Effective
1The short version
This policy explains how Artistplus, Inc. ("Artistplus", "we", "us") handles personal data, both for artists who hold an account with us and for visitors to the websites we host for them.
- We do not sell your data
- We have never taken money for your personal information and there is no version of our business that involves it. Selling and sharing are different things under California law, though, so the next line says what we do share.
- We do share limited data with ad networks, if you accept
- Accept advertising cookies and Meta, TikTok, and Google receive a record that a signup or subscription happened, its value, and a scrambled (hashed) version of your email, verified phone number, and name, which lets them recognise an account they already hold. Under California law this counts as sharing for cross-context behavioural advertising. Decline, or send a Global Privacy Control signal, and none of it is sent.
- No advertising trackers on artist sites
- The websites we publish for artists carry our own first-party analytics and nothing else. No ad pixels, no conversion tracking, no third-party tag manager, no social trackers. Nothing a fan does on an artist site reaches an ad network, whatever anyone has accepted on artistplus.io.
- Analytics on artistplus.io is opt-in where consent is required
- In the EEA, the UK, and Switzerland, optional product analytics does not start until you accept it. Declining stops optional collection; we still retain a minimal record of the choice itself.
- Your content is yours
- We host it and show it to the people you publish it to. We do not license it out and we do not train models on it.
You can reach us about anything on this page at privacy@artistplus.io, or by post at:
- Artistplus, Inc.
- Chicago, Illinois
- United States
2What we collect about you
Account data
Your name, email address, and password, handled by our authentication provider Clerk. If you sign in with Google, we receive your name, email address, and profile picture from Google, and never your Google password. We also store your chosen username, your plan, your notification preferences, and the phone number you provide at signup, which for US and Canadian numbers is verified by text message. A verified phone number is used to prevent duplicate free trials, and it is shared with ad networks in scrambled form only if you accept advertising cookies, as described below.
Content and files
Everything you build or upload: page content, biography, images, audio, video, documents, press kits, catalog and release metadata, tour dates, contacts you add, and invoices you issue. Page content and metadata live in our database (Convex); files live in object storage (Cloudflare R2).
Billing data
Your plan, billing cycle, subscription status, invoice history, and the last four digits and brand of your payment card. Card numbers go directly to Stripe from your browser and never reach our servers.
Purchase acknowledgments
Where a purchase is one-time and not refundable, such as custom website design, we record that you confirmed the terms before payment: the exact wording shown to you, the moment you accepted it, and the browser user agent that accepted it. We keep this to answer payment disputes and chargebacks, and for no other purpose. It is never used for advertising or profiling.
Domain registrant data
If you register a domain through us, we collect the registrant name, email address, postal address, and phone number that ICANN requires, and pass them to our registrar partner. This is a legal requirement of holding a domain, not a choice we made.
Support and communications
Messages you send us, the ticket they create, and our replies. If you connect a Gmail account to reply to fan mail from inside Artistplus, we access that mailbox only to show and send the messages you act on.
Product usage
On signed-in dashboard, onboarding, and checkout pages, our first-party activity ledger can record pages and product areas visited; session, visibility, engagement, and scroll milestones; controls activated; form structure, field-change metadata, validity, selected file count/type/size bucket, and submission status without entered values or filenames; feature and lifecycle events; client error fingerprints without raw error messages; connectivity changes; and timing, layout-shift, long-task, and resource-performance summaries. These events are linked to your account and a random per-tab session id.
When optional analytics is allowed, we also collect campaign and referral parameters, first- and last-touch attribution, and broad browser environment data: language and time zone, browser and operating system, device and screen characteristics, accessibility display preferences, network quality, navigation timing, storage usage and quota, browser permission states, and browser client hints. We use this to understand acquisition, adoption, retention, conversion, product quality, and customer segments. PostHog may receive the explicit product events described in our Cookie Policy; our own database keeps a separate first-party marketing projection that excludes IP values, request headers, encrypted material, names, emails, credentials, and private form values.
