Privacy policy
Draft. This text has not yet been reviewed by a lawyer and is not final. Text in [BRACKETS] still has to be filled in.
This policy explains what personal data Dalinq processes when you use the Dalinq app (iOS and Android), open a Dalinq link, or visit dalinq.com, why we do that, and what you can do about it. We try to collect as little as possible. We do not sell personal data and we do not show ads.
1. Who is responsible
The controller for your personal data is [BEDRIJFSNAAM], registered with the Dutch Chamber of Commerce (KvK) under number [KVK-NUMMER], located at [ADRES], the Netherlands ("Dalinq", "we").
Questions or requests about privacy: [PRIVACY-E-MAIL]. We have [not] appointed a data protection officer.
2. What we process, why, and on what basis
2.1 Using the app without an account (guest)
The first time you open the app, it creates a random device ID. Linked to that ID we store: the music app you chose as your main app, the display name you enter (optional), your app language and time zone, counters for how often you shared and opened links, and when your device first contacted us.
Why: to make the app work, remember your choices, and show you your own statistics. Legal basis: performance of our agreement with you (Art. 6(1)(b) GDPR).
2.2 Your account
An account is optional. If you create one, we store your name, username, e-mail address, a hashed password (we cannot read it), and, if you add them, a profile photo and a short bio. We also store your settings, such as whether your profile is private and which notifications you want.
If you sign in with Google or Apple, we receive your verified e-mail address and, if you allow it, your name from Google or Apple. We never see your Google or Apple password. With Apple's "Hide My Email" we only receive a relay address.
E-mails. When you register with an e-mail address, we send you a message to verify it. If you forget your password, we send a reset link to your e-mail address; the reset token expires after 60 minutes. We only send these service e-mails, no newsletters or marketing.
Who sees what. Your name, @username and profile photo are always visible on your profile and on your invite page, so others can add you. If your profile is set to private, then for people who are not your friends: your name or @username is not shown as "Shared by" on your Dalinq links, you do not appear in search results or when people find friends through their contacts, and your bio, statistics, achievements and friend count are hidden. You can still be found by your exact @username and through your invite link. Friends see your full profile.
Why: to give you a profile, friends, chat and achievements across devices. Legal basis: performance of our agreement (Art. 6(1)(b) GDPR).
2.3 Songs you share and Dalinq links
When you share a song, we store the original link (for example a Spotify link), the song details (title, artist, album, artwork, ISRC code), the matching links on the other music services, which device or account shared it, and when.
Dalinq link pages are public. Anyone who has the link can open the page. It shows the song and, if known, the name or @username of the person who shared it ("Shared by"), unless that person has a private profile: then no name is shown. Only share a link with people you want to see it.
Why: creating a working link is the core of the service. Legal basis: performance of our agreement (Art. 6(1)(b) GDPR).
2.4 Share and open statistics
Every share and every open of a Dalinq link is recorded as an event: the type (share or open), whether it happened in the app or on the web, the time, the song (ISRC), the source and destination music service, the channel where we can tell (for example WhatsApp, from the app's share sheet or the referring website), the link code, whether it worked, and two coarse location fields:
- Country: looked up from your IP address with a MaxMind GeoLite2 database that runs on our own server. The IP address is only used in memory for that lookup and then dropped. We do not store IP addresses, and no IP address is sent to MaxMind.
- Language region: the region part of your browser's or device's language setting (for example "nl-NL" becomes NL). This is a language setting, not a location.
- A share is linked to the sharing device and, if signed in, the account. If you share a song you received earlier via a Dalinq link, we record which link that was (a "re-share"), and which link originally brought your device to Dalinq.
- An open in a web browser is not linked to the person opening it: we use no cookies or fingerprinting for that. It is linked to the link and its sharer, so the sharer can see that their link was opened.
- An open in the app is linked to that device and, if you are signed in, to your account.
- Link-preview bots (such as WhatsApp's) are not logged.
