Privacy Policy
Last updated: July 21, 2026
Introduction
Dionysia ("we", "us", or "our") is operated by Talent Hub ApS, which is the data controller responsible for your personal data. Dionysia is a marketplace connecting artists and musicians with event organizers and venues. This Privacy Policy explains how we collect, use, share, and protect your personal information when you use our website and services. By using Dionysia, you agree to the collection and use of information in accordance with this policy.
Data We Collect
We collect the following categories of information when you create an account, use our platform, or interact with our services:
Account Information
- Full name, display name, and email address
- Password (stored securely using bcrypt hashing)
- Phone number (optional)
- Preferred language and timezone
- Account role (artist, organizer, or both)
Profile Information
- Biography and description
- Profile avatar image
- Social media links (Instagram, Facebook, YouTube, Soundcloud)
- Musical genres and performance details
- Equipment details (sound and lighting)
- Location and allowed countries for performances
- Venue information (for organizers), including address and coordinates
Activity Data
- Bookings, bids, applications, counter-offers, and the structured terms attached to them
- Immutable agreement versions, document fingerprints, rider snapshots, amendments, and agreement lifecycle events
- Legal name, role, account snapshot, express-confirmation state, server-recorded time, locale, session version, pseudonymised network evidence, and user-agent hash recorded for agreement actions
- Availability slots and calendar data
- Chat messages and conversations
- Ratings and reviews
- Notification preferences and email preferences
- Event details and participation history
Technical Data
- Session data (encrypted session cookies)
- Error logs and performance data (via Sentry)
- IP address (for rate limiting and security purposes)
- For agreement evidence, the raw IP address is not stored in the agreement record; it is immediately transformed using a keyed HMAC together with the evidence-key identifier and account ID. The agreement record stores only that pseudonymised value and a SHA-256 hash of the limited user-agent string
- Usage analytics via Google Analytics - collected only with your consent (page views, approximate location, device and browser type, in anonymised and aggregated form)
How We Use Your Data
- To create and manage your account on the platform
- To facilitate connections between artists and event organizers
- To process bookings, bids, and applications
- To create tamper-evident agreement versions, prove which signed-in party took an agreement action, preserve amendments, and provide both parties with an audit history
- To enable real-time messaging between users
- To process subscription payments via Stripe; Dionysia does not process artist performance fees
- To send transactional emails (booking confirmations, agreement notifications, magic links)
- To verify artist identities through social media platforms
- To provide analytics and insights to organizers about their events
- To monitor and improve the security and performance of our platform
- To enforce our terms of service and prevent abuse
Data Sharing & Disclosure
We take your privacy seriously and are committed to transparency about how your data is handled:
- We do not sell, rent, or trade your personal data to any third parties.
- We do not share your Google user data with third parties for their own marketing, advertising, or any unrelated purposes.
- Google user data (name, email, profile picture) obtained through Google Sign-in is used solely for account authentication and creation on our platform.
- YouTube channel data obtained through Google OAuth is used to verify your identity as an artist. If you choose to display YouTube videos on your profile, we fetch your publicly available videos to showcase your work to event organizers. This data is not shared with any third parties beyond what is visible on your public Dionysia profile.
- When you make or accept a proposal, the necessary agreement terms, recorded legal name, account display name, and decision history are shared privately with the other contracting party. They are retained as part of both parties' agreement record and where necessary to establish, exercise, or defend legal claims. Raw network evidence and user-agent hashes are not shown to the counterparty.
- Apart from disclosures to your contracting counterparty and disclosures required by law, we share personal data with the third-party service providers listed below only to the extent necessary to operate our platform.
- We may disclose your personal data if required to do so by law, regulation, or legal process, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
Third-Party Services
We use the following third-party services to operate our platform. Each service has its own privacy policy governing how they handle your data:
Stripe
Payment processing for organizer subscriptions. Stripe handles all payment card data directly - we do not store your card details. We store only your Stripe customer ID and subscription status.
Google OAuth
Optional sign-in method. When you sign in with Google, we request access to your name, email address, and profile picture. This data is used solely to create and authenticate your account on Dionysia. Your Google authentication tokens are stored securely in our database. We do not share your Google account data with any other third parties, and we do not use it for advertising or marketing purposes.
Google Analytics
Consent-based website analytics provided by Google. We load it only after you opt in via our cookie banner, and use it to measure aggregated usage - such as page views and approximate region - so we can improve the platform. Google Analytics 4 does not store IP addresses, Google Signals and ad personalisation are disabled, and we do not use Google Analytics data for advertising or share it for others' marketing. Google's handling of this data is governed by its own privacy policy.
Spotify
Optional sign-in and artist verification. We may access your Spotify profile information and top tracks to verify your artist identity and display your music.
YouTube
Artist verification and optional profile display. With your consent, we request read-only access to your YouTube channel information to verify your identity as an artist by confirming channel ownership. If you choose to enable YouTube video display on your profile, we use the YouTube Data API to fetch your most popular public videos (titles, thumbnails, and links) to showcase your work to organizers. This video data is publicly available on YouTube and is not stored permanently — it is fetched on demand. YouTube channel and video data is not shared with any third parties beyond what you choose to display on your public artist profile on Dionysia.
