Privacy Policy

mypie.app

Version Information

Version: 1.0

Effective Date: August 2025

Last Updated: August 2025

These terms may be updated as MyPie evolves. We will notify users of significant changes through the platform or email.

MYPIE PRIVACY POLICY

SUMMARY

This privacy policy explains how MyPie, Inc. ("we," "us," or "our"), a Delaware C-Corporation, handles your information when you use our platform to support artists based on your Spotify listening activity.

Key Points:

  • We collect: Email, username, and Spotify listening data
  • We do NOT collect: Payment information (handled by Stripe)
  • We use: Essential cookies for authentication only
  • We do NOT share: Your personal data with third parties
  • Analytics: Privacy-focused, cookie-free analytics

Questions? Contact us at team@mypie.app

1. WHAT INFORMATION DO WE COLLECT?

1.1 Basic Profile Information

When you create an account, we collect:

  • Email address
  • Username
  • Basic profile information

1.2 Spotify Listening Data

When you connect your Spotify account, we collect:

  • Recently played tracks (which includes artist, duration, and timestamp information needed for contribution distribution)

This data is essential for calculating the "LISTEN-TIME-FACTOR" that determines how your monthly contributions are distributed among artists.

1.3 Social Media Login Data

If you choose to register using social media accounts, we may receive basic profile information from supported platforms.

1.4 Technical Information

We collect minimal technical data for security and service operation:

  • IP address (for security and fraud prevention)
  • Basic device information (browser type, operating system)

1.5 What We Do NOT Collect

We do not collect or store:

  • Payment information (handled entirely by Stripe)
  • Billing details
  • Credit card numbers
  • Bank account information
  • Precise location data

2. HOW DO WE USE YOUR INFORMATION?

We use your information for:

  • Service Provision: Creating and managing your account, processing contributions
  • Artist Distribution: Calculating how to distribute your contributions based on listening activity
  • Security: Preventing fraud, protecting accounts, maintaining service security
  • Communication: Sending important service updates and notifications
  • Legal Compliance: Meeting regulatory and legal obligations

2.1 Business Model Context

MyPie operates as a platform that collects monthly contributions from fans and distributes them to artists based on listening activity. We use a "collect now, pay later" model where we collect your monthly contribution and then transfer the appropriate amounts to verified artists using secure payment infrastructure.

2.2 Legal Basis for Processing (GDPR Compliance)

Under GDPR and other applicable privacy laws, we process your data based on the following legal grounds:

  • Contract Performance: To provide our service and fulfill our agreement with you
  • Legitimate Interest: To improve our service, prevent fraud, and ensure security
  • Consent: For optional features like social media login and marketing communications
  • Legal Obligation: To comply with financial regulations and tax requirements
  • Vital Interest: To protect your safety and security

2.3 Automated Decision Making and Profiling

We use automated systems for certain aspects of our service:

  • LISTEN-TIME-FACTOR Calculations: Automated algorithms calculate how to distribute your contributions among artists based on your listening patterns
  • Fraud Detection: Automated systems monitor for suspicious activity and payment patterns
  • Payment Processing: Automated distribution of funds to verified artists
  • Account Verification: Automated checks for Spotify account verification

Your Rights: You have the right to request human review of automated decisions that significantly affect you. Contact us if you believe an automated decision has been made incorrectly.

3. DATA SHARING AND THIRD-PARTY SERVICES

We use third-party services but do not share your personal data with them:

3.1 Third-Party Services We Use

  • Spotify: We access your listening data through their API (you authorize this connection)
  • Stripe: We send payment instructions to them (they handle all payment data)

3.2 What We Do NOT Do

  • We do not sell or rent your personal information
  • We do not share your data with advertisers or marketing companies
  • We do not use your data for purposes unrelated to our service
  • We do not allow third parties to access your personal information

3.3 Legal Requirements

We may be required to share information only in these specific situations:

  • When required by law or government request
  • To protect our rights, safety, or property
  • To prevent fraud or security threats
  • To comply with financial regulations and tax authorities
  • To respond to valid legal process (subpoenas, court orders)

4. COOKIES AND TRACKING

We use cookies for essential functions only:

4.1 Essential Cookies

  • Authentication: User login sessions
  • Spotify Integration: Spotify authentication tokens
  • Preferences: Cookie consent settings

4.2 No Tracking Cookies

  • We do not use cookies for advertising or tracking
  • We do not use third-party tracking cookies
  • Analytics are handled by privacy-focused, cookie-free tools

4.3 Cookie Management

You can manage cookie preferences in your account settings. Essential cookies cannot be disabled as they are required for the service to function.

