Legal
Privacy Policy
This Privacy Policy explains what information SpotiPaid collects, how we use it, and the choices available to you. SpotiPaid is not affiliated with or endorsed by Spotify. Spotify’s privacy practices are governed by Spotify’s own policies.
1. Information we collect
- Account and admin data — hashed admin credentials (environment passphrase hash and/or admin user password hashes); claim evidence URLs/notes you submit.
- Wallet and chain data — public wallet addresses, connection/disconnect timestamps, network labels, transaction signatures, and fee/payout ledger entries you interact with through the Service. We do not collect seed phrases, private keys, or wallet secrets. We do not silently fingerprint devices beyond standard security metadata (approximate IP / user agent) needed to protect the Service.
- Usage data — approximate IP, user agent, and rate-limit metadata needed to secure APIs.
- Reports and opt-outs — content of reports and opt-out requests, stored as integration / audit events.
- Music metadata — publicly available catalog fields (titles, artist names, artwork URLs) from catalog providers when configured. We do not collect Spotify listenership or private listening history.
2. How we use information
- Operate fee routing, claims, moderation, and payouts.
- Secure the Service (rate limits, audit logs, abuse response).
- Display protocol analytics based on SpotiPaid / on-chain activity.
- Respond to rightsholder opt-out and removal requests.
- Comply with law and enforce our Terms.
3. Sharing
We do not sell personal information. We may share data with infrastructure providers (hosting, databases), chain networks (public by design), and advisors or authorities when legally required. Public blockchain data is inherently public and outside our control once published.
4. Retention
Ledger, audit, and moderation records may be retained for operational integrity, fraud prevention, and legal compliance. Wallet connection activity records (public address, event type, timestamp, optional network) are retained for security and operations for up to 24 months, then deleted or anonymized unless a longer period is required for an active investigation or legal obligation. You may request deletion of certain account-linked personal data subject to legitimate retention needs (for example, settlement and audit records).
5. Security
Admin passphrases and passwords are stored only as strong one-way hashes (never in source or client bundles). Session cookies are HTTP-only, SameSite=Strict, and short-lived. No method of transmission or storage is perfectly secure; use strong unique credentials and protect wallet keys.
6. Your choices
- Rightsholders: submit an opt-out / removal request.
- Anyone: report abusive or impersonating content via /report.
- Disable third-party cookies/trackers in your browser as applicable; core Service cookies may still be required for admin sessions.
7. Children
The Service is not directed to children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect children’s personal information.
8. Changes
We may update this Policy by posting a new version. Material changes will be reflected by the “Last updated” date below.
Last updated: September 19, 2026