Legal Document

Privacy Policy

Effective: 25 July 2026Last updated: 21 August 2026
Article 4(7) GDPR

1. Data Controller

The data controller responsible for the processing of your personal data is YourLabel LLC, operating the music distribution platform at yourlabel.app (“Platform”, “we”, “us”, “our”).

For all matters relating to your personal data, including exercising your rights under the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and other applicable data protection legislation, contact us at [email protected].

Note: YourLabel does not currently appoint a formal Data Protection Officer, as it does not meet the thresholds under GDPR Article 37; data protection is handled as a core operational responsibility.

Articles 13–14 GDPR

2. Personal Data We Collect

We collect only what is strictly necessary for the Service (data minimisation, GDPR Article 5(1)(c)):

CategoryData PointsSource
Account dataEmail address, hashed passwordYou, at registration
Identity / KYC dataLegal name, country of residence, phone number, scan of government-issued ID; for entities: incorporation documents, beneficial owner identificationYou, in Settings
Artist profileDisplay/artist name, optional store profile URLsYou
Music content & metadataAudio files, artwork, titles, lyrics, genre, dates, UPC/ISRC, creditsYou, on upload
Financial dataPayPal email address, or bank payout details (account holder name, IBAN, SWIFT/BIC, bank name, bank country)You, in Settings
Technical / usage dataIP address at login, last login timestamp, session tokenAutomatic
Service usage measurementDevice category (mobile, tablet or desktop), operating system, browser family and two-letter country code, recorded when you use your dashboard. Stored both as daily totals and as the most recent values on your account. We do not store the User-Agent string or the IP address this is derived from, and we do not use cookies, pixels or any third-party analytics service for it.Automatic, dashboard
Traffic measurementFor a visit to a public page: the referring website (or the utm_ tags on the link followed), the page landed on, device category and two-letter country code. Kept only as daily totals across those buckets — never tied to a person, a device or an IP address, and with nothing written to your device.Automatic, public pages
Signup sourceThe referring website or campaign tags that were in play when your account was created, stored once on the account and never updated afterwards.Automatic, at registration
Smart link analyticsAnonymised click counts per platform; no listener personal dataAutomatic, public pages
Support communicationsTicket content and attached imagesYou

We do not collect special category data (GDPR Article 9). Identity documents are collected solely for verification, compliance, and legal-claims purposes and are not processed for biometric profiling.

Service usage measurement exists so we can decide what to build — for example whether artists work mainly from a phone or a desktop, and which countries to prioritise. It is deliberately coarse: we keep buckets, not fingerprints. Public pages are counted the same way — how many arrivals came from which website or campaign, on what kind of device, from which country — without cookies, without any identifier stored on your device and without a third-party analytics service. The country comes from a header our network provider adds to the request; we never look up your IP address in a geolocation database. That same country header also decides whether the service is available in your region. The legal basis is our legitimate interest in understanding and improving the service (Article 6(1)(f) GDPR), and you can object to it at any time under Article 21 by writing to [email protected].


Article 6 GDPR

3. Lawful Basis for Processing

Processing ActivityLawful BasisGDPR Ref.
Account creation and authenticationPerformance of a contractArt. 6(1)(b)
Identity verification (KYC)Legal obligation; legitimate interests (fraud prevention; establishment of legal claims)Art. 6(1)(c), 6(1)(f)
Music distribution to storesPerformance of a contractArt. 6(1)(b)
Royalty calculation and payoutPerformance of a contractArt. 6(1)(b)
Transactional emailsContract; legitimate interestsArt. 6(1)(b), 6(1)(f)
IP logging at loginLegitimate interests (security)Art. 6(1)(f)
Smart link click countingLegitimate interests (analytics for you)Art. 6(1)(f)
Bot protection on auth formsLegitimate interests (security, abuse prevention)Art. 6(1)(f)
Where we rely on Article 6(1)(f), we have assessed that our legitimate interests are not overridden by your fundamental rights and freedoms, given the limited and proportionate nature of the data processed.

Article 5(1)(b) GDPR — Purpose Limitation

4. Purposes of Processing

We process your personal data exclusively for:

  • Account management.
  • Identity verification as required by our distribution partners, AML/sanctions obligations, and internal anti-fraud policies.
  • Music distribution, including transmitting your name, artist name, and release metadata to the stores you select.
  • Royalty administration and withdrawal processing.
  • Transactional service communications (we do not send unsolicited marketing emails).
  • Security and fraud prevention.
  • Legal compliance, including retention of financial records under tax and accounting laws.
  • Enforcement of our agreements — establishing the identity of account holders for the purpose of pursuing or defending legal claims arising from breach of our Terms or the Distribution Agreement, including intellectual-property infringement and fraud.

We do not use your personal data for automated decision-making or profiling producing legal or similarly significant effects (GDPR Article 22).


Article 28 GDPR — Processor Agreements

5. Third-Party Processors & Data Recipients

We engage the following processors under Data Processing Agreements (GDPR Art. 28):

ProcessorRoleData TransferredLocation
SupabaseDatabase & authenticationAccount, profile, release metadata, earningsEU (AWS eu-central-1)
Cloudflare (R2)Object storage & CDNAudio, artwork, identity documentsEU region pinned
ResendTransactional emailEmail address, email contentUS (SCCs apply)
Google reCAPTCHABot protection on login/register formsIP address, device signalsUS (SCCs apply)
PayPalRoyalty payout processing (where you choose PayPal)PayPal email address, payout amountUS (SCCs apply)
Banks and payment institutionsExecution of bank transfers (where you choose bank transfer)Account holder name, IBAN, SWIFT/BIC, bank name and country, payout amountDepends on the bank you nominate
Digital stores & streaming platformsDistribution recipients (independent controllers)Artist name, metadata, audio, artwork, UPC/ISRCWorldwide

Digital stores act as independent controllers once content is delivered; their own privacy policies apply on their platforms. We do not sell your personal data and do not share it for advertising or data brokerage.