Technical and security data
For signed-in product activity we add server-observed request time, request id, approximate country, region, and city, browser headers and client hints, and IP-derived protections. A masked IP may appear in the owner-only activity ledger. The raw IP is isolated from event tables, encrypted with AES-256-GCM, available only to the platform owner in our admin console after a written reason, and permanently redacted after 30 days. A keyed one-way IP hash used for abuse detection and correlation is permanently redacted after 24 months. Every raw-IP reveal is separately audited. Our hosting provider also processes request metadata to serve and secure requests, and Sentry receives diagnostic context when something errors.
3Analytics on artist websites
Every website we publish for an artist includes our own first-party analytics. There is no third-party analytics, advertising, or social tracking on those sites. This section describes what a VISITOR to an artist site generates, and it applies whether or not that visitor has an Artistplus account.
What is recorded
- The page that was viewed and the site it belongs to.
- Country and city, taken from the edge network that served the request. This is approximate, derived from the IP by our hosting provider, and is never more precise than a city.
- The referring website, if the visitor arrived from a link.
- Browser, operating system, and whether the screen is phone, tablet, or desktop sized.
- A one-way hash of the IP address, used to rate-limit the endpoint and to give server-side page views a stable pseudo-identifier.
What is not recorded
- The raw IP address. It is hashed before anything is stored, and the hash cannot be reversed to the address.
- Names, email addresses, or anything else that identifies a visitor by name.
- Anything a visitor types into a page, including form fields.
- Behaviour on any website other than the artist site being viewed.
- A profile that follows a visitor from one artist site to another. Each site's figures stand alone.
Visitor identity, and how to avoid it
To count returning visitors as one person rather than several, the page stores an identifier in your browser's local storage under the key ap_visitor_id, plus a per-session identifier under ap_session_id. The value is generated from coarse browser characteristics and a timestamp. It is not a cookie, it does not leave the site that set it, and it carries no personal data.
To avoid it: browse in a private window, block storage for the site in your browser settings, or clear site data afterwards. Doing so does not degrade the site in any way. Without it, the visit is still counted, but as a new visitor rather than a returning one.
What the artist sees
Artists see aggregate figures about their own site: totals, trends, top pages, countries and cities, referrers, and device split. They cannot see individual visitors, IP addresses, hashes, or anything that identifies one person, and there is no view in the product that would let them.
Raw event records are deleted after 400 days, which is about 13 months. The daily totals we roll them up into contain no visitor identifiers and are kept for as long as the artist's account is open.
4Why we collect it, and the legal basis
| What we do | Why | Legal basis (UK and EU GDPR) |
|---|---|---|
| Run your account, publish your site, store your files | It is the service you asked for | Performance of a contract |
| Charge your subscription and keep billing records | To get paid, and to satisfy tax law | Contract, and legal obligation |
| Register and renew a domain in your name | ICANN requires registrant details | Contract, and legal obligation |
| Send transactional email about your account | You need to know about payments, expiry, and security | Contract |
| Answer your support messages | To help you | Contract, and legitimate interests |
| Detect abuse, spam, and fraud, and rate-limit endpoints | To keep the service usable and safe | Legitimate interests |
| Diagnose errors through Sentry | To fix what is broken | Legitimate interests |
| Count visits on artist sites | So the artist can see what is working | Legitimate interests |
| Product analytics on artistplus.io and the dashboard | To understand acquisition, product quality, adoption, retention, and conversion | Consent where required, otherwise legitimate interests |
| Authenticated user activity and consent audit records | To secure the service, investigate abuse and support issues, and prove product or privacy actions | Contract, legal obligation, and legitimate interests |
| First-party customer and marketing intelligence | To segment our customers and improve product and campaign decisions without cross-site advertising | Consent where required, otherwise legitimate interests |
| Send product announcements and marketing email | To tell you about what is new | Consent, withdrawable at any time |
Where we rely on legitimate interests, we have weighed our interest against your rights and concluded the processing is what a reasonable person would expect from a website host. You can object to any of it under section 8.
