Privacy

Your information and your choices.

Who we are

Groovedesk is operated by 9516-8555 Québec Inc. (Mega Labs Industries), 1619 William, Suite 201A, Montreal, QC H3J 1R1, Canada. We decide how the information described here is used, which makes us the controller of it.

Our privacy officer is Francis di Stasio. Reach him at contact@groovedesk.io or at the postal address above. That is the only address you need for anything on this page, and it is monitored.

Because we offer this waitlist to people in the European Union and the United Kingdom without being established there, we are required to have a representative in each. We have engaged DataRep for both. Their appointment is being completed and we will publish their names and addresses here as soon as it is. Until then, write to contact@groovedesk.io and we will handle your request ourselves.

What this notice covers

Three things, and they work differently:

  • This website and the waitlist — joining the list, the emails we send you, and the referral offer.
  • The Groovedesk application — your account, and the work your team does inside a workspace.
  • Calls you book with us — the conversation and the notes we take from it.

One distinction matters throughout. For your account and for how you use the app, we decide what happens to the information, so you deal with us. For the work your team puts inside a workspace, the company that owns that workspace decides, and we act on its instructions. If you want that content corrected or removed, your workspace owner is the person who can tell us to do it. We will help them, and we will point you to them if you write to us instead.

What we collect

When you join the waitlist

When you join, we collect your name, email address, company, team size and your email permission, including when and how you gave it.

We record signup time, email delivery and opt-out status, referral activity, and campaign information included in the link you followed. Spam checks process your IP address and request details; referral checks store a hashed IP signal. Our hosting provider keeps short-term server logs that can include IP addresses and request details; these are kept for up to 30 days.

If you later create a Groovedesk account using the same email address, we link your waitlist record to that account and record when that happened. We use that to give you the trial length you earned and to know that your place on the list has been taken up.

When you use the application

Your account. Your name, email address and password. The password is stored hashed, which means we cannot read it. If a workspace invited you, the invitation record with your email address.

What your team puts in Groovedesk. Releases, tasks, marketing plans, files you upload, and anything typed into the app. Uploaded files are scanned for viruses.

Identity details in artist and team records. Some of what music teams need to track is genuinely sensitive: passport numbers, nationality, place and date of birth, tax identifiers and home addresses, used for touring, travel and payment. These fields are encrypted where they are stored, they are excluded from analytics, and the parts of the screen that show them are blocked from session recordings rather than merely hidden.

How you use the app. Which screens you open, which features you use, and errors the app runs into. We do not record general page views, individual clicks, or console output. Your IP address is discarded before usage data is stored.

Session replays. In some parts of the app, a recording of how the screen changes as you use it. Everything you type and all text on screen is masked, so a replay shows layout, navigation and interaction rather than your content. We use them to find bugs and to see where the app is confusing, and only the Groovedesk team can watch them. Replay can be switched off for a whole workspace.

Voice clips. If you use dictation, the audio is sent for transcription and the text comes back into the field you were filling in. The audio is not stored, by us or by the service that transcribes it. What you then save is kept like anything else you type.

We do not ask for payment details on the waitlist, and we do not ask anyone for government identifiers, or any special category of information such as health or biometric data, for our own purposes. Please do not send us those.

Why we use it, and our legal basis

Where data protection law requires us to name a legal basis, these are the ones we rely on:

  • Your consent — sending you waitlist updates, early-access invitations and Groovedesk product news, and setting optional analytics or marketing cookies. In the application, consent also covers product analytics that remember your browser and session recording. You can withdraw consent at any time, and withdrawing it does not affect anything we did beforehand.
  • Performing our contract with you — running the application for you and your workspace, keeping your account working, and taking payment for a subscription.
  • Our legitimate interests — keeping your place on the list, preventing spam and referral abuse, keeping the website and the application secure, measuring campaign interest, understanding which parts of the product work, and reviewing company and team information so founders can follow up where it is relevant. We balance these against your interests, and you can object.
  • Our legal obligations — keeping the minimum record needed to honor an opt-out, to show that permission was given, and to keep billing records for as long as tax law requires.

We use feedback and signup information to improve our website, product and customer experience. Joining the waitlist does not create an app account, subscription, payment method or running trial. We do not email people you refer unless they sign up themselves.

If you choose not to provide it

Every field on the signup form is needed to add you: the email address so we can contact you about your place, and your name, company and team size so we can prepare relevant early access and decide invitation order. If you would rather not provide them, please do not join the waitlist — you can email us instead, and you can still read the whole website.

In the application, your name and email address are needed to have an account at all. Dictation and session replay are not: dictation only runs when you choose it, and replay can be switched off for your whole workspace.

