1. What we collect
We collect different data from the two kinds of people who use YouOwnMusic.
Venue owners and staff
- Business name, owner name, email address, mobile number, country and city
- A hashed password (we never store the password itself)
- Billing records: plan, amount, currency, gateway and transaction identifiers
- Images you upload for your player background and logo
- Sign-in timestamps and actions taken in the dashboard, for the audit log
Venue customers requesting songs
- The first name you enter
- A secure one-way identifier derived from your mobile number, plus the last four digits
- The songs you request, with timestamps and the resulting status
- IP address and browser user-agent, kept for abuse prevention and moderation
2. Why we collect it
Verification and logging exist for one reason: a venue is publicly playing whatever gets requested, and needs to be able to trace a problematic request back to a verified session. We collect what is necessary for verification, moderation and operating the service, and nothing beyond that.
3. How phone numbers are protected
Your mobile number is used to send a one-time code. Once verification completes, we store a keyed HMAC of the number and its last four digits — not the number itself. That identifier lets a venue recognise a repeat requester and lets us enforce request limits, but it cannot be reversed into a phone number and cannot be dialled.
Phone numbers and identifiers are never shown publicly. Venue queues and screens display a first name only.
We do not claim that this identifies a real-world individual. What it provides is an auditable record of the verified session that submitted each request.
4. Who can see what
- Other customers at the venue see a song title, artist and a first name. Nothing else.
- The venue ownersees the requester's name, the masked identifier (last four digits), the song and the request status.
- YouOwnMusic staff access data only for support, moderation, security and billing, and such access is logged.
- Processors we rely on: our payment gateways (Razorpay for INR, our international card processor for USD), our SMS provider for OTP delivery, our hosting and object-storage providers, and — only if a venue enables them — analytics providers.
We do not sell personal data, and we do not use it for advertising.
5. Data retention
- OTP codes — expire after 5 minutes and are stored only as a hash.
- Verified customer sessions — expire 6 hours after verification.
- Song request records — retained for 12 months for moderation, dispute handling and abuse prevention, then deleted or anonymised.
- IP and user-agent data — retained for 90 days for abuse prevention.
- Venue account and billing records — retained while the account is open and afterwards for as long as tax and accounting law requires.
- Audit logs — retained for 24 months.
6. Deletion and your rights
You can ask us to confirm what we hold about you, correct it, or delete it. Because a customer's number is stored only as an irreversible identifier, we ask you to submit a deletion request from the venue where you made the request, or contact us with the venue name, the approximate date and the last four digits of the number you used, so we can locate the records.
Venue owners can request full account and customer-data deletion by emailing us from their registered address. We action verified deletion requests within 30 days, other than records we are legally required to keep.
Email hello@youownmusic.com or use the contact form.
7. Security
- Passwords are hashed with bcrypt; we can never read them
- Sessions use signed, httpOnly cookies over HTTPS
- Mobile numbers are keyed-hashed before storage
- Payments are verified server-side; gateway secrets never reach the browser
- Uploads are validated by decoded content and re-encoded before storage
- Rate limiting protects OTP requests, logins and song requests
- Every venue's data is isolated; one venue cannot read another's
No system is perfectly secure. We do not claim that a breach is impossible, only that we design to reduce the chance and the impact of one.
8. Cookies and analytics
We set a small number of strictly necessary cookies: a signed session cookie for venue staff, and a per-venue verification cookie for customers. Neither is used for advertising.
Analytics and pixel tracking are off unless a platform administrator configures them, and venues are responsible for meeting their own cookie-consent obligations where applicable.
9. Children
YouOwnMusic is intended for use by adults at commercial venues. We do not knowingly collect data from children. If you believe a child has submitted a mobile number, contact us and we will delete the associated records.
10. Changes
We will post any material change to this policy on this page and update the date above. If a change materially affects how customer data is handled, we will also notify venue owners by email.
Questions about this document? Get in touch. This page is provided for transparency and is not legal advice.