Articles 44–49 GDPR — International Transfers

6. International Transfers

Where personal data is transferred outside the EEA, we ensure an appropriate safeguard: Standard Contractual Clauses (Commission Decision 2021/914) for transfers to the US and other non-adequate countries, or an adequacy decision where available (GDPR Article 45). Distribution of your music necessarily involves worldwide transfer of your artist name and release metadata; this transfer is strictly necessary for the performance of our contract with you (GDPR Article 49(1)(b)) and is limited to the metadata required by each store.


Article 5(1)(e) GDPR — Storage Limitation

7. Retention Periods

Data CategoryRetention PeriodJustification
Account dataUntil account deletion, then 30 daysContractual necessity
Identity / KYC documents5 years from account closureAML compliance (Art. 6(1)(c)); establishment, exercise or defence of legal claims (Art. 17(3)(e)), incl. copyright-infringement and fraud claims under the Distribution Agreement
Earnings & payout records7 years from the financial year of recordingTax and accounting law
Support ticket content3 years from closureDispute resolution
Login IP address12 months rollingSecurity
Smart link click data24 months rolling or until link deletionService analytics
Music files & metadata on storesUntil takedown is processed by each store (up to 30 business days)Contractual obligations with partners

Upon expiry of the applicable period, personal data is securely deleted or irreversibly anonymised (GDPR Article 5(1)(e)).


Articles 15–22 & 77 GDPR

8. Your Rights Under GDPR

You have the rights of access (Art. 15), rectification (Art. 16), erasure where no overriding legal basis applies (Art. 17), restriction (Art. 18), portability (Art. 20), and objection to legitimate-interest processing (Art. 21); the right not to be subject to solely automated decisions with significant effects (Art. 22 — we do not use such processes); and the right to lodge a complaint with a supervisory authority (Art. 77). Note that erasure requests cannot override the statutory retention periods in Section 7, including KYC retention for AML and legal-claims purposes.

Right of Access
Article 15 GDPR
Obtain confirmation of whether we process your personal data and receive a copy of it.
Right to Rectification
Article 16 GDPR
Have inaccurate or incomplete personal data corrected. You can update most data directly in Settings.
Right to Erasure
Article 17 GDPR
Request deletion of your personal data where no overriding legal basis applies.
Right to Restriction
Article 18 GDPR
Request that we restrict processing of your data without deleting it.
Right to Portability
Article 20 GDPR
Receive your personal data in a structured, machine-readable format.
Right to Object
Article 21 GDPR
Object to processing based on legitimate interests.
No Automated Decisions
Article 22 GDPR
Not be subject to decisions based solely on automated processing with significant effects.
Right to Lodge a Complaint
Article 77 GDPR
Lodge a complaint with a supervisory authority in your EU member state.
We respond to verified requests within 30 calendar days (extendable by 60 days in complex cases, with notice). To exercise any right, email [email protected] from your registered address, naming the right you invoke; we may request additional information to verify your identity (Art. 12(6)).

ePrivacy Directive; GDPR Recital 30

9. Cookies & Local Storage

We use only strictly necessary cookies and functional storage; see the Cookie Policy at yourlabel.app/cookies for the complete list. We do not use advertising cookies, third-party tracking, or analytics platforms such as Google Analytics or Meta Pixel.


Article 32 GDPR — Security of Processing

10. Security Measures

Pursuant to GDPR Art. 32 we implement:

  • TLS 1.2+ in transit with HSTS.
  • AES-256 encryption at rest for files in R2.
  • bcrypt password hashing with per-user salts.
  • Row-level security ensuring users access only their own data, with role-restricted and logged admin access.
  • Rate limiting on authentication endpoints.
  • Enforced CSP, X-Frame-Options (DENY), and Permissions-Policy headers.
  • Least-privilege scoping of service accounts and tokens.

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours (Art. 33) and affected data subjects without undue delay where required (Art. 34).


GDPR Recital 38

11. Children

The Service is directed exclusively at individuals aged 18 and over. We do not knowingly collect personal data from persons under 18 and will delete such data promptly upon becoming aware of it. Reports: [email protected].


GDPR Article 13(2)

12. Changes to This Policy

We may amend this Policy from time to time. The version in force at any time is the version published at yourlabel.app/privacy, and an amendment takes effect when it is published there. Publication is the method by which we inform you of a change: we do not send individual emails or dashboard notices about amendments to this Policy, we do not publish a change log or version history, and the date at the head of this page indicates the edition then published rather than the date of each individual change. You should therefore read the current version before continuing to use the Service.

This does not affect the rights the GDPR gives you. Where we intend to process your personal data for a new purpose that is not covered by this Policy, we will inform you of that purpose, and of the information required by Article 13(2) or 14(2) GDPR, before that further processing begins, as Article 13(3) and 14(4) require. Where a change relies on your consent, we will ask for that consent and will not act on the change until you give it. Where applicable law requires advance notice of a change or gives you a right to object, we will comply with that requirement.


Contact the Data Controller
YourLabel LLC
Data protection: [email protected]
General support: [email protected]
Website: yourlabel.app
EU supervisory authorities: edpb.europa.eu