FanStage Privacy Policy
Last updated: May 21, 2026
1. Personal Data Administrator
- The administrator of your personal data is Fan Stage Mateusz Bednarski with its registered office in Łódź, ul. Małachowskiego 90, 90-159 Łódź, NIP: 7252021896, REGON: 363999620 ("Administrator").
- In matters concerning the protection of personal data, you can contact us at: privacy@fanstage.pl.
- In general matters related to the functioning of the Service, you can write to: support@fanstage.pl.
2. Scope of the Policy
- This Privacy Policy describes the rules for processing personal data in connection with the use of the FanStage platform available at fanstage.pl, including in connection with:
- creating and maintaining a User Account,
- using community functions, such as feed, forum, friends system, or messenger,
- using voting, following artists, and other functions related to community activity,
- managing Artist Profiles and using promotional and analytical tools,
- using the FanScore system, Account levels, benefits, and referral links,
- integrating the FanStage account with external services, in particular Spotify,
- using the Service in Polish and English,
- contacting the Administrator, complaints, reporting violations, and exercising rights under the GDPR.
3. What data we process and where we get it from
- We process personal data that:
- you provide during registration or later in the Account settings,
- you generate while using the Service,
- comes from voluntarily connected external services,
- is collected automatically while using the Service,
- you provide in correspondence with the Administrator.
- Depending on how you use FanStage, we may process in particular the following categories of data:
3.1. Account and login data
- e-mail address,
- user identifier,
- password in a secured/encrypted form in accordance with accepted technical solutions,
- information about the date of registration, logins, password changes, and security settings.
3.2. Profile data
- nickname, username, profile picture, or avatar,
- profile description, visibility settings, and account preferences,
- information about rank, Account level, FanScore points, and badges,
- information about the social account, including relationships with friends or followed profiles, if a given function is available.
3.3. Service activity data
- followed artists, bands, and profiles,
- votes cast, indicated cities, saved notifications, and other Demand Signals,
- activity on the feed, forum, and in other community functions,
- messages sent via the messenger, provided they are processed as part of the functioning of the service, security, or handling reports,
- use of referral links, invitations, and the referral system,
- information about issued warnings, restrictions, blocks, or bans, if applied.
3.4. Music preferences and personalization data
- data on favorite artists independently indicated by the User, e.g., within the TOP-5 list,
- data on recommendations, interests, and behavior in the Service used to personalize content,
- data obtained from voluntary integrations with external services, in particular Spotify.
3.5. Spotify integration data
- If you voluntarily connect your Spotify account with FanStage, we may process data provided through this integration, in particular information about the most frequently listened to artists, including the Top 50 listened artists list, in accordance with the scope of authorization granted by you within Spotify. Spotify requires applications to use user data only to the extent necessary for the service to function and based on appropriate user consent.
- Based on this data, we can, among other things, better match recommendations and automatically add artist profiles you listen to most often to your followed list, if such a function is active in the Service.
3.6. Technical and operational data
- IP address,
- session identifiers and system logs,
- device type, operating system, browser type, language settings,
- data on technical errors, security, and diagnostics,
- data on the use of cookies or similar technologies.
3.7. Contact and report data
- data provided in e-mail correspondence,
- data contained in complaints, violation reports, privacy and personal data requests,
- data needed to verify identity when exercising your rights.
4. Purposes and legal bases for processing
- We process your personal data based on appropriate legal bases under the GDPR, in particular Article 6(1)(a), (b), (c), and (f) of the GDPR. The privacy policy should indicate the purposes of processing, legal bases, data recipients, storage periods, and user rights, as these are basic information requirements under the GDPR.
4.1. Performance of a contract or action prior to entering into it – Article 6(1)(b) GDPR
- We process data in order to:
- create and maintain an Account,
- enable logging into the Service,
- operate community functions, feed, forum, and messenger,
- save follows, votes, Demand Signals, notifications, and account settings,
- implement functions related to FanScore, Account levels, and benefits,
- implement personalization and recommendation functions,
- handle integration with external services, if you use it,
- handle account deletion requests, password changes, and other functions related to account security.
4.2. Legitimate interest of the Administrator – Article 6(1)(f) GDPR
- We process data in order to:
- ensure the security of the Service,
- detect abuse, fraud, attempts to manipulate voting, rankings, or the referral system,
- prevent spam, harassment, violations of the Terms, and other threats to the community,
- maintain technical logs, diagnostics, and develop the Service,
- pursue claims or defend against claims,
- conduct internal statistics and analyses regarding the development of the Platform,
- limited content personalization and community organization based on activity in the Service.
4.3. Legal obligation – Article 6(1)(c) GDPR
- We process data when necessary to fulfill legal obligations, in particular regarding:
- handling complaints,
- handling requests concerning personal data,
- fulfilling obligations towards public authorities,
- maintaining documentation required by law.
4.4. Consent – Article 6(1)(a) GDPR
- Based on your consent, we process data in order to:
- conduct traffic analytics using Google Analytics 4,
- send marketing information by e-mail or other channels outside the Service,
- use selected integrations with external services, if their activation requires your action and authorization,
- possibly share certain data with partners or action organizers to a broader extent, if such a function is launched in the future based on separate consent.
5. Is providing data mandatory?
- Providing data marked as required during registration is voluntary, but necessary to create and maintain an Account. Failure to provide them will prevent the use of functions requiring a login.
- Providing additional profile data, using Spotify integration, adding favorite artists, signing up for notifications, enabling marketing or analytical consents is voluntary. Failure to provide such data or consents does not prevent the use of the basic functions of the Service, but may limit the level of personalization, recommendations, or access to some functions.