Why: to show you your statistics and achievements, and to understand and improve Dalinq (for example which services need better song matching and how songs spread). Legal basis: performance of our agreement for your own statistics (Art. 6(1)(b)), and our legitimate interest in measuring and improving the service (Art. 6(1)(f)). You can object, see section 7.
2.5 App use and how you found Dalinq
App opens. When the app comes to the foreground we record at most one event per device per 30 minutes: the device, your account if signed in, the platform (iOS or Android), the app version, the app language and the country (looked up as described above, without storing the IP address). We use this to count active users and how many keep using the app.
How your device found Dalinq. If you install or first open the app through a Dalinq link or an invite link, we record that once ("first touch"), only within 24 hours of your device's first contact with us: which link or invite it was, the device and account of the person who shared it, and when. On Android we read the Google Play Install Referrer for this, which tells us the Dalinq link you came from when you installed via the Play Store button on our pages. On iPhone we only know this if the app opens on that link. We do not use fingerprinting, IP matching or your clipboard for this. Self-referrals are ignored.
Why: to measure growth and which shared songs bring new people to Dalinq. Legal basis: our legitimate interest in measuring and improving the service (Art. 6(1)(f)). You can object, see section 7.
2.6 Friends and chat
If you have an account, you can add friends. We store friend requests, friendships, and how the connection was made (for example via search, an invite link or your contacts). Chat in Dalinq consists of shared songs: for each message we store the sender, the song (title, artist, artwork, link) and when it was read.
Legal basis: performance of our agreement (Art. 6(1)(b) GDPR).
2.7 Finding friends via your contacts (optional)
You can choose to add your own phone number so friends can find you. We store only a salted hash of the number (a fingerprint made with a secret key that only our server knows), never the number itself.
If you choose to search your contacts, the app sends the phone numbers from your address book to our server over an encrypted connection. The server turns each number into the same kind of salted hash, compares the hashes with those of other Dalinq users, and returns the matches. We do not store your address book; the numbers are discarded right after the comparison. Note that a hash of a phone number is pseudonymised data, not anonymous data.
Legal basis: your consent (Art. 6(1)(a) GDPR), given through the permission prompt. You can withdraw it at any time by removing your number in the app or revoking contacts access in your phone's settings.
2.8 Push notifications
If you allow notifications, we store a push token from Firebase Cloud Messaging for your device, and a record of which notifications we scheduled and sent (for example about a friend request, an achievement or a weekly challenge), so you don't get the same one twice.
Legal basis: your consent via your phone's permission prompt (Art. 6(1)(a)). You can switch notifications off in the app or in your phone's settings.
2.9 Achievements, streaks and challenges
Based on your activity we calculate achievements, levels, streaks and challenge progress, and compare them with your friends. Legal basis: performance of our agreement (Art. 6(1)(b)).
2.10 App analytics (Firebase Analytics)
The app uses Google Firebase Analytics to see how the app is used: for example which screens are opened, app version, device type, operating system and an app-instance identifier. Google derives an approximate location from your IP address but does not share the IP address with us. We do not use this for advertising.
Legal basis: [legitimate interest (Art. 6(1)(f)) or consent (Art. 6(1)(a)); have a lawyer decide. If consent is required, the app needs a consent choice before analytics starts.]
2.11 Crash reports (Sentry)
When the app crashes or hits an error, the release version sends a crash report to Sentry: the error, technical details of your device and operating system, and the app version. Crash reports are not meant to contain your name, e-mail or music. Legal basis: legitimate interest in a working, secure app (Art. 6(1)(f)).
2.12 Website and cookies
dalinq.com uses no tracking or advertising cookies and no analytics. We only use functional cookies: a cookie that remembers your language choice (lang, 1 year), and a session and security cookie (CSRF) that the web framework sets (until you close your browser or up to [2 hours]). Our hosting provider keeps web server logs with IP addresses for security and troubleshooting for [BEWAARTERMIJN-LOGS, e.g. 14 days].
2.13 Contact with us
If you e-mail us, we use your e-mail address and message to answer you, and keep them for as long as needed for that, at most [BEWAARTERMIJN-SUPPORT, e.g. 1 year]. Legal basis: legitimate interest (Art. 6(1)(f)).
