Who is responsible for your data
ConcertLove is operated by Pieter Bas Donkersteeg ("we", "us"), based in the Netherlands. Under the GDPR we are the controller of the personal data described below, and you can reach us at the address in the next paragraph.
Questions, requests, or complaints: info@concertlove.nl. You also have the right to lodge a complaint with your national data protection authority. In the Netherlands that is the Autoriteit Persoonsgegevens.
The short version
ConcertLove keeps a record of the concerts you have been to. Until recently that record lived only on your phone. It no longer does: since the app got accounts, friends and shared concert threads, your archive is stored on a server we run so that it survives a lost phone and so that the people you were at a concert with can talk to each other.
We do not sell your data, we do not show advertising, and we do not use analytics or tracking of any kind — no SDKs, no identifiers for advertisers, no profiling.
What we store, and where
On our server
We use Supabase (PostgreSQL, authentication and file storage) hosted in the European Union — Stockholm, Sweden (AWS eu-north-1). Your data does not leave the EU. The following is stored there and linked to your account:
Your account
- Your e-mail address and a hash of your password, if you sign up with e-mail.
- If you use Sign in with Apple: the identifier Apple gives us, and the e-mail address Apple passes on. If you chose to hide your address, we only ever receive Apple's private relay address and never your real one.
- If you use Sign in with Apple, we also keep one token from Apple. It exists for a single purpose: Apple requires that we cancel the connection when you delete your account, and that cancellation is not possible without it. It cannot be used to sign in to anything, and it tells us nothing about you.
- A username, generated when you register and changeable by you. This is how other users find you.
- A display name, optional, taken from Sign in with Apple or typed by you.
- A profile photo, only if you upload one.
- Optionally, your setlist.fm username, if you choose to link that account. We never ask for or receive your setlist.fm password.
Your concerts
- Which concerts you marked as attended: artist, venue, city, country and date.
- Which of them came from a search, a setlist.fm import, an invitation, or your own manual entry.
- The note you wrote about a concert, your rating, and the start time from your ticket or calendar, where you filled those in.
- Songs you added to a concert yourself, including ones identified with Shazam.
Your people
- The friends you added: their name, and a link to their ConcertLove account if they have one and you are connected. Photos you add for a friend stay on your phone and are not uploaded.
- Friend requests and concert invitations between accounts, and whether they were accepted or declined.
- Invitation links you created: the link's token, which concert it was about, and when and by whom it was used.
Who you would rather not hear from
- The accounts you blocked. The person you blocked is never shown this.
- Reports you send us: what you reported, the reason you picked, anything you chose to add, and — when you report a message — the text of that message as it was at the moment you reported it. We keep that copy because a reported message is often deleted straight afterwards, and a report about nothing helps nobody.
Your messages
- The messages you write in a concert thread, including the one-line answer to "how was it?". These are stored in plain text on the server. They are not end-to-end encrypted, which means that we, as the operator of the database, are technically able to read them. We do not, other than where we are legally obliged to or where it is strictly necessary to investigate abuse.
On your phone only
- A local copy of your archive, so the app works without a connection and so a marking made at a festival is sent later.
- Photos you add for friends who do not use the app.
- Your Spotify access and refresh tokens, if you connect Spotify.
- App preferences and settings.
Signing out or deleting your account removes all of this from the device.
What we deliberately do not store
- No setlist.fm password. The app no longer asks for one.
- No payment details. There is currently no purchase in the app; if that changes, Apple would handle payment and we would still never see your card details.
- No setlists. The songs of a concert are fetched live from setlist.fm every time and are not copied into our database. The only songs we store are the ones you added yourself.
- No location data, no contacts, no device identifiers, no usage analytics.
Who can see what
This matters more in ConcertLove than in most apps, because some of what you write is meant for other people. In plain terms:
- Your concerts, notes and ratings are yours. Nobody else can read them. This is enforced by row level security in the database, not only by the app.
- Your username, display name and profile photo are findable. Any signed-in ConcertLove user who searches can see them. Your e-mail address and your setlist.fm username are never shown to anybody.
- Profile photos are stored in a public bucket. Anyone who has the direct URL of the image file can open it without signing in. If you would rather not have a photo that is reachable that way, do not upload one — the app shows your initials instead.
- Messages in a concert thread are readable by the people in that thread: everybody who confirmed, through an accepted invitation, that they were at that concert. The app shows you who those people are.
- Reports are seen by us and nobody else. The person you reported is not told who reported them.
- Invitation links are public by design. Anyone who has the link can see the first name of the sender, the artist, the venue and the date, without an account. Anyone who opens it in the app becomes a connection of the sender. Send these links to the person they are for.
Why we are allowed to store it (legal bases)
- Performance of a contract (Art. 6(1)(b) GDPR) — your account, your archive, your friendships and your messages. Without them the app cannot do the thing you installed it for.
- Legitimate interest (Art. 6(1)(f)) — keeping the service secure and working, and preventing abuse.
