Privacy Policy
1. Who We Are
SINK (‘we’, ‘us’, ‘our’) operates a curated internet radio service. This policy explains what personal data we collect, why we use it, how long we keep it, and how you can exercise your rights.
2. Information We Collect
We collect the following categories of data:
- Account data — email address, display name, role, timezone, password hash, sign-in provider identifiers, account timestamps, and avatar references.
- Player preferences — volume, last station snapshot, and update time so playback can resume across devices.
- Media data — avatar metadata and storage keys for user-owned images.
- Session data — session records, client category, device label, and lifecycle timestamps. We do not store raw IP addresses or user-agent strings in session records.
- Signed-out browse data — local player and interface state stored in your browser before sign-in.
- Subscription data — internal access plan, subscription status, relevant trial or period timestamps, and, when you buy a paid plan, purchase identifiers received from our payment providers (for example an app user ID and transaction identifier) linked to your account. We never store your full card details.
- Audit and security data — records of sensitive account, privacy, admin, and editorial actions.
- Operational data — route paths, timestamps, request metadata, diagnostic logs, and performance metrics needed to secure and operate the Service.
3. How We Use Your Data
- To provide authentication, profiles, player continuity, station playback, and account settings.
- To allow signed-out browsing and keep player preferences on this device.
- To secure accounts, detect abuse, investigate incidents, and retain evidence of sensitive actions.
- To track internal subscription and access status once the plan model is finalized.
- To operate, debug, and improve reliability using logs and performance monitoring.
- To meet legal obligations and respond to data-subject requests.
We do not send marketing or product-update email unless a consent or communication-preference model is available.
4. Legal Bases
We process account, authentication, playback, and subscription data to provide the Service you request. We process security, audit, and operational data based on our legitimate interests in protecting the Service and its users.
5. Payments
When you buy a paid plan, SINK never receives or stores your full card details. In the iOS app, purchases go through Apple in-app purchase, mediated by RevenueCat, which manages your subscription and reports its status and purchase identifiers back to us. On the web, checkout and subscription billing are handled by Creem as merchant of record. We link a purchase to your account with an internal account identifier, not your payment details.
Each provider's purpose, data categories, retention, and transfer safeguards are recorded in our internal processor register and confirmed before paid plans launch.
6. Data Sharing and Processors
We do not sell your personal data. We share data only with:
- Google Cloud — hosting, database, object storage, logs, DNS, and infrastructure monitoring.
- Google, Apple, and Facebook — OAuth sign-in when you select one of them.
- Email provider — transactional password, account, and security messages when delivery is enabled.
- Error-monitoring provider (BugSink) — EU-hosted diagnostic capture of technical error reports from the web player (stack traces and app state, with personal data removed before sending) so we can detect and fix failures.
- RevenueCat — mediates Apple in-app purchases in the iOS app: it manages your subscription and shares its status and purchase identifiers (such as an app user ID linked to your account and the transaction identifier) with us.
- Creem (Armitage Labs OÜ, Estonia) — merchant of record for web checkout and subscription billing: it processes your payment and the name, email and billing details you enter at checkout, and shares subscription status back to us.
- Authorities or legal advisers — when required by law or needed to protect legal rights, users, or the Service.
7. Data Retention
- Account, profile, player, session, subscription, and avatar records are kept while your account is active.
- Deleting your account revokes sessions and deletes user-owned media, the account, and related account-owned records.
- Audit events retain compact security evidence, but direct user references are redacted after deletion.
- Operational logs and monitoring data are retained only for bounded security, reliability, and incident-response needs.
- Signed-out browser state remains on this device until browser storage is cleared.
- Subscription and payment records held by SINK last while your account is active; purchase identifiers received from payment providers are deleted or redacted with the account, and SINK never stores full card details. Separately, our web merchant of record (Creem) keeps its own billing and invoice records under Estonian accounting law for up to 7 years. That retention is a statutory obligation of Creem's, applies to records it holds rather than records we hold, and is not shortened by deleting your SINK account.
8. Your Rights
Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to processing. Signed-in users can export or request deletion from Settings; deletion requires recent password verification.
You can also contact us at privacy@sink.fm.
9. Cookies and Browser Storage
We use necessary cookies for sessions and OAuth authentication, not advertising cookies. The app uses browser storage for player state, metadata cache, theme, preferences, signed-out browsing, and short-lived interface state. Account deletion clears user-owned browser storage.
10. Security
We use encrypted connections, access controls, token rotation, rate limits, audit events, and monitoring. We do not intentionally log passwords, raw tokens, authorization headers, cookies, request bodies, signed storage URLs, or full stream URLs with query strings. No system is completely secure.
11. International Transfers
We may process data where our infrastructure and providers operate. International transfers use appropriate contractual, technical, and organizational safeguards.
12. Changes to This Policy
We may update this policy. We will notify you of material changes by email or in the Service. Continued use after changes constitutes acceptance.
13. Contact
Questions or requests about this policy should be sent to privacy@sink.fm.
