Privacy policy
Last updated: 5 August 2026
1. Who we are
Consolync is operated by Crew Entertainment LTD, a company registered in England and Wales under company number 15908962, with its registered office at Flat 32, 124 Charles Street, Leicester, England, LE1 1LB, United Kingdom (“Consolync”, “we”, “us”, or “our”).
For the purposes of the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and equivalent data protection laws, Crew Entertainment LTD is the data controller for the personal data described in this Privacy Policy, except where we act as a data processor on behalf of our customers (see Section 3).
Questions about this policy or your personal data can be sent to privacy@consolync.com.
2. Who this policy applies to
This Privacy Policy applies to four groups of people:
- Customers: artists, labels, managers, and other music industry professionals who sign up for a Consolync account at app.consolync.com.
- SmartLink visitors: anyone who visits a public SmartLink page hosted by Consolync on behalf of a customer.
- Fans who submit contact details: individuals who opt in to a customer’s fan-capture form, SMS list, or email list operated through Consolync’s CRM features.
- Waitlist and marketing contacts: people who give us their email address on our marketing site at consolync.com to hear about Consolync’s launch, product news, or offers.
3. Our role under data protection law
Consolync as a data controller. We are the data controller for personal data we collect directly about our customers (account registration, billing, usage of the Consolync dashboard) and for data we collect automatically about SmartLink visitors for our own purposes (fraud prevention, bot detection, service performance).
Consolync as a data processor. When our customers upload fan data, launch advertising campaigns, or send messages through our CRM features, we act as a data processor on behalf of that customer, who is the data controller for that data. Customers are responsible for having a lawful basis (including consent where required) to collect and use their fans’ personal data, and for providing their own privacy notices to those fans. Consolync offers a separate Data Processing Agreement (DPA) to customers on request.
4. What we collect
4.1 Account information (from customers)
Name, email address, password (hashed using bcrypt), profile photo, organisation name, time zone, and any other information you provide during onboarding or in your account settings. If you sign in via Google OAuth, we receive your Google account identifier and email.
4.2 Meta Platform Data (from customers’ connected Meta accounts)
When a customer connects their Meta Business Manager or Ad Account to Consolync, we receive and store the following data from Meta:
- User identification: Meta user ID, name, email, profile picture URL
- Business and asset identifiers: Business Manager ID, Ad Account ID, Page ID, Pixel ID
- Ad account configuration: campaign, ad set, and ad settings (name, status, budget, schedule, targeting)
- Ad creative assets (images, videos, and copy created or uploaded through Consolync)
- Advertising performance metrics: spend, impressions, clicks, conversions, reach, frequency, and demographic and geographic breakdowns
- Access tokens used to operate on your behalf, stored in encrypted form (see Section 12)
We use Meta Platform Data solely to provide the Service — to display campaign performance in your dashboard, to let you create and manage campaigns, and to generate optimisation recommendations. We do not sell Meta Platform Data, do not share it with third parties except as described in Section 8, do not use it for purposes outside the Service, and do not use it to train generalised artificial intelligence or machine learning models.
When you disconnect your Meta account, we delete Meta Platform Data associated with that connection within 30 days, except aggregated, de-identified statistics we retain for service analytics.
4.3 Content you provide
SmartLink titles, descriptions, artwork, custom links, bio text, social handles, videos, and ad campaign configurations that you create in your dashboard.
4.4 SmartLink visitor analytics
When someone visits a public SmartLink page, we collect the following data to provide analytics to the SmartLink owner and to protect against fraud and bot traffic:
- Device and browser information (type, model, operating system, screen resolution, language)
- IP address (used for geolocation and rate limiting, not stored in long-term analytics)
- Approximate location (country, region, city, and IP-derived latitude/longitude accurate to roughly 50-100 miles per MaxMind GeoIP2 published characteristics) — used to power audience targeting features such as “send to fans within X miles of a city.” Latitude and longitude are derived from your IP at first capture and stored once on your profile; we do not continuously track location.