3. Music services
To find a song on other services, our server looks it up at Spotify, Apple Music, Tidal, Deezer and YouTube Music using only song details (such as title, artist and ISRC), not your personal data. We also fetch catalogue details such as genre, release date and whether a song is explicit. These are about the song, not about you. When you open a song in one of these apps, that service's own privacy policy applies.
4. Who receives your data
We do not sell personal data. We use the following service providers, who process data on our behalf under a data processing agreement or their standard terms:
| Provider | What for | Location |
|---|---|---|
| [HOSTINGPARTIJ] (server hosting), managed through Ploi | Running our servers and database | [LAND, e.g. EU] |
| Google (Firebase Cloud Messaging, Firebase Analytics, Google Sign-In) | Push notifications, app analytics, sign-in | EU / USA |
| Apple (Sign in with Apple, Apple Push Notification service) | Sign-in, delivering notifications on iPhone | USA / EU |
| Sentry (Functional Software, Inc.) | Crash and error reports | [USA or EU region] |
| [E-MAILPROVIDER] | Sending e-mails such as password resets | [LAND] |
The country lookup uses a MaxMind GeoLite2 database file that we download and run on our own server; MaxMind receives no data about you. The Google Play Install Referrer is provided by Google Play on your Android device.
We may also share data when the law requires it, for example with a court order.
5. Transfers outside the EU
Some providers (Google, Apple, Sentry) may process data in the United States. We rely on the EU-US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses. [Verify per provider.]
6. How long we keep data
- Account data, friends, chat, achievements: until you delete your account.
- Guest device data: as long as the app is in use; devices inactive for [BEWAARTERMIJN-TOESTEL, e.g. 24 months] are deleted.
- Dalinq links and song details: as long as the link exists, so links you sent keep working. After account deletion they are no longer linked to you.
- Share and open events: [BEWAARTERMIJN-EVENTS, e.g. 26 months], after which they are deleted or made anonymous. On account deletion they are no longer linked to your account.
- App opens and how your device found Dalinq: [BEWAARTERMIJN-SESSIES, e.g. 26 months], after which they are deleted or made anonymous.
- Phone number hash: until you remove it or delete your account. Your contacts' numbers are not stored.
- Push token: until you switch notifications off, the token expires, or you delete the app data.
- Crash reports: [e.g. 90 days] at Sentry.
7. Your rights
Under the GDPR you have the right to access your data, to have it corrected or deleted, to restrict processing, to data portability, and to object to processing based on our legitimate interest. Where we rely on consent, you can withdraw it at any time; this does not affect processing before the withdrawal.
E-mail [PRIVACY-E-MAIL]. If you use the app without an account, include your device ID so we can find your data. We answer within one month. We may ask you to confirm your identity.
You also have the right to complain to a data protection authority. In the Netherlands that is the Autoriteit Persoonsgegevens; you can also contact the authority in your own country.
8. Deleting your account
You can delete your account in the app under Settings. This permanently deletes your account, profile, photo, friendships, chats, phone number hash, achievements and notification history. Links you shared keep working for the people you sent them to, but are no longer linked to your name. Share and open events stay only without a link to your account. You can also ask us by e-mail to delete your data.
9. Security
All traffic between the app, the website and our servers is encrypted (HTTPS). Passwords are stored hashed. Requests from the app are signed so that only the real app can use our API. Access to production data is limited to people who need it.
10. Children
Dalinq is intended for people aged [MINIMUMLEEFTIJD, suggestion: 16] and over. If you are younger, you need permission from a parent or guardian. If you believe a child has given us personal data without that permission, contact us and we will delete it.
11. Changes
We may update this policy, for example when we add features. For important changes we will let you know in the app before they take effect. The latest version is always at dalinq.com/en/privacy.
12. Contact
[BEDRIJFSNAAM] · [ADRES] · KvK [KVK-NUMMER] · [PRIVACY-E-MAIL]