We do not use your data for automated decision-making that produces legal effects. We create first-party customer intelligence profiles for our own product and marketing decisions, but do not create or share cross-site advertising profiles.
5Cookies and browser storage
The full table of every cookie and storage key we set, with its purpose and lifetime, is on the Cookie Policy page. That table and this summary are generated from the same list, so they cannot disagree.
- Strictly necessary
- Needed for the site to work at all: keeping you signed in, remembering the choice you made about this banner, and stopping cross-site request forgery. These cannot be switched off, and we do not ask for consent to set them.
- Preferences
- Remember a setting you chose, like light or dark mode. They are set by your own actions and never leave your browser.
- Analytics
- Tell us which signed-in product pages, controls, and features get used so we can improve the product and understand our customers. Optional collection is off until you accept where consent is required, and stops if you decline.
On your first visit to artistplus.io from the European Economic Area, the United Kingdom, or Switzerland, analytics does not load at all until you choose. Accept and decline are presented as equal choices, and declining is a single click. Everywhere else, the banner is a notice with the same two buttons, and declining takes effect immediately. You can change your mind at any time from the Cookie settings link in the footer of every page.
Artist websites do not use cookies for analytics. They store the visitor identifier described in section 3, and nothing else.
6Who else processes your data
We share personal data with service providers who process it on our instructions and under a written contract, only for the purposes below. This list is maintained by auditing the codebase rather than by copying a template, and it is complete as of the effective date at the top of this page.
| Company | What they do for us | What they receive | Where | When |
|---|---|---|---|---|
| Clerk | Account sign-up, sign-in, and session management | Name, email address, password hash, sign-in metadata | United States | Always |
| Convex | Application database and backend functions | Account records, site content, catalog, invoices, analytics events | United States | Always |
| Cloudflare | File storage (R2), content delivery, and DNS for artistplus.app | Uploaded audio, video, images, documents, and press kits | Global edge network | Always |
| Vercel | Website hosting, edge routing, and TLS for custom domains | Request metadata, IP address, approximate location from edge headers | Global edge network | Always |
| Stripe | Subscription billing and payment processing | Billing name, email, address, card details (held by Stripe, never by us) | United States and European Union | Always |
| Resend | Transactional email delivery | Email address, name, and the contents of the message we send you | United States | Always |
| PostHog | Product analytics for artistplus.io and the dashboard | Page paths, feature events, account id, email, plan | United States | Always |
| Meta | Measures which Facebook and Instagram ads bring people to Artistplus | That a signup or subscription happened, its value, and a scrambled (hashed) email, verified phone number, name, and location used only to match an account they already hold | United States and European Union | Only if you accept advertising |
| TikTok | Measures which TikTok ads bring people to Artistplus | That a signup or subscription happened, its value, and a scrambled (hashed) email, verified phone number, name, and location used only to match an account they already hold | United States, Ireland, Singapore | Only if you accept advertising |
| Google Ads | Measures which Google ads bring people to Artistplus | That a signup or subscription happened, its value, and a scrambled (hashed) email, verified phone number, and name used only to match an account they already hold | United States | Only if you accept advertising |
| Sentry | Error monitoring and crash diagnostics | Error traces, browser and request metadata, account id | United States | Always |
| Discord | Internal operational alerting for our own team | Incident summaries, which can include an account id or email address | United States | Always |
| Namecheap | Domain registration, renewal, and DNS for domains bought with us | Registrant name, email, postal address, and phone number | United States | Only if you use it |
| OpenSRS (Tucows) | Mailbox hosting for addresses on your own domain | Mailbox address, display name, and the contents of the mailbox | United States and Canada | Only if you use it |
| Gemini generates onboarding copy; Gmail APIs send and read replies you connect | Public profile text you ask us to import, and Gmail messages in a connected inbox | United States | Only if you use it | |
| OpenAI | Fallback model for onboarding copy generation | Public profile text you ask us to import | United States | Only if you use it |
| Anthropic | Fallback model for onboarding copy generation | Public profile text you ask us to import | United States | Only if you use it |
| Apify | Reads your public Spotify discography during import | Your Spotify artist identifier and public release data | United States and European Union | Only if you use it |
| Spotify | Reads your public artist profile and catalog when you connect it | Your Spotify artist identifier and public release data | United States and European Union | Only if you use it |
| SoundCloud | Reads your uploads when you connect the account | OAuth tokens and your SoundCloud track metadata | United States and European Union | Only if you use it |
Rows marked "Only if you use it" are engaged when you take a specific action, such as buying a domain, connecting SoundCloud, or asking us to build a site from a link. If you never do those things, that provider never receives anything about you.
