Privacy Policy

1. Data protection at a glance

General notes

The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data is all data with which you can be personally identified.

2. Controller for data collection

Data processing on this website is carried out by the website operator. Their contact details are:

Alexander - Ingo Webernig
Annablick 3
9061 Reifnitz am Wörthersee
Österreich

Email: apps@weappu.com
Phone: +43 660 / 767 4 833

3. Data collection, user roles & platform features

Registration & user roles

You can register on our platform with a specific role (Artist/Band, Venue/Location, Booker/Promoter, Technician/Crew, Caterer, Press, or Fan). The basic registration data (email address, username, password) is processed to provide your account. A verification token is emailed for address verification.

Password reset procedure

When using the "Forgot Password" function, we temporarily store a cryptographic security token and an expiration timestamp (1 hour) in the database to send you a secure reset link via email. Once reset or expired, the token is cleared.

Role-specific profiles, media & uploads

Depending on your selected role, we collect and publish data that you voluntarily provide in your profile:

Upon account deletion, all profile data and uploaded files (images, PDFs) are permanently purged from our servers.

Fan Geo Radar, Location Fuzzing & Visibility

Fans and listeners can set their location (city, state, country) to find concerts nearby and appear on the Fan Radar map. To protect your privacy, our system employs **location fuzzing**: geocoordinates are slightly randomized and shifted by several hundred meters on the map so that your exact private address remains completely hidden.

Furthermore, you have full control in your profile settings: Using the **"Location & Radar Visibility"** toggle, you can hide your location completely with a single click at any time.

Internal messaging & message archiving

The internal messaging system enables direct networking between members. To ensure performance and data minimization, received messages are automatically archived into a secured backup table after 30 days and hidden from the active inbox.

Browser Web Push Notifications

If you grant explicit browser permission, we utilize the standardized Web Push API (VAPID) to send notifications about new direct messages or gig applications directly to your device. A cryptographic key pair and endpoint token are stored in our database for this purpose. You can revoke this permission at any time in your browser settings.

Gig board & matching system

Promoters and bookers can post live slots. Artists can apply for open gigs. During application, the artist's profile data (EPK, audio links, rider, region) is shared with the host. A matching algorithm compares genre and regional data to determine compatibility.

Event & concert calendar

Artists, venues, and bookers can publish public dates, concerts, and gigs. Published information includes date, time, venue, genre, description, flyer images, and external ticket presale links.

Notice board

Classified ads are stored including text, category, images, and expiry date. Our system automatically deletes expired ads along with attached images.

Public RSS 2.0 Feed

Our platform provides a public RSS feed via rss.php. It exclusively contains content explicitly published for the public (such as new artist profiles, upcoming events, and classified ads) including links and preview images.

Reviews & follow feature

When submitting reviews, we store the star rating, comment, username, and timestamp publicly. Your followed artists are stored to generate your personalized feed.

4. Hosting, server logs & email spooler

External hosting

This platform is hosted on servers of helloly GmbH (Austria). We have concluded a Data Processing Agreement (DPA) pursuant to Art. 28 GDPR.

Server log files

The provider automatically collects server log files: browser type/version, OS, referrer URL, hostname/IP address, and request time. Legal basis is Art. 6 (1) (f) GDPR for system stability and security.

Email queue & transactional emails via SMTP

System and notification emails (account activation, password resets, message alerts, gig applications) are processed asynchronously via an internal email queue and dispatched securely over TLS/SSL SMTP connections. Once sent, queue entries are purged.

5. External services, maps & media embeds

Interactive radar map (OpenStreetMap & Nominatim)

We integrate interactive map tiles from OpenStreetMap (OSM) via the OpenStreetMap Foundation. The map is blocked by default via a 2-click consent. Only upon clicking "Load Map", your IP address is sent to OpenStreetMap servers.

For exact placement of profiles, the map uses the Nominatim geocoding service. Coordinates are cached locally in your browser (localStorage) to minimize server load.

Two-click solution for Spotify & YouTube embeds

Audio and video players from Spotify and YouTube (Google LLC) are loaded only after clicking "OKAY". Only then is a connection established to third-party servers.

6. Cookies, LocalStorage & Progressive Web App

Essential session cookies

We exclusively use strictly necessary cookies (e.g. PHP session cookies for authentication and login status, and language preference). No third-party tracking or advertising profiling takes place.

Local storage

We store your consent for loading the interactive map (myeventspace_map_gdpr) and cached geocoordinates in your browser's LocalStorage to reduce network traffic.

Progressive Web App (PWA) & Service Worker

Our platform uses a Service Worker (sw.js) to cache static UI assets (CSS, icons) locally on your device for standalone homescreen app usage.

7. Your rights as a data subject

Under the GDPR, you have the right to:

You can edit or delete your profile data at any time in your dashboard. For any further privacy requests, please contact us directly.

Right to lodge a complaint with a supervisory authority

If you believe that the processing of your data violates data protection law, you have the right to complain to the supervisory authority. In Austria, this is:

Österreichische Datenschutzbehörde (DSB)
Barichgasse 40-42, 1030 Wien, Österreich
Website: www.dsb.gv.at

To use the radio, we load music via YouTube. Please agree to the cookies.
Radio ready
Waiting to start...
Community Chat

Chat locked

Please log in to read and chat.

Login / Register