- Consent (Art. 6(1)(a)) — access to your calendar, your microphone for Shazam, and your photo library. You grant these through iOS, per feature, and you can withdraw them at any time in iOS Settings. Connecting Spotify is also consent, and disconnecting withdraws it.
Third parties
The app talks to these services. Except where noted, they receive an artist, venue or search term and your device's IP address, but nothing that identifies your ConcertLove account.
| Service | What it is for | What it receives |
|---|
| Supabase | Our database, authentication and file storage; acts as our processor | Everything under "On our server" above |
| Theory7 b.v. (Hoogeveen, the Netherlands) | Hosting concertlove.nl and delivering the two e-mails the app sends — confirming your address and resetting your password; acts as our processor. Their servers are in the Netherlands | Your e-mail address and the contents of those messages, and the IP address of anyone who opens one of our web pages |
| Apple | Sign in with Apple, App Store, Shazam recognition, calendar and photo access | Your Apple ID sign-in; Shazam receives an audio fingerprint, not a recording |
| setlist.fm | Concert and setlist data | Searches and setlist IDs, through our server. One feature — finding shows that have not happened yet — is fetched by your phone directly from www.setlist.fm, which therefore sees your IP address |
| Spotify | Importing your favourite artists, only if you connect it | Your authorisation; we receive your followed and top artists |
| Ticketmaster | Finding upcoming shows | An artist name and your IP address |
| Last.fm, Deezer, Cover Art Archive, Wikipedia, iTunes | Artist images | An artist name and your IP address |
Calendar events are read on your device only. They are never sent to us or to anybody else.
The two e-mails, and the pages they lead to
The app sends you e-mail in exactly two situations, and never for anything else — no newsletter, no tips, no "we miss you".
- Confirming your address, once, when you sign up. The link in it confirms your address and then sends your browser to a page on concertlove.nl that says so. Nothing else happens there.
- Resetting your password, when you ask for it. That link carries a token and leads to a page on concertlove.nl with a form for your new password. Two things worth knowing about it: the link works for one hour and once, and for that hour anybody holding it can set a new password on your account. So treat it like a key: do not forward it. The token sits after the
# in the address, which means it is never sent to our web server — only your own browser sees it, and the page removes it from the address bar as soon as it has been used.
The new password you type goes straight from your browser to Supabase Auth over HTTPS. It does not pass through our web server and we never see it.
How we protect it
- All traffic between the app and our server, and between the app and every service above, uses HTTPS.
- Your sign-in session is stored in the iOS Keychain, tied to this device, and is not synced to iCloud.
- Access to your data is enforced in the database itself with row level security, so a bug in the app cannot hand your archive to another account.
- Passwords are hashed by Supabase Auth and are never visible to us.
No system is perfect. If a breach occurs that is likely to be a risk to you, we will notify you and the relevant supervisory authority as the GDPR requires.
How long we keep it
- Your account data and archive: until you delete your account.
- Invitation links: until you delete your account. They do not expire on their own; delete a link in the app if you no longer want it to work.
- Server logs used for troubleshooting and abuse prevention: kept by Supabase for a short period and not used for anything else.
- Reports: kept for as long as we need them to act on what was reported and to see a pattern across several reports. Two things follow from how they are stored: if you delete your own account, the reports you sent go with it; if the account you reported is deleted, the report stays but loses its link to that account, leaving the reason and the copied message without a person attached.
When you delete your account, your profile, concerts, notes, songs, friendships, invitations, messages, blocks and profile photo are deleted immediately and permanently. If you signed in with Apple, we also cancel the connection with Apple at that moment, so ConcertLove disappears from Settings → Apple ID → Sign in with Apple as well. Two things survive on purpose, because they belong to somebody else: a friend who had written down your name in their own list keeps that name, now unlinked from any account, and messages other people wrote in a thread stay theirs.
Your rights
Under the GDPR you have the right to access, correct, delete, restrict, object to and port your personal data. In practice:
- See it — everything we hold about you is visible in the app.
- Correct it — your name, username, photo and every note and rating can be edited in the app.
- Delete it — More → Account → Delete account. This deletes the account and everything belonging to it, on the server and on the device. It is immediate, it is permanent, and there is no separate request to make.
- Export it — write to info@concertlove.nl and we will send you a machine-readable copy.
- Withdraw a permission — iOS Settings → ConcertLove for calendar, microphone and photos; the app's Spotify screen to disconnect Spotify.
We answer requests within one month.
Children
ConcertLove is not intended for children under 16. We do not knowingly collect data from them. If you believe a child has given us personal data, write to info@concertlove.nl and we will delete it.
Changes to this policy
If we change what we do with your data, we update this policy and the date at the top. For a change that materially affects you we will also say so in the app before it takes effect.
Contact
Pieter Bas Donkersteeg The Netherlands info@concertlove.nl
Write to that address for anything in this policy — a question, a correction, an export of your data, or a complaint. We answer within one month, and usually the same week.