Privacy Policy
Einwilligungs-Management
Aktueller Status: Noch keine Entscheidung
Du kannst deine Einwilligung für optionales Fehler-Monitoring und Session Replay via Sentry jederzeit ändern oder widerrufen.
Last updated: 7/24/2026
1. Controller
The controller responsible for data processing on this website is:
Playlist Jungle
Paul Roggenbuck
Seesener Straße 73
10709 Berlin, Germany
Email: info@playlist-jungle.de
2. Data we process
When using Playlist Jungle, we process in particular the following personal data:
- Account data: email address, username, and role (artist/curator)
- Authentication data: session tokens, OTP hashes, OAuth credentials (Google, Spotify)
- Usage data: submissions, playlist data, ratings, messages, support tickets
- Security and log data: IP address, request ID, security events, rate-limit data
- Payment data: transaction references via Stripe (no payment instrument data stored by us)
- Curator billing data: invoice address, tax information, billing amounts, and encrypted IBAN or PayPal email address
- Spotify access tokens (stored encrypted, used only for authorised playlist operations)
- Technical device data with consent: browser information for error monitoring
- AI screening data: Spotify track ID and Spotify preview URL; Hive retrieves the publicly available audio preview and returns a technical suspicion score and screening result. Suspicion scores do not lead to a final restriction without human review.
3. Cookies and local storage
We use the following cookies and local storage mechanisms:
- Session cookie (next-auth.session-token): Technically required for login. Legal basis: Art. 6(1)(b) GDPR.
- Locale cookie (playlistjungle_locale): Stores your language preference. Technically required. Legal basis: Art. 6(1)(f) GDPR.
- Consent cookie and local storage (playlistjungle_consent_telemetry): Record your decision on optional Sentry monitoring for 12 months. Storage is based on § 25(2) no. 2 TDDDG.
- Stripe cookies: Set by Stripe during payment processing. Technically required for secure payments. See stripe.com/privacy for details.
4. Optional services (consent-based only)
Sentry error monitoring and Session Replay are activated exclusively with your explicit consent (Art. 6(1)(a) GDPR). You may withdraw consent at any time with future effect.
Error monitoring and Session Replay (Sentry): When enabled, error stack traces and technical device information are transmitted to Functional Software Inc. (Sentry, USA). With your consent, Session Replay is also activated; text and media are technically masked.
Cloudflare Turnstile is used only on forms particularly exposed to abuse. Its use is necessary to protect those forms and is based on Art. 6(1)(f) GDPR and § 25(2) no. 2 TDDDG.
5. Recipients and service providers
Depending on how the platform is used, data may be transmitted to the following service providers. Where a provider acts as a processor, an agreement under Art. 28 GDPR is required; some providers act as independent controllers for particular processing operations:
- Vercel Inc. (USA) – Hosting and serverless infrastructure. Privacy: vercel.com/legal/privacy-policy
- Supabase Inc. (USA) – PostgreSQL database. Privacy: supabase.com/privacy
- Stripe Inc. (USA/Ireland) – Payment processing. Data transfer based on SCCs and EU–US DPF. Stripe processes payment instrument data as an independent controller under PCI-DSS. Privacy: stripe.com/privacy
- Resend Inc. (USA) – Transactional emails (confirmations, notifications). Data transfer based on SCCs. Privacy: resend.com/legal/privacy-policy
- Spotify AB (Sweden) – OAuth authentication and playlist management via the Spotify Web API. Spotify processes data as an independent controller. Privacy: spotify.com/legal/privacy-policy
- Google Ireland Limited – optional login via Google OAuth. Google acts as an independent controller for this processing. Privacy: policies.google.com/privacy
- Hive AI / The Hive (USA) – technical screening of publicly available Spotify audio previews for potentially fully AI-generated music. The Spotify preview URL and the audio preview accessible through it are transmitted. Processing is based on Art. 6(1)(f) GDPR for fraud prevention and platform integrity; transfers to the USA rely on appropriate safeguards, in particular Standard Contractual Clauses where required. Results are only indicators for human review. Privacy: thehive.ai/privacy
- Functional Software Inc. (Sentry, USA) – Error monitoring and Session Replay (consent-based only, see Section 4). Privacy: sentry.io/privacy
- Cloudflare Inc. (USA) – necessary bot protection via Turnstile on forms exposed to abuse. Privacy: cloudflare.com/privacypolicy
6. Purposes and legal bases
We process personal data on the following legal bases:
- Art. 6(1)(b) GDPR (contract performance): Providing the platform, managing submissions, processing payments, curator communication.
- Art. 6(1)(c) GDPR (legal obligation): Retaining tax-relevant records for the applicable statutory periods.
- Art. 6(1)(f) GDPR (legitimate interest): Security logging, rate limiting, fraud prevention, platform stability, internal monitoring without consent.
- Art. 6(1)(a) GDPR (consent): Error monitoring and Session Replay via Sentry (revocable at any time).
7. Retention periods
We store personal data only as long as necessary for the stated purposes or as required by statutory retention obligations:
- Account and content data: Until account deletion or as long as required for contract performance. Data subject to retention duties or needed for legal claims is then restricted and deleted after the applicable period.
- Payment and invoice data: depending on the type of record, generally six, eight, or ten years under applicable tax and commercial law.
- Security logs (security events): 90 days, then automatic deletion.
- Rate-limit data: 14 days, then automatic deletion.
- Login and session cookies: until their technically defined expiry or logout; the precise duration depends on the login method used.
- Consent cookie: 12 months from your decision.
8. Your rights
As a data subject you have the following rights under GDPR. To exercise them, contact us at info@playlist-jungle.de:
- Access to your stored data (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure of your data (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability in a machine-readable format (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Withdrawal of consent with future effect (Art. 7(3) GDPR)
9. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. Based on our business address in Berlin, the Berlin Commissioner for Data Protection and Freedom of Information is particularly relevant: datenschutz-berlin.de.
10. Contact
For all privacy-related requests, access enquiries, or to exercise your rights, please contact: info@playlist-jungle.de
Version dated 10 June 2026.