bandcamped
Privacy Policy
Last updated: June 2026
1. Who we are (Data Controller)
2. What data we collect, why, and the legal basis
We collect and process personal data only for the purposes described below. For each purpose we identify the legal basis under GDPR Article 6.
Account information
When you register, Clerk collects your email address and, if you sign in with Google, your name and profile picture. We store your email and any Bandcamp username you choose to link. Legal basis: performance of contract — this data is necessary to provide your account and personalise your experience (Art. 6(1)(b)).
Bandcamp connection
When you link your Bandcamp account, we store your Bandcamp username and sync the URLs of releases in your collection to power overlap analysis. Legal basis: performance of contract (Art. 6(1)(b)).
Digging history, crate, and taste map
We store the releases you search, items you save to your crate, and the results of the taste overlap analysis. This data is tied to your account and visible only to you. Legal basis: performance of contract (Art. 6(1)(b)).
Public Bandcamp data we cache
To power overlap analysis and improve performance, we cache publicly available data from Bandcamp — including fan collection lists and release metadata. This data is already public on Bandcamp. Legal basis: legitimate interest in providing a fast, functional service (Art. 6(1)(f)). This caching does not involve any sensitive personal data and users can reasonably expect their public Bandcamp collections to be read by third-party tools.
Authentication cookies
Clerk sets session cookies strictly necessary to authenticate you and maintain your session. Legal basis: performance of contract (Art. 6(1)(b)). No consent is required for strictly necessary cookies under the ePrivacy Directive.
Server logs
Our hosting infrastructure (Vercel) automatically logs IP addresses and request metadata for security and diagnostic purposes. Legal basis: legitimate interest in maintaining service security and stability (Art. 6(1)(f)).
We do not use advertising cookies, tracking pixels, or behavioural analytics. We do not sell your data to any third party.
3. How long we keep your data
- —Account data (email, linked Bandcamp username): retained while your account is active. Upon deletion, purged within 30 days.
- —Digging history, crate, and taste map: deleted immediately and permanently when you delete your account.
- —Cached public Bandcamp data: cached with a 30-day rolling TTL. It expires automatically and is not linked to any identifiable individual.
- —Server logs: retained for up to 12 months for security purposes, then deleted.
- —Session cookies: expire when you close your browser or sign out.
4. Who we share your data with
We do not sell or share your personal data with third parties for their own purposes. We use the following processors who act on our behalf:
- —Clerk (authentication) — United States. Transfers are protected by Standard Contractual Clauses and the EU–US Data Privacy Framework. Privacy policy: clerk.com/privacy.
- —Supabase (database) — our primary database is hosted in Frankfurt, Germany (EU). Your personal data is stored within the European Economic Area. Privacy policy: supabase.com/privacy.
- —Vercel (hosting) — United States. Transfers are protected by Standard Contractual Clauses. Privacy policy: vercel.com/legal/privacy-policy.
- —Upstash (temporary caching) — United States. Used solely to cache Bandcamp API responses (not personal account data). Transfers are protected by Standard Contractual Clauses.
We are not affiliated with Bandcamp, Inc. We read only publicly available data from Bandcamp's APIs and are not responsible for Bandcamp's privacy practices.
5. Your rights under the GDPR
As a data subject under the GDPR, you have the following rights, exercisable at any time by emailing hi@bandcamped.io. We will respond within one month.
- —Right of access (Art. 15) — obtain confirmation of whether we process your data and receive a copy of it.
- —Right to rectification (Art. 16) — have inaccurate personal data corrected.
- —Right to erasure (Art. 17) — request deletion of your personal data. You can exercise this directly from the Account page at any time.
- —Right to restriction (Art. 18) — request that we limit our processing in certain circumstances.
- —Right to data portability (Art. 20) — receive your personal data in a structured, machine-readable format.
- —Right to object (Art. 21) — object to processing based on legitimate interest. We will stop unless we can demonstrate compelling legitimate grounds that override your interests.
- —Right to lodge a complaint — if you believe your rights have been infringed, you have the right to lodge a complaint with the Spanish Data Protection Authority (Agencia Española de Protección de Datos, AEPD) at www.aepd.es, or with the supervisory authority of the EU member state where you reside or work.