- Precise location (optional, with explicit consent). After you submit a fan signup form, your browser may ask whether you wish to share your device’s GPS or Wi-Fi-derived coordinates with us. If you grant permission, we receive your approximate latitude/longitude plus an accuracy radius (typically 20-100 m on desktop, 5-30 m on mobile with GPS, up to 10 km if your device is set to share approximate location only). We use this only for (1) the artist’s audience location reports (city/region rollups) and (2) optional tour-radius targeting when the artist sends a broadcast about a local show. We do not sell or share precise location, never use it for advertising profiling, and do not associate it with categories listed in Article 9 UK GDPR (such as health, religion, or political affiliation). Lawful basis: your explicit consent under UK GDPR Article 6(1)(a) + Article 7. You can decline the browser prompt with no penalty (we fall back to the IP-derived approximate location described above), and you can withdraw consent at any time by revoking browser permission for the site or by emailing privacy@consolync.com — we will erase the lat/lng on request. California residents: precise geolocation is “sensitive personal information” under the CCPA; we honor “Limit Use of Sensitive Personal Information” requests.
- Referrer URL and UTM parameters (utm_source, utm_medium, utm_campaign, utm_content, utm_term)
- Interaction data: visit timestamps, clicks on platform buttons, time on page, scroll depth, and mouse movement (used for bot detection)
- A hashed browser fingerprint (derived from user agent, language, screen dimensions, and other attributes) used solely for bot detection and analytics accuracy
- Cookies and tracking identifiers set by Meta Pixel (fbp, fbc) when the SmartLink owner has configured Meta advertising — see Section 6
We do not use SmartLink visitor data for cross-site behavioural advertising on our own behalf. We do not build visitor profiles for resale.
4.5 Fan contact information (CRM features)
If a customer uses Consolync’s CRM features, we collect and store fan identifiers that the fan submits to the customer: email address, phone number, name, country, date of birth (optional), communication preferences, and message engagement history. The customer is the data controller for this information; we process it on their instructions.
4.6 Usage and device data (dashboard)
How you interact with the Consolync dashboard, features you use, session duration, error logs, and performance metrics. This is collected via first-party session cookies and server logs.
4.7 Payment information
Subscription and payment data are processed by Stripe. We receive limited information from Stripe (card brand, last four digits, billing country, subscription status) but never store full card numbers on our systems.
5. How we use your information
We use the information we collect to:
- Provide and maintain the Service, including SmartLink hosting, analytics, and campaign management
- Create and manage advertising campaigns on Meta on behalf of customers
- Generate audience targeting recommendations using Spotify and Meta data
- Detect and prevent fraud, abuse, and bot traffic on SmartLink pages
- Send transactional emails about your account, billing, and Service updates
- Send you news about Consolync’s launch, product updates, and offers, where you have asked us to — you can unsubscribe from these at any time
- Improve the Service and develop new features (using aggregated, de-identified data)
- Comply with our legal obligations and enforce our Terms of Service
- Respond to requests from law enforcement where legally required
6. Legal basis for processing (UK / EU GDPR)
We rely on the following legal bases under UK GDPR and EU GDPR:
- Contract: to deliver the Service you subscribed to and fulfil our obligations to you
- Legitimate interests: to prevent fraud and abuse, secure our systems, analyse and improve the Service, and operate our business, balanced against your rights
- Consent: for optional features that require opt-in, for marketing emails to people who are not existing customers, and for cookies and tracking that are not strictly necessary
- Legal obligation: to comply with tax, accounting, and law enforcement requirements
7. Meta Pixel and Conversions API
Public SmartLink pages may include Meta tracking technology — the Meta Pixel (a browser-side JavaScript tag that sets fbp and fbc cookies) and the Meta Conversions API (a server-side integration that sends event data directly from our servers to Meta) — when the SmartLink owner has connected a Meta Ad Account and Pixel to Consolync.
