WRISTBAND.

Trust center

Privacy Policy.

This draft explains what Wristband collects, why it is used, where it is processed, and the controls available during private beta.

Private-beta draft · Effective August 27, 2026 · Attorney review required before broader public launch.

Information you provide

  • Account information, including email address and authentication records.
  • Profile information such as name, username, hometown, tagline, visibility, and avatar.
  • Concert history, attendance, performance status, memories, companions, ratings when enabled, and privacy choices.
  • Photos and related metadata that you choose to upload.
  • Requests you make to export or delete your information.

Information collected automatically

Wristband records first-party page paths, timestamps, and a random session identifier to understand site use. Signed-in visits may be associated with an account by the database. Wristband does not intentionally store raw IP addresses, device fingerprints, or external browsing history in product analytics.

Abuse controls convert a network or account identifier into a salted one-way hash. Operational monitoring stores route names, safe error codes, status codes, timestamps, and—when signed in—an account identifier. It does not store request bodies, memories, filenames, search terms, passwords, or photo contents in error records.

How information is used

  • Provide authentication, profiles, Show history, memories, photos, privacy controls, exports, and deletion.
  • Find and enrich Shows through replaceable music-data providers.
  • Protect the service, enforce limits, diagnose failures, and measure aggregate beta usage.
  • Comply with law, enforce rules, and protect users and the service.

Service providers

Wristband currently relies on Supabase for authentication and database services, Vercel for application hosting, Cloudflare R2 for private media storage, and Setlist.fm for concert and setlist lookups. These providers process information under their own terms and privacy practices.

Wristband does not currently sell personal information or use personal concert history for targeted advertising. Optional marketing, sponsorship, CRM, or commerce features will require separate consent and policy work before activation.

Visibility and sharing

Profile, memory, attendance, and photo visibility settings determine what other people may see. Shared canonical Show and performer records can remain after you remove a Show or delete your account because they are not solely your personal record. Your personal attendance, memories, companions, uploaded media, and profile are removed through the applicable deletion flow.

Retention and security

Account content is retained while your account is active unless you remove it. Structured application errors are retained for up to 90 days. Rate-limit counters expire automatically. Beta page-view analytics are retained for operational analysis while a formal retention schedule is being established.

Wristband uses row-level database controls, private object storage, short-lived signed media links, authentication checks, rate limits, and typed confirmation for destructive actions. No system can guarantee absolute security.

Your choices and requests

  • Edit your profile and visibility choices.
  • Change memory and photo visibility.
  • Download your Show archive.
  • Remove your content or permanently delete your account.
  • Ask the private-beta organizer for help through the channel used for your invitation.

Children

Wristband is not directed to children under 13 and does not knowingly collect their personal information. If you believe a child under 13 has provided information, contact the beta organizer so it can be reviewed and removed.