Privacy Policy
Last updated: 3 September 2026
1. Who controls your personal data
This Privacy Policy explains how LineApp processes personal data when you visit lineapp.live, create or use a LineApp account, connect an external music service, follow an artist, save an event, choose notification locations or contact us.
The data controller is the LineApp service operator identified in the Legal Notice. For privacy questions and requests, contact [email protected]. Where applicable law requires an additional representative or data protection contact, the relevant details will be made available through the applicable privacy notice or on request.
2. What this policy covers
This policy covers information collected directly from you, received from an external provider at your request, generated when you use account features, or technically processed when the website delivers pages and security functions. The public catalogue may contain information about artists, events and venues supplied by partners or public sources; that catalogue information is not normally your account data.
External websites, ticket providers, Google, Spotify, YouTube and other providers have their own privacy notices. This policy does not describe processing that they carry out independently after you leave LineApp or authorise their service.
3. Personal data we may process
Depending on how you use LineApp, we may process the following categories:
- account data: name, email address, password hash, email-verification status, language preference and account timestamps;
- external-account data: provider account identifier, provider email or verification status, display name, avatar URL, scopes, provider response data and encrypted access or refresh tokens for a connection you authorise;
- preferences and selections: followed artists, saved events, dismissed or accepted recommendations, music-service source labels, notification locations and optional start and end dates, notification delivery status, theme and language choices;
- technical and security data: IP address and request metadata may be processed transiently by the web server, hosting, security, CAPTCHA, email and infrastructure providers; security logs and error diagnostics may include technical identifiers according to their retention settings;
- approximate-location data: if the feature is enabled and the relevant consent condition is met, the request IP may be used briefly to estimate a city or area for a first-visit suggestion. A short-lived cache may retain a hash-derived lookup key and coarse result to avoid repeated database work; these values are not stored as account data or in the consent journal. LineApp does not use this feature to obtain precise GPS coordinates or identify an exact address;
- communications: messages you send to support, legal or rights contacts and records needed to respond to them.
4. Where data comes from
We receive account and preference data from you. When you use Google, Spotify or YouTube Music sign-in or connection, we receive the fields and permissions returned by that provider after you authorise the request. We receive event, artist, venue, image and ticket information from partners, public sources, providers and editorial or automated catalogue processes. Technical and security data is generated by the website, your browser and service providers while a request is delivered.
5. Why we process data and the legal grounds
We use personal data only as needed for the purposes below. Where a law requires a lawful basis, the basis and required notice may depend on the specific context; other laws may impose separate duties:
- to create, authenticate, secure and maintain your account, verify your email, reset your password and provide the account features you request — performance of a contract or steps requested before a contract;
- to store and apply followed artists, saved events, notification locations and preferences, and send the event notifications you request — performance of a contract or provision of a requested service;
- to connect and synchronise Spotify or YouTube Music and produce optional artist recommendations — your request and authorisation, performance of the requested service, and any consent required by the external provider or applicable law;
- to operate, secure, troubleshoot, prevent abuse, investigate incidents, protect rights and comply with legal obligations — legitimate interests, legal obligations or another lawful ground available in the applicable jurisdiction;
- to protect registration, sign-in and password-reset forms from automated abuse with reCAPTCHA — a security purpose and, where required, another lawful basis disclosed before the technology is used;
- to suggest an approximate location, use non-essential cookies or run optional measurement or marketing technologies — consent where consent is required, or another lawful ground clearly disclosed before use.
6. Google, Spotify and YouTube Music
Google sign-in uses the identity fields shown on the Google consent screen. Spotify connection can receive the authorised profile and artist information needed for followed-artist and Top Artists recommendations. YouTube Music uses the YouTube Data API to read the authorised channel and subscriptions, compare subscribed channel URLs with LineApp artist channel URLs, and show possible matches for you to choose manually.
LineApp does not receive your external password and does not use these connections to edit videos, comments, subscriptions, follows or other external content. OAuth access and refresh tokens are encrypted and stored server-side for the connected LineApp account. Disconnecting removes the active connection and related recommendations; you can also revoke access in the external provider’s settings.
Information received from Google APIs is used only to operate the requested LineApp feature and is handled consistently with the Google API Services User Data Policy, including its Limited Use requirements. LineApp does not sell that data or use it for advertising.
7. Notifications and email links
If you follow an artist and configure a matching notification location, LineApp may send an operational event notification to your account email. A message can combine several followed artists for one event to avoid duplicate notices. It may include the event name, image, place, date, time, lineup, ticket links and links to view or save the event or unfollow the matched artist.
Email delivery providers process the recipient address and message data needed to deliver the message.
8. Who may receive data
LineApp may disclose the minimum data needed to the following categories of recipients or processors:
- hosting, database, backup, object-storage, image-delivery, email and monitoring providers that operate the service;
- Google, Spotify and YouTube when you request sign-in or a music-service connection, and Google reCAPTCHA when it protects an enabled form;
- map, geolocation and address-search providers when you search for or display a location;
- ticket, affiliate and other linked providers when you follow a link or start an external transaction; they may receive normal browser and request data and may set their own cookies;
- professional advisers, regulators, courts, law enforcement or another party when disclosure is required by law or reasonably necessary to protect people, rights, security or the service.
LineApp does not publish your email address, password, notification locations, external tokens or music-service recommendations as part of the public artist and event catalogue. We do not sell account personal data as a standalone product or use Google API data for advertising. If a third-party technology creates additional statutory opt-out rights, we will provide the information and controls required by law.
