Legal

Privacy Policy

Last updated: 3 August 2026

Placeholder version. This document is a placeholder legal draft based on how AMDS actually operates. The trading name, registered address and data-protection contact will be filled in before formal launch. The Trust summary at Privacy & Security explains the same content in plain English.

1. Who we are

AMDS ("All Musicians Diary Service") is operated by [[YOUR BUSINESS NAME]], registered at [[YOUR REGISTERED ADDRESS]]. For any privacy-related enquiry, contact [[privacy@amdsdiary.org]].

2. What we collect

When you use AMDS we collect only the data required to run the service:

  • Account: name, email, role (musician / booker / conductor / admin), password (hashed with bcrypt, never stored in plain text).
  • Profile: instrument(s), voice type, location, travel-radius preference, playing standard, ensemble experience, short bio, optional photo.
  • Diary: events you create manually, events created from confirmed bookings, and events you optionally import from a .ics file.
  • Interactions: bookings, dep responses, messages between users of the platform.
  • Operational: IP address, browser user-agent, timestamps on key actions (login, verify, password reset) — used for auditing and abuse prevention only.

3. How we use it

Data is used exclusively to operate AMDS features: finding musicians and deps, checking availability, sending booking / dep notifications, and running the diary. We do not sell your data. We do not use it to train external AI models.

4. Diary privacy

The contents of your diary — event titles, venues, notes, exact start/end times — are visible only to you when signed in. When a booker searches, they see only whether you are available, tentative or unavailable for the requested time band. Event details are never shared.

5. Third parties

  • Resend — transactional email delivery (verification, password reset, booking notifications, feedback receipts).
  • Stripe — payment processing if you upgrade to a paid tier. AMDS never sees your full card number.
  • MongoDB Atlas — cloud database hosting.

Each processor is bound by its own privacy policy and by a data-processing agreement with AMDS.

6. Your rights (UK GDPR)

You have the right to access, correct, export and erase your data. You can update your profile at any time from the Profile page, delete your account from Profile → Settings, or write to [[privacy@amdsdiary.org]] for anything more complex. AMDS responds to data-subject requests within one calendar month.

7. Retention

Account data is retained for as long as your account is active, plus 30 days after deletion to allow for accidental-deletion recovery. Audit logs of login / verification / password events are retained for 12 months for security purposes.

8. Cookies

AMDS uses a small number of first-party cookies that are strictly necessary to keep you signed in (JWT access token + refresh token). We do not use analytics cookies, advertising cookies, or third-party tracking.

9. Governing law

This policy is governed by the laws of [[England & Wales]]. Complaints may also be lodged with the UK Information Commissioner's Office (ICO).

Back to AMDS