1. Overview
Drum Up (“we,” “us,” or “our”) operates the Drum Up platform, a marketplace connecting restaurants and venues with musicians and live performers. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have.
By using Drum Up, you agree to the collection and use of information as described in this Policy. If you do not agree, please do not use the Service.
2. Information We Collect
Information You Provide
When you create an account or use the Service, you may provide:
- Account details: name, email address, password (hashed), and account type (restaurant, musician, or fan).
- Profile information: bio, profile photo, genre preferences, instruments played, venue capacity, cuisine type, and social media links (Instagram, TikTok, Spotify, YouTube).
- Location: your city, state, and geographic coordinates (latitude and longitude), provided either via your device's location services or by entering an address manually.
- Slot and booking data: dates, times, pay amounts, and descriptions for slots posted by restaurants and applications submitted by musicians.
- Messages: content you send and receive through the Drum Up messaging system.
- Payment information: processed through Stripe. Drum Up does not store full card numbers or bank account details; Stripe handles all sensitive payment data under their own privacy and security policies.
Information We Collect Automatically
When you use the Service, we automatically collect:
- Log data: IP address, browser type, pages visited, time and date of visits, and referring URLs.
- Device information: operating system, device type, and browser version.
- Usage data: features you use, searches you perform, and how you interact with the platform.
- Cookies and similar technologies: session tokens and preference data. See Section 8 for more detail.
Information from Third Parties
If you sign in with Google, we receive your name, email address, and profile photo from Google as permitted by your Google account settings. We do not receive your Google password.
3. How We Use Your Information
We use the information we collect to:
- Create and maintain your account.
- Match restaurants with musicians based on location, genre, and availability.
- Process bookings and facilitate payments between parties.
- Send transactional communications (booking confirmations, application updates, payment receipts).
- Display your public profile to other users of the appropriate type.
- Provide customer support and resolve disputes.
- Detect and prevent fraud, abuse, and violations of our Terms of Service.
- Improve the platform through analysis of usage patterns and behavior.
- Comply with legal obligations.
We do not sell your personal information to third parties. We do not use your data to serve third-party advertising.
4. Location Data
Location is central to how Drum Up works. We use your location to:
- Show musicians nearby open slots within a radius you select.
- Show restaurants musicians available in their area.
- Help fans discover live music near them.
Your precise coordinates (latitude and longitude) are stored in our database and used for distance calculations. Your city and state are displayed publicly on your profile. Your precise coordinates are never displayed to other users.
If you grant browser location access during onboarding, we capture a one-time reading. We do not continuously track your location in the background. You may update your location at any time from your profile settings.
5. How We Share Your Information
Other Users
Your public profile (name, photo, bio, genre, location city, and social links) is visible to other users. Restaurants can see musician profiles; musicians can see restaurant slot listings; fans can see both. Your email address and precise coordinates are never shared with other users.
Service Providers
We share data with trusted third-party providers who help us operate the Service:
- Supabase: database, authentication, and file storage infrastructure.
- Stripe: payment processing and Stripe Connect for musician payouts.
- Google: OAuth authentication and location autocomplete (Places API).
- Vercel: hosting and edge network delivery.
- Resend: transactional email delivery for booking confirmations, notifications, and account alerts.
These providers are contractually bound to use your data only to provide services to us, not for their own purposes.
Legal Requirements
We may disclose your information if required by law, subpoena, court order, or government request, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Drum Up, our users, or the public.
Business Transfers
If Drum Up is acquired by or merged with another company, your information may be transferred as part of that transaction. We will notify you before your information is subject to a materially different privacy policy.
6. Data Retention
We retain your account data for as long as your account is active. If you delete your account, we will delete or anonymize your personal information within 30 days, except where we are required to retain it for legal or regulatory purposes (such as tax records related to payments).
Message content between users is retained until one or both parties deletes the conversation thread. Deleted messages are purged from our systems within 7 days of deletion.
7. Your Rights and Choices
Access and Correction
You may view and update your profile information at any time from your account settings. If you believe we hold inaccurate data about you that you cannot correct through the app, contact us at brogan.smith525@gmail.com.
Account Deletion
You may delete your account at any time from your account settings. Deleting your account immediately removes your public profile and personal data (including your profile details, messages, follows, saved items, and reviews you have written) from the platform. Records we are legally required to keep — such as booking and payment records used for tax and accounting — are retained in anonymized form for up to seven years, then deleted. All other personal data is deleted or anonymized within 30 days.
Location
You can revoke browser location permission at any time in your browser or device settings. You can also update or remove your stored location from your profile settings.
Communications
Transactional messages (booking confirmations, payment receipts, account alerts) are necessary for the Service and cannot be opted out of while you have an active account. If we introduce marketing emails in the future, you will be able to opt out via an unsubscribe link.
California Residents
If you are a California resident, you have the right to request disclosure of the categories and specific pieces of personal information we have collected about you, to request deletion of your personal information, and to opt out of any sale of personal information. We do not sell personal information. To exercise your rights, contact brogan.smith525@gmail.com.
8. Cookies and Tracking
Drum Up uses cookies and similar technologies to:
- Maintain your logged-in session.
- Remember your preferences (such as your selected browse location and radius).
- Understand how users interact with the platform so we can improve it.
We do not use third-party advertising cookies. You can configure your browser to block or delete cookies, but doing so may affect your ability to log in and use the Service.
9. Security
We implement industry-standard security measures including encrypted data transmission (TLS), hashed passwords, Row Level Security policies on our database, and access controls that limit which employees can access user data. No method of transmission or storage is 100% secure. If you discover a potential security vulnerability, please report it to brogan.smith525@gmail.com.
10. Children's Privacy
Drum Up is not intended for users under the age of 18. We do not knowingly collect personal information from anyone under 18. If we become aware that a minor has created an account, we will delete the account and associated data promptly. Contact us at brogan.smith525@gmail.com if you believe we have collected information from a minor.
11. Changes to This Policy
We may update this Privacy Policy as the Service evolves. When we make material changes, we will update the effective date at the top of this page and, where appropriate, notify you by email or via a notice in the app. Your continued use of the Service after changes take effect constitutes acceptance of the revised Policy.
12. Contact Us
If you have questions about this Privacy Policy or how we handle your data, please contact us:
brogan.smith525@gmail.com