← Back to Home

Privacy Policy

Last Updated: April 2, 2026

1. Introduction

Welcome to Soundsta.sh ("we," "our," or "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

By using Soundsta.sh, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our service.

2. Information We Collect

2.1 Personal Information You Provide

We collect information that you voluntarily provide to us when you:

  • Register for an account (email address, name)
  • Subscribe to a paid plan (billing information via Stripe)
  • Contact us for support (name, email, message content)
  • Connect external storage providers (access tokens, authorization data)
  • Purchase a track through another user's store (buyer name and email are shared with the seller via PayPal as part of the payment transaction)

2.2 Automatically Collected Information

When you use Soundsta.sh, the following information is collected automatically:

  • Session cookies – set by our authentication provider (Clerk) to keep you logged in.
  • Page views and session metrics (browser type, pages visited, session duration) – collected by Google Analytics only if you have granted analytics consent.

We do not read or store IP addresses, device fingerprints, or other identifying request metadata in our own application code. Standard server and CDN infrastructure (Vercel, Cloudflare) may process IP addresses at the network level as part of routing and security, but this data is not stored or accessible to us directly.

2.3 Audio Files and Content

When you upload audio files to Soundsta.sh, we store metadata about these files (filename, size, upload date) and the files themselves. Depending on your setup, files may be stored on:

  • Soundsta.sh cloud storage – our own managed storage hosted on Cloudflare infrastructure, included with all plans within the respective storage quota. Both playlist audio files and Track Store files (uploaded via the Store feature to sell to fans) are stored on the same Cloudflare infrastructure and count together toward your plan's storage quota.
  • Google Drive or Dropbox – external storage providers you choose to connect to your account. Soundsta.sh automatically creates a dedicated "Soundsta.sh" folder in your connected account and stores only files uploaded through Soundsta.sh within that folder. Soundsta.sh does not access any files or folders outside this managed folder. When you disconnect, the managed folder and all its contents are permanently deleted from your external storage account.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • To provide, maintain, and improve our services
  • To process your transactions and manage subscriptions
  • To send you technical notices, updates, and support messages
  • To respond to your comments, questions, and customer service requests
  • To monitor and analyze usage patterns and trends
  • To detect, prevent, and address technical issues and security threats
  • To comply with legal obligations and enforce our terms

4. Third-Party Services and Storage Providers

4.1 Authentication

We use Clerk for authentication and user management. Clerk processes your account information according to their privacy policy.

4.2 Payment Processing

Subscription fees are processed securely through Stripe. We do not store your complete credit card information on our servers.

Track Store purchases are processed through PayPal. When you buy a track from a user's store, your payment details (including name and email) are handled directly by PayPal and shared with the seller as part of the transaction. Soundsta.sh does not access or store buyer payment credentials. PayPal's own privacy policy governs how they process that data.

4.3 External Storage

When you connect Google Drive or Dropbox, Soundsta.sh uses OAuth authorization to create and manage a dedicated "Soundsta.sh" folder in your connected account. Access is strictly limited to this managed folder — we do not browse, read, or modify any other files or folders in your external storage. Their respective privacy policies apply.

4.3.1 Dropbox

When you choose to connect your Dropbox account, Soundsta.sh requests the following OAuth permissions:

  • Account info (read) – to confirm your identity and verify the connection is active.
  • File metadata (read) – to list and display audio files stored within the dedicated Soundsta.sh folder in your Dropbox account.
  • File content (read) – to generate secure temporary links that allow your audio files to be streamed and shared within Soundsta.sh.
  • File content (write) – to upload audio files directly to your chosen Dropbox folder when you use the upload feature.
  • Offline access – to obtain a refresh token so the connection remains active without requiring you to log in to Dropbox on every visit.

What we do NOT do with your Dropbox data: We do not read, copy, store, or process any Dropbox files or metadata other than what is strictly necessary to provide the features described above. We do not share your Dropbox data with any third party. Non-audio files in your Dropbox are never accessed.

Token security: Your Dropbox access and refresh tokens are encrypted at rest using AES-256-GCM before being stored in our database. They are decrypted only when needed to make an API call on your behalf.

Retention and deletion: Your Dropbox tokens and all associated cached metadata are stored only for as long as you keep Dropbox connected. When you disconnect Dropbox from your account settings, the managed "Soundsta.sh" folder and all audio files it contains are permanently deleted from your Dropbox account. Your access token is then immediately revoked via the Dropbox API and permanently deleted from our database. No residual Dropbox data is retained.

Your control: You can disconnect Dropbox at any time from the Storage section of your account settings. You may also revoke Soundsta.sh's access directly from your Dropbox account's Connected Apps page at dropbox.com/account/connected_apps.

4.3.2 Google Drive

When you choose to connect your Google Drive account, Soundsta.sh requests the following OAuth permission:

  • Google Drive (file-level access – drive.file scope) – limited to files and folders created by Soundsta.sh within your Drive. This allows Soundsta.sh to automatically create a dedicated "Soundsta.sh" folder, upload audio files to it, read file content and metadata for playback and sharing, and delete files when you explicitly remove them from your library within Soundsta.sh. No access to any pre-existing files or folders in your Drive is granted.

What we do NOT do with your Google Drive data: We do not read, copy, store, or process any Google Drive files or metadata beyond what is strictly necessary for the features described above. We do not share your Google Drive data with any third party. Non-audio files in your Drive are never accessed. Deletion only occurs when you explicitly trigger it within Soundsta.sh.

Token security: Your Google OAuth refresh token is encrypted at rest using AES-256-GCM before being stored in our database. It is decrypted only when needed to make an API call on your behalf. We do not store your Google account password or any other Google credentials.

