Draft. This document is a working draft awaiting lawyer review. It is published for transparency and will be replaced with a reviewed version before public launch.
Last updated: 2026-04-18

Privacy Policy

Undercurrent Ltd ("Undercurrent", "we", "us") is the data controller for personal data we process through the Platform. We are registered in England and Wales with our registered office in Manchester, United Kingdom.

This Privacy Policy explains what personal data we collect, how we use it, and the rights you have over it under the UK GDPR, EU GDPR, and California Consumer Privacy Act (CCPA) where applicable.

1. What we collect

You give us:

  • Account details (email, display name, profile info) when you sign up — via our authentication partner Clerk.
  • Content you post (profile text, images, music embeds, gig listings, marketplace listings, messages).
  • Payment details (processed by Stripe; we never see or store full card numbers).

Collected automatically:

  • Log data (IP address, browser, device, timestamps) when you use the Platform.
  • Analytics events (pageviews, feature interactions) via PostHog and Vercel Analytics.
  • Error telemetry via Sentry when something crashes, including stack traces and the state of the page at that moment.
  • Cookies — see our Cookie Policy.

From third parties:

  • From Clerk, if you sign in via a social provider (Google, Apple, etc.), we receive your email and whatever profile info you authorise.
  • From Stripe, for payment processing (transaction status, payout info; no card numbers).

2. How we use it

We process your personal data for the following purposes and lawful bases under UK/EU GDPR:

| Purpose | Lawful basis | | --- | --- | | Providing the Platform (account, profile, social graph, music, gigs, marketplace, services) | Contract (Art. 6(1)(b)) | | Payment processing and fraud prevention | Contract + Legitimate interests (Art. 6(1)(f)) | | Service emails (account, transactional, security) | Contract | | Product analytics to improve the Platform | Consent, collected via the cookie banner (Art. 6(1)(a)) | | Error telemetry to diagnose crashes | Legitimate interests | | Marketing emails (where you opted in) | Consent | | Legal compliance (tax records, disputes, regulatory requests) | Legal obligation |

3. Who we share it with

We share personal data with service providers strictly to the extent necessary to run the Platform:

  • Clerk — authentication
  • Neon — database hosting
  • Cloudflare R2 — file storage
  • Stripe — payment processing
  • Resend — transactional email
  • Sentry — error monitoring
  • PostHog — product analytics (conditional on consent)
  • Vercel — hosting and edge analytics
  • Inngest — background jobs

Each of these processes personal data as our data processor under contract.

We may also disclose personal data if required by law, court order, or to protect the rights, property, or safety of Undercurrent, our users, or the public.

We do not sell your personal information and we do not share it for cross-context behavioural advertising (CCPA terms).

4. International transfers

Some of our processors (e.g. Stripe, Resend, Sentry, PostHog) are based outside the UK/EU. Where personal data is transferred internationally we rely on appropriate safeguards such as the UK International Data Transfer Agreement, EU Standard Contractual Clauses, or adequacy decisions.

5. Retention

We keep personal data only as long as needed for the purposes described:

  • Active account data: for as long as your account is open.
  • Financial records: as required by HMRC and other tax authorities (typically 6–7 years).
  • Logs and analytics: up to 24 months.
  • Error telemetry: up to 90 days.

When you delete your account we soft-delete immediately and hard-delete personal data after 30 days (see §7). Anonymised or aggregated data may be retained indefinitely.

6. Security

We use industry-standard controls: TLS in transit, encryption at rest where supported by our processors, access controls on production systems, and audit logging. No service can guarantee perfect security — if we discover a breach that affects your personal data we will notify you and the relevant regulator as required.

7. Your rights

Under UK/EU GDPR you have the right to:

  • Access a copy of the personal data we hold about you.
  • Rectify inaccurate personal data.
  • Erase your personal data ("right to be forgotten").
  • Restrict or object to processing in certain cases.
  • Portability — receive your personal data in a structured, machine-readable format.
  • Withdraw consent at any time, without affecting the lawfulness of past processing.
  • Lodge a complaint with the UK Information Commissioner's Office (ico.org.uk) or your local EU data-protection authority.

Under CCPA, California residents additionally have the right to opt out of any "sale" or "sharing" of personal information (we do neither), and to request deletion.

You can exercise access, portability, and deletion rights directly from your account settings at any time. For anything else, email privacy@undercurrent.band.

8. Children

The Platform is not intended for children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact privacy@undercurrent.band and we will delete it.

9. Changes

We will post material changes to this Privacy Policy at least 14 days before they take effect, and notify registered users by email.

Contact

Undercurrent Ltd, Manchester, United Kingdom. privacy@undercurrent.band