Data protection
Privacy Policy
Last updated: 24 August 2026
1. Controller
Alec Schneider Solutions
Inhaber: Alec Peter Schneider
Pappelallee 25, 10437 Berlin, Germany
Email: alec@a3.lol
Phone: +49 175 5593082
2. Website delivery and technical data
When you visit the website, technical request data is processed so the site can be delivered securely. Depending on the request, this can include your IP address, date and time, requested URL, referrer, browser or device information, and response status.
The legal basis is our legitimate interest in providing a secure, reliable website (Article 6(1)(f) GDPR). Vercel hosts the website and processes this data on our behalf. Operational logs are retained only for the short period needed to operate, diagnose, and protect the service, unless a security incident requires longer preservation.
With your consent, we use PostHog to understand anonymous website and app usage. Analytics is disabled by default. After consent, we collect page and screen navigation, app lifecycle, feature steps, coarse outcomes and counts, interaction types, performance metrics, and fully masked session recordings. Website recordings mask all text, images, and inputs; iOS recordings are masked wireframes that hide all text, images, and sandboxed views. Contact and email forms are also excluded from automatic capture.
We do not send names, email addresses, message or form contents, lineup images or text, festival names, artist or song names, playlist URLs, advertising identifiers, raw error messages, console logs, network headers, or network bodies. PostHog is configured not to create person profiles or enrich events with location, and the project discards client IP data. Website URLs contain only the origin and path; the Spotify authorization callback is excluded entirely.
The legal basis is your consent under Article 6(1)(a) GDPR. You may decline without losing any functionality and withdraw at any time through the controls in the website's Cookie Notice or the app's settings menu. PostHog processes this data for us in its EU cloud. Analytics events are retained for up to 12 months and session recordings for up to 30 days. We do not use analytics for advertising or cross-service tracking.
3. Contact and support
If you contact us, we process your message and any name, email address, or other details you choose to provide. A message is required; name and email are optional. Without contact details, we can review the message but cannot reply directly.
The website sends the message through our Convex backend to a private support channel in Discord. The backend does not create a separate database record of the message. Access to the channel is restricted to the operator and authorized support automation.
We process support and pre-contractual questions under Article 6(1)(b) GDPR. General feedback is processed under Article 6(1)(f) GDPR based on our legitimate interest in answering inquiries and improving the service. Privacy requests and related records may also be processed to comply with legal obligations under Article 6(1)(c) GDPR.
Support messages are normally deleted no later than 12 months after the request is closed. We may retain necessary records longer where required by law or to establish, exercise, or defend legal claims. Please do not include health information, payment details, government identifiers, passwords, or other sensitive information.
4. Email updates and promotions
You can voluntarily provide your email address and separately choose whether to receive Festival2Playlist product and release updates, occasional news and offers about other Alec Schneider Solutions apps, or both. Neither option is selected in advance, and the choices do not affect your ability to use the app or website.
We store the normalized email address, your current choices, consent and withdrawal timestamps, signup source, language or locale, consent text version, and verification status in Convex. We do not associate this record with an app account, music account, purchase identifier, festival, or advertising profile.
The legal basis is your consent under Article 6(1)(a) GDPR. Email delivery is not active yet, and records are marked unverified. We will require confirmation of the address before activating email delivery. You can update your choices by submitting the form again or withdraw consent by contacting us. Future emails will also include an unsubscribe option. Withdrawal does not affect processing that took place before withdrawal.
5. Lineup images, local recognition, and saved festivals
The app receives only the lineup images you select through the iOS photo picker. Apple Vision recognizes text on your device. The original image is not uploaded to our backend. If you save a festival, the image, recognized festival details, artists, day selections, catalog matches, and related app state are stored locally on your device until you remove the saved festival or delete the app.
To identify the festival, artists, and any day-by-day sections, the recognized text is sent to our Convex backend and then to OpenRouter. We send the text rather than the image and configure routing to providers that support zero-data-retention handling. The legal basis is Article 6(1)(b) GDPR because this processing is necessary to provide the lineup extraction you request.