Sentry
Error tracking and performance monitoring. Sentry collects technical error data, which may include your email address and name, to help us identify and fix issues on the platform. This data is used solely for debugging and platform reliability purposes.
UploadThing
File storage service for profile images. Your uploaded avatar images are stored securely on UploadThing's servers.
OpenStreetMap & CartoDB
Map display services for venue locations. These services may collect anonymized usage data when maps are displayed.
International Data Transfers
Some of our third-party service providers (such as Stripe, Sentry, and UploadThing) are based in the United States. When your data is processed by these services, it may be transferred to and stored in countries outside the European Economic Area (EEA). We ensure that any such transfers are carried out in compliance with applicable data protection laws, including the use of Standard Contractual Clauses (SCCs) or other approved transfer mechanisms.
Cookies
Cookies are small text files stored on your device when you visit a website. Dionysia keeps its own cookies to a minimum: one strictly necessary cookie that keeps you signed in, and - only if you give consent - Google Analytics cookies that help us understand how visitors use the site. Some pages also embed third-party media players (Spotify, SoundCloud, Vimeo) that may set their own cookies when you play them - these are listed in the table below. We do not use cookies for advertising, and we do not sell your data.
Session cookie
NecessaryKeeps you securely signed in and maintains your session. Encrypted, HTTP-only, and uses the SameSite "Lax" attribute. Strictly necessary, so it does not require consent.
Consent preference (dionysia_cookie_consent)
NecessaryRemembers your cookie choice so we do not ask you on every visit.
Google Analytics (_ga, _ga_*)
AnalyticsSet only after you accept. Measures page views and aggregated usage so we can improve the platform. Google Analytics 4 does not store IP addresses, Google Signals is disabled, and the data is never used for advertising.
Embedded media players
FunctionalWhen you play an embedded track or video on an artist's profile or EPK, these providers may set their own cookies or storage. They load only on pages that contain embedded media. YouTube embeds use the privacy-enhanced no-cookie mode.
Google Analytics cookies are loaded only after you click "Accept" in our cookie banner. If you decline, no analytics cookies are set and the Google Analytics script is never loaded. You can withdraw or change your consent at any time using the button below or the "Cookie settings" link in the footer.
Data Security
We take the security of your data seriously and implement the following measures to protect your information:
- Passwords are hashed using bcrypt with a high work factor
- Session data is encrypted using iron-session
- Secure, HTTP-only cookies with SameSite protection
- Rate limiting on authentication endpoints to prevent brute-force attacks
- Content Security Policy (CSP) headers to prevent cross-site scripting
- Stripe webhook signature verification for payment security
- OAuth state validation with time-limited tokens
Your Rights
Under the General Data Protection Regulation (GDPR) and applicable data protection laws, you have the following rights regarding your personal data:
- Right of access - request a copy of the personal data we hold about you
- Right to rectification - request correction of inaccurate personal data
- Right to erasure - request deletion of your personal data
- Right to restrict processing - request that we limit how we use your data
- Right to data portability - request your data in a machine-readable format
- Right to object - object to our processing of your personal data
- Right to withdraw consent - withdraw consent at any time where processing is based on consent
To exercise any of these rights, please contact us using the details provided below. We will respond to your request within 30 days.
Data Retention
We retain your personal data for as long as your account is active or as needed to provide the services. If you delete your account, we remove or anonymise personal data within 30 days except where retention is necessary for legal, tax, regulatory, fraud-prevention, security, or legal-claims purposes. Immutable booking-agreement documents and their acceptance or amendment evidence may be retained with the recorded legal name and action evidence where necessary to preserve the record for the other contracting party and to establish, exercise, or defend legal claims. Imported legacy records are retained as explicitly partial records and do not contain invented acceptance evidence. Other chat, booking, and transaction data may be retained in anonymised form for analytics and dispute resolution.
Account Deletion & Data Erasure
You have the right to delete your account at any time through your profile page. When you request account deletion:
- Your personal information (name, email, phone number, bio, profile photo) is permanently anonymized
- Your artist or company profile details (location, business registration) are removed
- Pending bids and applications are automatically rejected
- Future unperformed event bookings are released
- Your OAuth connections and social verifications are permanently deleted
- Historical records (past bookings, performances, ratings, and reviews) are retained in anonymized form as "Deleted User" to maintain platform data integrity
- Immutable agreement records may retain the legal name, agreed document, and integrity-protected action evidence where required for the counterparty's record or legal claims; they are not presented as current public profile data
- Non-personal data such as music genres, equipment preferences, and performance statistics are retained for historical context
To delete your account, navigate to your Profile page and scroll to the Danger Zone section at the bottom. You will be asked to confirm by entering your email address. If you have an active subscription, you must cancel it before deletion. If you have upcoming confirmed performances, they must be completed or cancelled first.
Account deletion is immediate and permanent. Once deleted, your account cannot be recovered. If you need assistance, please contact us at privacy@dionysia.live.
Children's Privacy
Dionysia is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If you are a parent or guardian and believe that your child has provided us with personal information, please contact us and we will take steps to remove that information.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. We will notify registered users of significant changes via email or through a notice on our platform. We encourage you to review this policy periodically. Your continued use of Dionysia after any changes constitutes acceptance of the updated policy.
Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at privacy@dionysia.live.