Privacy Policy

Last updated 21 July 2026

This Privacy Policy explains how AudienzRoom ("AudienzRoom", "we", "us") processes personal data when you use AudienzRoom — including artist Studio accounts, public artist rooms, fan accounts, events, uploads, notifications, and email campaigns.

We aim to comply with the EU General Data Protection Regulation (GDPR), UK GDPR, and applicable ePrivacy rules. This notice is not legal advice.

1. Controller and contact

Controller: AudienzRoom
Address: 6 Chief Adejinmi Adu St, Alimosho, Lagos 100212, Lagos, Nigeria
Privacy contact: privacy@audienzroom.com
General support: hello@audienzroom.com

Artists who message their fans through AudienzRoom may also act as separate controllers for their fan relationship data. Where that applies, the artist is responsible for their own compliance, while AudienzRoom processes data as a platform provider and, for campaign delivery, often as a processor on the artist's instructions.

2. Personal data we collect

Depending on how you use AudienzRoom, we may process:

  • Artist account data: first name, last name, stage name (used as your public page name and URL slug), email address, password hash, role, and verification status;
  • Fan account data: first name, last name, phone number (stored in international E.164 format), email address, password hash, role, verification status, and an internal account handle derived from your name for comments and audience tools (we do not ask fans to choose a public username at signup);
  • Profile and room data: bios, links, images, public page content, posts, comments, and engagement signals;
  • Audience data: fan join relationships, saved audiences, RSVP status, notification preferences, email consent records;
  • Campaign and transactional email data: send logs, delivery events, unsubscribe actions, reply routing metadata;
  • Uploads: images, video, audio, and related technical metadata stored for posts, events, and campaigns;
  • Technical data: device/browser type, IP address, logs, security signals, and cookie/local storage identifiers needed to operate the service;
  • Support communications you send to us.

Fan phone numbers are collected at signup for account recovery and related account security. We do not currently send SMS or use phone numbers for one-time verification codes. If we introduce SMS verification or other phone-based messaging, we will update this notice before expanding that use.

3. Why we process data and lawful bases

  • Provide the service (contract): account creation, authentication, artist rooms, events, uploads, and fan workflows;
  • Security and abuse prevention (legitimate interests / legal obligation): fraud prevention, audit logs, and platform integrity;
  • Email verification and service messages (contract / legitimate interests): OTP codes, password reset, critical account notices;
  • Marketing email to fans (consent): where artists send promotional campaigns, artist campaign emails are on by default when a fan joins that artist, RSVPs, or claims an artist invite. Fans can unsubscribe or turn campaign emails off at any time;
  • Push notifications (consent / settings): when enabled on supported devices;
  • Legal compliance: responding to lawful requests and maintaining records where required.

4. How artists use fan data

When a fan joins an artist room, RSVPs to an event, or claims an artist invite, room email updates and artist campaign emails are on by default for that artist. The artist can view and use that relationship inside Studio — for example to send posts, event reminders, or campaigns. Fans can turn those emails off, and artists must honor unsubscribe requests and applicable marketing rules.

AudienzRoom provides tooling to record consent, exclude unsubscribed fans, and deliver messages, but artists choose audiences and message content.

5. Processors and sharing

We use trusted providers to run AudienzRoom. They process data on our instructions and only as needed to deliver the service:

  • Resend — transactional and campaign email delivery;
  • Cloud hosting / database providers — application hosting and MongoDB storage (provider depends on deployment environment);
  • Cloudflare R2 — media and asset storage;
  • Firebase Cloud Messaging — optional web push notifications when enabled;
  • Payment providers — if and when paid features are offered.

We may also disclose data if required by law, to protect rights and safety, or in connection with a merger or acquisition with appropriate safeguards.

6. International transfers

Some providers may process data outside your country. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms.

7. Retention

We keep personal data only as long as needed for the purposes above — including while your account is active, to comply with law, resolve disputes, and maintain security logs. Campaign and delivery logs may be retained for analytics, billing, and compliance for a limited period.

8. Your rights

If GDPR/UK GDPR applies, you may have the right to access, rectify, erase, restrict, or port your data, and to object to certain processing. Where processing is based on consent, you may withdraw consent at any time without affecting prior lawful processing.

Email marketing: use unsubscribe links in campaign emails or adjust notification preferences in your account where available.

To exercise privacy rights, contact privacy@audienzroom.com. You may also lodge a complaint with your local supervisory authority.

9. Cookies and similar technologies

We use essential cookies and local storage for authentication, session management, and core product functionality. See our Cookie Policy for details. We do not use advertising or analytics cookies in the current MVP.

10. Children

AudienzRoom is not directed at children under 16. If you believe a child has provided personal data, contact us and we will take appropriate steps.

11. Changes to this notice

We may update this Privacy Policy from time to time. We will post the revised version with an updated date. Material changes may also be communicated through the product where appropriate.

Last policy revision ID: 2026-07-21.