The recognized text is not stored as a user profile. Parsed festival names, dates, locations, artist names, artwork references, and music-catalog matches may be retained in a shared Convex cache to improve future festival and song matching. This cache contains professional or public festival information and is not associated with an app account, device identifier, or advertising profile. If a lineup poster unexpectedly contains personal information that is not public festival data, contact us so we can review it.
6. Apple Music and Spotify
If you choose Apple Music, the app asks for access to your Apple Music account and uses Apple Music to search the catalog and create the playlist you request. Apple handles your account and music library under its own terms and privacy policy. We do not receive your Apple account password.
If you choose Spotify, the app sends the selected song metadata—such as title, artist, album, duration, and recording identifier—to our Convex backend and Spotify so tracks can be matched and a playlist can be created. Spotify playlists created by this feature are public, so anyone with the link may be able to view them. Do not use the feature if you do not want your selected lineup reflected in a public playlist.
This processing is based on Article 6(1)(b) GDPR and occurs only when you ask us to create the relevant playlist.
7. In-app purchases
Apple processes payment for the Festival Pass. RevenueCat processes purchase status, purchase history, and a randomly generated, app-specific identifier so the app can unlock paid features, restore purchases, prevent purchase fraud, and show purchase-management information. We do not receive payment-card details and do not assign your name or email address to the RevenueCat identifier.
The legal basis is Article 6(1)(b) GDPR. Purchase records are retained by Apple and RevenueCat for as long as needed to provide and restore the purchase and to meet applicable legal, fraud-prevention, and accounting requirements.
8. Service providers and recipients
We use the following recipients for the stated purposes:
- Apple: iOS, photo selection, Apple Vision, MusicKit, and payment
- Vercel: website hosting and security
- PostHog: consent-based anonymous product analytics in EU cloud
- Convex: backend hosting, request processing, festival cache, and email-preference storage
- OpenRouter and routed model providers: lineup text extraction
- RevenueCat: purchase entitlement and purchase support
- Spotify: track matching and public Spotify playlist creation
- Discord: private delivery and handling of support messages
We do not sell personal data, use it for third-party advertising, or track you across other companies' apps and websites.
9. Processing outside the EEA
Several providers above are based in, or use infrastructure in, the United States. Our Convex production backend and Vercel application compute are configured in the United States. Where personal data is transferred outside the European Economic Area, the transfer is based on an applicable adequacy decision, including the EU–US Data Privacy Framework where the recipient is certified, or appropriate safeguards such as the European Commission's Standard Contractual Clauses. Provider-specific privacy and transfer terms also apply.
10. Retention and deletion
- Local app data remains on your device until you delete the saved festival or the app.
- Lineup request content is routed using zero-data-retention processing and is not added to a user profile by us.
- Shared public festival and catalog-match data may be kept while it remains useful and accurate, because it is not linked to an app user.
- Support messages follow the retention period described in section 3.
- Email subscription records are kept while the relevant consent is active. After withdrawal, we may retain a limited suppression and consent record for up to three years where needed to document compliance and prevent further messages.
- Technical logs are kept only as long as needed for operations, security, and incident handling.
- Consent-based analytics data is retained for up to 12 months.
If data is needed to comply with a legal obligation or handle a legal claim, deletion may be restricted until that purpose ends.
11. Your data-protection rights
Subject to the legal requirements, you can request access, rectification, erasure, restriction, and data portability. You can object to processing based on legitimate interests. Where processing is based on consent, you may withdraw it for the future. No significant decision producing legal or similarly significant effects is made about you solely by automated means.
Send a request to alec@a3.lol or use the contact form. We may need to verify that a request relates to you before acting on it.
12. Right to complain
You may complain to a data-protection supervisory authority, in particular in the EU member state of your residence, workplace, or the alleged infringement. Our competent local authority is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61, 10555 Berlin, Germany
13. Changes to this policy
We update this policy when the product, providers, or legal requirements change. The current version is published here with its update date. Material changes will be communicated in an appropriate way before they take effect where required.