatar-effect preferences, and a vanity URL if you choose one.
  • Location. Your city and state, and — if you provide one — a street address, which we convert to precise coordinates. If you use the “use my location” button, your browser asks your permission and sends us your device coordinates for that one lookup. We also derive an offset (“fuzzed”) pair of coordinates from your precise ones. See Section 4 for which of these ever leaves our server.
  • Content. Events you create and their images, band pages and band media, questions and answers, reviews and star ratings you write, songs and setlists, and media you embed from YouTube or SoundCloud.
  • Messages. Direct messages, group chats, band chats, and event chats you send — their content, participants, and timestamps. These are private to the participants of the conversation, not published publicly. See Section 7.
  • Safety reports. Reports you file about a user, event, or message, including any details you write, and the identity of the person reporting.
  • Product feedback. Bug reports and ideas you submit. The dialog also captures the page you were on, your browser user-agent, your window size, and the app version, so we can reproduce the problem.
  • Saved searches. The filters you save for alerts, including any location or distance in them.
  • Billing (subscribers only). If you subscribe, our payment processor Stripe collects your payment details directly — we never receive or store your full card number. We store only your Stripe customer and subscription identifiers and your subscription status (tier, status, renewal date).

2. Information we collect automatically

  • Session data. Your IP address and user-agent, stored with your login sessions so we can keep you signed in and investigate suspicious access.
  • Page analytics. Aggregated, cookieless page-view and performance (Web Vitals) measurements via Vercel, used to understand which pages are used and which are slow. These are not tied to your account and are not used to build a profile of you.
  • Profile-view counts. When someone opens your profile or your band page, or it appears in a search result, we increment a daily counter — including a coarse breakdown of where the view came from (search, an event, another profile, or a direct link) and whether the viewer was signed out, a musician, or a band member. Members and Band Pro bands can see these totals. We do not store who viewed you. There is no list of viewer identities, and we could not show you one.
  • Push subscriptions. If you enable push notifications, your browser gives us a device endpoint and encryption keys so we can deliver them. You can revoke this in the app or in your browser at any time.
  • Error diagnostics. Crash and error reports via Sentry, which may include your IP address and limited personal data that happened to be part of the error.
  • Abuse-prevention signals. Your IP address is used as a short-lived rate-limit counter key, and a Cloudflare Turnstile bot check runs on sign-up.
  • Referral attribution. If you arrive on an invite link shared by another member, we note who shared it and which page you landed on. See Section 10.

3. How we use it

We use the information above to:

  • operate the Service, authenticate you, and keep your account secure;
  • show you and others relevant musicians, bands, and events near a location, and place them on the map;
  • deliver messages, invitations, RSVPs, and notifications between users;
  • send email — account and transactional mail (verification, invitations, event reminders, billing), and the optional digests and alerts you can turn off in your settings;
  • maintain safety and moderation: reports, blocks, bans, and enforcing our Terms;
  • process and manage subscriptions, through Stripe;
  • produce the aggregate profile-view analytics shown to Members and Band Pro bands;
  • diagnose errors, prevent abuse, and improve the Service.

We do not read your messages routinely. We access message content only when you or another participant reports a message or conversation, or where access is necessary to investigate abuse, enforce our Terms, resolve a dispute between users, or comply with law. Admin access to reported message content is logged.

We do not sell or share your personal information for money or for cross-context behavioural advertising, we do not run ad networks or cross-site trackers, and we do not use your content or messages to train AI models.

4. Location, in detail

Precise coordinates are treated as sensitive. They are used on our servers to compute distance for discovery and matching, and they are never sent to anyone but you.

  • If your profile is discoverable and your address is not marked private: other people see your city and state and an offset approximate point on the map — never your exact coordinates or street address.
  • If you mark your address private: we publish no location at all for you — no city, no state, no map point. You still appear in distance-based search results, because the distance is computed server-side.
  • Events are different. An event you post is a place other people are being invited to, so the address you give an event is shown to people who can see that event. Do not put your home address on a public event unless you intend strangers to have it.
  • Address lookup. Address autocomplete and map tiles are proxied through our servers, so the mapping provider receives the search text and tile requests but not your IP address.

