Privacy Policy
ଶେଷ ଅପଡେଟ୍: January 15, 2025
Introduction
Drimystic Records ("we", "us", "our") operates a global music distribution platform at drimystic.com (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
By creating an account or using our Service, you consent to the data practices described in this policy. We are committed to protecting your privacy and being transparent about how your data is used.
Information We Collect
We collect information in the following ways:
Information You Provide
- Account information: name, email address, password (bcrypt-hashed), country, and optional profile details (stage name, bio, social links).
- Release information: song titles, artist names, audio files, artwork, metadata (genre, ISRC, UPC), and royalty split configurations.
- Financial information: payout method details (PayPal email, bank account, UPI VPA), tax identification numbers, and billing address.
- Support communications: ticket subjects, messages, and any information you share with our support team.
Information Collected Automatically
- IP address, browser type, device information, and operating system.
- Usage data: pages visited, features used, time spent, and click patterns.
- Location data (country and city, derived from IP).
- Cookies and similar tracking technologies.
Information from Third Parties
- Streaming and royalty data from stores (Spotify, Apple Music, etc.) — including stream counts, revenue, and listener demographics aggregated for your releases.
- Payment verification data from our payment processors.
How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service — including distributing your music to stores and paying your royalties.
- Process transactions, manage subscriptions, and issue invoices.
- Verify your identity and prevent fraud, abuse, and unauthorized access.
- Provide customer support and respond to your inquiries.
- Send you service announcements, updates, and administrative messages.
- Aggregate stream and revenue data to display analytics in your dashboard.
- Comply with legal obligations, including tax reporting and copyright enforcement.
- Improve our Service, develop new features, and personalize your experience.
Data Retention
We retain your information for as long as your account is active or as needed to provide the Service. After account closure:
- Account data is retained for 90 days to allow for reactivation, then permanently deleted.
- Release and royalty data is retained for 7 years for tax and accounting compliance.
- Support ticket history is retained for 2 years.
- Audit logs are retained for 5 years.
You may request early deletion of your data, subject to legal retention requirements, by emailing privacy@drimystic.com.
Your Rights
Depending on your location (GDPR, CCPA, and similar laws), you have the right to:
- Access: request a copy of your personal data.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request deletion of your data ("right to be forgotten").
- Restriction: limit how we process your data.
- Portability: receive your data in a machine-readable format.
- Objection: object to processing based on legitimate interests.
- Withdraw consent: for any processing based on consent.
To exercise these rights, email privacy@drimystic.com. We respond within 30 days.
Data Security
We implement industry-standard security measures:
- Bcrypt password hashing (cost 10+).
- TLS 1.3 encryption for all data in transit (HTTPS everywhere).
- Encrypted backups with restricted access.
- CSRF tokens on all forms and API requests.
- Quarterly security audits and penetration testing.
- Strict role-based access controls for our team.
No system is 100% secure. We notify affected users within 72 hours of any confirmed data breach, in compliance with GDPR Article 33.
International Data Transfers
Your data may be processed in countries other than your own, including the United States, India, Germany, and Nigeria. When we transfer data outside the EU/EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or other lawful transfer mechanisms.
Children's Privacy
The Service is not directed to children under 13 (under 16 in the EU). We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact privacy@drimystic.com and we will delete it immediately.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email and post a notice on our website 30 days before the changes take effect. The "Last updated" date at the top of this page indicates when the policy was last revised.
Contact Us
If you have questions about this Privacy Policy or our data practices, contact us:
- Email: privacy@drimystic.com
- Mail: Drimystic Records, Attn: Privacy, 540 Music Row, Los Angeles, CA 90028, USA
- Data Protection Officer: dpo@drimystic.com