Privacy Policy
Non-binding courtesy translation. This English text is provided for your convenience only. The legally binding version is the German one: Datenschutzerklärung. In the event of any discrepancy, the German wording prevails. See also the terms and conditions in English.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Timothy Schulz
Düsseldorfer Straße 131
51063 Cologne
Germany
Email: support@squaresmile.de
2. Overview
Protecting your data matters to me. This website (squaresmile.de) is deliberately built to collect as little as possible: the public pages load no content from third-party servers. Fonts, icons, images and all program libraries are served directly from my own server (first-party). No tracking cookies and no third-party analytics scripts are embedded. For that reason, no cookie consent banner is required on the marketing pages.
Some features do call third-party services — but only if you actively use them (e.g. weather, notifications, embedded Spotify content) or for order processing when you make a purchase. Below I explain which data is processed in which case.
3. Hosting
This website is hosted by an external service provider (the host):
ALL-INKL.COM – Neue Medien Münnich
Owner: René Münnich
Hauptstraße 68, 02742 Friedersdorf, Germany
The host processes, on my behalf, the data generated when you visit the website (in particular server log files, see below). The servers are located in Germany. The legal basis is my legitimate interest in providing the website securely and reliably (Art. 6(1)(f) GDPR). A data processing agreement pursuant to Art. 28 GDPR has been concluded with the host.
4. Server log files
When the website is accessed, the server automatically collects information transmitted by your browser and stores it in what are known as server log files. These are:
- the address (URL) requested and the date/time of access
- the volume of data transferred and confirmation of successful retrieval
- browser type and version, operating system used
- referrer URL (the page visited previously)
- the IP address in truncated or anonymised form
This data is not merged with other data sources. Processing is based on Art. 6(1)(f) GDPR for the technical provision, security and stability of the website. Log files are stored for a limited period and then deleted.
4a. Tool usage counters (aggregated, anonymous)
In order to understand which tools are used and how often, the platform collects purely aggregated usage counters: for each tool, a daily count is kept of how often it was opened and which actions were performed in it (e.g. “opened”, “exported”). These counters deliberately use the same technique as the click counters already used for support links (see the section on server log files / internal statistics) and are subject to the same data-minimisation requirement.
No personal data is stored in the process — in particular no IP address, no user identifier, no cookie and no timestamp more precise than the calendar day. The counters are pure daily totals per tool and allow no conclusions about individual persons. They are not linked with other data sources. The legal basis is my legitimate interest in the basic statistical improvement of the service (Art. 6(1)(f) GDPR); consent is not required because no personal reference exists.
5. Contact by email
If you write to me by email (e.g. to support@squaresmile.de), I process the details you provide (email address, content of the message) in order to deal with your enquiry. The legal basis is Art. 6(1)(b) GDPR (for contract-related enquiries) or Art. 6(1)(f) GDPR (for other enquiries, legitimate interest in responding). The data is deleted as soon as it is no longer required and no statutory retention obligations conflict with deletion.
6. Registration and user account
You can create a user account to use the platform. On registration I process:
- Name (a display name of your choosing, used among other things for the salutation in emails)
- Email address
- Password (stored exclusively in encrypted/“hashed” form)
I process this data in order to provide you with the account and its associated features. The legal basis is Art. 6(1)(b) GDPR (establishment and performance of the user relationship).
In addition, I store the time at which you accepted the terms and conditions and the privacy policy and — if you ticked the optional box — the time of your newsletter consent (see section 14). These timestamps serve as proof of the consent given and of the conclusion of the contract (Art. 7(1) GDPR, accountability under Art. 5(2) GDPR).
The account gives you limited storage (up to 50 MB) with which you can link content from the apps (e.g. saved projects) to your profile and back it up server-side. This content is stored on the host’s server (see section 3) in Germany, is assigned to your account and is removed when the account is deleted. For details, see section 13.
Your account also stores the licence keys of the premium products you have purchased, so that the corresponding features remain unlocked. The validity of these licence keys is checked with Gumroad (see section 8). The legal basis for storage is Art. 6(1)(b) GDPR (performance of a contract).
