Legal
Privacy Policy
Short version: we collect what a booking actually needs — who you are, what you play, where and when you are performing, and what you were paid. We do not sell personal information, we do not run advertising networks on the Platform, and we do not email you things you did not ask for.
1. Scope of this policy
This Privacy Policy explains how Jump The Line Partners LLC ("MusicStaff", "we", "us") handles personal information in connection with the MusicStaff mobile applications, the musicstaff.app website and related services (the "Platform").
It applies to organizers, musicians, organization co-admins, and visitors who join the early-access list. It does not apply to third-party services you reach from the Platform, which have their own policies.
2. Information we collect
Account and profile
- Name, email address, phone number, password (stored only as a cryptographic hash).
- Role — musician or organizer — and, for organizations, organization name, type, address and logo.
- Musician profile: instruments and roles, genres, years of experience, rate, travel radius, availability and exceptions, profile photo, links to media you choose to add, and biography.
Booking and engagement data
- Opportunities you post or apply to, invitations, applications, confirmations and cancellations.
- Engagement details: date, call time, duration, venue address, entry instructions, setting and rate.
- Check-in records, including the time of check-in and whether you were within the venue's check-in radius.
- Ratings and reviews you give and receive, and reports you submit about another user.
Payment and tax
- Payment and payout records: amounts, service fees, holds, releases, refunds and their status and timing.
- Tax information required for payouts and information returns, such as legal name, address and taxpayer identification number.
- Identity-verification results.
We never receive or store your full card number, bank account number or government-ID images. Those go directly to Stripe. We receive only a token and limited descriptors — for example, "Visa ending 4382" — plus the pass or fail result of a verification.
Communications
- Messages you send through the Platform, which are attached to a booking or conversation.
- Emails and support requests you send us, and our replies.
- Notification preferences and push-notification tokens.
Device and usage
- Device model, operating system, app version and language.
- Log data: IP address, timestamps, screens viewed, and errors or crashes.
- Approximate location derived from IP address, used for security and to understand which markets to open.
3. Where the information comes from
- From you — when you create an account, build a profile, post or apply to an opportunity, message someone, or write to support.
- From your device — automatically, when you use the Platform, subject to the permissions you grant.
- From other users — for example, a review or a report another user writes about you, or an invitation an organizer sends you.
- From service providers — for example, Stripe returning a verification result or a payout status, or a sign-in provider confirming your email address if you sign in with Google or Apple.
4. How we use information
- Run the marketplace — create your account, show opportunities, rank matches on instrument, distance, availability and rating, and let organizers and musicians reach each other.
- Process money — charge organizers, place and release holds, pay musicians, issue invoices and handle refunds and disputes.
- Verify and protect — confirm identity, detect fraud and abuse, enforce our Terms, and keep accounts secure.
- Communicate — send booking confirmations, call-time reminders, payout notices, security alerts and support replies.
- Improve the Platform — understand which features are used, diagnose errors, and decide which markets to open next.
- Comply with law — tax reporting, records retention, and responding to lawful requests.
We do not sell personal information.
We do not share personal information for cross-context behavioural advertising, and we do not run third-party ad networks inside the Platform. We do not use your messages or profile to build advertising profiles about you.
5. Location and day-of check-in
Day-of check-in uses your device's location to confirm you are at the venue. This matters because check-in anchors the payment-release timeline described in our Terms of Service.
- Precise location is used only while you are checking in for a booking, and only if you grant the permission.
- We record the check-in time and whether you were inside the venue's check-in radius. We do not track your location in the background or build a location history.
- You can decline or revoke the permission in your device settings. Without it, you may need the organizer to confirm your arrival another way, which can delay a payout.
6. Payments and identity verification
Card processing, payouts and identity verification are handled by Stripe. Card details, bank details and government-ID images are submitted directly to Stripe and are processed under Stripe's Privacy Policy. Stripe acts as an independent controller of that information for its own compliance obligations.
MusicStaff receives the outcome and the record — amounts, statuses, timestamps, the last four digits and brand of a card, and whether a verification passed — which is what we need to run bookings and keep accurate books.
7. Who we share information with
- The other side of a booking — see Section 8 for exactly what is visible.
- Service providers acting on our instructions: payment processing and identity verification (Stripe), cloud hosting and database (Supabase), email delivery, push notifications, error monitoring and analytics. They may use the information only to provide their service to us.
- Professional advisers — accountants, auditors and lawyers, under confidentiality.