5. What other people can see

New profiles are private by default. At onboarding you choose whether to be discoverable, and you can change it at any time in your profile settings.

  • A private profile is absent from the musician directory, the map, search, and matching, and its page is not readable by anyone you have no established tie with. The ties that grant access are narrow: an accepted friendship, a shared band, a shared event, or an open conversation.
  • A discoverable profile — your name, photo, cover image, bio, social links, instruments and genres, rates, availability, and your approximate location — is visible to anyone on the internet, including people without an account, and can be reached by direct link. Rates are hidden from signed-out visitors.
  • Search engines. We ask search engines not to index individual profile, band, and press-kit pages, and we do not submit them for indexing. Public event pages are indexable and are submitted to search engines — an event page shows the event, its location, and its organizer. Private events are not indexed. We cannot guarantee that a third party never caches content that was public.
  • Images are stored at public URLs. Anyone holding the link to a profile, cover, or event image can open it, whether or not the page it sits on is private. Treat an uploaded image as public.
  • Bands and events have their own private/public setting, chosen by whoever created them. Joining a public event makes your participation visible to others who can see that event.
  • Calendar feed. If you subscribe to your events calendar, the feed URL contains a signed token and works without logging in. Anyone you give that URL to can read your upcoming events — treat it like a password.

6. Who we share it with

We do not sell your personal information. We share it with service providers who process it on our behalf, under contract and only for the purposes below:

ProviderPurposeData
SupabaseDatabase and image storageAll account and app data; uploaded profile, cover, and event images (served from public URLs)
VercelHosting, plus first-party page analytics and performance metricsRequest data, IP address, user-agent; aggregated, cookieless page-view and Web-Vitals measurements
StripeSubscription payments and billing portalEmail, name, payment details (collected and stored by Stripe, not by us), Stripe customer/subscription ids, payment status
ResendSending transactional and notification emailEmail address, name, message content
GoogleSign-in (OAuth)Your Google profile (name, email, profile photo) and OAuth tokens
GeoapifyAddress autocomplete, geocoding, and map tilesAddress search text and map tile requests, proxied through our server so the provider does not see your IP
CloudflareTurnstile bot check on sign-upIP address, browser signals, challenge token
UpstashRate limiting and abuse preventionIP address or account id as a short-lived counter key
SentryError monitoring and diagnosticsError and diagnostic data, IP address, and any limited personal data incidentally present in an error
Browser push servicesDelivering push notifications you opted into (Apple, Google, or Mozilla, depending on your browser)Your device's push endpoint and the notification title, body, and link
Have I Been PwnedChecking a chosen password against known breachesThe first five characters of a SHA-1 hash of the password — never the password itself, and not linked to your account

We may also disclose information to comply with law or valid legal process, to enforce our Terms, to investigate fraud or abuse, or to protect the rights, property, or safety of our users, the public, or Riff Circle. If Riff Circle is involved in a merger, acquisition, or sale of assets, your information may transfer to the successor, which will remain bound by this policy or give you notice of any change.

7. Messages: privacy and retention

A conversation is shared content belonging to everyone in it, so we treat it differently from data that is solely yours.

  • Messages are automatically deleted. Message bodies are erased after 30 days, extended to 365 days while an active Member is in the conversation, or while the band holds Band Pro for a band chat. If that subscription lapses, the shorter window applies again and older messages are then deleted. Keep your own copy of anything you need.
  • Deleting a message — one message, your whole history, or by deleting your account — hides it from the other participants immediately. We keep the underlying record in a restricted, non-public state for up to 30 days so we can still handle safety reports and disputes, then the content is permanently erased.
  • Reported messages may be retained longer where necessary to resolve the report, enforce our Terms, or comply with law.
  • Deleting your account removes your messages’ content from other participants’ threads, but the thread structure remains for them, attributed to a removed user.

