Legal
Privacy Policy
What we collect, why we collect it, how we keep it safe, and the control you keep over it — across the website, the waitlist and the CueBridge apps.
Last updated 8 October 2026
1. Who we are and what this covers
CueBridge, the professional network for artists, DJs, labels, venues, radio stations and promoters, is operated by Francis Koroma, Founder & CEO ("CueBridge", "we", "us"). We are the controller of the personal data described here.
This policy covers cuebridge.io, the CueBridge waitlist, the CueBridge apps for iOS and Android, and any other service that links to it (together, the "Services"). Some parts describe features of the full app that are not live yet; we say so where it matters, and we will update this policy before anything here changes.
Questions about privacy go to privacy@cuebridge.io.
2. Information we collect
Information you give us
- Waitlist. Your email address, the role you work in, the roles you want to reach, and the referral code you joined with, if any. If you choose to add them, your city and genre. We generate your referral code, waitlist position and founding-member status. Your sign-up is stored in our database (Supabase), a copy is kept in our hosting provider's form storage (Netlify), and the CueBridge team gets an email when you join.
- Account. Your name or artist name, email address and password (stored only as a salted hash — never in readable form). If you sign in with Apple or Google, we receive the name and email address that service shares with your permission; with Sign in with Apple you can hide your real email.
- Profile. Photo, bio, roles, genres, skills, rates, availability, city or region, links, credits and endorsements. You decide what to publish.
- Content you upload. Tracks, mixes, images, video, press kits, tech riders, stage plots and other files.
- Messages and bookings. Messages and attachments you send, and booking requests, dates, fees, venue details and confirmations.
- Purchases. If you buy a subscription in the app, Apple or Google processes the payment. We receive confirmation of what you bought and whether it is active — never your card number.
- Support and safety reports. What you tell us when you contact support or report content or a member.
Information collected automatically
- Device and log data. IP address, device and browser type, operating system, app version, language, the pages or screens requested and when, and crash and performance diagnostics.
- Usage within CueBridge. Features used, searches and profiles viewed, so we can run matching and improve the product. We do not use it to build advertising profiles.
- Approximate location. Your country or region, derived from your IP address, for security and to suggest your city. Precise device location is collected only if you allow it and use a feature that needs it, and you can switch it off at any time.
- Notification token. If you allow push notifications, a token that lets us deliver them to your device.
- Device storage. The website stores two small preferences in your browser and the app keeps your sign-in session in your device's secure storage. The Cookie Policy lists exactly what and why.
Information from other people
- Members who refer you, credit or endorse you, tag you in a booking, or message you.
- Sign-in providers (Apple, Google), limited to what you authorise them to share.
What we do not collect
We do not ask for sensitive information — racial or ethnic origin, health, religion, political opinions, sexual orientation, biometric data or government ID numbers — and we ask you not to add it to your profile or messages. We do not read your contacts, and the app only reaches photos, files, the camera or the microphone when you pick something to upload or start a recording.
3. App permissions
The app asks for a permission only at the moment a feature needs it, explains why, and keeps working if you say no. You can change any of these in your device settings at any time.
| Permission | What it is used for | Required? |
|---|---|---|
| Photos and files | Choosing a profile picture or a file to upload. Only the items you select are read. | No |
| Camera | Taking a profile photo or capturing media. | No |
| Microphone | Recording audio inside the app, where that feature is offered. | No |
| Notifications | Message and booking updates. | No |
| Location | Showing members and venues near you. Approximate location is enough. | No |
4. How we use information, and our legal bases
We use personal data only for the purposes below. Where the law requires a legal basis (for example, the GDPR in the EEA and UK), it is listed alongside.
| Purpose | Legal basis |
|---|---|
| Providing CueBridge: your account, profile, discovery, messaging, file sharing and bookings. | Performance of our contract with you |
| Running the waitlist: your invitation, position, referrals and building beta cohorts. | Steps you asked us to take before a contract; legitimate interests |
| Matching: using your roles, genres, location and availability to suggest people to work with. | Performance of our contract with you |
| Service messages: security alerts, booking and account emails, and notice of changes to our terms. | Contract; legal obligation |
| Marketing email. Before launch, the only email you get is the one telling you CueBridge is open. | Your consent, which you can withdraw at any time |
| Safety and integrity: preventing fraud, spam and abuse, moderating content, and enforcing our Terms. | Legitimate interests; legal obligation |
| Improving the Services using aggregated or de-identified statistics and diagnostics. | Legitimate interests |
| Complying with the law and responding to valid legal requests. | Legal obligation |
Matching suggests people; it never makes decisions about you that have legal or similarly significant effects. Where we rely on legitimate interests, we have weighed them against your rights, and you can object (see section 9).
6. No advertising, no cross-app tracking
CueBridge carries no third-party advertising and no advertising SDKs. We do not use your device's advertising identifier, we do not link our data with other companies' data for advertising, and we do not sell to or buy from data brokers. Because we do not track you across other companies' apps and websites, the iOS app does not show the App Tracking Transparency prompt. If that ever changes, we will ask for your permission first and update this policy before we do.