The data is stored for as long as your account exists. You can delete your account at any time or request deletion by email to support@squaresmile.de; the associated data is then deleted, unless statutory retention obligations conflict with deletion.
A technically necessary session cookie is used for signing in and maintaining your session. It is strictly necessary for login and requires no consent (Section 25(2) no. 2 of the German Digital Services Data Protection Act, TDDG).
7. Sending transactional emails
Functional emails (e.g. confirmations, system-related notifications) are sent via the SMTP server of my host ALL-INKL.COM – Neue Medien Münnich (address see section 3). The recipient’s email address and the content of the message are processed in doing so. Processing takes place in Germany; no transfer to a third country occurs. The legal basis is Art. 6(1)(b) GDPR (performance of a contract) or Art. 6(1)(f) GDPR (legitimate interest in reliable delivery). Sending is covered by the existing data processing agreement with the host pursuant to Art. 28 GDPR.
8. Sale of tools and plugins via Gumroad
The sale of the paid tools and plugins (e.g. SoundSense, SetlistForge, SubPress) is handled via the platform Gumroad:
Gumroad, Inc., 548 Market St, San Francisco, CA 94104, USA
Gumroad acts as seller/reseller (merchant of record) and independently handles ordering, payment and invoicing. When you buy something, you enter your payment and billing details directly with Gumroad; from Gumroad I receive only the information necessary for order processing (e.g. email address and the product purchased).
In addition, the validity of licence keys is verified server-side with Gumroad (“licence validation”). The licence key you enter is transmitted to Gumroad and the result (valid/invalid) is returned. Purchase links also point to the product pages on Gumroad.
Processing takes place for the performance of a contract (Art. 6(1)(b) GDPR). As Gumroad is based in the USA, data may be transferred to the USA. Such transfers are based on the EU standard contractual clauses or — where applicable — on the EU-US Data Privacy Framework. Details: gumroad.com/privacy
9. Show Clock – weather data via Open-Meteo
The Show Clock feature can display weather data. This data is retrieved only once you have set a location for the weather display; after that Show Clock refreshes it about every 15 minutes while it is open in the foreground. To do so, your browser sends a request to the weather service Open-Meteo (open-meteo.com); your IP address and the coordinates of the location are transmitted to Open-Meteo in order to return the matching weather data. The coordinates are also synchronised with your account (see section 13a); share links do not contain them.
The legal basis is my legitimate interest, respectively your active use of the feature (Art. 6(1)(f) GDPR). Further information: open-meteo.com/en/terms
10. Show Clock – notifications (web push)
The Show Clock can send you notifications (web push) if you enable them. This feature is opt-in: it only becomes active once you expressly allow it and confirm your browser’s notification request.
If you enable push notifications, your browser registers a push subscription with the push service of the respective browser/device manufacturer (e.g. Google for Chrome, Mozilla for Firefox, Apple for Safari). A technical subscription address (endpoint) is generated and stored, through which notifications are delivered. This is not intended to identify you personally.
The legal basis is your consent (Art. 6(1)(a) GDPR). You can disable notifications again at any time in your browser settings. Delivery runs via the infrastructure of the respective browser/device manufacturer; their privacy policy applies in addition.
11. Embedded Spotify content (click to load)
In individual places, content from Spotify may be referenced. It is not loaded automatically. Instead, you initially see only a button (“Play on Spotify” with the note “Loads content from open.spotify.com”). Only when you actively click that button is a connection to Spotify established and the player loaded. No data is transmitted to Spotify before that.
By clicking, you consent to the content being loaded (Art. 6(1)(a) GDPR). From that moment, Spotify’s privacy policy applies: spotify.com/de/legal/privacy-policy. The provider is Spotify AB, Regeringsgatan 19, 111 53 Stockholm, Sweden.
12. Google Search Console
I use Google Search Console to monitor how the website can be found in Google Search. Search Console evaluates aggregated, anonymised data on how the website appears in search results (e.g. search terms, click and impression figures). No analytics script is embedded in the website and no cookies are set on your device; the data comes from Google Search itself. It does not enable me to identify individual visitors. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
12a. Update check in the KlarFunk desktop application
Our KlarFunk desktop application can check, if you want it to, whether a newer version of the program is available.
