DS DistroShield

Legal

Privacy Policy

Effective date: 2026-04-27 · Last updated: 2026-04-27

This Privacy Policy explains how DistroShield ("we", "us", "our") collects, uses, and protects information when you use our API and customer portal (the "Service").

1. What we collect

CategoryExamplesSource
Account infoName, work email, company name, volume estimateSignup form / Google OAuth
AuthenticationAPI key (stored hashed), session cookie tokensGenerated by us
Customer ContentAudio files (via URL you provide), track metadata (title, artist, ISRC)Submitted by you to /v1/analyze
Analysis resultsAI scores, classifications, duplicate matches, metadata issuesGenerated by us
Usage logsAPI request timestamps, endpoints, status codes, IP addressesAuto-collected for billing & abuse prevention
Billing infoStripe customer ID, subscription stateStripe (we do not store card numbers)

2. How we use it

3. How we share it

We do not sell your data. We share it only with:

4. Subprocessors

ProcessorPurposeRegion
ContaboServer hostingUSA / Germany
StripePayment processing & billingUSA
ResendTransactional email deliveryUSA
CloudflareDNS, email routingUSA / Global
Google (OAuth)Sign-inUSA
Spotify, Deezer, YouTubeDuplicate detection (Module 2) — we send title/artist/ISRC to query their public APIsUSA / Global

5. Data retention

6. Security

7. Your rights

Depending on your jurisdiction, you may have the right to:

To exercise any of these rights, email contact@distroshield.com. We respond within 30 days.

8. International transfers

The Service is operated from the USA. If you access from outside the USA, your data is transferred to and processed in the USA under standard contractual clauses where applicable.

9. Children

The Service is for B2B use and is not directed at individuals under 16. We do not knowingly collect data from minors.

10. Changes to this Policy

We'll notify registered users of material changes by email at least 30 days before they take effect.

11. Contact

Privacy questions: contact@distroshield.com