Privacy Policy
Last updated: April 2025
1. Introduction
Mystics of Sound Ltd (“Mystics of Sound”, “we”, “us”, or “our”) is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you access or use our platform, including our website, mobile applications, and any related services (collectively, the “Platform”).
Mystics of Sound Ltd is registered in England and Wales. We act as the data controller for personal information processed through the Platform. Where we act as a processor on behalf of artists or organisers, this will be made clear in the relevant service agreement.
This policy applies to all users of the Platform, including artists who create profile listings, event organisers who submit booking enquiries, fans who browse and engage with content, and any other visitors to our website. By using the Platform, you acknowledge that you have read and understood this Privacy Policy.
We may update this policy from time to time. When we make significant changes, we will notify you via email or a prominent notice on the Platform. Your continued use of the Platform after any such changes constitutes acceptance of the updated policy.
2. Data We Collect
We collect information in several ways depending on how you interact with the Platform. The categories of personal data we may collect include:
Account & Identity Information
Your full name, email address, username, password (stored as a hashed value), profile photograph, and date of birth. For artists, this also includes your stage name, biography, genre classifications, location, social media handles, and performance history.
Usage & Technical Data
Your IP address, browser type and version, operating system, device identifiers, pages visited, time spent on pages, search queries entered, features used, and referring URLs. This data is collected automatically when you use the Platform.
Booking & Transaction Data
Details of booking enquiries you submit or receive, including event dates, venues, proposed fees, performance requirements, rider details, correspondence within the Platform's messaging system, and the status and outcome of each booking.
Payment Information
Where payments are processed through the Platform, we collect billing name and address, and the last four digits of a card number for reference purposes. Full payment card details are processed and stored by our PCI-DSS compliant payment processor and are never held on our own servers.
Communications
Any messages you send to us via email, contact forms, or support channels; your responses to surveys or feedback requests; and records of customer support interactions.
Publicly Posted Content
Content you voluntarily post on the Platform that is visible to other users, including artist profile descriptions, audio samples, photographs, videos, reviews, and community posts.
We do not intentionally collect sensitive personal data (such as information about health, religion, political opinions, or sexual orientation). Please do not submit such information through the Platform. If you believe we have inadvertently collected sensitive data, please contact us at privacy@mysticsofsound.com so we can delete it promptly.
3. How We Use Your Data
We use the personal information we collect for the following purposes:
Platform Operation. To create and maintain your account, authenticate your identity when you log in, provide the features and functionality you have requested, and ensure the technical performance and security of the Platform.
Booking Facilitation. To connect artists with organisers, facilitate enquiry and negotiation processes, send booking-related notifications, manage disputes between parties, and maintain records of confirmed engagements.
Communications. To send you transactional emails (account confirmations, booking updates, password resets), service announcements, and — where you have consented — marketing communications about new features, curated opportunities, and platform news.
Platform Improvement. To analyse how users interact with the Platform, identify bugs and performance issues, conduct A/B testing, develop new features, and produce aggregated, anonymised analytics reports.
Safety & Fraud Prevention. To detect, investigate, and prevent fraudulent transactions, account abuse, spam, harassment, and other activities that violate our Terms of Service or applicable law.
Legal Compliance. To comply with applicable laws and regulations, respond to lawful requests from public authorities, enforce our contractual rights, and exercise or defend legal claims.
4. Legal Basis for Processing
If you are located in the United Kingdom or the European Economic Area, we are required to identify a lawful basis for each way we process your personal data under the UK GDPR and EU GDPR respectively.
Performance of a Contract. The majority of our processing is necessary to deliver the services you have signed up for. This includes operating your account, facilitating bookings, and providing customer support. Without this processing, we cannot provide the Platform to you.
Legitimate Interests. We process certain data to pursue our legitimate business interests, where those interests are not overridden by your rights. This includes fraud prevention and security, improving the Platform based on usage analytics, and communicating with existing users about relevant updates and features.
Consent. Where we rely on your consent — for example, for optional marketing emails or non-essential cookies — you have the right to withdraw that consent at any time without affecting the lawfulness of any prior processing. You can withdraw consent for marketing emails by clicking “unsubscribe” in any marketing email, or by visiting your account settings.
Legal Obligation. We may process your data where required to comply with a legal obligation, such as retaining financial records for tax purposes or responding to a valid court order.
