>v0.2.0-beta just dropped!
Who we are
Our website address is: https://beatshare.io.
BeatShare is an open-source project developed and maintained by a team of three software developers based in Denmark. While we operate as an independent open-source initiative and not a registered corporation, we are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) – and of course deliver a great software application.
For any privacy-related inquiries or to exercise your data rights, you can reach us through our support portal or by contacting the project leads.
Direct email: msa@beatshare.io
Support portal: https://beatshare.atlassian.net/servicedesk/customer/portals
What personal data we collect and why we collect it
We collect personal data only when it is necessary to provide our services or when you have given us your explicit consent.
Newsletter Subscriptions
- Data collected: Personal email address and IP address.
- Purpose: To send you updates, news, and marketing regarding the BeatShare software application and the beatshare.io website.
- Legal basis: Explicit consent provided via our double opt-in process.
User Accounts & Membership
- Social Login (Google): When you choose to sign up or log in using your Google Account, we receive your email address, name, and profile picture URL from Google.
- Purpose: To create and manage your user account without requiring a separate password, and to verify your identity.
- Legal basis: Necessity for the performance of a contract (providing the login functionality you requested).
Downloads & Technical Logs
- Data collected: IP address and download history (which files were downloaded and when).
- Purpose: To manage software distribution, prevent abuse of our download system, and ensure the security of our application.
- Legal basis: Legitimate interest in securing our website and managing software distribution.
Cookies
- Data collected: Session identifiers and technical preferences.
- Purpose: To keep you logged in, remember your preferences, and ensure that our subscription forms function correctly.
- Legal basis: Consent (via our cookie banner) or legitimate interest for strictly necessary cookies.
Sensitive Data
We do not collect any sensitive personal data (such as health information, political opinions, or religious beliefs).
Newsletters
When the user signs up to the newsletter, they sign up to receive any news regarding the BeatShare software application and the beatshare.io website. The user needs to confirm their newsletter sign-up by clicking on the confirmation link sent to the email they have stated.
Signing up to the newsletter requires that the user specifies their personal email. The user’s personal email and IP address will be stored in the beatshare.io database as long as the subscription is active. In accordance with GDPR, the user has the right to get insights into how their data is being stored, and also the right to be deleted completely from the database. If a user subscribed to the newsletter wants to gain insights or have their data removed, they can open a ‘Privacy enquiry’-ticket on the support portal.
The user can at any point unsubscribe from the newsletter either through the website, via their newsletter account, or on each email sent from the newsletter@beatshare.io email account. Unsubscribing from the newsletter will not delete the user’s email from the database completely. They will be marked as unsubscribed, and only be removed when we do our weekly maintenance. The user will not receive any further newsletters when unsubscribing.
Cookies
Our website uses cookies to ensure a functional and secure user experience. These include:
Newsletter
Our newsletter plugin uses cookies to manage subscription forms and improve the signup experience.
Session & Authentication
We use cookies (e.g., from Simple Membership) to keep you logged in and secure your account access.
Downloads
We use cookies (from Download Manager) to manage file downloads and ensure they function correctly.
Who we share your data with
By default, BeatShare does not share your personal data with any third-party marketing companies. However, to operate the website and provide our services, we share specific data with a few essential service providers:
Web Hosting Provider
Our hosting provider has access to our database and server logs to host the website and ensure its security. This includes your IP address and any data stored in our WordPress database (such as newsletter subscriptions).
Email Service Provider
When we send you a newsletter or a confirmation email, the data (your email address) is processed through our mail server to ensure delivery. This is handled by our hosting provider’s mail service.
Support Portal
If you open a ‘Privacy enquiry’ or support ticket, the information you provide (name, email, and description of your issue) is shared with our support system (Jira) to help us resolve your request.
Google Identity Services
When you use “Login with Google,” Google receives technical data about your interaction (such as your IP address and the fact that you are logging into beatshare.io) to facilitate the authentication. You can read more in Google’s Privacy Policy.