When these are active, Meta receives information about your visit, including your IP address, browser information, pages viewed, actions taken (such as clicking a platform button), and hashed contact identifiers (email, phone) where available. Meta uses this information to provide measurement services, target and deliver advertisements, and optimise advertising performance, both for the SmartLink owner and for Meta’s own purposes as described in Meta’s Privacy Policy (facebook.com/privacy/policy).
You can opt out of Meta’s use of tracking data for ad targeting through your Meta account settings (accountscenter.facebook.com/ads), or by using browser-level ad tracking controls and cookie preferences.
Customer responsibility for consent. If you are a Consolync customer operating a SmartLink directed at visitors in the United Kingdom, European Economic Area, or Switzerland, you are responsible for obtaining and maintaining verifiable, explicit consent from visitors before Meta Pixel and Conversions API events fire on your behalf, in accordance with Meta’s Business Tools Terms and applicable law.
8. Who we share information with
We share personal data only with the third-party service providers and recipients listed below, and only for the purposes described. We do not sell personal data. We do not use customer-provided data or Meta Platform Data to train generalised artificial intelligence or machine learning models.
Subprocessors
- Supabase — primary database, authentication, and file storage. Data hosted in the European Union.
- Vercel — application hosting and edge delivery. United States.
- Cloudflare — content delivery network, firewall, bot protection (Turnstile), and storage of waitlist consent records. United States / global edge.
- Upstash — Redis for rate limiting and distributed locks. United States.
- Stripe — subscription billing and payment processing. United States / Ireland.
- Meta Platforms, Inc. — Facebook Login, advertising campaign delivery, Meta Pixel, Meta Conversions API. United States / Ireland.
- Google — Google OAuth sign-in. United States.
- Spotify — artist metadata and audience-intelligence queries. Sweden / European Union. We do not share customer personal data with Spotify.
- Bandsintown — tour date feed for customers who enable the upcoming-shows feature. United States.
- Twilio — SMS delivery for the CRM features. United States (Ireland for EU traffic).
- SendGrid and Resend — transactional and broadcast email. United States.
- Sentry — application error monitoring. United States.
We require each subprocessor to provide adequate data protection, and we have signed data processing agreements and, where relevant, Standard Contractual Clauses with each of them.
Other disclosures
- Law enforcement and legal process: when required by law, subpoena, court order, or to report illegal content (such as CSAM reports to NCMEC).
- Business transfers: if Crew Entertainment LTD is involved in a merger, acquisition, or sale of assets, personal data may be transferred. We will notify you and update this policy.
9. International data transfers
Consolync is operated from the United Kingdom. Several of our subprocessors are based in the United States or other countries outside the UK and the European Economic Area. When we transfer personal data outside the UK or EEA, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission (Commission Implementing Decision (EU) 2021/914)
- The UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, approved by the UK Information Commissioner’s Office
- The EU–US and UK–US Data Privacy Framework, where a recipient is certified
- Your explicit consent, where no other transfer mechanism is available
Copies of the transfer mechanisms in place can be requested at privacy@consolync.com.
10. How long we keep your data
We retain personal data for the following periods:
- Customer account data: for the life of your account. Deleted within 30 days of account closure, except where retention is required by law.
- Meta Platform Data: for the duration of your Meta connection. Deleted within 30 days of disconnection or account closure.
- SmartLink visitor analytics (visits, clicks): up to 24 months, then aggregated and de-identified for historical reporting.
- Fan contact data (CRM): for as long as the customer maintains the list, or until the fan unsubscribes. Deleted within 30 days of a valid deletion request.
- Payment records: up to 7 years, as required by UK and EU financial and tax regulations.
- Waitlist and marketing contacts: until you unsubscribe, or 24 months after your last interaction with us, whichever is sooner.
- Consent records: the wording you agreed to and the date you agreed to it, kept for as long as we rely on that consent plus 12 months.
- Support and moderation logs: up to 2 years.
- Server logs and error reports: up to 90 days.
11. Your rights
Depending on your jurisdiction, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate or incomplete data
- Request deletion of your personal data (the “right to erasure”)
- Restrict or object to certain processing activities
- Receive your data in a portable, machine-readable format
- Withdraw consent at any time, where processing is based on consent
- Lodge a complaint with a data protection authority
UK residents may complain to the Information Commissioner’s Office (ico.org.uk). EU residents may complain to their national supervisory authority.