We treat a Global Privacy Control signal from your browser as a valid request to opt out of any sale or sharing — which, as above, we do not do anyway.
7. How we collect and protect your data safely
Protecting the people who trust us with their information is part of how CueBridge is built, not a step added at the end. These rules apply every time we collect personal data:
- Collect the minimum. Every field has to justify itself. The waitlist asks for an email address and two role questions because that is all it needs to invite you and build a beta cohort.
- Say why at the point of collection. Our forms say what we ask for and link to this policy before you submit anything.
- Use it only for the stated purpose. Data collected for one purpose is not quietly reused for another.
- Ask before anything optional, and make it as easy to withdraw as it was to give.
- Encrypt it. All traffic uses HTTPS (TLS). Databases, file storage and backups are encrypted at rest.
- Limit who can reach it. Access is restricted to the people and systems that need it, protected by multi-factor authentication and logged. The public website can only add a waitlist signup, through a single database function — it cannot read the list back.
- Never store what we do not need to hold. Passwords are stored only as salted hashes, and payment card details never reach our servers.
- Check our vendors. We use established providers with independent security certifications and sign data processing agreements with them.
- Keep it only as long as needed, then delete it securely (see section 8).
- Respond quickly if something goes wrong. If a breach puts your data at risk, we notify the relevant regulator within 72 hours where the law requires it, and tell affected members without undue delay.
No system is perfectly secure, but these are the standards we hold ourselves to. Our Data Security page describes the measures in more detail and explains how to report a vulnerability.
8. How long we keep information
| Information | How long we keep it |
|---|---|
| Waitlist details | Until you create an account (they then become part of it), or 12 months after public launch if you do not — or sooner if you ask us to remove them. This applies to both the database record and the copy in Netlify, and to the notification emails sent to the team. |
| Account, profile, uploads and messages | While your account is open. Deleted within 30 days of you deleting your account. |
| Records we must keep by law (for example, purchase records for tax) | Only those records, for the period the law requires. |
| Server and security logs | Up to 90 days. |
| Backups | Deleted data leaves our rolling backups within 35 days. |
| Safety reports and enforcement records | As long as needed to keep members safe, and no more than 3 years after an account closes — so that someone banned for serious abuse cannot simply return. |
| Inactive accounts | If an account is unused for 24 months, we email you and then delete it if you do not respond. |
Statistics we keep after deletion are aggregated or de-identified so they can no longer be linked to you.
9. Your rights and choices
Wherever you live, you can ask us to:
- Access the personal data we hold about you, and download a portable copy of it.
- Correct anything that is inaccurate or incomplete.
- Delete your data or your whole account. In the app, go to Settings → Account → Delete account; the Delete Your Account page explains every other way.
- Object to or restrict how we use your data, including where we rely on legitimate interests.
- Withdraw consent at any time, without affecting what we did before you withdrew it.
- Stop marketing email using the unsubscribe link in any message.
Most of this can be done in the app under Settings → Privacy. Otherwise, email privacy@cuebridge.io. We will confirm the request comes from you before acting on it, respond within 30 days (or explain if the law allows us longer), and never charge you or treat you differently for using your rights.
EEA and UK residents
You also have the right to lodge a complaint with your local data protection authority. We would appreciate the chance to resolve your concern first.
US state residents (including California)
In the last 12 months we have collected these categories of personal information: identifiers (such as name, email and IP address); customer records; commercial information (subscriptions); internet or app activity; approximate geolocation; audio and visual content you upload; and professional information on your profile. The sources, purposes and recipients are described in sections 2, 4 and 5. We have not sold or shared personal information as those terms are defined in California law, we do not use sensitive personal information to infer characteristics about you, and you may use an authorised agent to make a request on your behalf.
Everywhere else
We honour the data protection laws that apply to you — for example Nigeria's NDPA, Brazil's LGPD, Canada's PIPEDA and Australia's Privacy Act — and we offer the rights above to every member regardless of where they live.
10. International transfers
Our service providers may process data in countries other than yours, including the United States and the European Union. When personal data leaves the EEA, the UK or another country with transfer rules, we rely on an adequacy decision or on safeguards such as the European Commission's Standard Contractual Clauses and the UK Addendum, and we require the recipient to protect it to the standard this policy sets.
11. Children
CueBridge is a professional network and is not meant for anyone under 16. We do not knowingly collect personal data from children under 16. If we learn that we have, we delete it and close the account. If you believe a child has given us their information, contact privacy@cuebridge.io.
12. Links to other services
Profiles can link to streaming services, social networks and other websites. Those services are governed by their own privacy policies, not this one, and we encourage you to read them.
13. Changes to this policy
When we change this policy, we update the date at the top. If a change is significant, we tell you by email or in the app at least 14 days before it takes effect, and where the law requires it we ask for your consent again. Previous versions are available on request.
14. Contact us
CueBridge · Francis Koroma, Founder & CEO · privacy@cuebridge.io