▸ Version 2026-07-01 · Effective 22 July 2026

Privacy Policy

How we collect, use and protect your personal data

▸ Last Updated: July 2026

PRIVACY POLICY

This Privacy Policy explains how Music Mix Market ("Platform", "we", "us", "our") collects, uses, stores and protects your personal data when you use our website and services at musicmixmarket.com. It also explains your rights under the General Data Protection Regulation (GDPR) and Swedish data protection law.

By creating an account or using our services, you agree to the collection and use of your data as described in this policy.

1. WHO WE ARE AND HOW TO CONTACT US

Music Mix Market is operated as a Swedish-registered entity. We are the data controller responsible for your personal data.

If you have any questions about this policy or wish to exercise your data rights, contact us at:

Email: musicmixmarket@outlook.com

We aim to respond to all privacy-related enquiries within 30 days.

2. WHAT DATA WE COLLECT

We collect the following categories of personal data:

2.1 Account and profile data

When you register an account, we collect: your email address, display name, chosen role (Artist or Mixer), profile photo (if uploaded), bio text, and genre tags. This data is provided directly by you.

2.2 Identity verification data

If you register as a Mixer, we require you to complete identity verification through Stripe Connect. This process collects personal identification information and bank account details. This data is processed directly by Stripe and is subject to Stripe's privacy policy. We receive only a verification status confirmation — we do not store your bank account details or government ID on our servers.

Mixers who opt into the additional ID verification tier provide government-issued ID. This is processed by Stripe's identity verification service and is not stored on Music Mix Market's servers.

2.3 Audio files and project data

Artists upload audio files (stems, rough mixes) and associated project information (song title, genre, BPM, reference tracks, project descriptions, budget, deadline). This data is stored on our servers and in our cloud storage provider. Audio files are treated as confidential and are subject to the access controls and NDA obligations described in our Terms of Service.

2.4 Transaction and payment data

When a purchase is made, payment is processed by Stripe. We do not store payment card details on our servers. We retain records of completed transactions including: the amount paid, the date of transaction, the song title, the artist's user ID and the mixer's user ID. These records are retained for 7 years as required by Swedish accounting law (Bokföringslagen).

2.5 NDA acceptance records

We record each instance of an NDA being accepted by a mixer, including: their user ID, the song ID, the timestamp of acceptance, and the type of download (preview stems or full stems). These records are retained for the duration of any potential legal claim, which under Swedish law may be up to 10 years.

2.6 Communication data

We store messages sent through the platform's built-in messaging and revision system, including: waveform comment pins, chat messages between artists and chosen mixers, and system notifications. These are retained for the duration of the project and for 2 years after the project closes.

2.7 Usage and technical data

We automatically collect certain technical data when you use the platform, including: IP address, browser type and version, operating system, pages visited, time and date of visits, and session duration. This data is used for security monitoring, bug fixing and improving the platform. We do not use this data for advertising profiling.

2.8 Log data

We maintain security logs of account activity including login timestamps (retained for 90 days), stem download events (retained for the duration of any potential legal claim), and admin actions (retained indefinitely for audit purposes).

3. HOW WE USE YOUR DATA

We use your personal data for the following purposes, each with a corresponding legal basis under GDPR:

PurposeLegal basis
Providing and operating the platformPerformance of a contract (Article 6(1)(b))
Processing payments and payoutsPerformance of a contract (Article 6(1)(b))
Identity verification for mixersLegal obligation + legitimate interests (Article 6(1)(c) and (f))
Enforcing NDA obligations and Terms of ServiceLegitimate interests (Article 6(1)(f))
Sending transactional emails (project notifications, payment confirmations)Performance of a contract (Article 6(1)(b))
Security monitoring and fraud preventionLegitimate interests (Article 6(1)(f))
Retaining transaction records for accountingLegal obligation (Article 6(1)(c))
Improving the platform through usage analyticsLegitimate interests (Article 6(1)(f))
Responding to legal claims or regulatory requestsLegal obligation (Article 6(1)(c))

We do not use your personal data for advertising, sell your data to third parties, or use automated decision-making that produces legal or similarly significant effects.

4. WHO WE SHARE YOUR DATA WITH

We share your data only with the following categories of third parties, all of whom act as data processors on our behalf or as independent controllers where noted:

Stripe Inc. — payment processing, identity verification and Stripe Connect payouts. Stripe is an independent data controller for the data it collects during payment and verification flows. Stripe's privacy policy is available at stripe.com/privacy. Stripe may process data outside the European Economic Area under Standard Contractual Clauses.

Supabase Inc. — database hosting, authentication and file storage. Your data is stored on Supabase's infrastructure. Supabase processes data in accordance with GDPR and maintains appropriate security measures.

Resend / email service provider — transactional email delivery. We share your email address and the content of transactional notifications with our email delivery provider solely for the purpose of sending you emails you have a right to receive under our contract with you.

We do not share your data with any other third parties except where required by law, court order or regulatory authority.

5. INTERNATIONAL DATA TRANSFERS

Some of our service providers (including Stripe and Supabase) may process your data outside the European Economic Area (EEA). Where this occurs, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission. You can request information about the specific safeguards in place by contacting us at musicmixmarket@outlook.com.

6. HOW LONG WE KEEP YOUR DATA

We retain your data for the following periods:

Data typeRetention period
Account and profile dataUntil account deletion, then anonymised within 30 days
Audio files (stems, rough mixes, finished mixes)Until project deletion or account deletion, subject to active legal holds
Transaction records7 years from the date of transaction (Swedish accounting law)
NDA acceptance records10 years or until any related legal claim is resolved
Communication and message data2 years after project closure
Security logs (login activity)90 days
Stem download logs10 years or until any related legal claim is resolved
Admin audit logsIndefinitely

When a retention period expires, data is either permanently deleted or irreversibly anonymised so that it can no longer be linked to an individual.

7. YOUR RIGHTS UNDER GDPR

As a resident of the European Economic Area, you have the following rights regarding your personal data:

Right of access: you have the right to request a copy of all personal data we hold about you. You can do this at any time through the data export function in your account settings, which generates a downloadable JSON file of your data.

Right to rectification: you have the right to correct inaccurate personal data. You can update most of your profile data directly in your account settings.

Right to erasure ("right to be forgotten"): you have the right to request deletion of your personal data. You can do this through the account deletion function in your account settings. Note that certain data may be retained where we have a legal obligation to do so (see Section 6).

Right to restriction of processing: you have the right to request that we limit how we use your data in certain circumstances — for example, while you contest the accuracy of data we hold.

Right to data portability: you have the right to receive your personal data in a structured, commonly used, machine-readable format. The data export function in your account settings fulfils this right.

Right to object: you have the right to object to processing based on our legitimate interests. If you object, we will stop processing your data for that purpose unless we can demonstrate compelling legitimate grounds that override your interests.

Right to withdraw consent: where we rely on consent as a legal basis (we currently do not for any core processing), you have the right to withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

Right to lodge a complaint: you have the right to lodge a complaint with the Swedish data protection authority, Integritetsskyddsmyndigheten (IMY), if you believe we have processed your data unlawfully. IMY can be contacted at imy.se.

To exercise any of these rights, contact us at musicmixmarket@outlook.com. We will respond within 30 days. We may ask you to verify your identity before processing your request.

8. COOKIES AND TRACKING

We use only the following cookies and local storage mechanisms:

Strictly necessary: session cookies required for authentication (issued by Supabase Auth). These cannot be disabled as they are essential for the platform to function.

Functional: preferences stored in your browser (such as the selected role toggle state on the homepage). These are not tracking cookies and do not identify you to third parties.

We do not use advertising cookies, tracking pixels, or third-party analytics that share data with advertisers. We do not use Google Analytics or similar tracking services.

Because we use only strictly necessary and functional cookies, we are not required under ePrivacy law to display a cookie consent banner. We will update this section if our cookie use changes.

9. SECURITY

We take the security of your data seriously, particularly given that users upload unreleased audio content. Our security measures include:

  • All data transmitted between your browser and our servers is encrypted using TLS
  • Audio files are stored in encrypted cloud storage with access controlled by signed URLs that expire after a limited time
  • Stem files are never publicly accessible — they require authentication and NDA acceptance to access
  • Payment data is handled entirely by Stripe and never passes through our servers in unencrypted form
  • We maintain access logs for all stem downloads to support legal enforcement of NDA obligations
  • Admin access to the platform's backend is restricted and logged

In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected users without undue delay as required by GDPR Article 33.

10. CHILDREN'S PRIVACY

Music Mix Market is not directed at children under the age of 18. We do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account on our platform, please contact us at contact@musicmixmarket.com and we will delete the account and associated data promptly.

11. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. When we make material changes, we will notify registered users by email and update the "Last Updated" date at the top of this page. Your continued use of the platform after notification of changes constitutes acceptance of the updated policy. We recommend reviewing this policy periodically.

12. GOVERNING LAW

This Privacy Policy is governed by Swedish law. Any disputes relating to this policy are subject to the exclusive jurisdiction of the Swedish courts, with the District Court of Stockholm (Stockholms tingsrätt) as the court of first instance.