Privacy Policy

Last updated: 3 April 2025

1. Who we are

Local Jam (“we”, “us”, “our”) is the data controller responsible for your personal data. We operate the Local Jam platform available at localjam.live.

Contact: privacy@localjam.live

2. What data we collect

  • Account data: email address, password (hashed), profile type.
  • Profile data: display name, city, country, biography, profile photo, genres, instruments, media links, booking email.
  • Usage data: pages visited, features used, timestamps — collected anonymously for platform analytics.
  • Messages: content of direct messages sent through the platform.
  • Technical data: IP address, browser type, device information, cookies. See our Cookie Policy.

3. Why we process your data (legal basis)

  • Contract performance (Art. 6(1)(b) GDPR): to provide the service — account creation, messaging, gig posting, profile discovery.
  • Legitimate interests (Art. 6(1)(f) GDPR): platform security, fraud prevention, and improving our service.
  • Consent (Art. 6(1)(a) GDPR): for optional analytics cookies and any marketing communications you opt into.
  • Legal obligation (Art. 6(1)(c) GDPR): to comply with applicable laws.

4. How long we keep your data

  • Account and profile data: for as long as your account is active, plus up to 30 days after deletion to allow for recovery requests.
  • Messages: retained while both participants have an active account. Deleted on account removal.
  • Analytics data: aggregated and anonymised, retained for up to 24 months.
  • Legal/financial records: up to 7 years where legally required.

5. Who we share your data with

We do not sell your personal data. We share data only with trusted service providers who help us operate the platform, under strict data processing agreements:

  • Supabase: authentication and database hosting (EU data region).
  • Vercel: hosting and content delivery.

All sub-processors are contractually bound to process data only on our behalf and in accordance with GDPR.

6. International transfers

Where data is transferred outside the European Economic Area (EEA), we ensure adequate safeguards are in place — such as Standard Contractual Clauses (SCCs) approved by the European Commission.

7. Your rights under GDPR

You have the following rights regarding your personal data:

  • Right of access: request a copy of the personal data we hold about you.
  • Right to rectification: correct inaccurate or incomplete data.
  • Right to erasure: request deletion of your data (“right to be forgotten”).
  • Right to restriction: ask us to limit how we process your data.
  • Right to data portability: receive your data in a structured, machine-readable format.
  • Right to object: object to processing based on legitimate interests.
  • Right to withdraw consent: withdraw consent at any time without affecting prior processing.

To exercise any of these rights, contact us at privacy@localjam.live. We will respond within 30 days.

8. Right to lodge a complaint

If you believe we are not handling your data lawfully, you have the right to lodge a complaint with your local data protection authority. In the Netherlands, this is the Autoriteit Persoonsgegevens (AP) at autoriteitpersoonsgegevens.nl.

9. Security

We implement appropriate technical and organisational measures to protect your personal data, including encrypted connections (HTTPS), hashed passwords, and access controls. However, no online service is 100% secure.

10. Changes to this policy

We may update this policy from time to time. Material changes will be notified via email or a prominent notice on the platform. The date at the top of this page indicates when it was last revised.

Privacy Policy – Local Jam