Legal information

Privacy Policy

This policy explains which personal data VoteTheDJ processes, why it is processed and which rights data subjects have.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Noah Bohnwagner IT

Zur Lindenhart 2a

36129 Gersfeld (Rhön)

Germany

Email: info@votethedj.com

Represented by: Noah Bohnwagner

2. Processing overview

Depending on how VoteTheDJ is used, the following categories of data may be processed:

  • connection and device data such as IP address, time, requested URL, referrer, browser and operating system;
  • account data such as email address, internal user ID, sign-in provider and session information;
  • profile data provided by Google and Supabase when Google sign-in is used, such as name and profile image;
  • room data such as name, description, schedule, status, settings and the public room ID;
  • music data such as search terms, Spotify track ID, title, artist, album, cover image and Spotify link;
  • voting data such as a pseudonymous voter ID, requested track, vote and timestamp;
  • functional and preference data stored locally on the user's device.

We process this data to provide and secure the service, manage accounts, create and moderate rooms, search for music and display or update request lists and rankings. Depending on the processing activity, the legal basis is Art. 6(1)(b) GDPR for a contract or pre-contractual steps, Art. 6(1)(f) GDPR for our legitimate interest in a secure and functional service or, where expressly requested, Art. 6(1)(a) GDPR for consent.

There is generally no statutory obligation to provide personal data. Without data that is technically or functionally required, however, individual features such as sign-in, room creation, music search or voting cannot be provided.

3. Hosting and delivery through Cloudflare

The website is delivered through Cloudflare services. When the website is accessed, Cloudflare may process the IP address, date and time, requested resource, HTTP status, amount of data transferred, referrer and browser or device information. This is necessary to deliver content, prevent attacks, investigate errors and maintain the availability of the service.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the secure, fast and reliable delivery of the website. Technical Cloudflare logs configured for VoteTheDJ are retained for no longer than 3 days and are then deleted or anonymized, unless a specific security incident or legal obligation requires longer retention. Cloudflare may process data within its global network. Further information is available in the Cloudflare Privacy Policy.

4. Account, authentication and sign-in

Supabase Auth

Accounts and sessions are managed using Supabase Auth. This includes processing the email address, internal user ID, sign-in method, authentication credentials and session or security information. Authentication cookies maintain the session and are refreshed when necessary. The primary Supabase project and database are hosted in Ireland within the European Union. Processing is necessary to provide the organizer account and is based on Art. 6(1)(b) GDPR.

Email login link

When signing in by email link, the entered email address is transmitted to Supabase. Supabase or the email service configured there sends a time-limited sign-in message. The email address as well as delivery and security data may be processed. This sign-in method cannot be used without an email address.

Google sign-in

When “Continue with Google” is selected, the user is redirected to Google. Google receives connection data and information about the requested sign-in. After successful authentication, Google transmits the approved account data to Supabase and VoteTheDJ. This may include the email address, name, profile image, provider ID and Google account ID. Google sign-in is voluntary and alternative sign-in methods are available. The legal basis for processing initiated by VoteTheDJ is Art. 6(1)(b) GDPR. Google's own processing is described in the Google Privacy Policy.

Passkeys

Passkey sign-in uses the browser's WebAuthn functionality and the selected authenticator. The private key generally remains on the user's device or with the selected passkey provider. A public key and the technical proof required for authentication are transmitted to Supabase. Depending on the chosen operating system or passkey provider, that provider may carry out its own data processing.

5. Rooms, song requests, votes and Realtime

Signed-in organizers can create rooms. We store the owner ID, room name, description, schedule, time zone, status and visibility, request and voting settings. For public rooms, the room name, description, schedule, song requests, ranking and previously played tracks are visible to anyone who accesses the public room. Organizers should therefore not enter confidential or unnecessary personal information in room names or descriptions.

Guests do not need an account. For song requests and votes, the browser creates a random pseudonymous UUID. It is stored locally and processed with the corresponding vote to limit duplicate voting. Requested tracks, Spotify metadata and timestamps are also stored. The UUID does not directly contain a guest's name or email address, but it may still constitute personal data when combined with other information.

Changes to public request lists are sent to connected browsers through Supabase Realtime. The browser keeps a network connection to Supabase for this purpose. Connection data, the room reference and updated records are processed. Room administration, song requests and voting are based on Art. 6(1)(b) GDPR where the feature is provided at the user's request and otherwise on Art. 6(1)(f) GDPR. Our legitimate interest is a functional live request list and the prevention of misuse.

Song requests are ranked automatically by vote count and creation time. This sorting has no legal or similarly significant effect on data subjects. No further automated decision-making or profiling takes place.

6. Spotify search, metadata and cover artwork

When a user searches for music, the search term is sent to the VoteTheDJ server and from there to the Spotify Web API. When a track is selected, its Spotify ID and metadata such as title, artist, album, duration, genres, cover URL and Spotify link are processed and stored in Supabase. VoteTheDJ does not intentionally store search terms in the application database. Depending on request logging, however, a search term may temporarily appear in technical server logs, which are retained for no longer than 3 days at Cloudflare.

