privacy policy
last updated: april 12, 2026
what this policy covers
this privacy policy explains how setlist royalty tracker ("srt," "we," "us") collects, uses, and protects your personal information when you use our web application at setlistroyalty.com and our chrome browser extension.
data we collect
account information
email address, first name, last name, stage name, city (optional), country, and referral source (optional). collected during sign-up and onboarding.
pro affiliation
your performing rights organization (bmi, ascap, sesac, gmr, or international equivalents) and capabilities (songwriter, performer, dj, producer).
song catalog
song titles, tracked artist names, and metadata identifiers (bmi work id, ascap work id, iswc, musicbrainz recording and work ids). you enter this data manually or it is enriched automatically from musicbrainz.
performance data
discovered and confirmed live performances including event dates, venue names, venue locations, attendance estimates, and submission status. sourced from setlist.fm (crowdsourced) and serato dj history csv uploads.
usage analytics
we use posthog and vercel analytics to track anonymous product usage events (e.g., onboarding completed, scan initiated, csv exported). we use sentry for error monitoring. these tools may collect ip addresses, browser type, and device information.
how we use your data
- ·to match your songs against live performance databases and identify unreported performances
- ·to generate csv exports and auto-fill pro submission forms via the chrome extension
- ·to send you email notifications about new discoveries, expiration warnings, and account updates
- ·to enrich your song metadata with musicbrainz identifiers for better matching accuracy
- ·to improve the product based on aggregate, anonymized usage patterns
data we do not collect
- ·passwords — we use magic link authentication only
- ·payment information — srt is currently free
- ·your pro login credentials — we never access your bmi, ascap, or other pro account
- ·audio files or music recordings
third-party services
we use the following third-party services to operate srt:
- vercel — hosting and deployment
- neon — postgresql database (your data is stored here)
- resend — transactional email delivery
- setlist.fm api — crowdsourced setlist data (read-only, we do not share your data with them)
- musicbrainz api — open music metadata (read-only)
- posthog — product analytics
- sentry — error monitoring
- uptimerobot — uptime monitoring
- cloudflare — dns and email routing
we do not sell, rent, or share your personal data with advertisers or data brokers.
data retention
your account data and song catalog are retained for as long as your account is active. performance data is retained indefinitely to maintain your submission history. if you delete your account, all associated data will be permanently removed within 30 days.
your rights
you can update your profile information at any time from the settings page. you can opt out of email notifications from settings. to request a full export of your data or to delete your account, contact us at support@setlistroyalty.com.
chrome extension
the srt chrome extension communicates only with setlistroyalty.com using your api key. it reads form fields on bmi live (ols.bmi.com) to auto-fill performance data. it does not collect browsing history, inject ads, or communicate with any other server.
security
all data is transmitted over https. database access is restricted to application-level credentials. api routes are protected by session authentication and rate limiting. the chrome extension uses a per-user api key for authentication.
changes to this policy
we may update this privacy policy as srt evolves. significant changes will be communicated via email. the "last updated" date at the top reflects the most recent revision.
contact
for privacy questions, data requests, or concerns, email support@setlistroyalty.com.