The data controller responsible for the processing of your personal data is YourLabel LLC, operating the music distribution platform at yourlabel.app (“Platform”, “we”, “us”, “our”).
For all matters relating to your personal data, including exercising your rights under the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and other applicable data protection legislation, contact us at [email protected].
We collect only what is strictly necessary for the Service (data minimisation, GDPR Article 5(1)(c)):
| Category | Data Points | Source |
|---|---|---|
| Account data | Email address, hashed password | You, at registration |
| Identity / KYC data | Legal name, country of residence, phone number, scan of government-issued ID; for entities: incorporation documents, beneficial owner identification | You, in Settings |
| Artist profile | Display/artist name, optional store profile URLs | You |
| Music content & metadata | Audio files, artwork, titles, lyrics, genre, dates, UPC/ISRC, credits | You, on upload |
| Financial data | PayPal email address, or bank payout details (account holder name, IBAN, SWIFT/BIC, bank name, bank country) | You, in Settings |
| Technical / usage data | IP address at login, last login timestamp, session token | Automatic |
| Service usage measurement | Device category (mobile, tablet or desktop), operating system, browser family and two-letter country code, recorded when you use your dashboard. Stored both as daily totals and as the most recent values on your account. We do not store the User-Agent string or the IP address this is derived from, and we do not use cookies, pixels or any third-party analytics service for it. | Automatic, dashboard |
| Traffic measurement | For a visit to a public page: the referring website (or the utm_ tags on the link followed), the page landed on, device category and two-letter country code. Kept only as daily totals across those buckets — never tied to a person, a device or an IP address, and with nothing written to your device. | Automatic, public pages |
| Signup source | The referring website or campaign tags that were in play when your account was created, stored once on the account and never updated afterwards. | Automatic, at registration |
| Smart link analytics | Anonymised click counts per platform; no listener personal data | Automatic, public pages |
| Support communications | Ticket content and attached images | You |
We do not collect special category data (GDPR Article 9). Identity documents are collected solely for verification, compliance, and legal-claims purposes and are not processed for biometric profiling.
Service usage measurement exists so we can decide what to build — for example whether artists work mainly from a phone or a desktop, and which countries to prioritise. It is deliberately coarse: we keep buckets, not fingerprints. Public pages are counted the same way — how many arrivals came from which website or campaign, on what kind of device, from which country — without cookies, without any identifier stored on your device and without a third-party analytics service. The country comes from a header our network provider adds to the request; we never look up your IP address in a geolocation database. That same country header also decides whether the service is available in your region. The legal basis is our legitimate interest in understanding and improving the service (Article 6(1)(f) GDPR), and you can object to it at any time under Article 21 by writing to [email protected].
| Processing Activity | Lawful Basis | GDPR Ref. |
|---|---|---|
| Account creation and authentication | Performance of a contract | Art. 6(1)(b) |
| Identity verification (KYC) | Legal obligation; legitimate interests (fraud prevention; establishment of legal claims) | Art. 6(1)(c), 6(1)(f) |
| Music distribution to stores | Performance of a contract | Art. 6(1)(b) |
| Royalty calculation and payout | Performance of a contract | Art. 6(1)(b) |
| Transactional emails | Contract; legitimate interests | Art. 6(1)(b), 6(1)(f) |
| IP logging at login | Legitimate interests (security) | Art. 6(1)(f) |
| Smart link click counting | Legitimate interests (analytics for you) | Art. 6(1)(f) |
| Bot protection on auth forms | Legitimate interests (security, abuse prevention) | Art. 6(1)(f) |
We process your personal data exclusively for:
We do not use your personal data for automated decision-making or profiling producing legal or similarly significant effects (GDPR Article 22).