Cover artwork is embedded using URLs supplied by Spotify. When an image is loaded, the browser connects directly to the relevant Spotify or CDN server. The IP address, time, referrer and browser or device information may be transmitted. Processing is based on Art. 6(1)(b) GDPR where it is necessary for the expressly requested music search or room feature, and otherwise on our legitimate interest in a clear track display pursuant to Art. 6(1)(f) GDPR. Further information is available in the Spotify Privacy Policy.

7. Cookies and local storage

VoteTheDJ does not use its own analytics or advertising cookies. The following storage is used:

EntryPurposeDuration
Supabase authentication cookiesSign-in, session management and secure renewal of access credentialsUntil the session expires or according to the cookie lifetime
vtdj-voter-idPseudonymous assignment of votes and limitation of duplicate votingUntil the browser's website data is deleted
vtdj-votes-<room-ID>Local indication of which tracks have already received a vote in a roomUntil the browser's website data is deleted
votethedj:last-login-methodDisplay of the most recently used sign-in methodUntil the browser's website data is deleted

Authentication data and the pseudonymous voting ID and local voting list are used to provide expressly requested functions. Access to the user's device is therefore based on Section 25(2)(2) TDDDG. The most recent sign-in method is stored as a convenience feature. To the extent that this storage is not strictly necessary, it requires consent under Section 25(1) TDDDG. All local entries can be deleted through the browser's website data settings. This may sign the user out and may permit another vote.

8. Recipients, processors and international transfers

Personal data may be disclosed, limited to the relevant purpose, to the following recipients:

  • Cloudflare as a hosting, network, security and logging provider;
  • Supabase as the database, authentication and Realtime provider;
  • Google when Google sign-in is selected;
  • Spotify for music search and the retrieval of track metadata or cover artwork;
  • organizers and visitors to public rooms for the room and song request data visible there;
  • public authorities, courts or other bodies where disclosure is legally required.

Where a provider processes personal data on our behalf, it is engaged under a data processing agreement in accordance with Art. 28 GDPR. The primary Supabase project is hosted in Ireland. Cloudflare, Supabase, Google, Spotify or their subprocessors may nevertheless process certain data outside the European Economic Area, particularly in the United States. Such transfers take place only where an adequacy decision, appropriate safeguards such as the EU Standard Contractual Clauses or another statutory exception applies. Current subprocessor information is provided by the respective providers.

Further information: Supabase Privacy Policy, Supabase DPA, Cloudflare Privacy Policy.

9. Retention and deletion

We retain personal data only for as long as necessary for the relevant purpose:

  • account data is retained for the life of the account, subject to mandatory statutory retention periods;
  • rooms and their song requests and votes are retained until the room, queue or account is deleted;
  • saved tracks are retained until deleted by the organizer or until the account is deleted;
  • local browser data is retained until it is manually deleted by the user;
  • search data is used for the request only, while related Cloudflare request logs are retained for up to 3 days;
  • backup and security copies remain until they are overwritten during the provider's regular backup cycle.

Once the purpose no longer applies, data is deleted or anonymized unless statutory retention or evidence obligations, or the establishment, exercise or defense of legal claims, require further retention.

10. Rights of data subjects

Subject to the applicable statutory conditions, data subjects have the following rights:

  • access to personal data under Art. 15 GDPR;
  • rectification of inaccurate or completion of incomplete data under Art. 16 GDPR;
  • erasure under Art. 17 GDPR;
  • restriction of processing under Art. 18 GDPR;
  • data portability under Art. 20 GDPR;
  • objection to processing based on Art. 6(1)(e) or (f) GDPR under Art. 21 GDPR;
  • withdrawal of consent at any time with effect for the future under Art. 7(3) GDPR.

To exercise these rights, contact us using the email address above. We may request reasonable proof of identity to prevent unauthorized disclosure. Data subjects also have the right to lodge a complaint with a supervisory authority under Art. 77 GDPR, in particular in the Member State of their habitual residence, place of work or the place of the alleged infringement. A list of German authorities is available from the German Data Protection Conference.

11. Data security

VoteTheDJ uses appropriate technical and organizational safeguards, including HTTPS encryption, session-based authentication, server-side authorization checks, database Row Level Security and separation between public and account-bound access. Safeguards are reviewed in accordance with the risk and the state of the art. Absolute protection against every risk cannot be guaranteed for data transmitted over the internet.

12. Changes to this Privacy Policy

This Privacy Policy will be updated when features, service providers or legal requirements change. The version published on this page applies. Material changes will also be highlighted within the service where appropriate.

Last updated: September 9, 2026

Legal texts: General Data Protection Regulation and Section 25 TDDDG.