
How Round165 handles your information.
We only collect what we need to listen to your music, release it, and talk to you about it. We do not sell your data, we do not use it for advertising, and there is no tracking or analytics anywhere on this site. If you want your data gone, ask us and it is gone.
If you send a demo: your artist name, email address, the link to your track, your Instagram handle if you give one, and anything you write in the notes.
If we accept your track: your full name, links to your music, the promotional photos and audio files you send us, licence information for any samples you used, and your answer about the release date. We need these to actually put the record out.
If you use the contact form: your name, email address, the reason you picked, your message, and any link you include.
Automatically: when someone signs in to our internal system we record the attempt, including the IP address, so we can spot and block people trying to guess passwords. We also briefly record IP addresses to stop the public forms being flooded.
Some of our tracks are given away through a download gate: you connect your SoundCloud account, we carry out the actions you agreed to — following, liking, reposting, or posting a comment you wrote yourself — and the file unlocks.
What we keep: your SoundCloud user ID, your SoundCloud username and the address of your profile picture, plus a record of which actions succeeded. If a gate asks for your email address, giving it is optional, the consent box is never ticked for you, and you can withdraw it at any time.
Your SoundCloud login: we never see or store your password. The access token SoundCloud gives us is used once, for those actions, and then immediately discarded — we sign it out at the end and never write it down. We cannot touch your account again afterwards.
We link your unlocks across different download gates. Your SoundCloud user ID is the same everywhere, so we can see that the same person unlocked several of our releases, and we use that to recognise returning listeners. This is the one place where we build a picture of an individual across our whole catalogue rather than just counting downloads on one track. If you would rather we did not, ask us and we will delete your unlock records.
Why we are allowed to: for the actions themselves and for the download, because you asked for the file and explicitly authorised them — that is the contract between us. For recognising returning listeners, our legitimate interest in knowing who our audience is. For your email address, your consent.
How long: your personal download link stops working 30 days after you unlock. The unlock record itself is kept for as long as that download gate exists, and is deleted with it. Email addresses are kept until you withdraw consent or ask us to delete them.
Mostly because you asked us to do something — consider your demo, release your music, answer your message. That is the contract between us.
For the security records, because we have a legitimate interest in keeping the system from being broken into. We only keep what that actually requires.
Where you tick a confirmation box, that is your consent, and you can take it back at any time by contacting us.
Sometimes we create an artist record from a demo, or a member of the team adds an artist we are working with. If that is you, the information came from your submission or from your own public profiles, and you have exactly the same rights over it as if you had given it to us directly. Just ask.
Nobody outside Round165, with one exception: the service that delivers our email, so that confirmations and replies actually reach you. That means your name, your email address and the content of the message pass through them.
When we fetch the artwork for a track you linked, our server asks the streaming platform for it. Your browser is not involved, so they do not learn anything about you from us.
Our servers and our backups are in the EU. Backups are encrypted.
Sign-in records: 90 days, then deleted automatically.
Internal activity records: one year, then deleted automatically.
Notifications inside the system: 90 days, then deleted automatically.
Demos, artist details, messages and release material: while we are working together and for our records afterwards. If you ask us to delete them sooner, we will.
Backups are kept on a rolling basis, so something you deleted can survive in a backup for a short while before it ages out.
A copy of what we hold about you. A correction. Deletion. A limit on what we do with it. Or a copy in a portable format so you can take it elsewhere.
Send us a message and we will sort it out. It costs nothing and we will come back to you within a month.
If you are not happy with how we handle it, you can complain to the data protection authority in your country.
Only the ones that make the site work — keeping you signed in, and remembering a device you chose to trust for two-factor authentication. No advertising cookies, no analytics, nothing from third parties. That is why we do not show you a cookie banner.
Passwords are hashed and never stored in a readable form. Two-factor secrets are encrypted. Files you send are kept in private storage and can only be reached by our team over an authenticated connection. Everyone with access to the internal system is required to use two-factor authentication.
If we change how any of this works, we will update this page. If a change really affects you, we will tell you directly.