Retention and deletion: Your Google Drive refresh token and all associated cached metadata are stored only for as long as you keep Google Drive connected. When you disconnect Google Drive from your account settings, the managed "Soundsta.sh" folder and all audio files it contains are permanently deleted from your Google Drive. Your refresh token is then immediately revoked via Google's OAuth revocation endpoint and permanently deleted from our database. No residual Google Drive data is retained.

Your control: You can disconnect Google Drive at any time from the Storage section of your account settings. You may also revoke Soundsta.sh's access directly from your Google account's permissions page at myaccount.google.com/permissions.

4.4 Cloudflare (Soundsta.sh Storage Infrastructure)

Files uploaded to Soundsta.sh's own storage are hosted on Cloudflare infrastructure. Cloudflare acts as a data processor on our behalf and their data processing terms apply.

4.5 Analytics

We use Google Analytics to understand how users interact with the service. Currently, Google Analytics tracks page views and standard session metrics (session duration, device type, approximate location). Google Analytics may set cookies to distinguish returning visitors.

All data collection requires your analytics consent and can be withdrawn at any time via cookie settings. When consent is not granted, Google Analytics operates in consent-denied mode and does not set tracking cookies or collect identifiable data.

4.6 Advertising and Marketing

We use Meta Pixel (Facebook Pixel) to measure the effectiveness of our advertising campaigns and to build audience segments for ads on Meta platforms (Facebook, Instagram). Currently, Meta Pixel tracks only page views (PageView event) once marketing consent has been granted.

This service only activates after you explicitly grant consent for marketing cookies. You may withdraw consent at any time via cookie settings, at which point Meta Pixel is revoked and stops sending data to Meta.

4.7 Track Store and PayPal

Soundsta.sh provides a Track Store feature that allows eligible users ("sellers") to sell audio tracks to buyers. When a buyer completes a purchase, the transaction is processed exclusively through PayPal. As part of that payment flow, PayPal shares the buyer's name and email address with the seller to fulfill the order (e.g., to issue a download token). Soundsta.sh does not receive, store, or process buyer payment card data. Purchase metadata (such as transaction IDs, timestamps, and download token status) is stored in our database solely to facilitate delivery and detect misuse. PayPal's privacy policy governs the collection and use of payment information during checkout.

5. Data Sharing and Disclosure

We do not sell or rent your personal information. We may share your information in the following circumstances:

5.1 Service Providers

We share information with third-party service providers who perform services on our behalf, including hosting, authentication, payment processing, and analytics.

5.2 Legal Requirements

We may disclose your information if required by law or in response to valid legal requests (subpoenas, court orders, government investigations).

5.3 Business Transfers

If Soundsta.sh is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.

5.4 Shared Audio Links

When you share audio files via Soundsta.sh's sharing feature, recipients can access those files according to the sharing settings you configure (time limits, download permissions, etc.).

6. Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit (HTTPS/TLS)
  • Secure authentication through Clerk
  • Regular security assessments and updates
  • Access controls and authentication requirements
  • Encrypted storage for sensitive data

However, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security of your information.

7. Data Retention

We retain your personal information for as long as necessary to provide our services and fulfill the purposes outlined in this Privacy Policy. Specifically:

  • Account information: Retained while your account is active
  • Audio files: Retained according to your subscription plan and storage settings
  • Usage logs: Typically retained for 90 days
  • Billing records: Retained for tax and legal compliance (typically 7 years)

When you delete your account, we will delete or anonymize your personal information within 30 days, except where we are required to retain it for legal purposes.

8. Your Privacy Rights

Depending on your location, you may have the following rights:

8.1 Access and Portability

You can request access to your personal information and receive a copy in a portable format.

8.2 Correction

You can update or correct your personal information through your account settings.

8.3 Deletion

You can request deletion of your personal information by deleting your account.

8.4 Opt-Out

You can opt out of marketing communications at any time.

8.5 Data Protection Rights (GDPR)

If you are in the European Economic Area (EEA), you have additional rights including the right to object to processing, restrict processing, and lodge a complaint with a supervisory authority.

8.6 California Privacy Rights (CCPA)

California residents have the right to know what personal information we collect, request deletion, and opt out of the sale of personal information (which we do not do).

9. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to track activity on our service and hold certain information. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. You can also manage your cookie preferences at any time via the cookie settings on our website.

We use the following types of cookies:

  • Essential cookies: Required for the service to function (authentication, session management). Cannot be disabled.
  • Authentication cookies: To keep you logged in across sessions (provided by Clerk).
  • Preference cookies: To remember your settings such as theme preferences.
  • Analytics cookies: Google Analytics cookies that help us understand how you use our service (e.g., pages visited, session duration). Only active after you grant analytics consent.
  • Marketing cookies: Meta Pixel (Facebook) cookies used to measure ad campaign performance and build audiences for advertising. Only active after you grant marketing consent.

All non-essential cookies (analytics and marketing) are disabled by default. They are only activated after you explicitly accept them via our cookie consent banner.

10. Children's Privacy

Soundsta.sh is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you become aware that a child has provided us with personal information, please contact us, and we will take steps to delete such information.

11. International Data Transfers

Your information may be transferred to and maintained on servers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ. By using Soundsta.sh, you consent to the transfer of your information to these locations.

12. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. You are advised to review this Privacy Policy periodically for any changes.

Changes to this Privacy Policy are effective when they are posted on this page. Continued use of the service after changes are posted constitutes your acceptance of the revised policy.

13. Contact Us

If you have any questions about this Privacy Policy, please contact us: