Bandwise Privacy policy
Bandwise · Last updated 31 August 2026
Privacy Policy
Peopleaudio AB, and Högalidsgatan 36B, 11720 Stockholm, Sweden.
1. Who is responsible for your personal data?
Bandwise is provided by [LEGAL NAME], company/registration number [COMPANY/REGISTRATION NUMBER], with postal address [POSTAL ADDRESS] (“Bandwise”, “we”, “us”, or “our”). We are the data controller for the processing described in this policy when we determine why and how personal data is processed.
Contact for privacy questions and requests concerning your rights: erik.ring@guruaudio.com.
When a band, association, company, or venue uses Bandwise to administer information about its own members, ticket buyers, or partners, that organisation may be a separate data controller. If your request concerns information entered by an organisation, please contact its administrator first.
2. What information do we process?
The information we process depends on the features you use.
Account and identity
- Email address, display name, and technical user ID.
- Email verification status, login session, and security information.
- Onboarding choices, selected mode, active band, and other personal app settings.
Bands, members, and collaboration
- Band name, profile, city, contact details, and Swish information entered by the band.
- Memberships, roles, instruments, personal sales targets, and invitations.
- Concerts, rehearsals, setlists, scores, messages, activity records, and responses to concert enquiries.
Tickets and audience features
- The ticket buyer’s or visitor’s name and email address.
- Concert, ticket category, amount, payment status, reference, QR/validation data, and admission status.
- Name, email address, and amount for voluntary contributions.
Bandwise does not process card numbers or online banking credentials. In current flows, payment may take place outside Bandwise, for example through Swish, while Bandwise records its status and supporting information.
Musician and venue marketplace
- Musician profile, instruments, genres, location, biography, availability, travel radius, and requested fee.
- Venue or organisation details, contact details, address, map coordinates, stage dimensions, capacity, technical information, and available dates.
- Booking and gig requests, messages, offered amounts, and status.
Information is shown to other users only to the extent necessary for the selected directory, search, or collaboration feature and in accordance with the visibility choices available in the service.
Gig integration and compensation
- Identifier, name, and organisation number for a business linked from Gig.
- Compensation request, invoice or payroll route, amount, payment method, payment destination, invoice number, and status.
Bandwise does not copy complete accounting records from Gig and does not store your Gig login credentials.
Social media
When a band administrator connects Instagram, we process the Instagram account ID and username, access token and its expiry time, selected images and videos, captions, publication format, channels and scheduled times, as well as publication status, external post ID, and error messages.
Bandwise requests the instagram_business_basic and instagram_business_content_publish permissions to read basic account information and publish content that an authorised administrator has explicitly selected and scheduled. The access token is stored as a protected secret in the server vault and is not shown to other band members. Bandwise does not read private Instagram messages through this integration.
Photos, video, camera, maps, and local network
- Bandwise can access only the photos and videos that you select through Apple’s photo picker.
- The camera is used when you choose to scan QR codes.
- Address and venue searches are processed using Apple Maps/MapKit.
- If you enable nearby sharing, scores and setlists can be transferred directly between devices on the local network. The device name and a random local identifier are used to discover nearby devices.
Technical information
Our service providers may process IP address, timestamps, request status, error and security logs, and basic device and network information to operate, troubleshoot, and protect the service. Bandwise does not use this information for behavioural advertising.
3. Where does the information come from?
The information comes from you, other authorised users in a band or venue, ticketing and booking flows, the device you use, and external services that you explicitly connect, such as Instagram, Apple, and Gig.
4. Why do we process the information?
- Providing Bandwise and requested features – performance of a contract or steps taken at your request before entering into a contract.
- Managing optional integrations – performance of the feature you requested. You can disconnect an integration and revoke its permissions.
- Security, access control, troubleshooting, and abuse prevention – our legitimate interest in providing a secure and functioning service.
- Communication and support – performance of a contract and our legitimate interest in assisting users.
- Payment, compensation, and documentation records – performance of a contract and, where applicable, compliance with a legal obligation.
