Privacy
Privacy Policy
This Privacy Policy explains how StreamPilot handles personal data when you visit our website, contact us, create an account, subscribe through Stripe, use the StreamPilot Panel, use APIs, request support, or use optional managed mobile app services. It is designed for StreamPilot's actual radio station, DJ, scheduling, recording automation, API and managed app publishing services.
1. Who we are
StreamPilot is a UK-based SaaS platform for radio stations, DJs and audio publishers. For privacy questions, contact hello@streampilot.co.uk. Where StreamPilot decides why and how personal data is processed, StreamPilot acts as controller. Where a customer uses StreamPilot to manage its own users, DJs, team members, schedules, listener-facing content or app configuration, StreamPilot may act as processor for that customer.
2. Personal data we collect
- Account data: names, email addresses, account roles, invite tokens, login status, password hashes, customer organisation details and station/DJ account details.
- Billing data: customer name, email address, Stripe customer ID, Stripe subscription ID, selected plan, billing interval, billing status, invoice status and checkout metadata. Full card details are handled by Stripe, not stored by StreamPilot.
- Contact and support data: messages sent by contact forms, emails, support requests, operational notes, troubleshooting information and correspondence.
- Platform content: station names, DJ names, profile details, logos, artwork, stream URLs, contact details, schedules, events, show information, recording metadata, podcast/feed metadata and other content uploaded or configured by customers.
- Usage and log data: IP address, browser details, device information, request timestamps, API usage, authentication events, audit log entries, errors, webhook activity, build job events, recording job events and security logs.
- Managed App Service data: app names, bundle/package identifiers, app branding, store listing information, screenshots, release notes, developer account access status, app review correspondence and publication metadata.
- Cookie and analytics data: session identifiers, authentication cookies, preference cookies and analytics data where used and permitted.
3. How we collect data
We collect data directly from you when you sign up, contact us, configure a station or DJ account, upload content, use the Panel, use an API, select a plan or managed app option, or request support. We also receive data from Stripe, app stores, hosting providers, logs, security systems and other technical providers involved in operating StreamPilot.
4. Why we use personal data
- To provide StreamPilot Panel access, APIs, scheduling, storage, recording automation and related platform services.
- To create and manage accounts, authenticate users, invite team members and maintain audit logs.
- To process subscriptions, billing status, invoices, failed payment events and payment recovery through Stripe.
- To provide support, incident handling, service notices and operational communications.
- To build, submit, maintain and update managed iOS and Android apps where purchased.
- To secure the platform, investigate abuse, prevent fraud, rate-limit APIs and protect infrastructure.
- To comply with legal, tax, accounting, regulatory and contractual obligations.
- To understand website and product usage, improve reliability and plan product improvements.
5. Lawful bases
Depending on context, we rely on performance of a contract, legitimate interests, legal obligation and consent. Contract applies where we need data to provide paid services. Legitimate interests include platform security, service improvement, audit logging, abuse prevention and customer support. Legal obligation applies to tax, accounting, compliance and lawful requests. Consent applies where required for non-essential cookies, optional marketing or specific permission-based processing.
6. Stripe and billing
Stripe processes payment details, card data, payment method information, invoices, tax information where configured, billing addresses where collected and payment authentication. StreamPilot stores operational billing identifiers and status fields such as Stripe customer ID, subscription ID, price ID, plan, billing interval and billing status. Stripe's own privacy terms also apply to Stripe processing.
7. APIs, logs and audit records
StreamPilot may log API calls, authentication events, request metadata, IP addresses, error traces, webhook payloads, subscription events, station changes, recording automation activity, app build activity and administrative actions. These logs support security, troubleshooting, replay of billing events, abuse prevention and auditability.
8. Sharing personal data
We share data only where needed to provide, secure or administer StreamPilot. Recipients may include Stripe, hosting providers, email delivery providers, analytics providers, Apple, Google, app review teams, developer account platforms, professional advisers, support contractors and authorities where required by law. We do not sell customer personal data.
9. International transfers
Some providers, including payment, hosting, analytics, app store or support providers, may process data outside the UK. Where required, we rely on appropriate safeguards such as adequacy regulations, standard contractual clauses, provider data processing terms or other lawful transfer mechanisms.
10. Retention periods
| Data type | Typical retention |
|---|---|
| Account and customer records | For the life of the account and up to 7 years after closure where needed for legal, tax, billing or dispute purposes. |
| Billing records and Stripe identifiers | Up to 7 years for accounting, audit, tax and dispute purposes. |
| Support messages | Usually up to 3 years after the last interaction, unless needed longer for a dispute or legal reason. |
| Operational logs and API logs | Usually 30 days to 18 months depending on security, troubleshooting and audit needs. |
| Webhook and billing event ledger | Retained while commercially useful for subscription audit, replay and dispute investigation, generally up to 7 years. |
| Customer media and content | While the account is active, then deleted or archived according to operational processes after cancellation, subject to backups and legal holds. |
| Backup copies | Held for disaster recovery rotation periods and then overwritten in the ordinary course. |
11. Your rights
Under UK GDPR, individuals may have rights to access, rectification, erasure, restriction, portability, objection, withdrawal of consent and complaint to the Information Commissioner's Office. Some rights are limited where we must retain data for legal, billing, security, audit or contractual reasons.
To exercise rights, contact hello@streampilot.co.uk. If your data is controlled by a StreamPilot customer, we may refer your request to that customer or act on their instructions.
12. Security
We use technical and organisational measures intended to protect personal data, including access controls, password hashing, audit logging, webhook signature validation, operational backups, rate limiting where implemented, and restricted administrative access. No internet service can be guaranteed completely secure.
13. Children's data
StreamPilot is intended for business and professional use by DJs, stations and organisations. It is not aimed at children. Customers must not create accounts for children or publish children's personal data through StreamPilot unless they have a lawful basis, appropriate consent and safeguarding procedures.
14. Changes
We may update this Privacy Policy as StreamPilot evolves. Material changes will be communicated where appropriate. The latest version will be published on this website.
15. Contact and complaints
Contact hello@streampilot.co.uk. You also have the right to complain to the UK Information Commissioner's Office at ico.org.uk.