Privacy Policy
In short
- We ask for as little as possible: an email address and what you choose to publish.
- The international site does not take payments directly. An eligible Polish event may send you to Koncertuj.com, whose checkout processes order and billing data under the Polish Privacy Policy.
- We do not sell your data and run no advertising trackers.
- You can request account deletion from the panel. An open complaint, content notice or security case may need to be completed first.
1. Who is the controller
The controller of your personal data is Localize.pl Agenor Hofmann-Delbor, ul. Włościańska 57/13, 70-021 Szczecin, Polish tax ID (NIP) 9551885714 — the operator of letsplayagig.com. For anything in this policy, write to info@koncertuj.com or call +48 533 758 868.
The operator is established in the European Union, so the GDPR (Regulation 2016/679) applies to all of this processing.
2. What we process and why
| Data | Why | Legal basis |
|---|---|---|
| Email address, password hash, account type, document versions accepted at registration and a keyed HMAC of the registration IP address (not the raw address in the consent record) | Running your account and signing you in | Art. 6(1)(b) — performance of the agreement |
| What you publish: band or venue profile, tours, stops, posts, photos | Displaying it in the Service, which is the point of the Service | Art. 6(1)(b) |
| Newsletter address and optional city, confirmation/unsubscribe tokens and dates, and a versioned consent record | Sending you tour announcements you asked for | Art. 6(1)(a) — consent, withdrawable at any time |
| Notification preferences and the address for them | Emails about your own tours | Art. 6(1)(b) |
| Server logs (including IP address) | Security, diagnosing faults, rate limiting on public forms | Art. 6(1)(f) — our legitimate interest in a working, abuse-free service |
| Email address of somebody objecting to a directory entry | Confirming the request comes from the venue and answering it | Art. 6(1)(c) with art. 12(6) — handling a data-subject request |
| Name, email, reported URL, category, explanation and correspondence in an illegal-content notice | Acknowledging and deciding notices under the Digital Services Act | Art. 6(1)(c), and art. 6(1)(f) for legal claims |
Payments linked from the international site. Let's Play a Gig does not run a checkout of its own. Most ticket links lead to an external seller, which processes the transaction under its own privacy policy. An eligible Polish event may instead link to the Koncertuj.com checkout operated by the same controller. That checkout processes buyer, order, billing and payment-status data as described in the Polish Privacy Policy. Full card details and online-banking credentials remain with the payment provider.
3. The venue directory
The directory includes venues that have not registered here. For those entries we publish the name, the city, the type of venue, a link to the venue's own site and — where the venue publishes them itself — the address and an institutional phone number or email address. Personal names, private numbers and personal email addresses are filtered out and never published.
The basis is art. 6(1)(f): touring bands need to know which stages exist in a city, and a directory limited to venues that signed up would not serve that purpose. Where the data was not collected from the venue directly, each entry identifies its source and the date it was checked. The information required by art. 14 is permanently available on our Where venue data comes from page.
Any listed venue can object under art. 21. The entry disappears immediately, before anyone reviews the request.
We avoid employee-specific contact details. If directory information nevertheless constitutes personal data, we provide an individual notice where we have a suitable contact and doing so is reasonably possible. The public notice, source disclosure and immediate opt-out are safeguards where individual contact would involve disproportionate effort.
A band-account holder may add the names and roles of other members. The account holder must tell them about the listing and this policy. We use those details only to present the lineup, relying on the legitimate interests of the band and the Service. A member can object or ask us to correct or remove the entry at any time.
4. How long we keep it
- Account data: until you delete the account. Deletion is normally immediate. An open complaint, content notice or security investigation may have to be completed first. We then retain only data required by law or needed for legal claims.
- Newsletter: an unconfirmed address is deleted after 7 days. When you unsubscribe, the plain address, tokens and pending messages are deleted immediately. The minimal consent/withdrawal record contains a keyed HMAC instead of the plain address. It is not part of automated log cleanup and is kept as needed to demonstrate compliance and defend legal claims.
- Newsletter delivery history: terminal queue entries, meaning messages already sent or cancelled, are deleted automatically after 12 full calendar months from their last update. Pending and processing messages and consent records are excluded.
- Objection records: kept as long as the directory exists — that record is what stops a later import bringing the entry back.
- Server logs: for the period made available by the current hosting plan, never more than 30 days. We do not keep a separate 12-month log archive.
- Rate limiting: the database stores only a keyed HMAC and the counter for the current short window, never the raw IP address or email. Expired buckets are removed by recurring maintenance after the window ends.
- Ticket fulfilment and transactional records: gate scans, transactional-email delivery, payment, refund and settlement records are not covered by the 12-month operational-log cleanup. They are not deleted merely because 12 months have passed. Where Polish ticketing applies, they remain linked to the relevant account or order while operations, complaints and disputes are open. On account deletion, only the minimum record required by law or needed for legal claims is retained for the applicable period.
5. Who else sees it
We use a small number of providers, each processing data on our instructions:
- hosting and application infrastructure;
- the database provider;
- an email provider, for the messages described above.
Anything you publish in your profile, tours or posts is, by design, public — visible to anyone using the Service.
We do not sell personal data and do not share it for advertising.
6. Your rights
You have the right of access, rectification, erasure, restriction, data portability, and the right to object to processing based on our legitimate interest. Where processing is based on consent, you can withdraw it at any time without affecting what happened before.
Write to info@koncertuj.com. You can also complain to a supervisory authority — in Poland, the President of the Personal Data Protection Office (UODO).
8. Transfers outside the EEA
Some providers may process data outside the European Economic Area. Where that happens it is covered by an adequacy decision or by the European Commission's standard contractual clauses.