5. DATA SECURITY AND RETENTION

5.1 Security Measures

  • Encryption of data in transit and at rest
  • Regular security audits and updates
  • Access controls and authentication
  • Secure hosting infrastructure
  • Regular backups and disaster recovery
  • Employee training on data protection
  • Incident response procedures

5.2 Data Retention

  • Account Data: Kept while your account is active
  • Listening Data: Kept for contribution calculations and analytics
  • Payment Records: Kept for legal and accounting purposes (7 years)
  • Deleted Accounts: Data removed within 30 days of deletion request
  • Inactive Accounts: Data retained for 12 months, then anonymized
  • Financial Records: Retained for regulatory compliance (7-10 years)

5.3 Financial Data Retention Cycles

MyPie operates specific retention cycles for financial data protection:

  • Artist Fund Holdings: Unclaimed artist funds held for 12 months before returning to fan wallet
  • Fan Wallet Balances: Inactive fan wallet balances held for 12 months after account abandonment
  • Orphaned Contributions: After 24 months total (12 months artist hold + 12 months fan wallet), funds transfer to Public Pie
  • Transaction Monitoring: Real-time financial monitoring data retained for 12 months for reconciliation
  • Audit Trails: Complete financial audit trails maintained for 7 years minimum
  • Promotional Credits: Promotional code usage history retained permanently to prevent abuse

These cycles ensure proper fund management while protecting user financial interests and maintaining regulatory compliance.

5.3 Data Breach Response

In the event of a data breach affecting your personal information, we will notify you and relevant authorities within 72 hours as required by law.

6. YOUR RIGHTS AND CHOICES

6.1 Access and Control

You have the right to:

  • Access your personal information
  • Update or correct your information
  • Delete your account and data
  • Export your data
  • Withdraw consent for data processing
  • Request data portability

6.2 Account Management

You can manage your information by:

6.3 Regional Rights

Depending on your location, you may have additional rights under:

  • GDPR (European Union)
  • CCPA (California)
  • Other local privacy laws

6.4 Specific Rights for EU/UK Users (GDPR)

Under GDPR, you have additional rights:

  • Right to Erasure: Request complete deletion of your data ("right to be forgotten")
  • Right to Data Portability: Receive your data in a structured, machine-readable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Restrict Processing: Limit how we use your data
  • Right to Withdraw Consent: Withdraw consent for processing at any time
  • Right to Lodge Complaint: File a complaint with your local data protection authority

6.5 Specific Rights for California Users (CCPA)

Under CCPA, you have additional rights:

  • Right to Know: Know what personal information we collect and how we use it
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out: Opt out of the sale of personal information (we do not sell data)
  • Right to Non-Discrimination: Not be discriminated against for exercising your rights

6.6 Automated Decision Making Rights

You have specific rights regarding automated processing:

  • Request human review of automated decisions
  • Express your point of view about automated processing
  • Challenge automated decisions that significantly affect you
  • Request explanation of how automated decisions are made

7. INTERNATIONAL DATA TRANSFERS AND COMPLIANCE

As an international platform, your data may be processed in different countries:

7.1 Data Transfer Locations

  • Primary Processing: United States and other locations where we operate
  • Spotify API: United States and other locations (through their service)
  • Stripe Processing: United States and other locations (for payment processing)
  • Backup Storage: Multiple locations for redundancy and security

7.2 Transfer Safeguards

We ensure appropriate safeguards for international data transfers:

  • Standard Contractual Clauses (SCCs): EU-approved data transfer agreements
  • Adequacy Decisions: Only transfer to countries with adequate data protection
  • Data Minimization: Only transfer data necessary for service provision
  • Encryption: All data encrypted during transfer and storage

7.3 Regional Compliance

We comply with privacy laws in all regions where we operate:

  • United States: CCPA, COPPA, and state-specific laws
  • European Union: GDPR compliance
  • United Kingdom: UK GDPR compliance
  • Canada: PIPEDA compliance
  • Australia: Privacy Act 1988 compliance
  • Other Regions: Local privacy law compliance where applicable

8. CHILDREN'S PRIVACY

Our service is not intended for children under 18 years of age. We do not knowingly collect personal information from children under 18. If you believe we have collected such information, please contact us immediately.

9. CHANGES TO THIS POLICY

We may update this privacy policy from time to time. We will notify you of significant changes through:

  • Email notification
  • In-app notification
  • Updated policy on our website

Continued use of our service after changes constitutes acceptance of the updated policy.

10. CONTACT US

If you have questions about this privacy policy or want to exercise your rights, contact us:

MYPIE, Inc.
Data Protection Officer
Wittgensteinlaan, 281
Amsterdam 1062KH
Netherlands

10.1 European Union Representative

For EU residents, you can also contact our EU representative:

Wittgensteinlaan, 281
Amsterdam 1062KH
Netherlands

10.2 Data Protection Authority

If you believe we are not handling your data properly, you have the right to file a complaint with your local data protection authority.

10.3 International Support

We provide support in multiple languages and time zones to serve our global user base. Response times may vary based on your location and the complexity of your request.