Cookies and choices

Analytics and marketing cookies are optional, separate choices, and rejecting them does not affect joining the waitlist. Whether they start on or off depends on where you are. In the European Economic Area, the United Kingdom, Switzerland and Quebec, both start off, and nothing optional loads until you turn it on. We do the same whenever we cannot tell where you are. Elsewhere, both start on, and you can turn either off at any time. If your browser sends a Global Privacy Control signal, marketing starts off wherever you are. You can change your choices at any time using “Privacy choices” on this page or “Cookie settings” in the footer.

To choose the right starting point, our server estimates your country, and in Canada your province, from your IP address, using a location database it holds itself. Nothing is sent to anyone else for this, and the result is not stored. This product includes GeoLite Data created by MaxMind, available from https://www.maxmind.com.

Necessary browser storage remembers that choice and keeps your private waitlist session. Our spam check loads only when you submit the form. If you remove tracking permission, the page reloads to stop tags that are already running. Where browser storage is available, form entries are kept briefly in this tab across that reload and then removed.

When they are on, analytics measures visits and waitlist actions, and marketing partners measure campaigns and recognize visits. We exclude form answers, names, email addresses and private unsubscribe links from website analytics events. Your signup still counts in our own waitlist reports if you reject cookies.

The application asks separately. Product analytics that remember your browser, and session recording, do not start until you answer. Saying no thanks stops all of it in your browser, and you can change your mind in your account settings. Accepting the app’s terms is not that consent, and refusing does not limit your access to the product.

A small amount of information about how the product is used reaches us from our own servers rather than your browser, and turning the browser choice off does not stop it, because it is how we keep the service working and know what to fix. It uses an internal account identifier and a fixed list of events, never what you type. If you would rather we did not include you in it, write to us and we will stop it for your account.

Who else sees it

For the website and the waitlist we use Railway for hosting, our own application backend for signup records, Resend for email, Copper for founder follow-up, and Cloudflare Turnstile for spam protection. Cloudflare explains what the spam check collects in its Turnstile Privacy Addendum. When optional cookies are on, we also use Google Tag Manager, and tags can include Google Analytics, Google Ads, Meta, LinkedIn and X. If you book a call with us, that runs through Google Calendar appointment scheduling, and Notion transcribes the call.

For the application we use Railway for the app server and database, Tigris for the files you upload, Vercel to serve the app itself, PostHog for product analytics and session recordings, Groq to transcribe dictation, and OpenRouter to route marketing-plan generation to a model provider, currently OpenAI. Resend sends account email such as address verification.

Our hosting, backend, file storage, email, CRM, spam-check, transcription and analytics providers act on our instructions and may not use your information for their own purposes. We have a written data processing agreement with each one. Advertising partners are the exception: when marketing cookies are on, they also use what they receive for their own advertising business, not only for ours. That is why marketing is a separate choice that you can turn off on its own. We will update this list before adding a provider.

The AI features specifically. Marketing-plan generation sends the text it needs to OpenRouter, which passes it to the model provider. Dictation sends your audio to Groq. Both only run when you ask for them. Neither the router nor the model provider may use what we send to train their models, we have chosen settings that exclude providers who would, and the transcription service is configured to keep nothing at all. The model provider keeps a short abuse-monitoring log for up to 30 days. Generated plans are drafts and can be wrong; check them before you act on them.

We do not sell your personal information for money, and we never will. When marketing cookies are on, advertising partners receive information in a way that some United States state privacy laws describe as “sharing” or as “targeted advertising.” You can switch that off at any time in “Privacy choices” or “Cookie settings” in the footer, and a Global Privacy Control signal from your browser keeps it off.

We may also disclose information if the law requires it, or to establish or defend a legal claim.

If you book a call

We transcribe calls booked through this website so we can take accurate notes and follow up properly. No audio recording is made. We tell you at the start of the call, and you can ask us not to transcribe it — the call goes ahead either way. Canadian law lets a participant record a conversation they are part of, but we ask anyway, because being transcribed should be your choice and not a surprise.

A call covers more about your work than the signup form does: how your label operates, what you are planning, who you work with. We use the transcript and the notes to follow up with you and to understand what music teams need. We do not use them to advertise to you, and we do not share them outside Groovedesk.

We do not keep a recording of your voice. Our notetaker transcribes the call, writes up the notes we need, and then deletes the transcript. What we keep is our own summary. Transcription runs through Notion, in the United States, and Notion uses OpenAI and Anthropic to process the text. Our agreement with Notion only lets them and their providers use it to run the service for us, and not for anything of their own.

Where your information goes

We are based in Quebec, and our providers process information in other countries. Email delivery and founder follow-up are handled in the United States, spam protection runs on a global network, and our hosting runs in the United States. When analytics or marketing cookies are on, those providers are in the United States too. For the application, the app server, database and uploaded files are in the United States, product analytics and session recordings are in the European Union, and dictation and marketing-plan generation are processed in the United States.