This function is disabled by default. It only becomes active once you switch on the “Automatically check for updates” option in the application’s settings or press the “Check for updates” button. Without one of these actions the application establishes no connection to any server.
If the automatic check is enabled, the application retrieves a file containing the current version number at most once every 24 hours; if you press the button manually, the file is retrieved once, at the moment of your input. That file is not provided by us but via GitHub Pages, a service of GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA (a subsidiary of Microsoft Corporation):
https://square-smile.github.io/klarfunk-updates/latest.json
This is a plain request that transmits no content: no parameters, no identifiers, no device information and no details of the program version installed on your machine are transmitted. The version numbers are compared exclusively locally on your device.
No data reaches us through this function. For technical reasons, however, GitHub as the operator of the service processes the data that arises whenever a web address is retrieved, in particular:
- your IP address
- the date and time of the request
- the file requested
- the identifier of the browser engine used (user agent)
As GitHub is based in the USA, this data is transferred to a third country. Details of GitHub’s data processing and of the safeguards that apply to it can be found at: docs.github.com/site-policy/privacy-policies/github-general-privacy-statement
The legal basis is your consent under Art. 6(1)(a) GDPR, which you give by enabling the function. You can withdraw this consent at any time with effect for the future by switching the option in the application’s settings off again.
Beyond that, the application stores exclusively on your own device whether the function is enabled, when it last checked, and which version notice you have already dismissed. This information does not leave your device.
12b. Downloading the KlarFunk desktop application
The installer files for KlarFunk are not provided by me but via GitHub Releases, a service of GitHub, Inc. (for the address, see section 12a). When you, as a licence holder, click one of the download buttons, you are redirected to the file hosted there. In doing so GitHub processes the data that arises with every request (IP address, date and time, the file requested, user agent), and the data is transferred to the USA. The legal basis is Art. 6(1)(b) GDPR (provision of the software you have purchased).
13. Local storage in the tools (browser storage)
Many of the tools on squaresmile.de run entirely in your browser. Input and settings are first stored locally in your browser (e.g. via localStorage). Tools that are not named in the following list do not transmit them to my server. You can delete this local data yourself at any time by clearing your browser’s storage for this website. Local storage serves solely the function of the respective tool (Section 25(2) no. 2 TDDG, as it is strictly necessary for the service you have expressly requested).
Automatic synchronisation: as soon as you are signed in, the following tools reconcile their data with your account without a separate save step, so that every device you use shows the same state:
- Show Clock – timetables, notes, settings, share links and rider files (details in section 13a)
- Stage Plot Generator – your stage plots
- SetlistForge – automatically, unless you choose “Keep my library on this device only” in SetlistForge’s backup settings (the cloud button) – this switches synchronisation off for your account and deletes the copy stored in it: song library (including the names of composers, lyricists, arrangers and publishers, and ISWC codes), setlists with show details and the details for royalty reports, settings and the “reported” mark. The details for royalty reports can include other people’s data that you enter for them (e.g. the organiser’s name and address, venue or organiser phone numbers, the person responsible for the programme, the musicians), as well as your member numbers and money figures (ticket prices, revenue, costs, fees). Logos and audio files stay in your browser. If you create a read-only link to a setlist, anyone who knows the link can read that setlist (details in section 13c)
- SoundSense – training progress, best scores and settings, and the listening devices you name (for example "studio headphones") with your results per device; the hearing profile stays in your browser (see below)
- PatchSmith – your patches (band, venue, date, channel list and notes), routing presets and named versions
- RiderSmith – your riders (band and contact details: contact person, phone, email, website; venue, town and show date; the tables and texts of every section, e.g. crew tables and hospitality notes; the rider language and any further document languages, your own translations of clauses, versions with their date and the list of changes), your own text blocks and the images you attach (logo, band photo, stage plots and other pictures – each stored as its own entry in your account; images are re-drawn as JPEG, so location data in the original file is not kept; deleting a rider deletes its images too). A rider often contains data about other people that you enter, e.g. names, phone numbers and email addresses of band or crew members, photos in which people can be recognised, or catering notes. Such notes can be health data (allergies, intolerances) or reveal a religious belief; do not enter health data, religion, passport numbers or dates of birth – “on request” is enough – and enter other people’s data only with their consent and only as far as the venue needs it. If you create a venue link, anyone who knows the link can read that rider (details in section 13d)