8. Your choices and rights

  • Be invisible. Make your profile private to leave the directory, the map, and search entirely.
  • Hide your location. Mark your address private to publish no location at all, or simply give a city instead of a street address.
  • Control email. Turn off notification email in your settings, or use the unsubscribe link in any notification email. You can separately turn off social notifications, event reminders, and the weekly events digest. Essential account, security, and billing email cannot be turned off while you have an account.
  • Control push. Turn push notifications off in the app or in your browser.
  • Block and report. Blocking hides you and the blocked user from each other in both directions.
  • Delete your messages. Remove individual messages or your whole message history at any time, as described in Section 7.
  • Delete your account at any time in your profile settings. This is permanent: it deletes your profile, images, connections, and the events you organize, including events others have joined. It also cancels any paid subscription billed to you, so there are no further charges — you do not need to cancel first.
  • Access, correct, or export. Most of your data is editable in the app. For a copy of your data, a correction we do not offer in-app, or full erasure of your message content, email privacy@riffcircle.com and we will respond manually, normally within 30 days. We may need to verify your identity through the email address on your account.

State privacy rights. Riff Circle is currently below the thresholds that make the California Consumer Privacy Act and comparable state laws mandatory for us. We honour access, correction, deletion, and portability requests from residents of any state anyway — email privacy@riffcircle.com. We treat precise geolocation as sensitive information, we do not sell or share personal information, and we will not discriminate against you for exercising any privacy right. We do not currently respond to Global Privacy Control or Do Not Track signals, because we do not do the cross-site tracking they are designed to stop.

9. How long we keep it

DataRetention
Profile, content, events, bands, songs and setlistsWhile your account is active; deleted or anonymized on account deletion
Messages30 days, or 365 days while an active Member (or a Band Pro band) is in the conversation
Messages you delete, and messages of a deleted accountHidden immediately; body permanently erased within 30 days
Session logs (IP address, user-agent)30 days, then erased from the session record
In-app notifications30 days
Profile-view and search-appearance countsKept as daily totals while your account is active; deleted with your account
Reports, moderation records, and admin audit logsRetained as long as needed for safety, enforcement, and legal obligations
Billing recordsRetained by us and by Stripe as required by tax and accounting law
BackupsDeleted data persists in encrypted backups until they rotate out

After you delete your account we remove or anonymize your personal data, except where we must retain limited records for legal, tax, security, or abuse-prevention purposes.

10. Cookies and similar technologies

We do not use advertising or cross-site tracking cookies, and there is no third-party ad network on Riff Circle. We use:

  • Strictly necessary cookies for login and session security.
  • A first-party referral cookie (rc_ref) kept for up to 30 days when you arrive on an invite link, recording who shared the link and which page you landed on. If you then create an account, that is saved to your account so we can credit the person who invited you. It is first-party only, is never shared with advertisers, and is not used to track you across other websites.
  • Local browser storage for display preferences (such as whether a list shows as a grid, and which tips you have dismissed) and for offline support in the installable app. This stays on your device.
  • Cookieless analytics. Our page and performance analytics do not set cookies and do not identify you.

Third parties on our pages. Pages with embedded media load content from YouTube or SoundCloud, which may set their own cookies under their own privacy policies; we use YouTube’s privacy-enhanced (no-cookie) embed. Sign-up runs a Cloudflare Turnstile bot check. Checkout and billing management happen on Stripe-hosted pages, governed by Stripe’s privacy policy.

11. Security

We protect your information with HTTPS everywhere, hashed passwords, encrypted storage of OAuth tokens, optional two-factor authentication, per-row access controls, rate limiting, a strict content-security policy, admin audit logging, and encrypted database backups. No system is perfectly secure, and you are responsible for keeping your own credentials safe.

In the event of a breach affecting your personal information, we will notify affected users and any required regulators within the timeframes set by Florida’s Information Protection Act (generally within 30 days) and any other law that applies to you.

12. Children

Riff Circle is not for anyone under 18. We do not knowingly collect personal information from minors. If we learn that an account belongs to someone under 18 we will delete it and its data. If you believe a minor has an account, report it in the app or email privacy@riffcircle.com.

13. Changes to this policy

We will post updates here and revise the “last updated” date. For material changes we will notify you in-app or by email before they take effect.

Contact

  • Privacy questions and requests: privacy@riffcircle.com
  • Everything else: support@riffcircle.com
  • [LEGAL ENTITY NAME — e.g. Riff Circle LLC] · [BUSINESS MAILING ADDRESS — virtual mailbox / registered agent, not a home address]
    Privacy Policy · Riff Circle | Riff Circle