Other reasons we may share
- When the law requires it, such as a valid court order or subpoena. Where we are permitted to tell you, we will.
- To protect our rights or the safety of artists and visitors, including investigating abuse.
- In a merger, acquisition, or sale of assets, in which case the acquirer is bound by this policy until it gives you notice of any change.
We do not sell personal data, as that term is defined under the California Consumer Privacy Act. We have never received money or other value in exchange for personal information.
We do share personal data for cross-context behavioural advertising, as that term is defined under the same Act, but only for visitors who have accepted the advertising category on artistplus.io. What is shared is the fact of a signup or subscription, its value, and a hashed email, verified phone number, name, and coarse location that let Meta, TikTok, or Google match it to an account they already hold. Nothing you upload, nothing you write, no payment details, and no artist-site visitor data is ever included. You can withdraw at any time from Cookie settings in the footer, or by sending a Global Privacy Control signal, which we honour as a standing opt-out that no click on our banner can override.
7AI features and your data
The onboarding flow can generate draft website copy from a link you provide. To do that, we send publicly available text from that source, such as your biography and release titles, to an AI provider. The providers used, in fallback order, are Google (Gemini), OpenAI, and Anthropic. Which one handles a given request depends on availability at that moment.
- We send only what is needed to draft the copy. We do not send your account credentials, billing data, contacts, invoices, or private files.
- We use these providers under business terms that prohibit training on the data we send.
- Generated copy is a draft you review and edit before publishing. Nothing is published without you.
- We do not train our own models on your content, and we have no plans to change that without telling you first.
If you would rather no AI provider sees your material, do not use the link-import step. You can build a site from scratch instead, and everything else in the product works the same way.
8How long we keep things
| Data | Kept for |
|---|---|
| Account and profile data | While your account is open |
| Site content and uploaded files | While your account is open |
| Files you delete | Trash for 3 to 30 days depending on plan, then permanently removed |
| Raw analytics events | 400 days (about 13 months) |
| Signed-in user activity and first-party marketing events | While the account is open, plus the 30-day deleted-account recovery window |
| Encrypted raw IP for signed-in product activity | 30 days |
| Keyed IP hash for signed-in product activity | 24 months |
| Signed-in consent history | While the account is open, plus the 30-day deleted-account recovery window |
| Daily analytics totals | While the account is open. They contain no visitor identifiers |
| Support messages | Three years from the last message on the ticket |
| Billing and invoice records | Seven years, to satisfy tax and accounting law |
| Purchase acknowledgments for non-refundable orders | Seven years, alongside the billing record they defend |
| Error reports in Sentry | 90 days |
| A closed account | Recoverable for 30 days, then permanently deleted |
Closing your account marks it deleted and takes your published site offline immediately. For 30 days after that we can still restore it or export your content for you. After that window the content is permanently removed, apart from the billing records above and aggregate statistics that no longer identify you.
9Your rights, and how to use them
Depending on where you live, you have some or all of the following rights. We honour them for everyone, not only where the law compels it.
- Access
- Ask what we hold about you and get a copy of it.
- Correction
- Have inaccurate data fixed. Most of it you can edit yourself in settings.
- Deletion
- Have your data erased, subject to records we must keep by law.
- Portability
- Get your data in a machine-readable format, or ask us to send it to someone else.
- Objection
- Object to processing we base on legitimate interests, including analytics.