- Legal and safety — when required by law, subpoena or court order, or where we reasonably believe disclosure is necessary to prevent fraud, harm or a violation of our Terms.
- A successor — if MusicStaff is involved in a merger, acquisition or sale of assets, information may transfer as part of that transaction, subject to this policy.
8. What other users can see
Some information is necessarily shared to make a booking work:
- Public on your profile — name, photo, instruments and roles, general area, rate range, rating and review history, verification badges, and any media links you add.
- Shared once a booking is confirmed — the venue address and entry instructions go to the booked musician; the musician's contact within the Platform goes to the organizer.
- Not shared with other users — your email address, phone number, exact home address, tax identification number, government-ID images and payment details.
Reviews are attributed and public. Messages are visible to the participants in that conversation, and to us where we need to investigate a report or a dispute.
9. The early-access list on this website
If you request an invite on musicstaff.app, we store the email address you
entered, which side of the marketplace you selected, and any name, organization or city you
chose to add. We also store a truncated form of your IP address — the
network portion only, for example 203.0.113.0/24 — so we can see which regions
are asking for the app and limit automated submissions. We do not store your full IP
address for this purpose.
We use that information only to send you an early-access invitation and to prioritise which markets to open. We do not add you to a marketing newsletter, and we do not share the list. Every message we send includes a way to be removed, and you can ask us to delete your entry at any time by emailing privacy@musicstaff.app.
This website does not use advertising or third-party analytics cookies. Session and security cookies are used only where needed to keep the site working and to protect the form against abuse.
10. How long we keep information
- Account and profile — while your account is active, and for a limited period after closure to resolve disputes and enforce our Terms.
- Booking and payment records — retained as long as required for tax, accounting and anti-fraud obligations, typically at least seven years.
- Messages — for the life of the account, and longer where connected to a dispute or a legal hold.
- Check-in records — kept with the booking record they belong to.
- Early-access entries — until you ask us to delete them, or until the market you asked about has launched and the invitation has been sent.
- Logs and diagnostics — generally 90 days, unless needed for a security investigation.
When we no longer need information, we delete it or de-identify it. Backups are rotated and may briefly retain deleted content.
11. Security
We use encryption in transit, encryption at rest, row-level access controls in our database so users can reach only their own records, password hashing, least-privilege access for staff, and audit logging of sensitive operations. Card and identity data never touch our servers.
No system is perfectly secure. If a breach affects your personal information, we will notify you and the relevant regulators as required by law. Keeping your password private and your device secure is your part of this.
12. Your rights and choices
- Access and correct — most profile information can be edited in the app. For anything else, ask us.
- Delete — you can close your account and request deletion. We must retain booking and payment records for the legal periods in Section 10, so deletion removes your profile and de-identifies what we cannot delete.
- Export — request a copy of your personal information in a portable format.
- Object or restrict — ask us to stop a particular use, where the law gives you that right.
- Notifications — change email and push preferences in the app. Transactional messages about a booking or a payment cannot be turned off while you have an active booking.
- Device permissions — location, camera, photos and notifications can each be revoked in your device settings.
Write to privacy@musicstaff.app to exercise any of these. We will verify your identity before acting, and respond within the time the applicable law requires. We will not discriminate against you for exercising a privacy right.
13. US state privacy rights
Residents of California, Colorado, Connecticut, Texas, Virginia and other states with comprehensive privacy laws have the rights described in Section 12, including the right to know what is collected, to delete, to correct, to obtain a portable copy, and to opt out of sale or targeted advertising.
We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is no opt-out for you to exercise. We also do not use sensitive personal information for any purpose beyond providing the Platform.
You may use an authorised agent to make a request. If we decline a request, you may appeal by replying to our decision; where your state provides one, you may also complain to your attorney general.
14. International users
MusicStaff is operated from the United States and information is processed and stored in the United States. If you use the Platform from outside the US, you understand that your information will be transferred to and processed in a country whose data-protection laws may differ from your own. Where required, we rely on appropriate safeguards for those transfers.
15. Children
The Platform is for adults. It is not directed to anyone under 18, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has given us information, write to privacy@musicstaff.app and we will delete it.
16. Changes to this policy
We may update this Privacy Policy. When we make a material change, we will update the effective date above and notify you in the Platform or by email before it takes effect. Please review it from time to time.
17. How to reach us
Jump The Line Partners LLC
Privacy: privacy@musicstaff.app
Support: support@musicstaff.app