We do not sell or trade your personal information to outside parties.
How long we retain your data
We only keep your personal data for as long as it is necessary to fulfill the purposes for which it was collected.
Technical Logs
Server logs and IP addresses collected for security purposes (to prevent abuse and hacking) are typically stored for 60 days before being automatically overwritten or deleted.
Newsletter Data
We retain your email address and IP address for as long as your subscription is active. If you unsubscribe, your data will be marked for deletion and permanently removed from our database during our weekly maintenance cycle.
User Accounts (including Google Login)
Data associated with your user account is stored for as long as your account exists. If you choose to delete your account or request its removal, your personal information will be deleted within 30 days, unless we are legally required to keep it.
Support Tickets
Information submitted through our support portal (Privacy enquiries) is kept for up to 12 months after the ticket is closed to ensure we can provide consistent support and follow-up on previous issues.
What rights you have over your data
The user is able to delete their user account on their profile settings. The account will be deleted permanently and right away. Other conditions may apply to data such as data related to the software application (BeatShare) or the newsletter. To make sure all user data is deleted correctly, the user can open a ‘Privacy enquiry’-ticket on the support platform.
Where your data is sent
As a general rule, we strive to keep all personal data within the European Union (EU) and the European Economic Area (EEA).
Internal Storage (Self-Hosted)
The data collected through the BeatShare software application and website, including information from the Newsletter, Simple Membership, and Download Manager plugins, is stored directly on our web servers. This means that your email address, IP address, and account information are not automatically shared with or sold to third-party marketing companies.
Web Hosting
Our website is hosted by Simply.com, which maintains servers located within the EU. This ensures that your data is protected under European data protection standards.
Third-Party Services
While our core plugins store data locally on our server, some technical data (such as IP addresses) may be processed by security or maintenance tools provided by our host to protect the website from cyber threats. If we use any services that transfer data outside the EU in the future (such as external analytics or email delivery services), we will ensure they comply with the EU-U.S. Data Privacy Framework or use Standard Contractual Clauses (SCCs) to guarantee your data is safe.
Google OAuth
By using Google Login, some authentication data is processed by Google on servers that may be located outside the EU/EEA (e.g., in the United States). Google complies with the EU-U.S. Data Privacy Framework to ensure your data remains protected.
Contact information
If you have any questions or concerns regarding your privacy, you can always reach out to us through our support platform by opening a ‘Privacy enquiry’-ticket. We prioritize these tickets, so we will respond as fast as we can.
How we protect your data
As professional software developers, we prioritize the security of your personal information. We employ several measures to safeguard the data stored in the beatshare.io database:
Standardized Tools
We use well-maintained and widely-vetted WordPress plugins (such as The Newsletter Plugin and Simple Membership) to ensure that security patches are applied regularly.
Encryption
All data transmitted between your browser and our website is encrypted using industry-standard SSL/TLS (HTTPS) encryption.
Database Security
Access to the backend database where emails and IP addresses are stored is strictly limited to the core development team and protected by strong, unique credentials and 2FA.
Minimalism
We follow the principle of “Data Minimization,” meaning we only collect and store the absolute minimum information required to provide our services.
Secure Authentication
By offering Google Login, we reduce the need to store sensitive passwords in our own database, relying instead on Google’s secure authentication infrastructure.
What data breach procedures we have in place
In the unlikely event of a data breach, we have established a protocol to minimize the impact and ensure transparency:
Reporting
We encourage security researchers and users to report any vulnerabilities they find through our support portal or via email. We take every report seriously and will work to patch any issues immediately.
Monitoring
We regularly monitor our server logs and security plugins for any signs of unauthorized access.
Notification
If a breach occurs that is likely to result in a risk to the rights and freedoms of our users, we will notify the affected individuals via email and, if required by law, report the breach to the relevant data protection authorities (such as Datatilsynet in Denmark) within 72 hours of discovery.