Copythistune
Home
About
Pricing
FAQs
Blog
Legal

Privacy Policy

Last updated: May 28, 2026

This Privacy Policy explains what personal information Copythistune collects, why we collect it, how we use and share it, and the rights you have. It applies to the Copythistune platform at copythistune.com and any related services (the "Service"). It should be read together with our Terms of Service.

1. Who we are (data controller)

The data controller for personal information processed through the Service is Copythistune, based in Enugu State, Nigeria.

For any privacy or data-protection question, email support@copythistune.com with the subject line "Privacy Request".

2. Information we collect

Information you give us

When you create an account or use the Service we collect your name, email address, password (stored hashed), profile picture, and any payment information you submit. If you are an artist we also collect your artist name, social-media handles, music platform identifiers (e.g. Spotify ID), and any release metadata or images you upload.

Streaming-platform OAuth tokens (pre-save)

If you authorise a pre-save, we store the OAuth access and refresh tokens issued by Spotify, Apple Music, or Deezer in encrypted form, together with the streaming-service user ID associated with them. We use these only to add the relevant release to your library on the release date.

Payment metadata

When a fan sends a voluntary contribution, Flutterwave processes the payment. We receive transaction metadata (Flutterwave reference, amount, currency, status, payer email) but we do not receive or store raw card numbers or full card data.

Usage data

We automatically collect information about how you interact with the Service, including pages visited, links clicked, time spent, IP address, approximate location derived from IP, browser type, device information, operating system, and referring URLs.

Cookies and similar technologies

We use cookies, local storage, and pixels to keep you signed in, remember preferences, measure traffic, and measure advertising performance. See section 7 for details and how to control them.

3. Legal bases for processing

Under the Nigeria Data Protection Act and Regulation (NDPA/NDPR) and the EU/UK GDPR, we rely on the following legal bases:

  • Performance of a contract — to create and operate your account, generate your smartlinks, run pre-saves you set up, and process contributions
  • Legitimate interests — to keep the Service secure, prevent fraud and abuse, measure aggregate usage, improve features, and maintain backups, in each case balanced against your rights
  • Consent — for non-essential cookies and tracking pixels, for marketing emails, and for the OAuth scopes you grant to streaming services. You may withdraw consent at any time without affecting prior processing
  • Legal obligation — to keep payment records, respond to lawful requests from regulators or courts, and comply with tax or anti-money-laundering rules

4. How we use your information

  • Create, operate, and improve the Service
  • Generate smartlinks, pre-saves, bio links, and analytics for your music
  • Process voluntary fan contributions and artist payouts (via Flutterwave)
  • Authenticate you and keep your account secure
  • Send transactional emails (account, payment, pre-save, security notices) — you cannot opt out of these while you have an account
  • Send marketing or promotional emails (only with your consent, and you can opt out at any time)
  • Respond to support enquiries
  • Measure aggregate use of the Service and the performance of advertising
  • Detect, investigate, and prevent fraud, abuse, and security incidents
  • Comply with our legal and regulatory obligations

5. Who we share information with (subprocessors)

We do not sell your personal information. We share it only with the providers below, each under a contract that requires them to protect it, and only as needed to run the Service:

  • Flutterwave — processes fan-contribution payments and artist payouts
  • Koyeb — hosts the Copythistune web app, API, and background worker
  • Redis Cloud — caching and the queue used to fire pre-saves on release day
  • Spotify, Apple Music, Deezer, YouTube Music, Audiomack, Boomplay — link aggregation and (for Spotify, Apple Music, Deezer) pre-save OAuth
  • Meta (Facebook) — Meta Pixel for advertising measurement
  • Google — Google Analytics for site analytics
  • Quora — Quora Pixel for advertising measurement
  • TikTok and X (Twitter) — advertising pixels
  • Our email-delivery provider — sends transactional and marketing email on our behalf

We may also disclose information (a) to comply with a legal obligation, court order, or lawful request from a public authority, (b) to enforce our Terms of Service, (c) to protect the rights, property, or safety of Copythistune, our users, or others, or (d) in connection with a merger, acquisition, or sale of all or part of our business, in which case we will require the recipient to honour this Privacy Policy.

6. International data transfers

Some of the providers above are based outside Nigeria, including in the European Union, the United Kingdom, and the United States. As a result, your personal information may be transferred to and processed in countries with data-protection laws different from your own. Where required by law (for example for users in the EEA or UK), we rely on appropriate safeguards such as Standard Contractual Clauses, or on the vendor's adequacy or certification mechanisms.

7. Cookies and tracking

When you first visit the Service you are shown a consent banner. Essential cookies (used to keep you signed in and to remember your consent choice) are always on. Non-essential cookies and pixels (Meta Pixel, Google Analytics, Quora Pixel, TikTok and X pixels) only load after you give consent through the banner, and you can withdraw consent at any time by clearing site data or using the banner again.

We use the following categories:

  • Essential — authentication, security, and consent storage
  • Preference — remember your settings and language
  • Analytics — understand aggregate use of the Service (Google Analytics)
  • Advertising — measure ad performance and audiences (Meta, Quora, TikTok, X)

You can also block or delete cookies through your browser, but parts of the Service may stop working if you do.

8. Streaming-platform connections (pre-save)

When you authorise a pre-save we request the minimum OAuth scopes needed to add a release to your library on the release date. We store the resulting access and refresh tokens encrypted, and use them solely for that purpose. You can revoke the connection at any time from your Spotify, Apple Music, or Deezer account settings, which immediately invalidates the pre-save action.

9. How long we keep information

  • Account data — for the life of your account, plus a 30-day grace period after deletion in case you change your mind
  • Server logs and analytics — up to 24 months
  • Payment and payout records — up to 7 years, to comply with Nigerian tax and finance law
  • Pre-save OAuth tokens — until the release date fires or you revoke access (whichever is sooner)
  • Marketing-suppression list — kept indefinitely so we do not email you after you unsubscribe
  • Backups — kept on rolling cycles and overwritten in line with the periods above

10. Your rights

Depending on where you live, you have some or all of the following rights:

  • Access — request a copy of the personal information we hold about you
  • Correction — ask us to correct inaccurate or incomplete information
  • Deletion — ask us to delete your personal information, subject to legal exceptions
  • Portability — receive certain information in a structured, machine-readable format
  • Objection — object to processing based on our legitimate interests
  • Restriction — ask us to restrict processing in certain circumstances
  • Withdraw consent — at any time, for processing based on consent (without affecting prior processing)
  • Opt out of marketing — unsubscribe from marketing email at any time
  • Complain to a regulator — to the Nigeria Data Protection Commission (NDPC) for Nigerian residents, your national supervisory authority for EEA/UK residents (for example the UK ICO), or the California Privacy Protection Agency for California residents

To exercise any of these rights, email support@copythistune.com with subject "Privacy Request". We may need to verify your identity before acting on a request.

11. California residents (CCPA notice)

If you are a California resident, the California Consumer Privacy Act (CCPA) gives you specific rights. The categories of personal information we collect are: identifiers (name, email, IP address), commercial information (contribution history), internet or other electronic network activity (usage and analytics), approximate geolocation (derived from IP), and audio/visual information (profile photo and uploaded artwork).

We do not sell your personal information and we have not sold personal information in the past 12 months. You have the right to know what we collect, to request deletion or correction, and not to be discriminated against for exercising your rights. To make a request, email support@copythistune.com with subject "Privacy Request".

12. Security and breach notification

We use technical and organisational measures designed to protect your personal information, including HTTPS in transit, encrypted storage for sensitive fields such as OAuth tokens, hashed passwords, access controls, and logging. No system is perfectly secure, and we cannot guarantee absolute security.

If a personal-data breach is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority (including the Nigeria Data Protection Commission where required) within 72 hours of becoming aware of it, in line with applicable law.

13. Automated decision-making

We do not make decisions about you using solely automated means that produce legal effects on you or similarly significantly affect you.

14. Third-party services

The Service integrates with and links to third-party services including streaming platforms (Spotify, Apple Music, Deezer, YouTube Music, Audiomack, Boomplay, and others) and payment processors (Flutterwave). Those services have their own privacy policies, and we encourage you to review them. We are not responsible for the privacy practices of third parties.

15. Children's privacy

The Service is intended for users aged 18 and over. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, contact us and we will delete it.

16. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we update the "Last updated" date at the top of this page. For material changes we will give you reasonable advance notice (for example by email or an in-product notice). Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.

17. Contact us

For any question about this Privacy Policy or our data practices, contact us at:

support@copythistune.com

Copyright © 2026 copythistune|terms of service|privacy and cookies|refund policy