To exercise any of these rights, email privacy@consolync.com or use the data tools in your account settings. We respond to verified requests within 30 days.
12. How to delete your data
You can delete your Consolync account and associated data at any time from the account settings page at app.consolync.com/settings, or by emailing privacy@consolync.com. We will complete deletion within 30 days, except where retention is required by law.
Meta data deletion. If you delete your account from Facebook, Meta will send us a deletion request via our Data Deletion Callback endpoint. We process these requests automatically and delete Meta Platform Data associated with the request within 30 days. You can also request Meta-specific data deletion by emailing privacy@consolync.com.
Fan data deletion. If you are a fan who received a message from a Consolync customer and want your contact information removed, email privacy@consolync.com with the email address or phone number you want deleted, or reply STOP to any SMS you received.
13. Security
We protect personal data using industry-standard measures:
- All data in transit is encrypted using TLS 1.2 or higher
- Data at rest is encrypted using AES-256
- Meta access tokens are encrypted at rest using AES-256-GCM with keys held separately from the tokens themselves
- Passwords are hashed using bcrypt
- Access to production systems is restricted, logged, and subject to multi-factor authentication
- We undertake vulnerability scanning and apply security patches on a regular cadence
- In the event of a personal data breach that poses a risk to your rights, we will notify the relevant supervisory authority within 72 hours and affected users without undue delay, as required by law
14. Cookies and tracking technologies
Dashboard session cookies: the Consolync dashboard at app.consolync.com uses first-party session cookies managed by Supabase Auth to keep you signed in. These are strictly necessary and cannot be switched off.
Analytics and preferences (consolync.com): our marketing site at consolync.com may use cookies for analytics and to remember your preferences. You can manage these through the cookie banner shown on the marketing site and via your browser settings.
SmartLink pages: see Section 7 for Meta Pixel and Conversions API disclosures. A hashed browser fingerprint is used on public SmartLink pages solely for bot detection and analytics accuracy.
15. Automated decision-making
Consolync uses automated systems to detect bot traffic on public SmartLink pages (using signals such as user agent, interaction patterns, and request fingerprints) and to generate advertising audience recommendations from Spotify and Meta data. These systems do not make decisions that produce legal or similarly significant effects on individuals.
If you believe an automated system has wrongly flagged a visit as a bot and you are a visitor affected by this, email privacy@consolync.com and we will review the decision manually.
16. Children’s privacy
The Consolync dashboard is not directed to children. In the United States, we do not knowingly collect personal information from children under 13 (consistent with the Children’s Online Privacy Protection Act). In the United Kingdom, the European Economic Area, and other jurisdictions that set a higher age of digital consent, we do not knowingly collect personal information from children under 16 (or the lower age set by your local law, if applicable).
If you believe we have collected information from a child below the applicable age, email privacy@consolync.com and we will delete it promptly.
17. California residents (CCPA / CPRA)
California residents have additional rights under the California Consumer Privacy Act (as amended by the California Privacy Rights Act), including the right to know what personal information is collected, the right to delete personal information, the right to correct inaccurate personal information, the right to opt out of the sale or sharing of personal information for cross-context behavioural advertising, and the right to limit the use of sensitive personal information.
We have not sold personal information in the preceding 12 months and do not sell personal information. To submit a CCPA/CPRA request, email privacy@consolync.com. We will respond within 45 days.
18. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified by email or in-app notice, and the “Last updated” date at the top of this page will be revised. Your continued use of the Service after the effective date of any change constitutes acceptance of the updated policy.
19. Contact us
For any questions about this Privacy Policy or your personal data, contact us at:
- Email: privacy@consolync.com
- Post: Crew Entertainment LTD, Flat 32, 124 Charles Street, Leicester, England, LE1 1LB, United Kingdom
- Company number: 15908962 (registered in England and Wales)