PLAY IT / PRIVACY
Privacy Policy.
Effective: 20 August 2026
PLAY IT GROUP, CVR 42169048, Finlandsvej 69, 4. tv, 7100 Vejle, Denmark (“PLAY IT”, “we”, “us”) operates the PLAY IT website and live music-request service. This policy describes the data the current product actually uses. It is a product-facing draft and should receive legal review for the final controller, processor, retention, and jurisdiction analysis.
1. Data we receive
- Account data: name, email, phone when supplied, DJ or venue name, business name, city, country, selected plan, request price, currency, logo, and account status.
- Authentication data: a scrypt password hash (not the password), hashed bearer session records, expiry, and login/logout metadata. Password-reset records contain a one-way token hash and expiry.
- Social identity: when Google or Apple sign-in is used, the provider subject identifier, verified email, provider name, and limited profile name needed to create or link the same account. We do not receive a social provider password.
- Guest request data: random guest identifier, venue room, song title, artist, artwork URL, amount, PaymentIntent identifier, request status, and lifecycle timestamps. Guests do not need a PLAY IT account.
- Payment and payout data: Stripe customer, subscription, connected-account, checkout, and webhook state. Stripe handles card and wallet details; PLAY IT does not store full card numbers.
- Newsletter and support: an email address and subscription/unsubscription timestamps when you join the newsletter or contact us.
- Technical data: IP address and request metadata in ordinary server, security, and payment-provider logs. The current marketing pages do not use tracking cookies or third-party advertising pixels.
2. Browser storage
The client-rendered customer and account flows use localStorage for the session token, venue/operator identity, pending payment recovery, guest identifier, selected language, and limited UI preferences. It is not a cookie and it is not a substitute for server authorization. Clearing storage can sign you out or remove local recovery state. The server remains authoritative for account sessions, payment, requests, and payouts.
3. Why we use it
- To create accounts, authenticate, recover passwords, and keep the correct venue room bound to the current session.
- To search songs, create and recover requests, display status, and operate the DJ queue.
- To create Stripe subscriptions, payment intents, captures, cancellations, refunds or releases, Connect onboarding, and payouts.
- To deliver QR codes, branding, dashboard reporting, support, security, fraud prevention, and service improvements.
- To send newsletter messages only when you subscribe, and to honour unsubscribe requests.
- To meet legal, accounting, tax, dispute, and payment-network obligations.
4. Legal bases and sharing
Depending on the context, processing is based on contract, legitimate interests in security and operation, legal obligations, or consent for optional newsletter communications. We share relevant data with Stripe and Stripe Connect, Google or Apple when you choose those providers, Spotify for song search, hosting and infrastructure providers, email/newsletter providers when configured, and authorities or advisers where law requires. We do not sell personal data.
5. Retention
We retain account, subscription, payout, request, and financial records for as long as needed to operate the Service, resolve disputes, meet legal and accounting obligations, and protect the platform. Session and reset records expire and are pruned. Newsletter records remain until you unsubscribe or request deletion, subject to lawful suppression records. Exact retention periods and controller/processor roles require legal review.
6. International transfers and security
Our providers may process data outside the EEA under their own safeguards and contractual terms. We use HTTPS, hash passwords and bearer tokens, keep payment secrets server-side, validate OAuth state/nonce and provider identity tokens, and avoid returning raw secrets to browsers. No online system is risk-free; report suspected compromise to contact@getplayit.com.
7. Your choices and rights
Subject to applicable law, you may ask for access, correction, deletion, restriction, portability, objection, or withdrawal of consent. Newsletter recipients can use unsubscribe. Contact us to exercise a right or ask which provider holds the relevant data. You may also complain to your local data-protection authority.
8. Children, venues, and guest responsibility
Account creation is for adults or the applicable age of majority. Venues and DJs must not submit guest or staff data they are not authorised to share. Guests should avoid placing unnecessary personal information in song notes or requests.
9. Updates and contact
We may update this policy when the Service or providers change and will publish the new effective date. Contact PLAY IT GROUP at contact@getplayit.com or Finlandsvej 69, 4. tv, 7100 Vejle, Denmark.
Legal review required: confirm the final legal entity, data-controller allocation with venues, processor agreements, retention schedule, international-transfer mechanism, cookie/storage notices, VAT/accounting obligations, and any Data Protection Officer or representative details before treating this draft as final.