- PowerSense – your power distribution plan
- RiggingSense – your rigging plan
- FreqSense – your frequency plans and display settings
- RoomSense – venue profiles (with all input, including the level monitor’s calibration value), language and display setting; level protocols only if you choose “Save to my account”
- LoudSense – your own loudness targets (name, value, tolerance, ceiling). The audio files you check are decoded and measured in your browser and are not uploaded. A history of the files you checked (file name, measured values and date, no audio) stays in your browser and is not synced. If you share an audio file to the installed LoudSense app on Android, the browser’s service worker hands the file to the page inside your device, and it stays in your browser’s storage until LoudSense has read it. If the service worker is not active at that moment (e.g. right after an update or after you cleared the site data), your browser sends the file to our server instead; the server does not store or evaluate it, discards it at the end of the request and only redirects you to LoudSense
- BPM Forge – setlists and settings, including the tuner’s
- ClickSmith – click settings, projects and sets (only values such as tempo, time signature and cues; the audio files never leave your device)
- PitchSense – A4 reference, waveform and note-name style; the playback volume stays on each device
- SpectraSense – display and detection settings; the audio input and channel, the calibration, level logs, protocols, stored curves and the list of rings it found stay on your device (see section 13b)
- LightSense – your training progress: each answer with its time, points, game and level, how many questions you answered (counted per device under a random device identifier), the days you trained and your best streak, your rank and your settings (difficulty, path, console vocabulary). Resetting your progress clears it on every device of your account. The sound-delay setting for Busk It stays on the device
All other tools (e.g. TempoSense and MicSense) store data only in your browser.
Shared computers: browser storage belongs to the device, not to a person, and it survives signing out. So that one person’s data on a shared computer (e.g. at front of house) does not end up in someone else’s account, Show Clock, Stage Plot Generator, SetlistForge, SoundSense, PatchSmith, RiderSmith, PowerSense, RiggingSense, FreqSense, RoomSense, LoudSense, BPM Forge, ClickSmith, PitchSense, SpectraSense, MicSense and LightSense remember which account the data in this browser belongs to. If someone else signs in here, these tools neither show the previous account’s data nor transfer it to the new account; it is set aside or removed from this browser. Whatever had already been synchronised with the account of the person who created it stays there. On someone else’s computer it is still best to work in a private window.
When you are signed in to your user account, you can additionally save content server-side to your profile (limited storage of up to 50 MB, see section 6). This content is stored with the host (section 3) in Germany, is assigned to your account and serves to keep your work available and usable across devices. The legal basis is Art. 6(1)(b) GDPR (performance of the user relationship). When your account is deleted, this content is deleted as well.
Note on confidentiality: Content saved server-side is stored unencrypted in the database; there is no end-to-end encryption. It is therefore visible to me as the operator and technically to the host (see section 3). Access only takes place where it is necessary for operating the service — for example to investigate a fault at your request, to restore data after an incident, or to comply with legal obligations. The administration interface does not display the contents of your tool data. Content that stays exclusively in your browser (see above) is not affected. Please do not save information server-side that you consider particularly confidential.
Certain particularly sensitive data is deliberately refused by the server: the hearing profile (audiogram) from SoundSense constitutes health data within the meaning of Art. 9 GDPR and is rejected server-side — it remains exclusively local to your browser.
13a. Show Clock – share links, rider files and synchronisation
Show Clock is made for sharing: you pass your timetable on to crew, bands and technicians. This section explains which data sits on my server when you do, who can see it and when it is deleted. Timetables, notes and riders often contain information about third parties (names, phone numbers, and in riders sometimes allergies or intolerances, i.e. health data). Please put into a share link only what its recipients really need.