We engage the following processors under Data Processing Agreements (GDPR Art. 28):
| Processor | Role | Data Transferred | Location |
|---|---|---|---|
| Supabase | Database & authentication | Account, profile, release metadata, earnings | EU (AWS eu-central-1) |
| Cloudflare (R2) | Object storage & CDN | Audio, artwork, identity documents | EU region pinned |
| Resend | Transactional email | Email address, email content | US (SCCs apply) |
| Google reCAPTCHA | Bot protection on login/register forms | IP address, device signals | US (SCCs apply) |
| PayPal | Royalty payout processing (where you choose PayPal) | PayPal email address, payout amount | US (SCCs apply) |
| Banks and payment institutions | Execution of bank transfers (where you choose bank transfer) | Account holder name, IBAN, SWIFT/BIC, bank name and country, payout amount | Depends on the bank you nominate |
| Digital stores & streaming platforms | Distribution recipients (independent controllers) | Artist name, metadata, audio, artwork, UPC/ISRC | Worldwide |
Digital stores act as independent controllers once content is delivered; their own privacy policies apply on their platforms. We do not sell your personal data and do not share it for advertising or data brokerage.
Where personal data is transferred outside the EEA, we ensure an appropriate safeguard: Standard Contractual Clauses (Commission Decision 2021/914) for transfers to the US and other non-adequate countries, or an adequacy decision where available (GDPR Article 45). Distribution of your music necessarily involves worldwide transfer of your artist name and release metadata; this transfer is strictly necessary for the performance of our contract with you (GDPR Article 49(1)(b)) and is limited to the metadata required by each store.
| Data Category | Retention Period | Justification |
|---|---|---|
| Account data | Until account deletion, then 30 days | Contractual necessity |
| Identity / KYC documents | 5 years from account closure | AML compliance (Art. 6(1)(c)); establishment, exercise or defence of legal claims (Art. 17(3)(e)), incl. copyright-infringement and fraud claims under the Distribution Agreement |
| Earnings & payout records | 7 years from the financial year of recording | Tax and accounting law |
| Support ticket content | 3 years from closure | Dispute resolution |
| Login IP address | 12 months rolling | Security |
| Smart link click data | 24 months rolling or until link deletion | Service analytics |
| Music files & metadata on stores | Until takedown is processed by each store (up to 30 business days) | Contractual obligations with partners |
Upon expiry of the applicable period, personal data is securely deleted or irreversibly anonymised (GDPR Article 5(1)(e)).
You have the rights of access (Art. 15), rectification (Art. 16), erasure where no overriding legal basis applies (Art. 17), restriction (Art. 18), portability (Art. 20), and objection to legitimate-interest processing (Art. 21); the right not to be subject to solely automated decisions with significant effects (Art. 22 — we do not use such processes); and the right to lodge a complaint with a supervisory authority (Art. 77). Note that erasure requests cannot override the statutory retention periods in Section 7, including KYC retention for AML and legal-claims purposes.
We use only strictly necessary cookies and functional storage; see the Cookie Policy at yourlabel.app/cookies for the complete list. We do not use advertising cookies, third-party tracking, or analytics platforms such as Google Analytics or Meta Pixel.
Pursuant to GDPR Art. 32 we implement:
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours (Art. 33) and affected data subjects without undue delay where required (Art. 34).
The Service is directed exclusively at individuals aged 18 and over. We do not knowingly collect personal data from persons under 18 and will delete such data promptly upon becoming aware of it. Reports: [email protected].
We may amend this Policy from time to time. The version in force at any time is the version published at yourlabel.app/privacy, and an amendment takes effect when it is published there. Publication is the method by which we inform you of a change: we do not send individual emails or dashboard notices about amendments to this Policy, we do not publish a change log or version history, and the date at the head of this page indicates the edition then published rather than the date of each individual change. You should therefore read the current version before continuing to use the Service.
This does not affect the rights the GDPR gives you. Where we intend to process your personal data for a new purpose that is not covered by this Policy, we will inform you of that purpose, and of the information required by Article 13(2) or 14(2) GDPR, before that further processing begins, as Article 13(3) and 14(4) require. Where a change relies on your consent, we will ask for that consent and will not act on the change until you give it. Where applicable law requires advance notice of a change or gives you a right to object, we will comply with that requirement.