Privacy
This is a translation for your convenience. The German version of this page is the binding one.
MoshMate stores as little as it can. Here is what comes up anyway, why, and how you get rid of it again.
1. Controller
Matthew Mc Gregor, Eckertstraße 30m/17A, 8020 Graz, Österreich
Email address: [email protected]
2. Visiting the site and hosting
The application runs on a server operated by netcup GmbH in Germany. Visiting it produces technically necessary server logs (IP address, time, address requested, browser identifier). They serve operation and the defence against attacks (Art. 6(1)(f) GDPR) and are deleted shortly afterwards.
Delivery goes through Cloudflare (Cloudflare, Inc., USA, and Cloudflare Germany GmbH). Cloudflare processes your IP address in order to forward the request and to fend off attacks. Standard contractual clauses are the basis for this.
3. Approximate location for “nearby”
So that the home page can show concerts in your area, Cloudflare tells us the approximate place of every request, that is the city and the country, derived from your IP address. That derivation happens at Cloudflare; the IP address itself does not reach us for this purpose, only the name of the place.
We do not store that name, do not log it and do not pass it on. It is used for the duration of one page render and then discarded. We do not process coordinates: Cloudflare could send latitude and longitude along, and we deliberately do not read those fields. There is no radius search, no map and no movement history.
The legal basis is our legitimate interest in a usable service (Art. 6(1)(f) GDPR). If you would rather not: the place only decides which list of concerts appears first. Everything stays reachable through Cities, and when signed in you can set a city yourself under Settings.
4. Account and signing in
An account stores an email address, a display name you choose, a handle and a password hash. Never the password itself in clear text. Session data is added so that you stay signed in. The legal basis is performance of the user agreement (Art. 6(1)(b) GDPR).
Signing in and sessions run on the BetterAuth software in our own database on the server named above. No external sign-in service is involved, and accounts are not passed to anybody.
5. Your entries
When you write a concert down we store the concert, your state (interested, ticket, was there), optionally a rating, a note and a photo, and the visibility you chose. You decide per entry whether it is public, only for people you follow back, or private. Only public entries appear on concert pages and on your profile.
Notes are stored verbatim and are never rephrased automatically.
There is also a diary: a free-text field where you write for yourself and can optionally tag a concert as its reference. Diary pages are private without exception. They appear nowhere in the product, are shown to nobody and their content is not analysed; the small drawings subscribers see next to a page come from a fixed word list on our own server, and the text never leaves our database. Pages can be deleted individually, are part of the data export, and are deleted with the account. The legal basis is the performance of the usage contract (Art. 6(1)(b) GDPR).
6. Photos
Photos are held at Cloudflare R2 in the EU jurisdiction, that is on servers inside the European Union. Before storing, every image is re-encoded and scaled down to at most 1600 pixels. All metadata is stripped in the process, GPS coordinates from the camera in particular. MoshMate stores no location data.
If automatic image screening is switched on, an uploaded image is sent to Sightengine (France) to be checked for prohibited content. The basis is our legitimate interest in a lawful service (Art. 6(1)(f) GDPR).
7. Voice notes
You can speak a note instead of typing it. This uses the speech recognition built into your browser. MoshMate receives and stores no audio, only the recognised text, and even that only if you save the entry. Note that some browsers, Google Chrome among them, process the recording on their maker's servers, possibly outside the EU. That is written on the button too, before recording starts. The feature only ever starts on your own action; if you do not use it, nothing is recorded.
8. Public pages and other people
A concert page shows who wrote that night down publicly. On the day of the show you can additionally signal that you are there and open to company. Only the number of people is shown, never names. There is no people search, no user list, no radius search and no arranging of company.
9. Subscription (MoshPit Pro)
For the voluntary subscription we use Stripe (Stripe Payments Europe Ltd., Ireland). Payment data such as card numbers is processed by Stripe alone; it never reaches our servers. We store the subscription status, the end of the current period and the Stripe identifier. The legal basis is performance of the contract (Art. 6(1)(b) GDPR). Stripe may also process data in the USA; standard contractual clauses are the basis for that.
10. Concert data from third parties
Dates are fetched among other things through the Ticketmaster Discovery API. No data about you flows to Ticketmaster in the process. Our server makes the request, with no reference to any individual.
11. Statistics and errors
For usage measurement we run Umami, self-hosted on our own server. Umami works without cookies and without cross-site profiles, which is why there is no consent banner for it (Art. 6(1)(f) GDPR).
Errors are collected through GlitchTip, also self-hosted. User details, cookies, headers, form contents and query parameters are stripped from error reports before they are sent; what remains is the error message and the page it happened on.
12. Emails
We send emails to confirm your address, to reset your password, and as receipts for reports and cancellations. Scaleway (Scaleway SAS, France) handles the sending, on servers inside the EU; your address and the content of the message are processed in doing so. The legal basis is performance of the user agreement (Art. 6(1)(b) GDPR). We do not send marketing newsletters.
There are also three nudge mails that relate exclusively to your own entries: a question once a night you planned has passed, a note on anniversaries of your entries, and a weekly recap of reactions (the latter only if you switch it on). Each of these can be turned off individually in settings, and each says so. The legal basis is performance of the user agreement (Art. 6(1)(b) GDPR).
13. How long things are kept
Account and entry data stay as long as the account exists. If you delete your account, the profile, entries, diary pages, follows, blocks and sessions are removed and the photos belonging to them are deleted from storage as well. Billing-relevant details of the subscription are subject to statutory retention periods.
14. Your rights
You have the right to information, rectification, erasure, restriction, data portability and objection. Two of them you can exercise yourself right away: under Settings you download your data as JSON and delete your account. Both are free and will stay free.
You can also complain to a supervisory authority. In Austria that is the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna.
15. Changes
We adjust this statement when features or providers change. The version published here is the one that applies.