Share links (live view)
When you share a timetable, the server stores a copy of it under a random identifier that is
part of the link (/show-clock/view?s=…). Stored are: the show title and timetable
name, the slots (label, type, times, duration, day), the start date, a running-late offset,
the current cue, the colour theme and – if set – your logo. Notes and
riders are included only if the link expressly grants them; without that
grant the copy does not contain them, not even hidden.
Who can see the content? Anyone who has the link – no account is needed. The
identifier cannot be guessed, but whoever forwards the link also forwards the content. The view
is closed to search engines (noindex). Open views ask the server for changes every
few seconds; this produces the usual server log files (section 4).
For how long? A link exists until you withdraw it. You can delete any link at any time in your account under Share links; it stops opening immediately. Links you have not updated for 90 days are deleted automatically by the server – but not until 30 days after the last day of the show, if the timetable carries a date. Deleting your account deletes all your links.
Snapshot links (?c=… or ?show=…) work differently:
the whole timetable is contained in the link itself. The server keeps no copy; when the link is
opened, the address is merely recorded in the server log files like any other (section 4). A
snapshot link therefore cannot be withdrawn – only the rider files it refers
to stop opening once no live link grants them any more (see below).
Rider files
Files you attach to a slot (PDF, PNG, JPEG, WebP or GIF, up to 10 MB each) are at first stored only in your browser. While you are signed in, Show Clock uploads them to your account automatically so that you can open them on your other devices too; for a link with riders access they are uploaded as well. The files are stored non-publicly on the host’s server in Germany (section 3) and can only be retrieved through an address that cannot be guessed.
You can always open your own files on your devices. Other people can reach a file only while a live link of yours contains it with riders access. If you withdraw riders access, remove the file from the slot or delete the link, the file can no longer be retrieved by link holders from that moment on (I cannot, of course, recall copies that were already downloaded). Files are deleted when you remove them from the slot, when the link they were uploaded for is deleted, and when your account is deleted; a daily clean-up run removes orphaned files.
Please upload only files you are entitled to pass on (e.g. the rider the band sent you for this show). Reports of illegal content in hosted files or share links can be sent to me by email at support@squaresmile.de (subject “Content report”, with the link and a short reason). I review every report, block access where a report is substantiated, and inform the person who shared the content.
Push notifications for a link
If someone enables notifications in the shared view (section 10), the server stores the push subscription (endpoint and keys, and the chosen slot if any) together with the link. The content of the notifications is transmitted to the browser in encrypted form. The subscription is deleted when the person unsubscribes or when the link is deleted.
Automatic synchronisation
Like the other tools listed in section 13, Show Clock synchronises its data with your account automatically as soon as you are signed in – without a separate save step. This covers your timetables including slots and notes, the list of your timetables, settings (e.g. colour theme, 12/24-hour display, warning time, title), the access keys of your share links, the current cue and running-late offset and – if you set a location for the weather display – the coordinates of that location. This way every device you are signed in on shows the same state. Section 13 applies to this data (stored with the host in Germany, unencrypted, deleted with the account). The legal basis is Art. 6(1)(b) GDPR (performance of the user relationship); the same applies to share links and rider files.
13b. Microphone access in the tools
Some tools analyse the sound that your device’s microphone or audio interface delivers:
- PitchSense – live tuner: detects frequency and note
- BPM Forge – tuner (the “Tuner” tab) and the freely accessible tuner demo at squaresmile.de/online-tuner: detects the pitch
- TempoSense – detects tempo and beat
- SpectraSense – shows the frequency spectrum and finds feedback frequencies; it also measures sound levels (level meter and level protocol) and a system’s transfer function
- RoomSense – the “LUFS” tab (live loudness meter) and the “Level” tab (level monitor, calibration and level protocol)
How the access works
- Only when you ask for it: a tool only accesses the microphone when you press the tool’s start button, and your browser asks for your permission first. While a tool is listening, your browser or operating system shows this (e.g. with a microphone or recording icon).
- Only on your device: the sound is analysed exclusively in your browser on your device. It is not recorded, not uploaded and not stored – neither on my server nor with any third party.
- End of access: access ends when you stop the measurement or close the page. PitchSense, BPM Forge’s tuner, the tuner demo and SpectraSense also release the microphone as soon as you switch tabs; so does TempoSense, unless you have switched on a MIDI output. The measurements in RoomSense deliberately keep running in the background (e.g. for a level measurement across a whole evening).