9. Cookies, analytics and external resources
LineApp uses necessary cookies for sessions, security, consent, language, selected location, theme and some interface state. The Cookie Policy groups the known first-party cookies by purpose and explains third-party technologies. The public experience recorder can store short-lived context events for selected locations or future date ranges without storing raw IP address, User-Agent, user ID, session ID or full URL in that event table.
When you follow a ticket link on the website or from a LineApp email, LineApp may record the ticket, time, channel, linked account or email recipient when available, email campaign or source page path, link placement, locale, coarse device and browser family, and whether the request resembles an automated scanner. Ticket click records do not store raw IP addresses, raw User-Agent strings or full source URLs and are retained for the configured ticket-click period.
The website loads Google Tag Manager only after you allow the Analytics category. The configured container may then load Google Analytics, Yandex Metrica or other tags; the exact tags and cookies can change and may be controlled by Google or other providers. Third-party providers may have independent processing responsibilities.
LineApp uses Google reCAPTCHA only as an anti-abuse security control on enabled registration, sign-in and password-reset forms. LineApp does not use reCAPTCHA tokens or results for analytics, advertising, profiling or artist recommendations, and does not store the token in the account database. The verification request may include the request IP address and other technical browser data needed by Google to assess the challenge; Google’s independent processing is governed by its own notices and terms.
LineApp may keep a limited server-side consent journal containing the consent-policy version, selected categories, consent method, time, locale and, when available, the signed-in account identifier. The journal is not a tracking profile and does not store raw IP addresses or User-Agent values.
10. International transfers
LineApp is operated from Georgia and some service providers or external APIs may process data in other countries, including countries outside the EEA, the United Kingdom, Switzerland or Brazil. Where a transfer law applies, LineApp will use a legally available transfer mechanism and supplementary safeguards appropriate to the processing. Provider identities and processing locations may change; questions about the current processing categories can be sent to [email protected].
11. Retention
We keep account data while the account is active and for as long as reasonably needed to provide the service, resolve disputes, meet legal obligations, protect security and maintain reliable backups. When an account is closed or a deletion request is accepted, active personal records are removed or anonymised unless a longer period is required or permitted by law; backup copies may disappear only through the normal backup cycle.
OAuth tokens are retained while a connection is active or until they are no longer needed. Recommendations and connection-specific records are removed when the connection is disconnected or the relevant cleanup runs, subject to legal, security and backup needs. Notification-delivery records may be retained long enough to prevent duplicate sends, investigate failures and demonstrate operational history. Password-reset and verification tokens are short-lived. Public-experience context events use the configured retention period, currently 30 days unless configuration changes. Ticket-click records use the configured ticket-click retention period, currently 90 days unless configuration changes.
Consent journal records are retained for the configured journal period, currently up to 730 days, and are then removed by the scheduled cleanup process unless a longer period is required or permitted by law.
12. Security
LineApp uses measures appropriate to the service, including password hashing, encrypted OAuth tokens, HTTPS where configured, access controls, rate limits and operational logging. No internet service can guarantee absolute security. Do not send passwords or private tokens by email, and tell us promptly about suspected account or security incidents.
13. Your privacy rights
Depending on where you live and the law that applies, you may have the right to know whether we process your data, obtain access or a copy, correct inaccurate information, request deletion, restrict or object to processing, receive portable data, withdraw consent, and complain to a supervisory or data-protection authority. You can manage much of your account data directly in the account area and can send a request to [email protected].
We may need to verify your identity and clarify the scope of a request before disclosing or deleting data. We will respond within the period required by applicable law and may explain why a lawful exception, retention duty or third-party limitation applies. Withdrawal of consent does not affect processing that occurred before withdrawal or processing based on another lawful ground.
14. Regional information
EEA, United Kingdom and Switzerland: where the relevant data-protection law applies, the rights and legal grounds described above are intended to cover access, rectification, erasure, restriction, portability, objection and consent withdrawal. You may complain to the authority in the country where you live, work or believe an infringement occurred. Where local law requires a representative or data protection officer, the applicable contact details are available through the relevant privacy notice or on request.
California: California residents may have rights to know, access, correct, delete and receive equal service, as well as rights concerning sale, sharing, sensitive personal information and automated opt-out signals when those concepts apply. LineApp does not sell account personal data for money. If a third-party technology creates additional statutory opt-out rights, the applicable information and controls will be provided as required by law.
Brazil, Canada and other jurisdictions: local law may provide confirmation, access, correction, deletion, anonymisation, portability, information about sharing, consent withdrawal or complaint rights. Mandatory rights and response duties in the user’s jurisdiction prevail over any general wording in this policy.
15. Children and automated recommendations
LineApp is not directed to children under 16 or the higher local age threshold. If you believe a child supplied personal data, contact us so that we can investigate and remove it where appropriate.
Artist recommendations are produced from rule-based matching of authorised external artist identifiers or channel URLs with the LineApp catalogue and from your selections. They are not used to make decisions about credit, employment, insurance, housing, education or another similarly significant legal or personal matter.
16. Changes and contact
We may update this Privacy Policy when our service, providers, data use or legal obligations change. We will publish the new version and date and provide additional notice where the applicable law requires it. For privacy requests, legal notices or questions, contact [email protected].
Contact
If you have any questions, please contact us at [email protected].
See also: Terms & Conditions, Privacy Policy, Cookie Policy.