BANDSTAND

Legal

Privacy Policy

Last updated: July 4, 2026

Bandstand (“Bandstand,” “we,” “us”) is an editorial app for live jazz, currently active in Chicago, New York, Kansas City, and Washington DC. This policy explains what data we collect, why, and what we do (and don't do) with it. We try to be plain-spoken; if anything below is unclear, write support@bandstand.fm.

What we collect

Account info. Bandstand supports three sign-in methods:

Favorites, follows, and RSVPs. If you favorite a venue, follow an artist, or tap “I'm going” on a show, we store that association so we can show you your own activity on your devices.

City preference. The city you last browsed (Chicago, NYC, etc.) is remembered so the app opens where you left off. We do not use GPS or IP-based geolocation.

Push notification tokens. If you opt in to Editor's Pick or Week Ahead alerts, we store your device's Expo push token so we can deliver those notifications. You can disable notifications at any time in the app, or in your device settings.

Payment and supporter data. If you tip Bandstand or make a monthly donation as a Sideman / Bandleader / Patron / Producer supporter, our payment processor (Stripe) collects your payment information directly. Bandstand receives only a customer identifier, the tier or amount, and (for monthly donations) renewal status. We never see or store your full card number or CVV. If you leave a supporter message, we retain the message text alongside your tier.

Outbound link taps. When you tap a “Buy Tickets,” venue website, Spotify, Apple Music, or similar external link inside the app, we log the tap (event id, venue id, artist id, target domain, timestamp) so we can measure editorial reach and share aggregate referral data with partner venues. We do not follow you off the app or track what you do on the destination site.

Basic diagnostics. Standard server logs (IP address, timestamps, requested URLs) for security and uptime monitoring. Logs are rotated and discarded within 30 days. If the app crashes we also collect a crash report via Sentry (device model, OS version, stack trace — no personal content).

What we do NOT collect

Who we share data with

Only the third parties strictly required to make the app work:

No advertising networks. No data brokers. No “partners.”

Where data lives

All Bandstand data is stored on servers in the United States. If you sign in from outside the US, your data is transferred and stored in the US under standard contractual clauses.

How long we keep data

Your rights

You can delete your account and all associated data at any time from inside the Bandstand app: Profile → Delete Account. Deletion is immediate and removes your account, favorites, follows, RSVPs, and supporter messages. Payment records may be retained where required by law but will no longer be linked to your account.

If you can't access the app (for example, you've lost your device), you can also request deletion by emailing support@bandstand.fm from the email address you signed in with. We process email deletion requests within 14 days.

If you are in the EU or UK, you have rights under GDPR to access, correct, port, or restrict processing of your data. If you are in California, you have equivalent rights under CCPA / CPRA. Use the same email address.

Children

Bandstand is intended for users 13 and older. We do not knowingly collect data from anyone under 13. If you believe a child has provided us data, email support@bandstand.fm and we will delete it.

Security

All data in transit is encrypted with TLS. Session tokens and sign-in codes are stored using platform-standard secure storage (iOS Keychain / Android Keystore) on your device. Payment card data is handled exclusively by Stripe and never touches Bandstand's servers.

Changes

If we change this policy, we'll update the “Last updated” date and, for material changes, notify you via push notification or an in-app banner.

Contact

Bandstand
support@bandstand.fm