Last Updated: 8/5/2026
BandUp is a platform that brings a band's rehearsal and stage workflow into one
place. This policy explains which of your personal data we process, why we
process it, and what rights you have over it.
We have tried to keep this readable. If anything is unclear, write to us at[email protected].
Legal name | UBIG Teknoloji A.Ş. |
Address | Caferağa Mah. Moda Cad. No: 5, 34710 Kadıköy/Istanbul, Türkiye |
Trade registry (MERSIS) | 0883122063200001 |
Tax office / number | Kadıköy Tax Office — 8831220632 |
Web |
BandUp is a product of UBIG Teknoloji A.Ş. In this policy, "we", "us", "BandUp"
and "the Company" all refer to UBIG Teknoloji A.Ş., which is the data
controller.
This policy applies to all BandUp services: the bandup.io website, the BandUp
web application, the iOS and Android mobile apps, and the Apple Watch app.
Third-party services you connect to BandUp — for example Google, Facebook or
Apple when you use social sign-in — are governed by their own privacy policies.
Data in BandUp falls into two categories. The distinction matters because it
determines how you exercise your rights.
Band data. Everything you put into a workspace: songs, lyrics and chords,
notes, setlists, calendar events, availability blocks, the tech rider and the
files you upload. Control over this data belongs to the band — its owner and
admins can access, edit and delete it. BandUp hosts and processes it on the
band's behalf.
Platform data. What we collect to run your account, deliver the service and
keep it secure: your account details, session records, preferences, billing
records and technical logs. We are the controller for this data.
When you leave a band or a band is deleted, the content you contributed stays
with — or is deleted along with — that band. The platform data tied to your
account follows the retention rules in this policy.
Email address and password (we store only an irreversible hash — we never see
your actual password)
First and last name (asked during onboarding, not at sign-up; a single name is
valid)
Profile photo (optional)
Instruments you play (optional)
Country code — determined at sign-up from your IP address using a database
that runs locally on our own server, with no data leaving it (see section
6, "processing that never leaves our servers")
Language, theme and notification preferences
If you use social sign-in: the name, email and profile photo returned by the
provider, plus your provider account identifier
Song titles, artists, key and tempo information, lyrics and chords, personal
and band notes, stage setup lists, setlists, calendar events, availability
blocks, date polls and their comments, tech rider content, and files you
upload (sheet music, PDFs, images).
Plan and subscription status, billing period, invoice history, and transaction
records received from our payment provider.
We never see or store your card details. Payments are taken by Paddle acting
as our Merchant of Record; your card details go directly to Paddle. BandUp has
no in-app purchases — all payments are made on the web.
Location data is processed only in the Listings section and only with your
permission.
When posting a listing: if you allow location sharing, your coordinates are
stored rounded to 2 decimal places (roughly 1.1 km). Your exact
coordinates are never written. If you decline, your listing is placed at the
centre of the city you selected — posting is never blocked.
When browsing listings: your device location is used only to sort results
nearest-first and to compute the distance badge, again rounded, and it is
not stored. Without permission, results are sorted newest-first and no
functionality is disabled.
Every listing requires a country and city, which you enter yourself.
Session records: sign-in time, IP address, browser/device information and the
country derived from it. You can see these under Settings → Active Devices and
revoke any session.
Push notification device tokens and platform (iOS/Android/web)
Consent records: the permissions you grant or withdraw, with a timestamp, IP
address and browser information (we keep these to meet our legal burden of
proof)
Policy acceptance records: which version you accepted and when
Your listing content, images attached to listings, the messages you send and
receive, reports, blocks and moderation records.
Listings are independent of workspaces: when posting, you can present
yourself as an individual or as a band you belong to. On listings posted under a
band's name, the other party sees the band's name rather than yours.
Error records, crash reports, performance measurements and server access logs.
These exist to keep the service running and to diagnose faults.
See the Cookie Policy.
Purpose | Data | Legal basis |
|---|---|---|
Creating your account and delivering the service | Account, profile, band content | Performance of a contract |
Subscriptions, invoicing and payment | Subscription and billing data | Performance of a contract; compliance with tax law |
Sending notifications and reminders | Email, device token, preferences | Performance of a contract |
Security, abuse and fraud prevention | Session, IP, device, logs | Legitimate interests |
Improving the service, fixing faults | Technical logs, usage data | Legitimate interests |
Distance sorting in Listings | Rounded location | Consent |
Marketing emails | Email, name | Consent |
Analytics cookies | Cookie data | Consent |
Legal obligations and responding to legal claims | Data required | Legal obligation |
You can withdraw consent at any time for anything based on it. Withdrawal
does not affect the lawfulness of processing carried out beforehand.
We do not carry out automated decision-making. We do not make decisions about
you based solely on automated processing that produce legal effects or similarly
significantly affect you. We do not profile you or score you based on your
behaviour.
For users in Türkiye, a separate disclosure notice prepared under Law No. 6698
also applies: KVKK Aydınlatma Metni.
We do not sell your data. We do not share it with third parties for
advertising.
