Band in TourBAND IN TOUR

Privacy Policy

Last updated: May 2026  ·  Version 2.0  ·  Applies to bandintour.com and all related services

We collect only what we need to run the platform. We do not sell your data, we do not currently run advertising, we do not use third-party analytics, and you can delete your account and all associated data at any time. This policy explains exactly what we collect, why, on what legal basis, and what you can do about it.

1. Introduction

Welcome to Band in Tour. Whether you are a band, a venue, a promoter or a music fan, the respect of your privacy is important to us.

This Privacy Policy describes how Band in Tour ("we", "us", "our") collects, uses and protects your personal data when you use our platform and services. It has been written in compliance with Regulation (EU) 2016/679 ("GDPR"), Directive 2002/58/EC ("ePrivacy"), Regulation (EU) 2022/2065 ("Digital Services Act" or "DSA") and applicable Italian data-protection law (D.lgs. 196/2003 as amended by D.lgs. 101/2018).

This policy applies to personal data collected through bandintour.com and any related pages or services operated by us. It does not apply to third-party websites you may reach through links on our platform.

2. Definitions

3. Data Controller

The data controller is IOCOS di G.C. (P.IVA 02758080804), with registered office at Via F. Baracca traversa De Salvo 158, 89123 Reggio Calabria, Italy. Band in Tour is developed under the Sunakoma project; legal responsibility for processing rests with IOCOS di G.C.

Band in Tour qualifies as a micro-enterprise online platform under Article 19 of the DSA. We do not have a statutory obligation to appoint a Data Protection Officer (DPO) under GDPR Art. 37, but our designated point of contact for privacy matters and for Member State authorities is:

4. Personal Data We Collect

The data we collect depends on how you use the platform.

4.1 All visitors

4.2 Registered users (all roles)

4.3 Event data (bands, venues, promoters)

4.4 Activity data (all registered users)

4.5 Interest and recommendation data

All interest data is voluntary and can be deleted at any time from your Profile settings or by contacting us.

4.6 Membership and payment data (future)

Stripe is our designated payment provider for Pro Membership and Boost purchases. Payment processing is not yet active on the platform: no card or transaction data is currently collected. When payments go live, all card data will be handled directly by Stripe and will never transit through or be stored on our servers. We will retain only the record of the tier purchased, the associated event or subscription, the expiry date and the fiscal invoice data required by Italian tax law. This section will be updated, and where required additional consent collected, before the payment feature is activated.

5. Purposes and Legal Bases

PurposeLegal basis (GDPR Art. 6)
Creating and managing your account and profileContract performance (Art. 6.1.b)
Publishing and displaying events on the platform and mapContract performance (Art. 6.1.b)
Authenticating your session securely (JWT)Contract performance (Art. 6.1.b)
Sending service emails (account confirmation, event approval or rejection notifications)Contract performance (Art. 6.1.b)
Processing boost and membership purchases and managing membership status (when activated)Contract performance (Art. 6.1.b)
Displaying your availability to other users in the Live Music ClubContract performance (Art. 6.1.b)
Operating the report/abuse mechanism and applying moderation decisionsLegal obligation (Art. 6.1.c — DSA Art. 16/17) and contract performance (Art. 6.1.b)
Anti-abuse, rate limiting and platform securityLegitimate interest (Art. 6.1.f)
Platform analytics and improvement (aggregated, anonymised data from our own server logs only)Legitimate interest (Art. 6.1.f)
Issuing fiscal invoices and complying with accounting obligations (when payments are activated)Legal obligation (Art. 6.1.c — Italian fiscal law)
Responding to legal requests and managing disputesLegal obligation (Art. 6.1.c) / Legitimate interest (Art. 6.1.f)
Providing personalised recommendations ("Recommended for you") based on your interest preferencesConsent (Art. 6.1.a) — interests are optional and can be removed at any time
Sending the biweekly recommendations newsletter and admin newsletters (if opted in)Consent (Art. 6.1.a) — opt-out available in every email and in Profile > Settings
Optional marketing communications (if you explicitly opt in)Consent (Art. 6.1.a)

6. Recipients of Your Data

We do not sell, rent or share your personal data with third parties for commercial or marketing purposes. We do not currently transfer personal data outside the European Economic Area.

Your data may be disclosed only in the following cases:

7. Data Retention

8. Your Rights Under the GDPR

If you are located in the EU or EEA, you have the following rights regarding your personal data:

To exercise any of these rights, contact us at privacy@bandintour.com. We will respond within 30 days. We may need to verify your identity before processing the request.

You have the right to lodge a complaint with the Italian Garante per la protezione dei dati personali (garanteprivacy.it) or with the supervisory authority of your country of residence.

9. Cookies and Local Storage

We use only first-party essential technical cookies and local-storage items required to operate the platform (session management, CSRF protection, login token, consent preference). We do not currently use advertising cookies, tracking pixels or third-party analytics cookies that share data with external parties.

For full details, including the planned future activation of Google Analytics 4 and Google AdSense — which will be enabled only after a renewed consent mechanism — see our Cookie Policy.

10. Security

We apply appropriate technical and organisational measures to protect your personal data:

No system is completely immune from risk. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Italian Garante within 72 hours and, where the risk is high, communicate the breach to affected users without undue delay, as required by GDPR Art. 33 and 34.

11. Minors

Band in Tour is not directed at minors. In compliance with GDPR Art. 8 and the Italian implementing rules (D.lgs. 101/2018), users must be at least 16 years old to register on the platform. If we become aware that we have collected personal data from a minor without appropriate parental consent, we will delete it promptly. If you believe a minor has registered on our platform, please contact us at privacy@bandintour.com.

12. Third-Party Links

Profiles on Band in Tour may contain links to external websites (social media, artist websites, streaming platforms, ticket vendors). We are not responsible for the privacy practices of those third-party services. We encourage you to read their privacy policies before sharing any personal data with them.

13. Changes to This Policy

We may update this Privacy Policy to reflect changes in the law, our services or our data practices. If we make material changes — including before activating Stripe payments, Google Analytics 4 or Google AdSense — we will notify registered users by email and update the version date at the top of this page. Continued use of the platform after the effective date of changes constitutes acceptance of the updated policy.

14. Contact

For any questions, requests or concerns regarding this Privacy Policy or your personal data: