Controller
Bybooth, publisher of Bybooth — legal@bybooth.app. Processing is to provide DJ-set features, subscriptions and product improvement.
Data we collect
Account: email, display name, Firebase ID, optionally Google profile photo.
Crate: briefs, track lists, notes, track IDs (Deezer, Spotify, Apple). Stored locally and/or in Firestore if you are signed in.
Payments: handled by Stripe. Bybooth keeps the Stripe customer ID, subscription status and period dates — not card numbers.
Usage: limited technical events (Firebase Analytics if enabled), error logs, anti-abuse quotas (hashed IP / session id, short retention).
Purposes and legal bases
Contract: account, sets, export, subscription.
Legitimate interest: security, fraud prevention, aggregated stats.
Consent: non-essential cookies, if any (see Cookies).
Legal obligation: invoicing and accounting retention.
Recipients
Google Firebase (auth, database, optional analytics) — transfers outside the EU under standard contractual clauses.
Stripe (payments).
Deezer, Spotify, Apple: catalog queries (search, artwork, previews). We do not send your email to those catalogs unless you explicitly connect Spotify / Apple Music.
Retention
Account and cloud crate: until you delete the account.
Local crate: until you clear site storage.
Billing data: statutory period (typically 10 years).
Technical logs: 13 months maximum.
Your rights
Access, rectification, erasure, portability, objection, restriction — legal@bybooth.app. You may also lodge a complaint with the CNIL (cnil.fr) or your local authority.
To delete the account and cloud crate, write from the account email. Local-only sets clear when you wipe site data.
Security
Firebase auth, HTTPS, per-user Firestore rules, quotas. Nothing is foolproof; report incidents to legal@bybooth.app.