- Public directories and profiles – providing the directory or marketplace feature that the user or organisation chose to enable.
We do not sell personal data. We do not make decisions producing legal or similarly significant effects based solely on automated processing.
5. Who may receive the information?
- Other authorised members, administrators, ticket staff, or counterparties where required by the feature you use.
- The public in relation to concerts, profiles, venues, and available dates that have explicitly been published.
- Supabase for authentication, databases, storage, and server functions.
- Apple when you use iCloud, Photos, system features, or Apple Maps.
- Meta/Instagram when you connect an Instagram account or publish content.
- Google or another configured email provider for login codes and member invitations.
- Gig when you explicitly choose to link a business or create supporting information.
- Public authorities or other recipients where required by law or necessary for legal claims.
Providers processing information on our behalf may use it only in accordance with our instructions and applicable agreements. External platforms may also act as independent data controllers under their own terms and privacy policies.
6. Storage and transfers outside the EU/EEA
Bandwise’s shared data is stored using Supabase. Personal app state may be stored in Apple iCloud if an iCloud account is available on the device. Certain providers, including Apple, Google, and Meta, may process information outside the EU/EEA. Where required, such transfers must be supported by an adequacy decision or appropriate safeguards, such as the European Commission’s Standard Contractual Clauses.
7. How long do we keep the information?
- Account and workspace data is retained while the account or workspace is in use and afterwards for as long as necessary for deletion, backups, legal claims, or legal obligations.
- Concert media, drafts, and schedules are retained until an authorised administrator removes them or the workspace is deleted. Published material may remain on the external platform until removed there.
- An Instagram token is retained until the connection is disconnected, the token expires, or the account/workspace is deleted.
- Temporary Instagram OAuth state normally expires after ten minutes and can be used only once.
- Ticket, payment, compensation, and booking records are retained as long as necessary for the event, the parties’ claims, and applicable documentation requirements.
- Local data remains on the device until it is deleted or the app’s data is removed. Personal iCloud state may remain in the user’s iCloud until removed there or through a deletion request.
- Backups and technical logs are deleted according to each provider’s security and recovery procedures.
Where an exact period cannot be stated, we use the purpose, activity, security needs, and legal obligations as the criteria for determining retention.
8. Security
We use measures including encrypted communications, access controls, verified email, row-level database rules, private storage, server-side validation, and protected storage of session and integration tokens. No technical solution can guarantee complete security.
9. Your rights
Depending on the circumstances, you may have the right to receive information and a copy of your data, correct it, request deletion or restriction, object to certain processing, receive certain data in a machine-readable format, and withdraw consent where consent is used. You can lodge a complaint with the Swedish Authority for Privacy Protection (IMY).
These rights are not absolute. We may need to retain certain information for legal obligations or claims. We may need to verify your identity, but will not request more information than necessary.
10. Deletion of your account, Instagram data, and other user data
- Send an email from the address connected to Bandwise to erik.ring@guruaudio.com.
- Use the subject Delete Bandwise data.
- State which email address, band, and—where relevant—Instagram account the request concerns. Never send passwords or access tokens.
- We will acknowledge the request and may ask for limited information to verify your identity securely.
- We will delete or anonymise the relevant information, disconnect Instagram, and delete the stored Instagram token, unless certain information must be retained by law or for legal claims.
We normally respond to a valid request within one month. If the information was entered by a band, company, association, or venue, we may need to coordinate deletion with that organisation.
You can also revoke Bandwise’s access through Instagram’s/Meta’s settings for apps and websites. Signing out or deleting the app from your phone does not automatically delete server data, published Instagram posts, or personal iCloud data.
11. Changes to this policy
We may update this policy when Bandwise or applicable legal requirements change. The date at the top identifies the current version. If a change is material, we will provide notice in the app or through another appropriate channel.
12. Contact
Send privacy questions, complaints, and rights requests to erik.ring@guruaudio.com with the subject Privacy – Bandwise.