5. Data Sharing
We do not sell your personal data to third parties. We do not share your personal data with third parties for their own independent marketing purposes. The following describes the limited circumstances in which we share your data:
With Artists and Organisers. When a booking enquiry is submitted, the relevant contact and event details are shared with the artist or organiser in order to facilitate the booking process. Artists' publicly listed profile information (name, biography, genres, location, media) is visible to all Platform users. Contact details are shared only with verified parties actively engaged in a booking.
With Service Providers. We engage trusted third-party companies to perform services on our behalf, including cloud hosting and infrastructure, payment processing, email delivery, analytics, and customer support tooling. These providers are contractually bound to use your data only as instructed by us and to maintain appropriate security standards.
With Payment Processors. Payments made through the Platform are processed by our third-party payment processor. Your payment card details are transmitted directly to the processor and are governed by their privacy policy. We receive only the minimum transaction information necessary to reconcile payments on our side.
For Legal Reasons. We may disclose your personal data if required to do so by applicable law, regulation, or legal process, or if we reasonably believe disclosure is necessary to protect the rights, property, or safety of Mystics of Sound, our users, or others.
Business Transfers. If Mystics of Sound is involved in a merger, acquisition, or sale of assets, personal data may be transferred as part of that transaction. We will notify users by email or prominent Platform notice prior to such transfer and before your data becomes subject to a different privacy policy.
6. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying any legal, accounting, or reporting obligations.
Account Data. We retain your account information for as long as your account remains active. If you close your account, we will delete or anonymise your personal account data within 90 days, except where we are required to retain it for legal or compliance purposes.
Post-Closure Retention. Even after account closure, we may retain certain data for up to two years to handle disputes, enforce our agreements, support investigations, or comply with legal obligations.
Booking Records. Records of confirmed bookings, including financial transaction data, are retained for seven years from the date of the transaction to comply with tax and accounting legislation in England and Wales.
Communication Records. Support correspondence and dispute-related communications are retained for up to three years after resolution.
Usage & Analytics Data. Aggregated, anonymised usage data with no personal identifiers may be retained indefinitely for Platform improvement and reporting purposes.
7. Your Rights
Depending on your location, you may have the following rights regarding your personal data. To exercise any of these rights, please contact us at privacy@mysticsofsound.com. We will respond to all verifiable requests within 30 days.
Right of Access. You have the right to request a copy of the personal data we hold about you, along with information about how we use it and who we share it with.
Right to Rectification. You have the right to request that we correct any inaccurate or incomplete personal data we hold about you. You can update much of your account information directly through your account settings.
Right to Erasure. You have the right to request that we delete your personal data in certain circumstances — for example, if the data is no longer necessary for the purpose it was collected, or if you withdraw your consent and there is no other legal basis for processing.
Right to Data Portability. Where processing is based on your consent or on a contract with you, and is carried out by automated means, you have the right to receive a copy of your data in a structured, commonly used, machine-readable format and to transmit it to another controller.
Right to Object. You have the right to object to processing based on legitimate interests, and to object to direct marketing at any time. Where you object to direct marketing, we will cease such processing immediately.
Right to Restrict Processing. You have the right to request that we restrict processing of your personal data in certain circumstances, for example while a correction or objection is being resolved.
If you are dissatisfied with our response to a data rights request, you have the right to lodge a complaint with the relevant supervisory authority. In the UK, this is the Information Commissioner's Office (ICO) at ico.org.uk.
9. International Data Transfers
Mystics of Sound is based in the United Kingdom. Where we transfer personal data to countries outside the UK or European Economic Area that do not provide an equivalent level of data protection, we take steps to ensure your data remains protected.
Transfers to the United States and other third countries are conducted under the International Data Transfer Agreements (IDTAs) approved by the UK Information Commissioner's Office, or the European Commission's Standard Contractual Clauses (SCCs) as appropriate. Where relevant, we also rely on adequacy decisions issued by the UK Secretary of State or the European Commission.
Our third-party service providers (including cloud hosting, analytics, and payment processing providers) may store or process data in data centres located outside the UK or EEA. In each case, we have performed transfer impact assessments and put in place appropriate safeguards. You may request a copy of the relevant transfer mechanism by contacting privacy@mysticsofsound.com.
10. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or the way we handle your personal data, please contact our data protection team:
We aim to respond to all privacy-related correspondence within 30 days. If your request is complex or you have made multiple requests, we may extend this period by a further two months and will inform you of the extension and the reasons for it.