6. Community functions, messenger, and moderation
- Content published by you on the feed, forum, in comments, or in other community places may be visible to other Users according to the settings of a given function.
- Private messages in the messenger are used for communication within the Platform. The Administrator does not constantly monitor all messages, but may access them to the extent necessary to handle reports, ensure the safety of Users, prevent abuse, or fulfill legal obligations.
- Data on warnings, blocks, restrictions, and bans may be processed to enforce the Terms, protect the community, and ensure the security of the Service.
7. Artist profiles, partners, and statistical data
- FanStage may provide artists, bands, their representatives, or other partners with selected analytical and promotional tools related to the activity of the community gathered around a given artist, event, or voting.
- Data shared to this extent is generally statistical, aggregated, or pseudonymized in nature and does not include direct identifying data, such as an e-mail address or IP address, unless explicitly informed otherwise and a separate legal basis has been obtained.
- Depending on the functionality of the campaign, a partner or Artist Profile Manager may receive, e.g., information on the number of votes, number of followers, demographic structure, locations, interest in an event, Spotify account connection in statistical terms, or a list of community activities to the extent provided by a given function.
8. Personalization and automated content matching
- FanStage may use data about your activity, followed artists, favorite performers, FanScore, community activity, and data from voluntary integrations to better match recommended artists, content, voting, profiles, and other elements of the Service.
- Such actions have the character of personalization and content segmentation. In the current model, they are not used to make decisions regarding you that produce legal effects or similarly significantly affect you within the meaning of Article 22 of the GDPR, but rather to improve the matching of functionalities and user experience.
9. Google Analytics 4 and analytics consents
- If you consent, we use Google Analytics 4 to analyze traffic and how the Service is used. GA4 should not be launched before obtaining appropriate user consent for analytics, and Google describes Consent Mode as a mechanism adapting tag operation to the user's consent status.
- If there is no analytical consent, we do not launch analytics requiring such consent or we limit its operation in accordance with accepted technical settings and applicable regulations.
10. Cookies and similar technologies
- The Service may use cookies and similar technologies in order to:
- ensure the proper functioning of the Service,
- maintain user session,
- remember preferences,
- ensure security,
- conduct analytics – solely to the extent consistent with your consent settings,
- improve the performance and development of the Service.
- Detailed information on the cookies used and consent settings may be provided in the cookie banner, preference panel, or a separate Cookie Policy.
11. Data recipients and processors
- Your data may be disclosed to entities that support us technically or organizationally in providing services. Currently, these may be in particular:
- Supabase – database infrastructure, authentication, data storage, backend services,
- Google – Google Analytics 4, only after you have given your consent,
- providers of hosting, technical infrastructure, e-mail, security, error monitoring, or tools supporting the operation of the Service,
- partners, artists, bands, or their representatives – exclusively in the scope of statistical, aggregated, or pseudonymized data and in the scope provided by a given function of the Service,
- entities authorized on the basis of legal regulations.
- The privacy policy should indicate data recipients and the scope of data transfer, as this is one of the basic information obligations of the administrator resulting from the GDPR.
12. Data transfer outside the EEA
- Some providers we use operate globally, which may involve transferring data outside the European Economic Area. This applies in particular to infrastructure or analytics providers, such as Google or cloud service providers. In this case, we apply appropriate safeguards required by law, in particular standard contractual clauses or other mechanisms provided by the GDPR.
13. Data retention period
- We store personal data for no longer than is necessary to achieve the purpose for which it was collected.
- As a rule:
- we store Account data for the period of having an active Account,
- we store data related to social activity, follows, FanScore, and account settings for the period of using the Service or until they are deleted or anonymized,
- we store data processed on the basis of consent until the consent is withdrawn or it loses its usefulness for the purpose for which it was collected,
- we store technical logs and security data for a period justified by security, diagnostic, and anti-abuse needs,
- we store data from correspondence, complaints, and reports for the period necessary to handle the matter, and then for the time required by regulations or needed to defend against claims,
- after initiating Account deletion, the account is immediately hidden, and permanent deletion of data generally occurs after 30 days, subject to data that we must continue to store based on law or legitimate interest.
14. Your rights
- You have the right to:
- access your data,
- rectify data,
- delete data,
- restrict processing,
- data portability,
- object to processing based on a legitimate interest,
- withdraw consent at any time, if the processing is based on consent,
- lodge a complaint with the President of the Personal Data Protection Office.
- To exercise your rights, you can contact us at: privacy@fanstage.pl.
- The Administrator may ask for additional information needed to confirm your identity if it is necessary for the safe processing of the request.
15. Account deletion and password change
- You can change your Account password at any time via security settings or another function provided in the Service.
- You can also initiate Account deletion at any time from the settings or by contacting the Administrator. Initiating deletion causes the Account to be immediately hidden in the Service, and after 30 days, data is generally permanently deleted, subject to cases where further processing is necessary based on law or to protect against abuse or claims.
16. Data security
- We apply appropriate technical and organizational measures to protect personal data, including authentication mechanisms, access control, infrastructure security, security monitoring, and restricting access to data to persons and entities who need it to carry out specific tasks.
17. Changes to the Privacy Policy
- The Privacy Policy may be updated in the event of changes in law, changes in Service functionality, technological changes, changes in the list of suppliers, or changes in the method of data processing.
- We may inform about significant changes through an announcement in the Service, e-mail, or in another appropriate way.
18. Contact
- Please direct any questions regarding privacy and personal data to: privacy@fanstage.pl.
- In general matters related to the operation of the Service, you can contact us at: support@fanstage.pl.