What is stored
Sound recordings are never stored – only settings and, where the function needs them, individual measured values from which the sound cannot be reconstructed:
- PitchSense: the A4 reference, waveform and note-name system (synced with your account); the volume, the engineer's view settings and the note history stay on your device.
- BPM Forge: the tuner settings (e.g. instrument, tuning, A4 reference). The tuner demo stores nothing.
- SpectraSense: its settings (display, detection and the A4 reference), synced with your account. The audio input you chose last – the identifier your browser assigns to it for this website, and the input’s name – stays on your device and is not synced. The list of rings it found (time, frequency and note of each, the suggested cut and the labels you type) is kept only in your browser on this device and is never uploaded. The measurement functions store the following only in your browser on this device; none of it is synchronised with your account or uploaded: the chosen input channel; the calibration (the content of a microphone calibration file you load, including its file name and serial number, and the calibration values with their date); the level log (one A- and one C-weighted value, the peak and the maximum per second); saved level protocols including the details you type in (e.g. organiser, author, event, venue, sound engineer); and stored transfer curves with the names you give them. You can export them as a file yourself.
- TempoSense: the settings including the chosen audio input and, if you record the set log, the measured tempo per section. Both stay in your browser; the set log only leaves your device if you export it as a CSV file.
- RoomSense: the level monitor keeps a log of the measured levels (one A- and one C-weighted value per second) in your browser. The calibration value and values you carry over from a measurement into an input field are stored in the venue profile like the rest of your input. A level protocol with its measured values only reaches your account if you choose “Save to my account”.
Which of these data are synchronised with your account is set out in section 13.
Withdrawing permission
You can withdraw the permission at any time in your browser’s site settings (usually via the icon to the left of the address) or in your operating system’s privacy settings. The functions that need the microphone are then unavailable; every other part of the tools keeps working.
Legal basis
Access to your device’s microphone is strictly necessary for the service you have expressly requested – the measurement you start yourself (Section 25(2) no. 2 TDDDG). Where personal data is processed in the process (for example when voices in the room are audible), this happens exclusively on your device and in order to provide the function you are using (Art. 6(1)(b) GDPR) or on the basis of my legitimate interest in offering you the analysis you requested (Art. 6(1)(f) GDPR).
13c. SetlistForge – read-only set link
If you create a read-only link to a setlist in SetlistForge (“Share read-only link”), the server
stores a copy (a snapshot) of that setlist under a random identifier that cannot be guessed and is
part of the link (/setlist/view/…).
What the link shows: the show’s title, date, venue and artist, the setlist’s name, and for each song its title, duration, key and BPM (for medleys, the titles of the parts), plus the set breaks with their label and planned length. Your stage notes on the songs are included only if you tick “Include stage notes”. Never included are composers, lyricists, arrangers, publishers, ISWC codes and any detail for royalty reports (e.g. organiser and addresses, phone numbers, member numbers, ticket prices, revenue, costs, fees); the server does not store these fields even if they are sent to it.
Who can see it? Anyone who has the link – no account is needed. Whoever forwards
the link also passes on its content. The page is closed to search engines (noindex)
and does not pass its address on when a visitor follows a link from it. The server counts how often
the page was opened, without any details about the people; each visit produces the usual server
log files (section 4).
For how long? The link shows the state of your last click on “Create link” or “Update link”. It works until 90 days after the last update – if the show carries a later date, until 30 days after the show, but never longer than one year. After that it says “Link expired”, and a daily clean-up deletes the copy. “Stop sharing” in SetlistForge, or deleting it under Share links in your account, removes the link at once; deleting your account deletes all your links. An account can have at most 50 set links active at a time.
Show details and notes can contain other people’s data (e.g. names). Please share only what the band really needs. The legal basis is Art. 6(1)(b) GDPR (performance of the user relationship).
13d. RiderSmith – read-only venue link
If you create a read-only link to a rider in RiderSmith (“Venue link”), the server stores a copy (a
snapshot) of that rider under a random identifier that cannot be guessed and is part of the link
(/rider/view/…).