Your data is shared only in these situations:
With other members of your band. When you join a workspace, your name,
profile photo, instruments and the content you contribute become visible to
its members.
With our service providers (subprocessors). We have a data processing
agreement with each of them, and each may access only the data needed to
provide its own service:
Railway — hosting, application servers and database (European Union)
Cloudflare — content delivery and file storage (R2)
Paddle — payment, invoicing and subscription management (Merchant of
Record; card details go to Paddle, never to us)
Resend — transactional email (verification, invitations, password reset)
Google (Firebase Cloud Messaging) — push notification delivery
Google, Apple, Facebook — sign-in, and only if you choose to use social
sign-in
Better Stack — error tracking and technical logs
With the other party in Listings. When you message a listing, your name and
profile photo — or the band's name if you are writing on a band's behalf —
become visible to them.
Where legally required. In response to a lawful request from a competent
authority. We review such requests for validity and, where legally permitted,
inform you.
In a corporate transaction. In a merger, acquisition or transfer of assets,
your data may pass to the acquirer. You will be told in advance.
Processing that never leaves our servers. Deriving your country from your IP
address and parsing browser/device information are both done with a local
database and libraries running on our own server. Neither operation sends a
request to any external service.
Two features deliberately make content reachable without signing in:
Tech rider sharing. When a band admin turns sharing on, anyone with the
generated link can view the rider — which includes band members' names,
instruments and the owner's contact details. The page is excluded from search
engines (noindex), but anyone holding the link can reach it. Sharing can be
switched off at any time.
Listings. A published listing can be viewed without signing in on our
public listing pages. The owner's identity is hidden there; contacting them
requires signing in.
Your data is hosted within the European Union.
Some of our subprocessors are established outside the EU. For those transfers we
rely on the Standard Contractual Clauses approved by the European
Commission and, where applicable, the EU-U.S. Data Privacy Framework. For
transfers from Türkiye we sign the standard contract published by the
Turkish Data Protection Board under Article 9 of Law No. 6698 and notify the
Authority accordingly. The providers we use are listed in section 6.
Data | Retention |
|---|---|
Account and profile data | For as long as your account is open |
Deleted account | 30-day recovery window; after it expires, personal data is irreversibly anonymised |
Band content | Until the band is deleted; deleting a band deletes its content |
Session records | Until the session is revoked; expires automatically after at most 60 days |
Notifications | 30 days |
Listings | Expire automatically 60 days after publication; remain in your account until you delete them |
Listing messages | Until the conversation or the account is deleted |
Stage session data (live transpose, stage presence) | 12 hours |
Invitation links | 7 days |
Email verification links | 24 hours |
Password reset links | 1 hour |
Consent and policy acceptance records | For the applicable limitation period (burden of proof) |
Invoices and financial records | 10 years, as required by tax law |
Technical logs | 3 days (deleted automatically thereafter) |
Aggregate technical metrics (contain no personal data) | 30 days |
If you delete your account, you can restore it within the 30-day window by
signing in with the same credentials. After that, the account row is not deleted
but anonymised: your name, email and other identifiers are cleared. This is
because deleting the row outright would also remove your votes, polls and
comments inside bands, corrupting other members' data.
Passwords are stored as irreversible hashes. All traffic is encrypted with TLS.
Session cookies are set with the HttpOnly, Secure and SameSite flags and
with the browser-enforced __Host- / __Secure- prefixes. Access is limited by
role-based authorisation, and every query is scoped to the relevant band.
No system is perfect. If a breach affects your personal data, we will notify the
competent authority within the statutory deadline and — where the risk is high —
notify you.
Depending on where you are, you have the right to:
Access your data and request a copy
Have inaccurate or incomplete data corrected
Request deletion of your data
Request restriction of processing
Receive your data in a structured format (portability)
Object to processing based on legitimate interests
Withdraw consent you have given
Seek compensation for damage caused by unlawful processing
You can exercise many of these yourself: correct your profile in Settings, revoke
sessions, turn off marketing consent, and delete your account from Settings →
Account. Step-by-step instructions, including how to delete your account without
signing in, are on the Account deletion page. For anything
else, write to [email protected]; we respond within 30 days at the latest.
Users in the European Economic Area and the United Kingdom may lodge a
complaint with their local data protection authority.
Users in Türkiye may exercise the rights in Article 11 of Law No. 6698 by
writing to the address above or through the other methods the Law provides, and
may complain to the Personal Data Protection Board if unsatisfied with our
response.
California residents: we do not sell or share your personal information. You
may exercise your CCPA/CPRA rights to know, delete and correct through the
address above, and we will not treat you differently for doing so.
BandUp is not for anyone under 16.
If we learn that we have unknowingly collected data from someone under 16, we
delete it. If you are aware of such a case, tell us at [email protected].
When we update this policy we change the "Last updated" date on this page. For
material changes we notify you by email or in the app and, where necessary, ask
you to accept the new version.
For any privacy question, request or complaint:
UBIG Teknoloji A.Ş.
Caferağa Mah. Moda Cad. No: 5, 34710 Kadıköy/Istanbul, Türkiye[email protected]