- Restriction
- Ask us to pause processing while a dispute about accuracy or grounds is resolved.
- Withdraw consent
- Where we rely on consent, take it back at any time. Doing so does not undo processing that already happened lawfully.
- Non-discrimination
- Using any of these rights never costs you service, features, or a worse price.
How to make a request
Email privacy@artistplus.io from the address on your account, or write to support@artistplus.io if that is easier, and say what you want. If we cannot tell that the request comes from you, we will ask one verification question rather than a form.
We acknowledge requests within 5 business days and complete them within 30 days. If a request is genuinely complex we may extend that by up to 60 days and will tell you why before we do. There is no charge, unless a request is repetitive or excessive, in which case we will tell you the cost before doing anything.
An authorised agent may make a request on your behalf where the law allows it. We will ask for proof of the authorisation.
If you are in the EEA or the UK and you think we have handled your data badly, you can complain to your national data protection authority. We would rather you told us first, but the right is yours either way.
10Where your data is processed
We are based in the United States and most of our providers process data there. Files and pages are served from a global edge network, so a copy may be cached near the visitor requesting it.
Where personal data is transferred out of the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision where one applies, together with the technical measures described in section 11.
11How we protect it
- Everything travels over HTTPS. Certificates for custom domains are issued and renewed automatically.
- Files at rest in object storage and records in our database are encrypted by the provider.
- Every backend function checks who is asking before it returns anything. Authorisation is enforced on the server, never in the browser.
- Share links use unguessable tokens, and can carry a password and an expiry you set.
- Third-party access tokens, such as a connected SoundCloud account, are encrypted before storage.
- Raw signed-in product IP addresses are isolated from event and marketing tables, encrypted with AES-256-GCM, and automatically redacted after 30 days. The marketing projection never contains IP values or hashes.
- Access to production data by our team is limited to the people who need it to do their job, and administrative actions are logged.
No system is perfectly secure. If a breach affects your personal data and is likely to present a risk to you, we will notify you and the relevant authority without undue delay, and within 72 hours of becoming aware of it where the law requires that.
12Children
The Service is not directed to children under 13, and we do not knowingly collect personal data from them. Artists between 13 and 18 need a parent or guardian to accept the Terms of Service on their behalf.
If you believe a child under 13 has given us personal data, write to privacy@artistplus.io and we will delete the account and its content promptly.
Websites published by artists are public and may be visited by anyone. Artists are responsible for what they publish and for any collection their own site performs.
13United States state privacy rights
If you are a resident of California, Colorado, Connecticut, Virginia, or another state with a comprehensive privacy law, you have rights to know, access, correct, delete, and port your personal information, to opt out of sale or sharing, and not to be discriminated against for using them.
We do not sell personal information. We do share it for cross-context behavioural advertising, but only if you accepted the advertising category on artistplus.io. To opt out, open Cookie settings in the footer and switch Advertising off; it stops immediately and for good.
Your browser can also opt out for you. We treat a Global Privacy Control signal as a binding opt-out of advertising that no choice on our banner can override, so if your browser sends one you do not need to do anything else. We honour it for optional analytics too.
The categories of personal information we collect, the purposes, and the parties we disclose to are set out in sections 2, 4, and 6. Use the process in section 9 to exercise any of these rights.
14Changes to this policy
We update this policy when what we do changes. For material changes, including adding a subprocessor that receives content or account data, we will give at least 30 days notice by email or an in-product notice before the change takes effect.
The effective date at the top of this page always reflects the current version, and every published version is kept in the revision history below it.
Revision history
- v1.2Disclosed the acknowledgment record kept for one-time non-refundable purchases such as custom website design: the wording shown, the time it was accepted, the browser user agent, and how long it is kept.
- v1.1Added signed-in user activity logging, first-party marketing intelligence, protected IP retention, and product environment collection.
- v1.0First published version. Subprocessor list audited against the codebase, not templated.
Every published version of this document is kept. If you need a copy of one that is no longer current, write to support@artistplus.io and we will send it.