What the link shows: the band, the venue, town and date of the show, the version number with its date and the list of changes since the previous version, the logo and band photo, and every section you switched on in the rider (heading, tables such as the input list, standard texts, your own texts and the attached image). Of the contact block only the contact person and the web address are included; phone numbers and email addresses only if you tick “Include contact details”. Never included are your account’s email address, your other riders and anything outside the rider; the server does not store such fields even if they are sent to it.
Who can see it? Anyone who has the link – no account is needed. Whoever forwards
the link also passes on its content. The page is closed to search engines (noindex)
and does not pass its address on when a visitor follows a link from it. The server counts how often
the page was opened, without any details about the people; each visit produces the usual server
log files (section 4).
For how long? The link shows the state of your last click on “Create link” or “Update link”. It works until 90 days after the last update – if the rider carries a later show date, until 30 days after the show, but never longer than one year. After that it says “Link expired”, and a daily clean-up deletes the copy. “Stop sharing” in RiderSmith, or deleting it under Share links in your account, removes the link at once; deleting your account deletes all your links. An account can have at most 50 venue links active at a time.
A rider often carries other people’s data (e.g. crew names). Do not enter health data (such as allergies or intolerances), religion, passport numbers or dates of birth – “on request” is enough; tell the promoter such things directly. Please share only what the venue really needs. The legal basis is Art. 6(1)(b) GDPR (performance of the user relationship).
14. Newsletter and product updates
During registration you can voluntarily tick the box “Send me occasional updates about new tools by email”. The box is not pre-selected, and consent is not a condition of registering or of using the platform. You can also give or withdraw it at any time later in your account under email preferences.
Data processed: your email address and the time of your consent; the name stored in your account may be used for the salutation. No separate mailing list is kept — the recipients follow from the consent timestamp on your user account. The legal basis is your consent under Art. 6(1)(a) GDPR.
Sending: Emails are sent from my own platform via the mail server of my host ALL-INKL.COM in Germany (see sections 3 and 7). I use no external newsletter service (e.g. Mailchimp, Brevo, CleverReach); your address is therefore not passed on to any further recipient for this purpose. The emails contain no tracking pixels and no open or click tracking.
Confirming your address: Consent is given inside your password-protected user account, and your email address is verified via a confirmation link during registration anyway (see section 7). I therefore do not send an additional confirmation email for the newsletter alone (a separate double opt-in).
Withdrawal: You can withdraw your consent at any time with effect for the future — using the checkbox in your account’s email preferences, using the “manage your email preferences” link at the end of every such email, or informally by email to support@squaresmile.de. On withdrawal, the stored consent timestamp is deleted and you receive no further updates. The lawfulness of processing carried out up to the withdrawal remains unaffected.
Transactional emails (e.g. email address confirmation, password resets, licence and account information) are independent of the newsletter. They are necessary for the performance of the user relationship and are sent regardless of this consent (see section 7).
15. Recipients of the data / processors
Your data is passed on only to the extent necessary for the performance of the contract, for the functioning of the features you use, or for the operation of the website, to the following recipients:
- ALL-INKL.COM – Neue Medien Münnich (hosting and the sending of transactional and newsletter emails, Germany)
- Gumroad, Inc. (order processing and licence validation for the paid products, USA)
- Open-Meteo (weather data in the Show Clock, only when used)
- The push service of the respective browser/device manufacturer (web push notifications, only if opted in)
- GitHub, Inc. (provision of the installer files and the version file for the KlarFunk desktop application, USA — see sections 12a and 12b)
16. Your rights
Under the GDPR you have the following rights regarding your personal data:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)
- Withdrawal of consent given, with effect for the future (Art. 7(3) GDPR)
An informal email to support@squaresmile.de is enough to exercise them.
17. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for me is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Kavalleriestraße 2–4, 40213 Düsseldorf, Germany
www.ldi.nrw.de
18. Currency of this policy
This privacy policy is adapted whenever something changes in the data processing (e.g. when new services or new features are integrated).
Last updated: September 2026 — non-binding translation of the German Datenschutzerklärung.