When we move information out of the European Economic Area, the United Kingdom or Quebec, we rely on the European Commission’s Standard Contractual Clauses, the United Kingdom Addendum, or a country the relevant authority has recognized as offering comparable protection. The privacy impact assessment that Quebec law requires before personal information is sent outside Quebec is complete and retained. You can ask us for a copy of the safeguards we rely on.

How long we keep it

We keep your information while we still need it for the reasons above, and no longer. In practice that means:

The waitlist

  • Members on the list — kept while you are on the list and we are still sending you the updates you asked for.
  • If you unsubscribe, or we can no longer reach you — your signup record is deleted within 30 days. That includes addresses that bounce and people who report our email as spam. We keep only your email address and the fact that you opted out, because we need that to honor your choice.
  • If you have unused referral days — we keep the minimum record needed to honour them, even after you unsubscribe, because we promised them to you. We delete it once those days are added to your trial, or after the 24-month period below if you never take up your invitation. This is the only reason we keep a waitlist record after you opt out.
  • If you stop engaging entirely — if we have been emailing you and you have not opened or clicked anything for 36 months, we delete your record. If we have not been sending you email, we do not count that against you, so this can mean we keep your record for longer.
  • If the waitlist ends for you — once Groovedesk has launched, if you have not taken up your invitation we delete or anonymize your record after 24 months.

Your account and your workspace

  • While your account is open — kept for as long as you have one.
  • If you close your account — closing it ends your access. It does not by itself erase what is stored, because the ordinary reason people write to us afterwards is to ask for it back. We keep the account so support can reopen it for 12 months, then review it and erase the account identity unless there is a specific reason to keep particular details, which we write down along with the date we will look at it again.
  • If you want your information erased sooner — write to us and we will assess the request when it arrives rather than on a fixed schedule, and tell you what we can and cannot remove.
  • Work inside a shared workspace — stays with the workspace, because it belongs to the company that owns it rather than to any one person. Removing you from a workspace does not delete the releases and tasks the team worked on together.
  • Billing records — kept for as long as tax law requires, which is longer than the account itself.

Everything else

  • Calls you booked — no audio recording is kept at all, and the transcript is deleted once we have written our notes. We keep our own summary of what we discussed.
  • Security and server logs — kept by our hosting provider for up to 30 days, then deleted.
  • Website analytics, when they are on — Google Analytics keeps the events from your visit for 2 months, and the identifier that links your visits together for 14 months, counted from your last visit rather than your first. If analytics stays off, none of this is collected.
  • Product analytics in the application — usage events are kept for up to 7 years and session recordings for 30 days, by the analytics provider.
  • Database backups — a copy of the database is taken daily and six are kept, so a backup is about six days old at most before it is overwritten.

Every deletion above runs automatically, on a schedule. The two analytics periods are the exception: those are settings inside Google’s own product, so Google applies them rather than our system. When we delete your record we also delete the copies held by our email provider and our CRM. Anonymized information — counts and trends that can no longer identify you — can be kept for our own research afterwards.

Backups are worth being plain about. When we erase something it goes from the live system straight away, but a backup taken before that still holds it. We do not edit backups: they are overwritten on the cycle above. So erasing something reaches every copy within about a week, not the same afternoon.

Your rights

Depending on where you live, you can ask us to give you a copy of your information, correct it, delete it, restrict how we use it, or send it to you or another organization in a portable form. You can withdraw permission at any time, and you can object to uses based on our legitimate interests.

Email contact@groovedesk.io to make a request. We will respond within the time the law where you live allows, and we will not charge you or treat you differently for asking. We may need to confirm who you are first. There is no self-service download: we put your copy together by hand, which is slower but means we can check we are giving the right information to the right person.

If the request is about work inside a workspace you belong to, we will tell you and help the workspace owner act on it, because that content is theirs to decide about rather than ours.

If you are unhappy with how we handled your request, you can complain to your data protection authority. In the European Economic Area that is the supervisory authority where you live or work; in the United Kingdom it is the Information Commissioner’s Office; in Quebec it is the Commission d’accès à l’information; elsewhere in Canada it is the Office of the Privacy Commissioner of Canada. You can also go to court.

Automated decisions

We do not make decisions about you by automated means alone that have a legal effect or similarly significant effect on you. Spam and referral checks can flag a signup, and the type of email address you use is one internal signal when we consider invitation order, but a person reviews anything that affects whether you get access. The AI features write drafts for you to edit; they do not decide anything about you.

Email permission

Email permission is separate from website tracking, and one does not imply the other. Use the unsubscribe link in any waitlist email to stop updates, or contact us. We act on it promptly and keep only the opt-out record needed to honor it. Email we send because you have an account, such as confirming your address or telling you about a payment, is part of running the service and does not stop when you unsubscribe from updates.

Changes to this notice

We will update this notice when the waitlist, the application or our data practices change. If a change materially affects how we use your information, we will email waitlist members and account holders before it takes effect. The date at the top shows the current version.