Privacy Policy
1. Data Controller
- Data Controller: Santiago Fernández Seoane
- Project: Makineo (beta phase)
- Contact: [email protected]
2. Data We Process
When you register or use Makineo, we process the following data:
- — Account: username, email address, password (stored encrypted with bcrypt), date of birth, city
- — Public profile: bio, profile picture, favorite genres, visible city
- — Platform activity: saved events, confirmed attendances, ratings, followed artists, crews you belong to
- — Communications: email address if you subscribe to the newsletter (with explicit consent)
- — Technical data: IP address, device type, browsing data for analytics purposes (Google Analytics, subject to your consent)
- — Mobile app: if you install the Android app and accept notifications, we store a device identifier (push token) and the platform so we can alert you about events
- — Approximate location: only if you tap the detect-location button and grant permission. We use it at that moment to infer your city and sort events by proximity
- — Ticket purchases: if you buy a ticket through Makineo: the event, ticket type, quantity, amount paid, and order status (pending, paid, refunded), together with Stripe's payment session identifiers. We never store your card number: you enter it directly on Stripe, which processes it as a PCI DSS certified entity
- — Payout account (promoters): if you enable ticket sales as a promoter, Stripe verifies your identity and bank account directly (KYC), without going through our servers. We only store your Stripe account identifier and whether it's enabled to charge — never your ID document or account number
- — Messages, photos and videos: chat text (encrypted on our servers) and files you upload: photos and videos in chats and in your crew gallery, the crew cover photo, artist recordings or press photos. A direct chat is only visible to its participants. Crew content is only visible to crew members. The crew cover appears on the invite link. Artist profile media is public. We do not sell this content, use it for advertising, or send it to third-party social networks
3. Purpose and Legal Basis for Processing
Account and service management
Legal basis: performance of a contract (Art. 6(1)(b) GDPR). Necessary for you to use the platform.
Newsletter and event-related communications
Legal basis: consent (Art. 6(1)(a) GDPR). Only applies if you expressly select the corresponding option. You may withdraw your consent at any time.
Web analytics
Legal basis: consent (Art. 6(1)(a) GDPR). Only applies if you accept analytics cookies. We use Google Analytics with anonymized IP addresses.
Legal compliance
Legal basis: legal obligation (Art. 6(1)(c) GDPR). To respond to requests from competent authorities.
Push notifications in the mobile app
Legal basis: consent (GDPR art. 6.1.a). Only if you accept the notification permission the app requests. You can revoke it from your Android settings at any time.
Approximate location
Legal basis: consent (GDPR art. 6.1.a). Only requested when you tap the detect-location button. Coordinates are not stored on your profile: they are used during that request and in a temporary cache, rounded to ~1 km.
Ticket sales and payment processing
Legal basis: performance of a contract (Art. 6(1)(b) GDPR), both with you as the buyer and with the promoter selling the ticket. Payments are processed by Stripe; Makineo charges a management fee shown separately from the ticket price.
Verification of the promoter's payout account
Legal basis: legal obligation (Art. 6(1)(c) GDPR), under anti-money-laundering regulations applicable to payment service providers. Verification is carried out by Stripe as the authorized entity; Makineo does not take part in that process or access the identity documentation.
Messaging and content you share
Legal basis: performance of a contract (Art. 6(1)(b) GDPR). Processed only if you use chat, a crew, or publish media on your profile. You choose what you upload and who can see it; it is not shared outside that circle.
4. Minors
Makineo is intended for individuals over the age of 16. We do not knowingly collect data from minors under that age. If you become aware that a minor has provided data without parental consent, please contact us so that we can proceed to delete it.
5. Data Retention
- — Account data is retained for as long as the account remains active
- — When you delete your account, your data is erased within a maximum of 30 calendar days
- — Newsletter data is deleted when you unsubscribe
- — Analytics data is retained according to Google Analytics' configuration (maximum 14 months)
- — The push token is deleted when you log out, uninstall the app, or when Google invalidates it
- — Orders, payments, and issued tickets are retained even if you delete your account, for the period required under Spanish commercial and tax law (Art. 30 of the Commercial Code: 6 years from the last entry); your profile is anonymized within the period indicated above
- — Photos and videos in chats and crews are kept for as long as the chat or crew exists, or until you delete the message or your account (max. 30 days). If you leave a crew, what you already shared may remain visible to the remaining members
How to request deletion of your Makineo account
- Open the app or makineo.es, go to your profile → Settings → Account, tap "Delete account" and confirm with your password.
- If you can't access your account, email us at [email protected] with the email or username associated with it and request deletion.
Once confirmed, your account is deactivated immediately and the data is permanently deleted within a maximum of 30 calendar days (see what is kept and for how long in the point above).
6. Disclosure of Data to Third Parties
We do not transfer your personal data to third parties for commercial purposes. The only parties with access to data are:
- — Infrastructure providers (servers, database) acting as data processors under contract
- — Google Analytics for web analytics, with anonymized IP addresses and only where you have given consent
- — Competent authorities where required by law
- — Firebase Cloud Messaging (Google) as a data processor, solely to deliver push notifications to your device
- — Stripe (Stripe Payments Europe, Ltd. and its group companies), as a data processor for processing ticket payments and promoters' payout accounts. For verifying promoters' identity (KYC), Stripe acts as an independent controller under its own privacy policy: stripe.com/es/privacy
- — Komoot (Photon service) as a data processor, to resolve a location into a city name when you tap "detect my location" or search for a place. Only the coordinates or the search text are sent, never linked to your account
7. Your Rights
Under the GDPR and the LOPDGDD (Organic Law 3/2018), you have the right to:
- — Access: find out what data we hold about you
- — Rectification: correct inaccurate data
- — Erasure: request the deletion of your data
- — Portability: receive your data in a structured format
- — Objection and restriction: object to certain processing activities or request that they be restricted
- — Withdrawal of consent: at any time, without affecting the lawfulness of processing carried out prior to withdrawal
To exercise any of these rights, write to us at [email protected]. You may also file a complaint with the Spanish Data Protection Agency (AEPD).
7. Consent Records (GDPR Art. 7)
We record explicit consents in the user_consents table to comply with GDPR Art. 7. Each consent record includes:
- — Type of consent (terms, privacy, analytics, marketing)
- — Accepted/rejected
- — Exact date and time of the decision
- — Client IP address (for audit purposes)
- — User-Agent (browser used)
You may withdraw your consent at any time. See Section 7 (Your Rights).
8. Cookies
Makineo uses its own cookies that are strictly necessary for the operation of the session. Google Analytics analytics cookies are only activated with your prior consent (requested when you first access the site). We do not use advertising or profiling cookies.
You can manage your cookie preferences at any time through your browser settings, or by withdrawing your consent in your profile.
9. Security
We apply appropriate technical and organizational measures to protect your data: password encryption with bcrypt, communications over HTTPS, restricted access to personal data, and servers located within the European Union.
Ticket payments are processed through Stripe, a PCI DSS Level 1 certified provider. Makineo never receives or stores your card details.
10. Changes to This Policy
We may update this policy to reflect legal or service changes. We will notify you of any material changes by email or through a notice on the platform. The date of the last update appears at the top of this document.